09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

!<br />

access-list 601 permit nbp 1 object CO server<br />

access-list 601 permit nbp 1 type AFPServer<br />

access-list 601 permit nbp 1 zone co-zone<br />

access-list 601 permit nbp 2 object Finance Server<br />

access-list 601 permit nbp 2 type AFPServer<br />

access-list 601 permit nbp 2 zone co-zone<br />

access-list 601 permit nbp 3 object p-press<br />

access-list 601 permit nbp 3 type LaserWriter<br />

access-list 601 permit nbp 3 zone co-zone<br />

access-list 601 permit o<strong>the</strong>r-access<br />

access-list 601 deny o<strong>the</strong>r-nbps<br />

!<br />

access-list 608 permit zone co-zone<br />

access-list 608 permit zone outland<br />

access-list 608 deny additional-zones<br />

The ACL applied as <strong>the</strong> permits <strong>the</strong> servers<br />

"co-server" and "Finance Server" and <strong>the</strong> printer <strong>to</strong> be accessible from <strong>the</strong> "outland"<br />

<strong>network</strong>. To suppress <strong>the</strong> zone announcements <strong>to</strong> <strong>the</strong> router and o<strong>the</strong>r workstations,<br />

ACL 608 was applied as <strong>the</strong> and <strong>the</strong><br />

. The numbers used with <strong>the</strong> <br />

action statement are sequence numbers that tie <strong>the</strong> object:name@zone elements<br />

<strong>to</strong>ge<strong>the</strong>r in <strong>the</strong> list.<br />

IPX Access-Lists<br />

The virtues of IPX filtering cannot be underestimated. With <strong>the</strong> IPX pro<strong>to</strong>cols, <strong>the</strong><br />

filtering of <strong>the</strong> pro<strong>to</strong>col's chattiness on some <strong>network</strong>s becomes a necessity, not an<br />

option. IPX, like IP, has two types of lists: standard and extended (IOS also supports<br />

named IPX lists). Standard lists are created using <strong>the</strong> global configuration command<br />

. The source<br />

and destination address match values can be ei<strong>the</strong>r <strong>the</strong> IPX 32-bit <strong>network</strong> address<br />

or 96-bit <strong>network</strong> and node address. Here is an example standard IPX ACL that<br />

allows any packet <strong>to</strong> reach <strong>network</strong> 45:<br />

asbr-a2(config)#access-list 810 permit -1 45<br />

NOTE

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!