09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Nlsp Match on NetWare Link State Pro<strong>to</strong>col<br />

Nping Match on standard IPX ping<br />

Rip Match on IPX RIP<br />

Sap Match on SAP<br />

Trace Match on traceroute<br />

Now, let's create an extended ACL that filters inbound SAP and RIP announcements:<br />

asbr-a2(config)#access-list 902 deny sap any sap any sap<br />

asbr-a2(config)#access-list 902 deny rip any rip any rip<br />

asbr-a2(config)#access-list 902 permit any any all any all<br />

asbr-a2(config)#interface s0<br />

asbr-a2(config-if)#ipx access-group 902<br />

Remember, when you apply access-filters, inbound filters match packets coming<br />

in<strong>to</strong> <strong>the</strong> interface and discard packets that fail. Outbound filters process <strong>the</strong> packet,<br />

and <strong>the</strong>n a match is performed. In addition <strong>to</strong> standard and extended IPX<br />

access-lists, <strong>the</strong> IOS supports several additional IPX traffic filtering options. Refer <strong>to</strong><br />

<strong>the</strong> IOS documentation for fur<strong>the</strong>r details.<br />

Displaying ACL Information<br />

To display ACLs and ACL logging information, use <strong>the</strong> user EXEC command . If no ACL pro<strong>to</strong>col (such as AppleTalk,<br />

IPX, IP, and so on) type or number is specified, all <strong>the</strong> lists will be displayed. If you<br />

plan <strong>to</strong> use ACLs for security purposes, it is also a good idea <strong>to</strong> enable accounting on<br />

<strong>the</strong> interfaces that are using ACL security filters. Accounting is available for IP and<br />

IPX.<br />

IP accounting is enabled as an interface configuration subcommand . To enable ACL violations, use <strong>the</strong> variation of <strong>the</strong> command. IP accounting information is<br />

displayed with <strong>the</strong> user EXEC commands and .<br />

IPX accounting is enabled using <strong>the</strong> interface configuration subcommand . To display IP accounting information, use .

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!