Title: Extended ACL
1Extended ACL
2Extended ACL
- Definition
- Configuration
- Interface Application
3Definition
- Filtering Tool SRC and DST Protocol s
- Multi Line Text File (One Command Issued Many
times) - Range (100-199 extended 2000 2699)
- First Hit Filtering
- Applications
- Interface Ports i.e. EO, SO
- Line VTY Telnet
- CON
Direct - AUX
Modem - Implied Deny All
- Interesting Traffic Crypto Maps
-
Route Maps -
SO
EO
4Configuration
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
Range 100-199 2000-2699
Protocol OSPF EIGRP ICMP TCP UDP
IP
5Configuration
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
192.168.5.0 0.0.0.255
192.168.5.254 0.0.0.0
Host 192.168.5.254
0.0.0.0 255.255.255.255
ANY
6Configuration
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
IP/EIGRP/OSPF LOG PRECEDENCE TOS
CONSOLE
NORMAL
DELAY
TYPE OF SERVICE
THROUGHPUT
7TCP-IP CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
8TCP-IP CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
53
DNS PORT
9CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
10CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
23
Use Ports
TELNET
A
B
23
11CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
20/21
Use Ports
FTP
A
B
20/21
12CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
TFTP
69
13CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
POPULAR PORT 1-1024
14CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
PING
A
B
15CONFIGURATION
Access-List ACL Permit Deny
1. Protocol 2. SRC IP SRC Wildcard Host
SRC IP ANY 3. DST IP DST Wildcard Host
SRC IP ANY 4. Operator Port Port
16Standard IP
- Definition
- Configuration
- Interface Application
17DESIGN
18DESIGN
BEST PLACE FOR ACL
19DESIGN
EXTENDED ACL
BOTH SRC AND DST
20DESIGN
21DESIGN
22ROUTER - ACL
23ROUTER CONFIG CONT
24ROUTER
25ROUTER
26DESIGN
254
FIREWALL
.252
27PING FROM 192.168.5.254
28WORKS
29To Block Other
30(No Transcript)
31Unreachable
32Extended ACL
- Definition
- Configuration
- Interface Application