Few days back I asked a question to a very confident CCNA Security guy...actually he just came to me before taking CCNA Security exam and asked me...hey,why don't you ask me something related to Security as I am feeling pretty confident that I know lots of security stuff now.
Hmmm...I said Okey and just asked him the following question :-)
How many ACLs and Firewall features we have in IOS related to Router Security ?
He said... Standard ACL, Extended ACL, Named ACL, Reflexive ACL, CBAC & Zone Based Firewall.
Hmmm...his list looks interesting but still not complete...maybe it was not a true CCNA Security Question as I never take a look at it's curriculum...Anyways...Following is my list and see if I missed something...Feel free to drop an email to me if you have something to add in this list.
1. Standard ACL
2. Extended ACL
3. Named ACL
4. TCP Established ACL / Reflexive ACL
5. Turbo ACL
6. CBAC
7. Zone Based Firewall
8. Time Based ACL
9. Dynamic ACL / Lock & Key ACL
10. Flexibal Packet Matching ACL
11. ACL to to prevent fragmented IP packets from reaching you application ports
Holy Cow...Did you ever think about that :-(
I must say even I still need to dig myself about which one takes precedence over other when multiple types are configured together
Some more ACL stuff in coming days along with solution of my last ACL Post...
Happy Studying...
Best Regards,
Deepak Arora
CCIE# XXXXX...Oops that number is still missing :-)
An Engineer by Heart !!! A Dreamer, A Pioneer, A Blogger. A Network Engineer Trying to overtake the world with his network engineering skills :) Opinions expressed here are solely my own and do not express the views or opinions of my Present or Past employer.
Tuesday, September 29, 2009
Friday, September 25, 2009
Filtering ALL Even Subnets With Single ACL
These days I am quite busy with my job schedule which is keeping me away from studies & blog.
Anyways... today lets play around some ACLs. I know many people who think that they know ACL stuff very well. But actually that's not the case. Specially if they were been given task like I show up in Diagram here. The challenge here is following:
R2 has got plenty of networks to advertise using EIGRP to R1. Administrator f R1 wants that only Odd Network Subnets like 192.168.1.0/24...3.0/24 etc of R2 should be able to reach LAN segment of R1 and all Even subnets should not be able to do that. And for that you are only allowed to use single ACL entry....but also don't use Group Objects ( If you know really what they are :-) )
So good luck to all of you * R1 Admins :-) * I will post the solution and some more ACL details soon.
Happy Studying...
Regards,
Deepak Arora
Anyways... today lets play around some ACLs. I know many people who think that they know ACL stuff very well. But actually that's not the case. Specially if they were been given task like I show up in Diagram here. The challenge here is following:
R2 has got plenty of networks to advertise using EIGRP to R1. Administrator f R1 wants that only Odd Network Subnets like 192.168.1.0/24...3.0/24 etc of R2 should be able to reach LAN segment of R1 and all Even subnets should not be able to do that. And for that you are only allowed to use single ACL entry....but also don't use Group Objects ( If you know really what they are :-) )
So good luck to all of you * R1 Admins :-) * I will post the solution and some more ACL details soon.
Happy Studying...
Regards,
Deepak Arora
Some More gr8 Video Tutorials By INE
http://classroom.internetworkexpert.com/ccna1_1/
http://classroom.internetworkexpert.com/p74646894/
http://classroom.internetworkexpert.com/p30707699/
http://classroom.internetworkexpert.com/vtunk/
http://classroom.internetworkexpert.com/p35024723/
Thanks!
Deepak Arora
http://classroom.internetworkexpert.com/p74646894/
http://classroom.internetworkexpert.com/p30707699/
http://classroom.internetworkexpert.com/vtunk/
http://classroom.internetworkexpert.com/p35024723/
Thanks!
Deepak Arora
Wednesday, September 23, 2009
Subscribe to:
Posts (Atom)