1 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI
ACL CCNA 2 ACLs Prof. Dr. Richard Sethmann Hochschule Bremen Fachbereich Elektrotechnik und Informatik Access Control Lists (ACLs) 2 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Content Access Control List Fundamentals Standard ACLs Extended ACLs Placing ACLs Firewall Architecture 2 3 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL What are ACLs? Packet filter 4 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL What are ACLs? The router examines each packet to determine whether to forward or drop it . 3 5 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL What are ACLs? With two interfaces and three protocols running, this router could have a total of 12 separate ACLs applied. 6 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL How ACLs work? 4 7 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL How ACLs work? CCNA 2 11.1.2 Graph 3 8 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Protocols with ACLs Specified by Numbers 5 9 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL The access-group Command 10 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL 32 bit Address and Wildcard Mask IP Address Wildcard Mask The wild card mask will allow a match to any IP value from 172.16.0.0 to 172.16.255.255. Access-list 1 permit 172.16.0.0 0.0.255.255 6 11 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL The ANY and HOST Options The is the format of the any and host optional keywords in an ACL statement. 12 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Standard ACL Statements 7 13 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Extended ACL Statements 14 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Transport-Application Layer Ports 8 15 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL How ACLs work? CCNA 2 11.2.2 Graph 3 16 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL IP Named ACLs 9 17 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Placing ACLs Standard ACLs: As close as possible to the destination Extended ACLs: As close as possible to the source of the traffic 18 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Firewall Architecture ACLs should be used in firewall routers, which are often positioned between the internal network and an external network, such as the Internet. DMZ: Demilitarized Zone - Web Server - Email Server - FTP Server 10 19 CCNA 2, ACLs, Prof. Dr. Richard Sethmann, HS Bremen, FB E&I, MI ACL Thank you very much for your attention!