Cisco Systems CCNA 2 Guia do Utilizador Página 121

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 120
120 - 238 CCNA 2: Routers and Routing Basics v3.1 Instructor Guide – Module 11 Copyright © 2004, Cisco Systems, Inc.
11.1.1 Introduction to ACLs
ACLs are lists of conditions that are applied to traffic that travels across a router interface.
These lists tell the router what types of packets to accept or deny. ACLs can be created for all
routed network protocols. ACLs filter network traffic and determine if routed packets are
forwarded or blocked at the router interfaces. The ACL parameters that can be defined include
source and destination addresses, protocols, and upper-layer port numbers. ACLs are created
on a per-protocol, per-direction, and per-port basis. ACLs control traffic in one direction on an
interface. Therefore, for every protocol, it is possible that two ACLs could be created, an
inbound and an outbound. The following are some of the primary reasons to create ACLs:
Limit network traffic and increase network performance
Provide traffic flow control
Provide a basic level of security for network access
Decide which types of traffic are forwarded or blocked at the router interfaces
Allow an administrator to control what areas a client can access on a network
Screen certain hosts to either allow or deny access to part of a network
Grant or deny user permission to access only certain types of files such as FTP or
HTTP
The labs in CCNA 2 have allowed all traffic with no filtering. The students must understand the
path, or know the source and destination address of the packets to apply the concept of an
ACL. Review the OSI model and the protocols at each layer with the students. The reasons for
ACLs and the methods that ACLs use to accomplish these functions may not be apparent to
the students. ACLs may require some time to grasp. Do not rush through these sections. Give
the students enough time to absorb this information. Encourage the students to use the labs to
reinforce this knowledge. Encourage the students to experiment with various ACL scenarios.
11.1.2 How ACLs work
An ACL is a group of statements to permit or deny traffic on an inbound or outbound router
interface. The order in which ACL statements are placed is important. The Cisco OS software
tests the packet against each condition statement in order from the top of the list to the bottom.
When a match is found in the list, an accept or reject action is performed and no other ACL
statements are checked.
If additional condition statements are needed in an access list, the entire ACL must be deleted
and recreated with the new condition statements. To simplify the process of revising an ACL it
is a good idea to use a text editor such as Notepad and paste the ACL into the router
configuration.
As a frame enters an interface, the router checks to see if the Layer 2 address matches or if it
is a broadcast frame. If the frame address is accepted, the frame information is stripped off
and the router checks for an ACL on the inbound interface.
As a review, ACL statements operate in sequential, logical order. If a condition match is true,
the packet is permitted or denied and the rest of the ACL statements are not checked.
Vista de página 120
1 2 ... 116 117 118 119 120 121 122 123 124 125 126 ... 238 239

Comentários a estes Manuais

Sem comentários

ASROCK SBC-210 manuals

Owner’s manuals and user’s guides for Motherboards ASROCK SBC-210.
We providing 1 pdf manuals ASROCK SBC-210 for download free by document types: User Manual






More products and manuals for Motherboards ASROCK

Models Document Type
A780LM User Manual   Asrock A780LM, 58 pages
Z68 PRO3-M User Manual   Asrock Z68 Pro3-M, 64 pages
Fatal1ty Z77 Professional-M series User Manual   ASROCK Fatal1ty Z77 Professional-M series User manual, 92 pages
Fatal1ty Z77 Professional-M series User Manual   Z77 Professional-M-en-01, 3 pages
Q2900M User Manual   Asrock Q2900M motherboard (Q2900M), 4 pages
A785GM-LE - V1.0 User Manual   price & specifications are subject to change without, 1 pages
X58 Extreme3 User Manual   X58 Extreme3 - Ingram Micro, 7 pages
4CORE1600-GLAN - V1.0 User Manual   OFERTA COMPONENTE SI PERIFERICE, 4 pages
H67M-GE User Manual   H67M-GE - Prodimex, 7 pages
Z97M Anniversary User Manual     1 - CD-rom land, 138 pages
4COREDX90-VSTA - V1.0 User Manual   ASROCK 4COREDX90-VSTA - V1.0 User`s manual, 107 pages
FM2A75M-HD User Manual   FM2A75M-ITX, 3 pages
H55ICAFE User Manual   H55iCafe, 6 pages
H61M-HVGS Installation Guide   ASROCK H61M-HVGS Installation guide, 29 pages
H61DEL User Manual    H61DEL - ASRock, 7 pages
Z87M Extreme4 User Manual   Z87M Extreme4 - Ingram Micro GmbH [en] , 3 pages
FM2A88M-HD User Manual   Asrock FM2A88M-HD+ (FM2A88MHD+), 4 pages
4CoreDual-VSTA User Manual   ASROCK 4CoreDual-VSTA User manual, 67 pages
P43C-ME - V1.0 Specifications   ASROCK P43C-ME - V1.0 Specifications, 87 pages
G41M-VGS3 User Manual   Página 1 de 2 ASRock > G41M-VS3 31/ 01/ 2013 http://www.asrock, 5 pages