【正文】
dcard 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE I Chapter 6 14 Using a Wildcard Mask Introducing Routing and Switching in the Enterprise – Chapter 8 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 12 ACL Processing ? ACLs consist of statements ? At least one statement must be a permit statement ? Final statement is an implicit deny ? ACL must be applied to an interface in order to work 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 10 Types and Usage of ACLs Extended ACLs ? Extended ACLs filter not only on the source IP address but also on the destination IP address, protocol, and port numbers. ? The range of numbers for Extended ACLs is from 100 to 199 and from 2022 to 2699. 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 8 Access Control Lists Possible issues with ACLs: ? Increased load on router ? Possible work disruption ? Unintended consequences from incorrect placement 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 6 Traffic Filtering Devices providing traffic filtering: ? Firewalls built into integrated routers ? Dedicated security appliances ? Servers 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE I Chapter 6 4 Using Access Control Lists Introducing Routing and Switching in the Enterprise – Chapter 8 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 2 Objectives ? Describe traffic filtering and explain how Access Control Lists (ACLs) can filter traffic at router interfaces. ? Analyze the use of wildcard masks. ? Configure and implement ACLs. ? Create and apply ACLs to control specific types of traffic. ? Log ACL activity and integrate ACL best practices. 169。169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE I Chapter 6 1 Filtering Traffic Using Access Control Lists Introducing Routing and Switching in the Enterprise – Chapter 8 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 3 Context Index ? Using Access Control Lists ? Using a Wildcard Mask ? Configuring Access Control Lists ? Permitting and Denying Specific Types of Traffic ? Filtering Traffic Using Access Control Lists 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 5 Traffic Filtering ? Analyze the contents of a packet ? Allow or block the packet ? Based on source IP, destination IP, MAC address, protocol, application type 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 7 Access Control Lists Uses for ACLs: ? Specify internal hosts for NAT ? Classify traffic for QoS ? Restrict routing updates ? Limit debug outputs ? Control virtual terminal access 169。 2022 Cisco Systems, Inc. All rights reserved. Cisco Public ITE 1 Chapter 6 9 Types and Usage of ACLs Standard ACLs ? The Standard ACL is the simplest of the three types. When creating a standard IP ACL, the ACLs filter based on the source IP address of a packet. Standard ACLs permit or deny based on the entire protocol, such as IP. So, if a host device is denied by a standard ACL, all services from that host are denied. ? For access lists permitting or denying IP traffic, the identification number can