01-16-2007 02:12 AM - edited 03-05-2019 01:47 PM
Hi all, for the ccna exam, if it asks me about applying access lists, where are they best applied, closest to source or dest ?
01-16-2007 02:18 AM
- place extended access list close to the source
- place standard access list close to the destination
M.
01-16-2007 02:28 AM
thanks for that, is there a reason for it ?
01-16-2007 03:34 AM
Coz standard access lists can only filter based on source IP. If you place it close to source, all traffic will be blocked.Thats why you place it close to destination.
Extended access list can do fine filtering based on ports and protocols.So you place it close to source so you can filter the traffic before it takes up your precious bandwidth!!
Hope this helps.
01-26-2007 10:21 PM
Hi
the router you are working is source and destination 2 ( inbound and outbound)
So when you want to restrict you inbound traffic to outbound you implement access list in inbound
and when you want to restrict your outbound traffic to enter into your domain then you implement access list in your outbound interface......
Hope this may helps you
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: