01-16-2007 02:12 AM - edited 03-05-2019 01:47 PM
Hi all, for the ccna exam, if it asks me about applying access lists, where are they best applied, closest to source or dest ?
01-16-2007 02:18 AM
- place extended access list close to the source
- place standard access list close to the destination
M.
01-16-2007 02:28 AM
thanks for that, is there a reason for it ?
01-16-2007 03:34 AM
Coz standard access lists can only filter based on source IP. If you place it close to source, all traffic will be blocked.Thats why you place it close to destination.
Extended access list can do fine filtering based on ports and protocols.So you place it close to source so you can filter the traffic before it takes up your precious bandwidth!!
Hope this helps.
01-26-2007 10:21 PM
Hi
the router you are working is source and destination 2 ( inbound and outbound)
So when you want to restrict you inbound traffic to outbound you implement access list in inbound
and when you want to restrict your outbound traffic to enter into your domain then you implement access list in your outbound interface......
Hope this may helps you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide