04-14-2017 10:53 PM - edited 03-08-2019 10:12 AM
I have been studying for CCNP Route 300-101 exam and have run across a perplexing question with an answer but not an explanation that is nagging me.
The question basically as which ACL is correct in preventing a TCP connection.
There are three, 2 with the established keyword at the end.
The difference between the 2 is one is a standard ACL 49 and the other is an extended ACL 149.
Only extended ACL's are allowed to use the established keyword correct?
ej
04-15-2017 12:16 AM
Hello Eric,
yes, only extended access lists allow the 'established' keyword. The question seems to look for the best way to prevent spoofing, which is what 'established' was initially added for.
So your correct answer is the extended access list with the 'established' keyword.
04-15-2017 07:07 AM
Hello,
The reason is that "established" is for TCP establishment and three-way handshaking.
With standard access-list, you only specify source addresses not TCP.
Masoud
04-20-2017 03:34 PM
Thank you for the information.
I'm scheduling attempt number 2 for next week.
Seems no matter how much I study I feel like it's not enough.
ej
04-20-2017 11:07 PM
Eric,
good luck with the exam.
There is a free router simulator available for download, with real IOS images, for testing and lab setups, not sure if you have heard of it:
https://gns3.com/
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide