Home > Access list Questions

Access list Questions

March 23rd, 2017 in ICND2 200-105 Go to comments

Question 1

Explanation

The syntax of a named ACL is:

ip access-list {standard | extended} {name | number}

Therefore we can configure a standard acl with keyword “standard” and configure an extended acl with keyword “extended”. For example this is how to configure an named extended access-list:

Router(config)#ip access-list extended in_to_out permit tcp host 10.0.0.1 host 187.100.1.6 eq telnet

Question 2

Explanation

Below is the range of standard and extended access list:

Access list type Range
Standard 1-99, 1300-1999
Extended 100-199, 2000-2699

In most cases we only need to remember 1-99 is dedicated for standard access lists while 100 to 199 is dedicated for extended access lists.

Question 3

Explanation

The syntax of an extended acl is:

access-list access-list-number {permit | deny} protocol source-IP {source-mask} destination-IP {destination-mask} [eq destination-port]

-> We can define protocol, source & destination IP addresses, destination port number.

For example, we will create an extended ACL that will permit FTP traffic (port 20, 21) from network 10.0.0.0/8 to reach 187.100.1.6 but deny other traffic to go through:

Router(config)#access-list 101 permit tcp 10.0.0.0 0.255.255.255 187.100.1.6 0.0.0.0 eq 21
Router(config)#access-list 101 permit tcp 10.0.0.0 0.255.255.255 187.100.1.6 0.0.0.0 eq 20

Question 4

Explanation

We can have only 1 access list per protocol, per direction and per interface. It means:

+ We can not have 2 inbound access lists on an interface
+ We can have 1 inbound and 1 outbound access list on an interface

Question 5

Question 6

Comments (4) Comments
  1. Anonymous
    March 23rd, 2017

    Just explain where are the questions ?

  2. guru
    March 24th, 2017

    Where are the questions amigo?

  3. Tim
    March 27th, 2017

    Passed today!
    Practice the labs in packet tracer it helps a lot.
    I used the dumps from here https://www.facebook.com/groups/1922148518071818/ all the questions were from this dumps.
    Good luck!

  4. icnd2 student
    March 29th, 2017