Home > Access list Questions

Access list Questions

March 23rd, 2017 in ICND2 200-105 Go to comments

Question 1

Explanation

The syntax of a named ACL is:

ip access-list {standard | extended} {name | number}

Therefore we can configure a standard acl with keyword “standard” and configure an extended acl with keyword “extended”. For example this is how to configure an named extended access-list:

Router(config)#ip access-list extended in_to_out permit tcp host 10.0.0.1 host 187.100.1.6 eq telnet

Question 2

Explanation

Below is the range of standard and extended access list:

Access list type Range
Standard 1-99, 1300-1999
Extended 100-199, 2000-2699

In most cases we only need to remember 1-99 is dedicated for standard access lists while 100 to 199 is dedicated for extended access lists.

Question 3

Explanation

The syntax of an extended acl is:

access-list access-list-number {permit | deny} protocol source-IP {source-mask} destination-IP {destination-mask} [eq destination-port]

-> We can define protocol, source & destination IP addresses, destination port number.

For example, we will create an extended ACL that will permit FTP traffic (port 20, 21) from network 10.0.0.0/8 to reach 187.100.1.6 but deny other traffic to go through:

Router(config)#access-list 101 permit tcp 10.0.0.0 0.255.255.255 187.100.1.6 0.0.0.0 eq 21
Router(config)#access-list 101 permit tcp 10.0.0.0 0.255.255.255 187.100.1.6 0.0.0.0 eq 20

Question 4

Explanation

We can have only 1 access list per protocol, per direction and per interface. It means:

+ We can not have 2 inbound access lists on an interface
+ We can have 1 inbound and 1 outbound access list on an interface

Question 5

Question 6

Comments (9) Comments
  1. Anonymous
    March 23rd, 2017

    Just explain where are the questions ?

  2. guru
    March 24th, 2017

    Where are the questions amigo?

  3. Tim
    March 27th, 2017

    Passed today!
    Practice the labs in packet tracer it helps a lot.
    I used the dumps from here https://www.facebook.com/groups/1922148518071818/ all the questions were from this dumps.
    Good luck!

  4. icnd2 student
    March 29th, 2017
  5. Sparkey Yates
    May 11th, 2017

    Sorry, those are from 2015, icnd2 student. Not going to do us a lot of good.

  6. Nirbad
    May 16th, 2017

    dumps please…no fckn ads

  7. Gary
    May 29th, 2017

    Thanks Tim,
    Those dumps are still good, passed today using them.

  8. Anonymous
    June 14th, 2017

    @i am bhaskar, I have booked my CCNA 200-125 exam on 9 july, plz provide me ccna dumps 200-125 .email me details to (bhaskar.sapkota016 @ gmail dot ca)
    Thanks

  9. Jonas
    June 24th, 2017

    where are the questions