From: Donny MATEO (donny.mateo@sg.ca-indosuez.com)
Date: Mon Feb 24 2003 - 04:58:17 GMT-3
I'll take the first one.
Reason, for a network, you might want to devide it into smaller network for newtork routing tweaking purpose or whatever purpose.
Although you can do the second options, if there are breakdown on the subnets that those breakdown route would not be filtered and could mess thing up.
Basically your first solutions is to stop any 192.168.1-9. xxx network while the second one is to stop 192.168.1-9.0, it wont stop 192.168.1-9.128 or 192.168.1-9.64 and so on.
Donny
"Tran Tien Phong"
<PhongTT2@FPT.COM To: <ccielab@groupstudy.com>
.VN> cc:
Sent by: Subject: Question about Prefix filtering
nobody@groupstudy
.com
24-02-2003 11:52
Please respond to
"Tran Tien Phong"
Hi guys,
For example, there are following network:
192.168.1.0
192.168.2.0
192.168.3.0
192.168.4.0
192.168.5.0
192.168.6.0
192.168.7.0
192.168.8.0
The question asks me to filter the odd routes, I think there are two
working configs:
1.
access-list 1 deny 192.168.1.0 0.0.254.255
access-list 1 permit any
2.
access-list 1 deny 192.168.1.0 0.0.254.0
access-list 1 permit any
Both of the configs will work well but which one is better and more
correct?
Thanks.
This message is for information purposes only and its content
should not be construed as an offer, or solicitation of an offer,
to buy or sell any banking or financial instruments or services
and no representation or warranty is given in respect of its
accuracy, completeness or fairness. The material is subject
to change without notice. You should take your own independent
tax, legal and other professional advice in respect of the content
of this message. This message may contain confidential or
legally privileged material and may not be copied, redistributed
or published (in whole or in part) without our prior written consent.
This email may have been intercepted, partially destroyed,
arrive late, incomplete or contain viruses and no liability is
accepted by any member of the Credit Agricole Indosuez group
as a result. If you are not the intended recipient of this message,
please immediately notify the sender and delete this message
from your computer.
This archive was generated by hypermail 2.1.4 : Sat Mar 01 2003 - 11:06:33 GMT-3