RE: Computing Access-List and Wildcard Pairs (was RE: Wildcard

From: Ken.Farrington@barclayscapital.com
Date: Sat Oct 04 2003 - 10:15:48 GMT-3


Can I just say a Special thx to Derek, Jason and Brian for this.
Excellent stuff, and lets face it, everyone has to master this if you are to
take your lab.

I encourage others to look at what these canys have posted here.

Many thx all

---------------------
THE RESULTS ARE IN :) (not yet for arsenal - but whey hey, Pires, what a
goal)
---------------------

121.10.17.0 /24
127.24.6.0 /24
122.35.35.0 /24
111.16.6.0 /24

so result of this particular range is
104.0.0.0 mask 23.59.55.255

Hope this is correct.

        *** *
121 01111001
127 01111111
122 01111010
111 01101111
-----------------
Sub-AND 01101000 104
Msk-XOR 00010111 23
        ** *
10 00001010
24 00011000
35 00100011
16 00010000
-----------------
Sub-AND 00000000 0
Msk-XOR 00111011 59

        ** *
17 00010001
6 00000110
35 00100011
6 00000110
-----------------
Sub-AND 00000000 0
Msk-XOR 00111011 55

but dont apply this as anything can match so normal rules apply .255 not .0
in the mask
        ********
0 00000000
0 00000000
0 00000000
0 00000000
-----------------
Sub-AND 00000000
Msk-XOR 00000000

-----Original Message-----
From: Brian McGahan [mailto:bmcgahan@internetworkexpert.com]
Sent: 03 October 2003 22:37
To: Ken.Farrington@barclayscapital.com; ccielab@groupstudy.com
Subject: Computing Access-List and Wildcard Pairs (was RE: Wildcard
Masks)

Ken,

        What a coincidence! I have recently written a white paper on
this exact subject! ;)

Computing Access-List and Wildcard Pairs:
http://www.internetworkexpert.com/resources/01700370.htm

HTH,

Brian McGahan, CCIE #8593
bmcgahan@internetworkexpert.com

Internetwork Expert, Inc.
http://www.InternetworkExpert.com
Toll Free: 877-224-8987
Direct: 708-362-1418 (Outside the US and Canada)

> -----Original Message-----
> From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf
Of
> Ken.Farrington@barclayscapital.com
> Sent: Friday, October 03, 2003 5:53 AM
> To: ccielab@groupstudy.com
> Subject: Wildcard Masks
>
> Hello,
>
> Does anyone have any comprehensive documentation on complex
wildcarding
> for
> spurious networks, ie
>
> 192.168.10.0/24
> 172.16.40.128/25
> 10.1.2.0/16
> 141.226.50.0/24
>
> Say I wanted to use an ACL with a wildcard mask to cover these
networks
> with
> the minimum configuration.
>
> Believe it or, not, it is really hard to find complex examples on the
web
> or
> on CCO.
>
> This is very confusing.
>
> Many thx
>
> ________________________________________________________________
> Ken Farrington
> Global Networks, Barclays Capital, 5 The North Colonnade, Canary
> Wharf, London, E14 4BB
> * Tel : 020 7773 3550
> * Mob : 07768-866655
> * ken.farrington@barcap.com
>
>
>
>
>
------------------------------------------------------------------------
> For more information about Barclays Capital, please
> visit our web site at http://www.barcap.com.
>
>
> Internet communications are not secure and therefore the Barclays
> Group does not accept legal responsibility for the contents of this
> message. Although the Barclays Group operates anti-virus programmes,
> it does not accept responsibility for any damage whatsoever that is
> caused by viruses being passed. Any views or opinions presented are
> solely those of the author and do not necessarily represent those of
the
> Barclays Group. Replies to this email may be monitored by the
Barclays
> Group for operational or business reasons.
>
>
------------------------------------------------------------------------
>
> ***Get your CCIE and a FREE vacation: Shop.GroupStudy.com***
>



This archive was generated by hypermail 2.1.4 : Mon Nov 24 2003 - 07:52:57 GMT-3