RE: a basic acl question..

From: Ian Stong (istong@stong.org)
Date: Sun Jan 18 2004 - 20:49:59 GMT-3


Hi,

The standard access lists (0-99) are source based. You can of course
apply the access list using ip access-group in or ip access-group out
depending on whether you want to filter traffic as it enters or leaves
an interface.

Ian

http://www.ccie4u.com
Rack Rentals and Lab Scenarios

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
Ellie Chou
Sent: Sunday, January 18, 2004 6:37 PM
To: ccielab@groupstudy.com
Subject: a basic acl question..

Hi, a basic acl question. (when you thought you know a topic pretty
well,
some questions always jump out and surprise you! ;-( )when using
standard IP access list or mac access-list (700-799), there is only one
IP or MAC can be specified. When applying this access-list to interface
to permit/deny traffic, is it the source or the destination IP/MAC
that's
going to be checked? thanks!Ellie

------------------------------------------------------------------------

Get a FREE online virus check for your PC here, from McAfee.



This archive was generated by hypermail 2.1.4 : Mon Feb 02 2004 - 09:07:47 GMT-3