RE: Log Vs log-input

From: samccie2004@yahoo.co.uk
Date: Sun Oct 24 2004 - 16:33:33 GMT-3


Hi Zack

Thanks for the reply.

My understanding is that Log-input will not stop anything, be it a smurf
or other, but would log a source of packets. The ACL though would block
the attack when denying packets.

So back to D-Day, when Cisco ask for Log...I guess I will ask the
proctor of the extend of the log they want.

Sam

-----Original Message-----
From: apache [mailto:apache@rustedhalo.net] On Behalf Of Zack Damen
Sent: 24 October 2004 20:47
To: ccie2be
Cc: samccie2004@yahoo.co.uk; studygroup
Subject: Re: Log Vs log-input

Very quick,

Log-input is used along with Smurf, if you get a question ask to protect
against a smurf attack, then there is a good chance you need to use
log-input, just doing a log will not stop or help stop the attack.

Regards

Zack

> Sam,
>
> I don't think that's an answerable question. It depends on the
wording of
> the question. What is the task trying to accomplish?
>
> If you know the difference between those 2 options and you still can
> figure
> out which is needed, maybe you should ask the proctor for
clarification.
>
> HTH, Tim
>
> ----- Original Message -----
> From: <samccie2004@yahoo.co.uk>
> To: "studygroup" <ccielab@groupstudy.com>
> Sent: Sunday, October 24, 2004 9:07 AM
> Subject: Log Vs log-input
>
>
>> Hi Group
>>
>> Back to basics again. When Cisco ask to log ACL entries do they
expect
>> standard ACL with log or extended with log-input ?
>>
>> Thanks
>>
>> Sam
>>
>>



This archive was generated by hypermail 2.1.4 : Sat Nov 06 2004 - 17:11:52 GMT-3