Re: Extentded -access list

From: Jai Prakash (jpjsr06@gmail.com)
Date: Mon May 22 2006 - 12:44:47 ART


Hi Tony,

  It depends upon application of Access-list , I mean applying these
access-list for INBOND or OUTBOND Traffic flow.

For OUTBOND (From INside to OUTside) Traffic Flow :--

case 1 ) ip access-list extended TEST
              permit tcp 10.10.10.0 0.0.0.255 172.16.0.0 0.0.255.255 eq
 www
                              Inside NW Outside
NW Outside Port

For INBond ( From OUTside to INside) Traffic Flow :--

case 1) ip access-list extended TEST
              permit tcp 10.10.10.0 0.0.0.255 172.16.0.0 0.0.255.255 eq
www
                              Outside NW INside
NW Inside Port

For OUTBond ( From INside to OUTside) Traffic Flow :--

case 2) ip access-list extended TEST
              permit tcp 10.10.10.0 0.0.0.255 eq www 172.16.0.0
0.0.255.255
                               INside NW INside Port
OUTside NW

For INBond ( From OUTside to INside) Trsffic Flow :--

 case 2) ip access-list extended TEST
               permit tcp 10.10.10.0 0.0.0.255 eq www
172.16.0.0 0.0.255.255
                                 OUTside NW OUTside
Port INside NW

Best Regards,
Jai

On 5/22/06, tony hall <tony_hall123@hotmail.co.uk> wrote:
>
> Hi,
> Sorry for this very basic question,Please if someone can expain the
> diffrence between the 2 following access-list.
>
> 1-ip access-list extented TEST
> permit tcp 10.10.10.0 0.0.0.255 172.16.0.0 0.0.255.255 eq www
>
> 2--ip access-list extented TEST
> permit tcp 10.10.10.0 0.0.0.255 eq www 172.16.0.0 0.0.255.255
>
> Regards,
>
> _________________________________________________________________
> Be the first to hear what's new at MSN - sign up to our free newsletters!
> http://www.msn.co.uk/newsletters
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Thu Jun 01 2006 - 06:33:22 ART