Answers to the Chapter 8 Do I Know This Already Quiz

1 Configure a numbered IP access list that stops packets from subnet 134.141.7.0 255.255.255.0 from exiting serial 0 on a router. Allow all other packets.

access-list 4 deny 134.141.7.0 0.0.0.255 access-list 4 permit any interface serial 0 ip access-group 4

The first access-list statement denies packets from that subnet. The other statement is needed because the default action to deny packets is not explicitly matched in an access-list statement.

2 How would a user who does not have the enable password find out what access lists have been configured and where they are enabled?

The show access-list command lists all access lists. The show ip interfaces and show ipx interfaces commands identify interfaces on which the access lists are enabled.

3 Name all the items that a standard IP access list can examine to make a match. Source IP address

Subset of the entire source address (using a mask)

4 How many IP access lists of either type can be active on an interface at the same time?

Only one IP access list per interface, per direction. In other words, one inbound and one outbound are allowed, but no more.

5 Configure and enable an IP access list that allows packets from subnet 10.3.4.0/24, to any Web server, to get out serial interface S0. Also allow packets from 134.141.5.4 going to all TCP-based servers using a well-known port to enter serial 0. Deny all other traffic.

access-list 101 permit tcp 10.3.4.0 0.0.0.255 any eq www access-list 102 permit tcp host 134.141.5.4 any lt 1023 interface serial 0 ip access-group 101 out ip access-group 102 in

Two extended access lists are required. List 101 permits packets in the first of the two criteria, in which packets exiting S0 are examined. List 102 permits packets for the second criterion, in which packets entering S0 are examined.

6 Name all the items that an extended IP access list can examine to make a match. Protocol type

Source port Source IP address

Subset of the entire source address (using a mask) Destination port Destination IP address

Subset of the entire destination address (using a mask)

7 How many IP extended access-list commands are required to check a particular port number on all IP packets?

Two statements are required. If the protocol type IP is configured, the port number is not allowed to be checked. Therefore, the TCP or UDP protocol type must be used to check the port numbers. Thus, if port 25 needs to be checked for both TCP and UDP, two statements are needed: one for TCP and one for UDP.

8 What command lists the IP extended access lists enabled on serial 1 without showing other interfaces?

The show ip interface serial 1 command lists the names and numbers of the IP access lists enabled on serial 1.

9 Configure a named IP access list that allows only packets from subnet 193.7.6.0 255.255.255.0, going to hosts in network 128.1.0.0 and using a Web server in 128.1.0.0, to enter serial 0 on a router.

ip access-list extended barney permit tcp 193.7.6.0 0.0.0.255 128.1.0.0 0.0.255.255 eq www

interface serial 0 ip access-group barney in

A deny all is implied at the end of the list.

10 Name all the items that a named standard IP access list can examine to make a match. Source IP address

Subset of the entire source address (using a mask)

Named standard IP access lists match the same items that numbered IP access lists match.

11 List the types of IP access lists (numbered standard, numbered extended, named standard, named extended) that can be enabled to prevent Telnet access into a router. What commands would be used to enable this function, assuming that access-list 2 was already configured to match the right packets?

Any type of IP access list can be enabled to prevent vty access. The command line vty 0 4, followed by ip access-class 2 in, enables the feature using access list 2.

12 Name all the items that a named extended IP access list can examine to make a match. Protocol type

Source port Source IP address

Subset of the entire source address (using a mask) Destination port Destination IP address

Subset of the entire destination address (using a mask)

These are the same things that can be matched with a numbered extended IP access list.

Answers to the Chapter 8 Q&A Section

1 Configure a numbered IP access list that stops packets from subnet 134.141.7.0 255.255.255.0 from exiting serial 0 on a router. Allow all other packets.

access-list 4 deny 134.141.7.0 0.0.0.255 access-list 4 permit any interface serial 0 ip access-group 4

The first access-list statement denies packets from that subnet. The other statement is needed because the default action to deny packets is not explicitly matched in an access-list statement.

2 Configure an IP access list that allows only packets from subnet 193.7.6.0 255.255.255.0, going to hosts in network 128.1.0.0 and using a Web server in 128.1.0.0, to enter serial 0 on a router.

access-list 105 permit tcp 193.7.6.0 0.0.0.255 128.1.0.0 0.0.255.255 eq www

interface serial 0 ip access-group 105 in

A deny all is implied at the end of the list.

3 How would a user who does not have the enable password find out what access lists have been configured and where they are enabled?

The show access-list command lists all access lists. The show ip interfaces and show ipx interfaces commands identify interfaces on which the access lists are enabled.

4 Configure and enable an IP access list that stops packets from subnet 10.3.4.0/24 from getting out serial interface S0 and that stops packets from 134.141.5.4 from entering S0. Permit all other traffic.

access-list 1 deny 10.3.4.0 0.0.0.255 access-list 1 permit any access-list 2 deny host 134.141.5.4 access-list 2 permit any interface serial 0 ip access-group 1 ip access-group 2 in

5 Configure and enable an IP access list that allows packets from subnet 10.3.4.0/24, to any Web server, to get out serial interface S0. Also allow packets from 134.141.5.4 going to all TCP-based servers using a well-known port to enter serial 0. Deny all other traffic.

access-list 101 permit tcp 10.3.4.0 0.0.0.255 any eq www access-list 102 permit tcp host 134.141.5.4 any lt 1023 interface serial 0 ip access-group 101 out ip access-group 102 in

Two extended access lists are required. List 101 permits packets in the first of the two criteria, in which packets exiting S0 are examined. List 102 permits packets for the second criterion, in which packets entering S0 are examined.

6 Can standard IP access lists be used to check the source IP address when enabled with the ip access-group 1 in command, and can they check the destination IP addresses when using the ip access-group 1 out command?

No. Standard IP access lists check only the source IP address, regardless of whether the packets are checked when inbound or outbound.

7 How many IP extended access-list commands are required to check a particular port number on all IP packets?

Two statements are required. If the protocol type IP is configured, the port number is not allowed to be checked. Therefore, the TCP or UDP protocol type must be used to check the port numbers. Thus, if port 25 needs to be checked for both TCP and UDP, two statements are needed: one for TCP and one for UDP.

8 True or false: If all IP or IPX access-list statements in a particular list define the deny action, the default action is to permit all other packets.

False. The default action at the end of any IP or IPX access list is to deny all other packets.

9 How many IP access lists of either type can be active on an interface at the same time?

Only one IP access list per interface, per direction. In other words, one inbound and one outbound are allowed, but no more.

For questions 10 through 12, assume that all parts of the network shown in Figure 8-8 are up and working. IGRP is the IP routing protocol in use. Answer the questions following Example 8-15, which contains an additional configuration in the Mayberry router.

Figure 8-8 Network Diagram for Questions 10 Through 12

Andy Opie

Continue reading here: Which Ethernet Cable is Right for Your Users? – Cat-5 vs. Cat-6

Was this article helpful?

0 0