Web Hosting Talk







View Full Version : Sorry OT: CISCO & Access lists


The Laughing Cow
04-18-2002, 10:20 AM
I am sorry if this may be the wrong place but here I go,

I was under the impression that

standard ACL's should be placed as near to the destination as possible and extended were to be placed as near to the source as possible?

Can anyone confirm this?

Two of my books say this however the accompanying CD-ROM questions bank says otherwise.

Cheers.

hardweb
04-21-2002, 12:31 PM
Yes, it's true. Standard ACL must be placed as close to destination as possible and extended ACL as close to source as possible. The explanation is quite simple, standard ACL are able to filter only on source basis, while extended ACL can filter on source and destination criteria. You should use extended ACL in most cases because they filter close to the source and no additional trafic flows in the network.

The Laughing Cow
04-21-2002, 01:25 PM
I though I was right - Thanks.

Looks like the Sybex CD was wrong again :(