All language subtitles for 10. Access Control Lists

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal) Download
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

In the section we're going to talk about the access control lists.

Let's go with the ACL or will a c as access lists are a set of commands which are grouped together to

filter the packet that enters or leaves to an interface.

They control the flow of traffic in their work and provide security for network access access lists

are implemented sequentially as a permit or deny statement to inbound or outbound of interface and used

for also different purposes such as for example maybe a rough map or something like that.

There are two types of access lists and they are standard or extended.

And they can be used with numbers or named format.

Please pay attention that each ACL must have a permit statement because there is an implicit denial

rule at the bottom of each ACL.

That's the key point.

Anywhere you see an example for the number access list which are permitting some networks.

And here's our configuration access list and the number.

Then permit or deny statement and we're using and network and we are using air field named Wild Cards

which we're going to exit mine later.

All access lists must be identified by a name or a number.

As I told you in the first slide and then the access lists are more common than then numbered access

lists because you can specify a meaningful name that is easier to remember and associate with that task.

You can reorder statements in or add statements to named access lists and name the access lists support

the following features that are not supported by a number to access such as IP options filtering noncontiguous

ports or TCAP flic filtering.

All right.

Here is how we can configure named access list to configure a name access list.

We are typing i p access list command and we're choosing.

If we're going to use an extended or if we're going to use a standard access that most of the time in

this Exxon-Mobile we're using standard and I pay access list and the standard configuration.

And we are writing the name of our access this thing here and as you can see in here under the access

this month we are denying or permitting to sign statements.

OK let's go ahead with the wild card mask.

What mask is a mask of bits that indicates which parts of an IP address are available for an examination

and determines what IP addresses should be permanent or denied in access control lists.

What kind of mask has a reverse logic logical subnet mask as 0 in the wild card mask means to focus

to that bet while as one means to ignoring the to when if you see is zero on the summer mask answer

on the current mess that means we need to take care we need to focus a little bit but if we're seeing

one that means we need to ignore that bit.

OK I'm going to show you an example as well.

In this access list we're seeing an accidental statement and this access list is saying and access this

didn't number access as one per minute wandered in some way to that 16 0 0 with that wild card massacre

of 0 0 255 255.

So what that means here is the network the and the here is the answer here is the wildcard mask what

that so you is if we're using zero that means we need to focus to relate to pets.

All right.

As you can see in here I have a zero and I need to focus to one hundred and seventy two in here.

We're another zero and we need to focus to 16 on the last two bits we have just once for the 2:55 as

you can see in the binary version.

And that means we need to ignore that bit.

So this wildcard mask means for cursor everything starting with the 100 and so and if for seven to that

16

and so that means we are permitting everything starting with they wandered 70 to that 16 for example

winers.

So into that 16 1.5 maybe Whatever were you want let's go with the World Cup mask example too.

And we have another configuration access list 50 per minute this time 192 100 and 68 8.00 outcome mask

of 0 0 0 255 which means a zero.

And here is the wildcard mask

which means we need to focus the first three portions and we don't care the last portion because we

have continuous ones in a year.

That means this access list permits everything starting with the ones that 90 to 100 and sixty eight

that's a lot.

For example oh that's strong strong.

That would be something like that.

And we can give an example like

63 5:06 to other Durnford for AM.

That's an arbitrarily OK let's go with the standard IPV for access lists standard access lists perform

packet filtering based on sound source sudras and must be implemented to other which is the closest

to the destination address for official see numbers where it wants 99 and 1000 and 300 and one thousand

nine hundred ninety nine.

These range are used for standard access this configuration and this access lists are applied to interfaces

by IPX this group command.

As you can see in here there is an standard access this configuration we're getting into the conflict

mode first then we are typing access lists and the number of access list and the permit or deny and

The relate to network.

Then we are getting into the interface mode and via implementing this access list.

Two are related interface which means for example we Heraldo in here we are faster than 0 0 and Fester's

0 1 and we are implementing this IP access group to inbound.

This would be fifth the to inbound.

Which means really we are implementing to this we are implementing this access this to this direction.

Let's go hat in this example we have another standard access list access list for in the first month

we are denying the Sen. 41 zeros Zeeuw.

I'm sorry 20 0.

That means everything beginning with this 10:41 20 and something like that.

If the second statement we're poor meaning the host then 12:56 to any that 5 in here R.K. access list

rules are implemented.

The international security issue as you as I told you in the first statement we're also denying discipled

this as you can see.

So the traffic will be blocked even if we type discipled this with a permit statement in here as is

consider the New Year there there's a conflict between two rules in this example.

Let's take a look at another configuration example on a topology now on rather one.

We are defining an access list standard access list and we are denying the host to that 5.

OK.

This guy will be denied.

And we're permuting any other traffic.

Ok then we are getting into the interface mode interface gig 0 0 which is here and we are implementing

the access list to inbound.

That means in that in this direction.

So PC to will be denied.

For example what if it wants to communicate with the PC Wan to that the standard access list configuration

for example as you know access list one denying the host 2.6 for this example which is the right thing

then the access list one is Poorman thing.

Any we are permitting any other things.

So if you want to added this configuration we are typing the show Oxus list command and we are seeing

the sequence number in here as you can see skirt's number 10 is denying this holes and sequence number

20 is permitting anything else.

So if you want to edit it we are typing.

I pay taxes and standard one then note 10 which means we are letting this through.

And we are typing in denying holes down 41 to that five maybe.

All right.

This is how that is to provide the access list to where the standard Access is configuration.

We can use the show access lists command and we can also use the Sharpy interface and the related interface

command.

And we can see that if there is an embargoed or outbound access was applied to that interface.

Let's go ahead with the extended IP for access lists extended access list performs packet filtering

based on Sarsour address destination address protocols and the port numbers Itzig.

It's good that the extent of the ACLU are implemented rather which is closest to source address for

f and c and here's the range that we can use for the extended access lists extends access lists are

Pletcher interfaces.

BI I picked this group name number in and out statements as well as in the standard access list and

there is the configuration example access lists this time 100 which is in this range as you can see

is the name the TZP traffic which is coming from this sarce and going to this destination for the ports

it Khune to 23 which is the telnet part.

I can also read this statement in here Access is 190 TCAP same thing same thing say it coolant too I

can write the porticos names start protocols names as well directly.

For example telnet for example.

Then the same thing as the standard Access is that I'm getting into the interface mode and am typing

the IP access group number of days sale and inbound or outbound as the direction and here is the same

text as we can see the access list and access number permit or deny the protocols named sources rest

and the wild card of the source then the port operator and source port.

And the answer is destination and destination wild card pool operator and the destination port.

Again you get to it better by this example in here as you can see here with an access list configuration

which is an excellent one in the first stateman access is 100 is permitting the TCAP traffic coming

from

this number by díaz wild card which means everything beginning with these three portions.

And via the net we are permitting this through a big way.

It's going through this horse directly.

I can also use in your sound San Juan one of four with a wildcard mask of 0 0 instead of here.

But I can also use force for simplicity.

HOST The host keyword and the host IP address with an equivalent of W W W port.

OK.

That means actually permit TCAP traffic from this guy from this network to port 80 which is the HTP

port on the host 10 1 1 and 2 or 4 OK.

Let's go ahead with the second.

Is 100 per minute.

IP this guy is permuting the traffic from this network while it's going through this network.

OK.

Permit the traffic for on this network slushed 24 to that network slashed two and four.

OK let's go ahead with this third denied teensy piece ok from the

host this time again as you can see that any year I'm using the one that my 268 that won that one with

the 0 0 0 0 wildcard mask which means actually this IP address I'm focusing all of these bets and the

destination will be what 10 on one to another of to four a cool and to £23 which is town and Port.

OK.

And denying the terminal traffic sourced by this destination is here.

OK let's go with the fourth one in the fourth step.

We're using another D-Nice statement from the this.

Horst to this first there is a missing statement and there may be in here there is a 0 0 0 0 as well

within a cube of to 80 which means air support.

And in the last statement we are seeing and access at least 100 per minute.

IP any any and this any key word means if you want to match all sources or all destinations subs to

the entire source or destination elements of command with keywords any Let's go with another configuration

example.

Create an access list that will per math this subnet for TCAP sessions OK.

Create an access list that will deny telnet sessions to actually these costs for this host.

Create an access list that will permit any IP traffic R.K. access this while wandering one will permit

to TCAP sessions

from this network.

From this subnetwork

to any destination.

OK as you can see here the wildcard mask is 0 0 0 15.

This time for slushed 28 OK Slish 20.

It means 255 2:55 255 and 240 to convert this guy to a wildcard mask we can use 0 0 0 and 55.

OK.

So if we add all these guys to each other the end result will be to worth to you for 255 and 250 five.

OK.

In the second we are writing it denies access is one on one denying TZP from any source.

To the destination was this guy with equal and Port of 23 which means tell that and in the third statement

we are creating an access that will permit any IP address Trevitt which is access this 100 on one permit

IP any Annie.

Here is another configuration example for you.

Arcade's saying as a block just tell that traffic coming from PC one and going to PC to OK this guy

will be our source.

And here will be our destination or other one I'm running an external access list.

Oxus is one or one denied TZP host from PC Wan to PC to with the equivalent of telnet.

And as I told you in our first slide we should have at least one spermine statement for each access

list and I'm writing the access this 100 percent IP any any which is permitting any other traffic from

different from the sky.

And we're also implementing these IP addresses.

I'm sorry this access to the E-Man direction of the first Internet 0 1

25 extended access configuration.

We can use the sure access list command as you can see and we can display them and we can also use your

IP interface and the related interface name as well.

Let's go with the IP version 6 to 8 sales.

We can't just use name.

The ACL for the IP version 6 that works and we have the similar logic with IP version for extended ACL

but any year we don't have any wildcard mask and we are using the IP version 6 traffic filter command

to apply to access list to do later.

The interface is the configuration example and we are type in first I perversions 6 axis lists for this

time and the name of Texas is we have just named a scale for IP version 6 and we are denying more a

host with an IP address of this and with an IP address of this.

And this guy will be our source with the destination of this IP address.

And we are permitting any other traffic and to implement this as safely to our interface.

We are using IP version 6 traffic filter command.

Instead of using IP access group command in RPV for a sales.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.