ACL IP and TCP ACL... What is the difference?

Hello

I have a few questions on the ACL.

1. for PIX ACL, let's say I want to host a Web server in the network internally (just to simplify my question), and I do not PAT, but only a static NAT

public static 202.188.100.1 (Interior, exterior) 10.1.1.1 netmask 255.255.255.0

acl_out tcp allowed access list all 10.1.1.1 eq 80

Access-group acl_out in interface outside

Done the above equivalent to

public static 202.188.100.1 (Interior, exterior) 10.1.1.1 netmask 255.255.255.0

ip access list acl_out permit any 10.1.1.1

Access-group acl_out in interface outside

2. for IOS ACL, is it possible to block A (10.1.1.0/24) network access to network B (10.1.2.0/24) but to allow access from network B to network A? How can I do?

Thank you.

Hello

1. first of all your ACL is a little bad, you need to enable connections to the public of your devices address and not the private sector when allowing traffic from the outside.

The answer to your first question is no, if you don't mind the tcp 80 port in your access list then you allow just that, if you allow ip in your access list then you allow all IP protocols based including all TCP ports, UDP and ICMP ports all.

2. you can do this using either the keyword in your access list or reflexive access lists.

Network B to an ACL

---

IP 10.1.2.0 allow 0.0.0.255 10.1.1.0 0.0.0.255

Network from A to B ACL

---

ip licensing 10.1.1.0 0.0.0.255 10.1.2.0 all created 0.0.0.255

Means that any traffic can pass from network B to network A, however only established connections (packets with the ACK bit value) are admitted from B to A.

The other method is reflexive-list using access which are with State of access lists. When the traffic moves from one network to the other a dynamic access list is created, traffic is only allowed to enter the network source if a dynamic entry is present in the table with the same source and destination IP information. An access list works in a direct, so from A to B, if you wanted to allow B to talk to A you need to configure specific static access list entries.

HTH

PJD

Tags: Cisco Security

Similar Questions

  • Product key and License Code - what is the difference?

    What is the difference between a product key and a License Code?

    Each license code is indicative of a single installation of the software?

    Debbie

    These terms are almost universally used to mean the same thing.  Just different terminology.  Your Windows product key is the proof that you have a valid license to use the software contract (you don't "own" Windows, you rent just the license to use it)

  • U2715H - USB 10 a and 10 b what is the difference?

    The manual for the U2715H list the USB ports on the bottom of the screen as being 10A (3) and10b (1 of them).  But none is as to what the difference is between the three 10 a and 10 b ports next to the space between them.

    What is the difference between them?

    Thank you

    David

    If you plug a USB Wifi or USB mouse dongle wireless to all three USB ports 10A, you'll get interference if a keyboard USB or USB HDD was also connected to 10 a. So for the WiFi or devices wireless dongle, use 10 b or on the rear window.

  • Re: NB510 - 10 d and NB510-11 - What are the differences?

    Hi all

    Does anyone know what the difference between the NB510 - 10 d and NB510-11, they´re be sold here in Spain, at the same price and Im see no difference in the Specificaciones.

    Could someone advice please?

    Concerning

    Can you please send again second netbook model name or perhaps send the link where we can see it?
    NB510-11 cannot be the name of the template to the right.

  • SG300 - 28 p and SG300-52, what is the difference?

    Hello

    I have SG300 - 28 p that I use as layer-3 switch. Recently, I ran to switch SG300-52 and even if loading the firmware even does not give me option to do 3-layer switching. For SG - 300 I see options in the GUI to create interfaces vlan under the information section of intellectual property, while SG300-52 option IP information only under the management section.

    Please let me know if these are 2 types of different materials and L3 is not possible on SG300-52. If its possible to activate the L3 switch on SG300-52, please tell us what Miss me in the config.

    Thanks in advance,

    Sam

    Hello Smunzani, there no difference in switches aside what is obvious, there POE and it has 52 ports vs 28 ports.

    To enable L3, you can console the switch and use the command

    "configure the router mode system.

    You can also set the mode of the system via the menu if you're using the old 1.0.0.27 firmware (that does not support the CLI textview)

    If you do not have access to the console, you can connect to the GUI and go to SECURITY-> TCP/UDP SERVICES and activate telnet then telnet to the switch as well.

    -Tom

  • What is the difference between SATA and regular cables?

    I am a student in the article so I have a small doubt
    What is the difference between sata cables and normal

    "What is the difference between sata cables and normal."

    If by "normal" you make cables referring to the old SCSI or IDE/PATA cables in water it

    is a very big difference.

    SCSI (IDE/PATA are similar, but with the pins are connecting less) is the former cable style and support of the motherboard for the latter is way of disappearance on newer systems.

    SATA cables are used on the latest HARD drives and SSD and are supported by all the "modern".

    motherboards. The one in the photo was an end at right angles, but most are right.

    Two types of cable are used for HARD disk SSD and optical drives.

    BTW - As an IT student would serve you yourself well learn how to search the Internet for

    answers to these questions.

    .

  • What is the difference between activation voice Dragan and voice activation Windows?

    I used to have voice activation Dragan and loved. What is the difference between the software you buy and the system already installed in Windows?

    original title: why NOT use speech recognition?

    I guess you have already watched on the site Web of Nuance for the features of Dragon & compared to Windows using Windows speech recognition.

    [I found useful, the following as well: How can I remove software voice of Windows 7 so it won't conflict with the Dragon Naturally Speaking software?]

  • What is the difference between single quotation mark (') and double quote ("")?

    What is the difference between single quotation mark (') and double quote ("") in reports using SQL. When you use "xxx" and "xxx"? What is the difference of two of them?

    Thank you.

    http://download.Oracle.com/docs/CD/E11882_01/server.112/e10592/sql_elements008.htm#SQLRF51129
    http://download.Oracle.com/docs/CD/E11882_01/AppDev.112/e10472/fundamentals.htm#LNPLS199

    Edit

    What is the difference of two of them?

    In fact: it is better to simply forget double quotes ;)

    Published by: hoek on October 23, 2009 21:22

  • Stupid question: what is the difference between RAC and Clusterware?

    Hi all

    I'm about to start experimenting with the 11 G RAC Setup (to begin with, is that a cluster of a node, will try to add another later).

    I am reading the docs... I'm on that of clusterware installation, and it seems to indicate that the clusterware and RAC are two different things?

    http://download.Oracle.com/docs/CD/B28359_01/install.111/b28263/prelinux.htm#BABJHGBE

    With quotes like "UDP is the default for Oracle RAC interconnect protocol and TCP is the Protocol of interconnection for Oracle Clusterware. You must use a switch for interconnection. Oracle recommends using a dedicated switch. "

    Can someone tell me the difference? I know it sounds stupid, but it's confusing me, and I'm new on this.

    Cayenne

    Published by: cayenne on March 20, 2009 11:25

    Published by: cayenne on March 20, 2009 11:25

    You can make your http://www.oracle.com/technology/products/database/clusterware/clusterware_for_unbreakable_linux_faq.html#7 understand

    What is the difference between the Oracle Clusterware and Oracle Real Application Clusters?

    In case of failure of the system, put in cluster guarantees availability high for users. Redundant hardware components, such as the additional nodes, interconnection, and discs, allow the cluster to provide high availability. These redundant hardware architecture avoid the single points of failure and provide exceptional resilience fault.

    In environments Oracle Real Application Clusters (RAC), Oracle Clusterware monitors and manages Real Application Cluster databases. When a node of the cluster is started, all instances, auditors and the services are started automatically. If an instance fails, the clusterware automatically restarts the instance, so that the service is often restored prior to the notice of the administrator, he was down. In this sense Oracle Clusterware is the base of Oracle Real Application Clusters.

    In these environments CCR ensures the continuous operation of the database, but also scalability by running several bases of instance data at the same time, usually one on each node in the cluster.

  • What is the difference between an icon of hard drive on my desktop and a home icon in the Finder?

    Hello

    I'm confused about the icon I have on my desk (hard drive) and a picture of a house in the Finder.  My iMac is divided between two discs?   What is the difference between these two, if any?

    the House is your account, which is located ON your hard disk, but it is NOT your hard drive.

  • Does conflict ghostery add-on, and what is the difference?

    I installed ghostery, but now Firefox tells me "add-on" is available. What is the difference and they will come into conflict?

    As far as I KNOW, Ghostery and Lightbeam match a little at work. What a difference I know that ghostery have some features integrated to block or whitelist of Web sites you visit.
    While lightbeam just likes to Watch supervisors and tell you graphically about third-party connections.
    so, if you use ghostery then it can useful for a faster loading Web sites because you block unusual food extracted from Web site, while lightbeam cannot do something with the site.

    Firefox is add-on cause reviews of >'s done it with our great
    developers, completely understand the part of the user experience.
    > because it is nothing to do with the Web sites, so a Web site owner perspective, you can display ads on your browser, without the authorization of changes external.
    Monitoring and privacy framework.
    Take a look at https://www.ghostery.com/en/ find out about Ghostery and Lightbeam is accessible via https://www.mozilla.org/en-US/lightbeam/ .

  • What is the difference between the cookies keep until I close firefox and the history of cookie empty closing firefox?

    In the settings of Firefox 33.0 (I use Ubuntu 14.04, but the functionality is the same for Windows 7) there are two ways to delete cookies when firefox closes. Or at least, there seems to be.

    Is first the cookies keep until firefox is closed

    Second is to check the box for clear history of firefox closing and in the settings check cookies.

    What is the difference between these two options?

    I usually have two configuration but I noticed that a connection was not save for td canada trust EasyWeb, even though I have an exception set for it. Now I unchecked to remove cookies by disabling the history on close and connection records correctly.

    This connection allows to save 7 cookes under easyweb.td.com and 10 cookies under td.com and I have exceptions defined for both. If I clear the history when closing and include cookies, half of the td.com cookies disappeared when I close firefox and re - open. The same is true if I'm not the exception.

    So currently I can't find a way to keep all cookies if I clear the cookie history when firefox closes. What is the difference with this option?

    When you change the default cookie 'to life' of "keep until: they expire" to "keep until the: I close Firefox", Firefox changes all persistent cookies that sites set session cookies. To allow a site to place a persistent cookie, you need to make an exception (site permission).

    When you turn on the story to stop compensation and include cookies, running a completely separate process that doesn't doesn't pay attention to the duration of cookie or exceptions (permissions site). There just nukes all.

    Note that some cookies could survive if they are encoded in the history file of your session of compensation at the stop, a Firefox uses to restore your tabs and windows from last session. I have not tested.

  • What is the difference between id and apple itunes password

    What is the difference between an apple and a iTunes

    ID and how do I get a password manager to deal with them?

    They are usually the same thing

  • What is the difference (if any) between iPhoto and iPhoto library? I managed to delete my pictures in freeing up space, but have a backup available. Do I have to download these two files in the pictures folder is one duplicate of the other?

    What is the difference (if any) between iPhoto and iPhoto library? I managed to delete my pictures in freeing up space, but have a backup available. I need to restore these two files in the folder images or one is one duplicate of the other?

    I use a MacBook Air 2013 model with a backup on a WD MyBook Duo disc for storage wireless as the Apple Time Machine.

    The Photos and the iPhoto library are totally separated - neither one is connected to the other somehow--you want to restore the library you need

    LN

  • What is the difference between extensions and Plugins and Add-ons?

    I'm sorry if here is not the right place for this post.

    What is the difference between extensions and Plugins and Add-ons? Apparantely, they differ in some sense or aspect, but I do not know how. Please, if it is not too complicated, explain in detail and simple language. Thanks in advance to 1 million.

    Kind regards
    Danesh

    Hi Danesh,

    You should take a look at this article for an explanation. Plugins and extensions are essentially types of Add-ons as well as of the characters and themes.

    Hope this helps!

  • What is the difference between 3.6.25 and more recently as the version 9.0.1

    I'm not sure to understand the difference between the versions of 3.6 and many 9.0.1 version. I have much more trouble with this new version - actually had to uninstall it because it kept crashing. I understand that there are more bells and whistles, but what is the advantage of the most recent on this old reliable version?

    See:

Maybe you are looking for

  • Portege Z830 - H5321GW Firmware R1F01 and R3C/1 Dif

    Hello someone at - it update its 3 G WWAN Modem with Toshiba Firmware Updater? For model H5321GW, there is an upgrade of * R1F01 * for the latest Firmware * R3C/1 *. And Yes Toshiba call this FW/1 R3C another provider call R3C18/R8C11. Is there an im

  • The browser crash

    After using a table VI in the web browser, when I close the page (by closing browser, closing tab or go to another web page), the browser crashes with this error message: Unrecoverable internal error: 'MemoryManager.cpp', line 437 LabVIEW version 8.6

  • How can I change the default action of record?

    My laptop with Windows vista has curently explores as the default action (because it does not open in a new window which is my chosen prefrence) and opened as the next option. How can I change the default action to open?

  • Hang in Service Adobe Office

    I see a regular issue in Windows 10 which interferes with my ability to use Adobe products (specifically, cloud creative and Photoshop).The problem seems to be that the Service Office Adobe hangs in NtDeviceIoControlFile:Gyazo - 4d52dc281041a691e61ff

  • My canvas is frozen and I can't do the project I am working on reading.

    I just changed a project very well and then all of a sudden... my canvas froze. I restarted the program twice, restarted my computer, deleted my cache of media, run a disk utility... I CAN'T READ ANYTHING MORE. Mega mega issue.System: iMac 21.5 i5 wi