05.01.2013 Views

CCNA Cisco Certified Network Associate Study Guide - FTP Server

CCNA Cisco Certified Network Associate Study Guide - FTP Server

CCNA Cisco Certified Network Associate Study Guide - FTP Server

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

456 Chapter 9 � Managing Traffic with Access Lists<br />

IPX SAP Filters<br />

Let’s take a look at a template for building lines in an IPX extended<br />

access list.<br />

access-list {number} {permit/deny} {protocol} {source}<br />

{socket} {destination} {socket}<br />

Again, when you move from standard to extended access lists, you’re simply<br />

adding the ability to filter based on protocol and socket (port for IP).<br />

IPX SAP filters are implemented using the same tools we’ve been discussing<br />

all along in this chapter. They have an important place in controlling IPX<br />

SAP traffic. Why is this important? Because if you can control the SAPs, you<br />

can control the access to IPX devices. IPX SAP filters use access lists in the<br />

1000–1099 range. IPX SAP filters should be placed as close as possible to the<br />

source of the SAP broadcasts; this is to stop unwanted SAP traffic from<br />

crossing a network because it will only be discarded.<br />

Two types of access list filters control SAP traffic:<br />

IPX input SAP filter This is used to stop certain SAP entries from entering<br />

a router and updating the SAP table.<br />

IPX output SAP filter This stops certain SAP updates from being sent in<br />

the regular 60-second SAP updates.<br />

Here’s the template for each line of an IPX SAP filter:<br />

access-list {number} {permit/deny} {source} {service type}<br />

Here is an example of an IPX SAP filter that allows service type 4 (file services)<br />

from a NetWare service named Sales.<br />

Router(config)#access-list 1010 permit ?<br />

-1 Any IPX net<br />

Source net<br />

N.H.H.H Source net.host address<br />

Router(config)#access-list 1010 permit -1 ?<br />

Service type-code (0 matches all services)<br />

N.H.H.H Source net.host mask<br />

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!