05.01.2013 Views

CCNA Cisco Certified Network Associate Study Guide - FTP Server

CCNA Cisco Certified Network Associate Study Guide - FTP Server

CCNA Cisco Certified Network Associate Study Guide - FTP Server

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Hands-on Labs 467<br />

3. Configure an access list on 2501A to allow only IPX traffic from <strong>Network</strong><br />

30 and to deny IPX <strong>Network</strong> 50. IPX standard lists use the<br />

access list numbers 800–899.<br />

2501A#config t<br />

RouterC(config)#access-list 810 ?<br />

deny Specify packets to reject<br />

permit Specify packets to permit<br />

4. First, deny IPX <strong>Network</strong> 50, then permit everything else. The –1 is a<br />

wildcard in IPX.<br />

2501A(config)#access-list 810 deny ?<br />

-1 Any IPX net<br />

Source net<br />

N.H.H.H Source net.host address<br />

5. Choose <strong>Network</strong> 30 as a source address:<br />

2501A(config)#access-list 810 deny 50<br />

-1 Any IPX net<br />

Destination net<br />

N.H.H.H Destination net.host address<br />

<br />

6. Choose <strong>Network</strong> 10 as the destination network:<br />

2501A(config)#access-list 810 permit 50 10<br />

7. Permit everything else with an IPX wildcard:<br />

2501A(config)#access-list 810 permit –1 -1<br />

8. Apply the list to the serial interface of 2501A to stop the packets as<br />

they reach the router:<br />

2501A(config)#int s0<br />

2501A(config-if)#ipx access-group 810 in<br />

2501A(config-if)#^Z<br />

9. Verify the list by looking at the IPX routing table. <strong>Network</strong> 50 should<br />

not be in the 2501A IPX routing table. Also, use the show accesslist<br />

and show ipx access-list commands to vary the list.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!