设为首页收藏本站language 语言切换
查看: 2498|回复: 9
收起左侧

[已解决] 813题库第99题疑惑

  [复制链接]
发表于 2011-11-23 09:44:03 | 显示全部楼层 |阅读模式
QUESTION 99
What is true about access control on bridged and routed VLAN traffic? (Select three)
A. Router ACLs can be applied to the input and output directions of a VLAN interface.
B. Bridged ACLs can be applied to the input and output directions of a VLAN interface.
C. Only router ACLs can be applied to a VLAN interface.
D. VLAN maps and router ACLs can be used in combination.
E. VLAN maps can be applied to a VLAN interface
Answer: ABD
Section: Implement a Security Extension of a Layer 2 solution, given a network design and a set of
requirements
Explanation/Reference:
Router ACL(3层ACL)和Bridge ACL(2层ACL)可以用在SVI的input和output方向的。VLAN map和Router ACL
可以放在一起使用。

这里bridged acl 是不是就是port acl ,我在思科网站上查到port acl只用用于ingress traffic,然后E,为什么不对?
答案是不是应该是ADE
发表于 2011-11-23 10:24:32 | 显示全部楼层
Bridged ACL不等于Port ACL吧。
沙发 2011-11-23 10:24:32 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2011-11-24 09:31:45 | 显示全部楼层
板凳 2011-11-24 09:31:45 回复 收起回复
回复 支持 反对

使用道具 举报

 楼主| 发表于 2011-11-30 12:31:42 | 显示全部楼层
回复 支持 反对

使用道具 举报

发表于 2011-11-30 13:48:24 | 显示全部楼层
应该是ACD吧
vlan map(vacl) 跟 router acl 可以结合使用,一个负责VLAN内部,一个负责VLAN之间。
5# 2011-11-30 13:48:24 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2011-12-1 11:52:24 | 显示全部楼层
sdwchow 发表于 2011-12-1 11:28
如你解释的话

你说C的选项正确不合适吧!

C. Only router ACLs can be applied to a VLAN interface.

E. VLAN maps can be applied to a VLAN interface
如果题目讲得时vlan map 和router alc 的话,E错误的话,也就是VLAN maps can not be applied to a VLAN interface 的话只能Only router ACLs can be applied to a VLAN interface (题目讲得就两种,)
6# 2011-12-1 11:52:24 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2011-11-30 23:39:38 | 显示全部楼层
sdwchow 发表于 2011-11-30 15:58
bridged ACL不是PORT ACL

详细请看

http://www.cisco.com/en/US/docs/ ... wacl.html#wp1135336

有详细说明

7# 2011-11-30 23:39:38 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2011-12-1 08:43:33 | 显示全部楼层
本帖最后由 SOMING 于 2011-12-1 10:57 编辑
sdwchow 发表于 2011-12-1 08:14
请你把你的意见写出来

你贴个LINK,并没有说明你想要表达什么!


What is true about access control on bridged and routed VLAN traffic? (Select three)
题目意思,,联系我的链接,这里的bridged vlan traffic 与routed vlan traffic 应该就是链接中router acl 与vlan map
捕获.PNG
8# 2011-12-1 08:43:33 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2011-12-1 09:37:03 | 显示全部楼层
sdwchow 发表于 2011-12-1 08:55
那有说明了什么呢?

说明
B. Bridged ACLs can be applied to the input and output directions of a VLAN interface.    错误

What is true about access control on bridged and routed VLAN traffic?
vlan map 与 router acl 两种里面
C. Only router ACLs can be applied to a VLAN interface. 正确
9# 2011-12-1 09:37:03 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2011-12-1 10:54:39 | 显示全部楼层
本帖最后由 SOMING 于 2011-12-1 11:04 编辑
sdwchow 发表于 2011-12-1 10:28
但是我认为bridged VLAN是2层MAC的ACL

MAC Address Filtering

我认为题目所指的bridged 联系整个题目应该就是指vlan map
Understanding ACLs
Packet filtering can help limit network traffic and restrict network use by certain users or devices. ACLs can filter traffic as it passes through a router and permit or deny packets from crossing specified interfaces. An ACL is a sequential collection of permit and deny conditions that apply to packets. When a packet is received on an interface, the switch compares the fields in the packet against any applied ACLs to verify that the packet has the required permissions to be forwarded, based on the criteria specified in the access lists. It tests packets against the conditions in an access list one by one. The first match determines whether the switch accepts or rejects the packets. Because the switch stops testing conditions after the first match, the order of conditions in the list is critical. If no conditions match, the switch rejects the packets. If there are no restrictions, the switch forwards the packet; otherwise, the switch drops the packet.
Switches traditionally operate at Layer 2 only, switching traffic within a VLAN, whereas routers route traffic between VLANs. The Catalyst 3550 switch with the enhanced multilayer software image installed can accelerate packet routing between VLANs by using Layer 3 switching. The switch bridges the packet, the packet is then routed internally without going to an external router, and then the packet is bridged again to send it to its destination. During this process, the switch can access-control all packets it switches, including packets bridged within a VLAN.
You configure access lists on a router or switch to provide basic security for your network. If you do not configure ACLs, all packets passing through the switch could be allowed onto all parts of the network. You can use ACLs to control which hosts can access different parts of a network or to decide which types of traffic are forwarded or blocked at router interfaces. For example, you can allow e-mail traffic to be forwarded but not Telnet traffic. ACLs can be configured to block inbound traffic, outbound traffic, or both. However, on Layer 2 interfaces, you can only apply ACLs in the inbound direction.
An ACL contains an ordered list of access control entries (ACEs). Each ACE specifies permit or deny and a set of conditions the packet must satisfy in order to match the ACE. The meaning of permit or deny depends on the context in which the ACL is used.
The switch supports two types of ACLs:
•

                               
登录/注册后可看大图
IP ACLs filter IP traffic, including TCP, User Datagram Protocol (UDP), Internet Group Management Protocol (IGMP), and Internet Control Message Protocol (ICMP).
•

                               
登录/注册后可看大图
Ethernet or MAC ACLs filter non-IP traffic.
Supported ACLs
The switch supports three applications of ACLs to filter traffic:
•

                               
登录/注册后可看大图
Router ACLs access-control routed traffic between VLANs and are applied to Layer 3 interfaces. All Catalyst 3550 switches can create router ACLs, but you must have the enhanced multilayer software image on your switch to apply an ACL to a Layer 3 interface and filter packets routed between VLANs.
•

                               
登录/注册后可看大图
Port ACLs access-control traffic entering a Layer 2 interface. The switch does not support port ACLs in the outbound direction. You do not need the enhanced image to apply an ACL to a Layer 2 interface. You can apply only one IP access list and one MAC access list to a Layer 2 interface.
•

                               
登录/注册后可看大图
VLAN ACLs or VLAN maps access-control all packets (bridged and routed). You can use VLAN maps to filter traffic between devices in the same VLAN. You do not need the enhanced image to create or apply VLAN maps. VLAN maps are configured to provide access-control based on Layer 3 addresses for IP. Unsupported protocols are access-controlled through MAC addresses by using Ethernet ACEs. After a VLAN map is applied to a VLAN, all packets (routed or bridged) entering the VLAN are checked against the VLAN map. Packets can either enter the VLAN through a switch port or through a routed port after being routed.
You can use both router ACLs and VLAN maps on the same switch. However, you cannot use port ACLs on a switch that contains input router ACLs or VLAN maps.
•

                               
登录/注册后可看大图
When a switch has a Layer 2 interface with an applied IP access list or MAC access list, you can create IP access lists and VLAN maps, but you cannot apply an IP access list to an input Layer 3 interface on that switch, and you cannot apply a VLAN map to any of the switch VLANs. An error message is generated if you attempt to do so. You can still apply an IP access list to an output Layer 3 interface on a switch with port ACLs.
•

                               
登录/注册后可看大图
When a switch has an input Layer 3 ACL or a VLAN map applied to it, you cannot apply an IP access list or MAC access list to a Layer 2 interface on that switch. An error message is generated if you attempt to do so. You can apply a port ACL if the switch has an ACL applied to an output Layer 3 interface.
捕获.PNG
10# 2011-12-1 10:54:39 回复 收起回复
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-2-4 06:52 , Processed in 0.062705 second(s), 15 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表