Home > CCNA Access List Sim 2

CCNA Access List Sim 2

February 15th, 2014 Go to comments

Question

access_list_sim2.jpg

Answer and Explanation

(Note: If you are not sure how to use access-list, please check out my access-list tutorial at: https://www.9tut.com/access-list-tutorial, also some modifications about the access-list have been reported so you should read the “Some modifications” section at the end of this question to understand more. You can also download this sim to practice (open with Packet Tracer) here: https://www.9tut.com/download/9tut.com_Access-list_sim2.zip

Corp1>enable (you may enter “cisco” as it passwords here)

We should create an access-list and apply it to the interface which is connected to the Server LAN because it can filter out traffic from both Sw-2 and Core networks. The Server LAN network has been assigned addresses of 172.22.242.17 – 172.22.242.30 so we can guess the interface connected to them has an IP address of 172.22.242.30 (.30 is the number shown in the figure). Use the “show running-config” command to check which interface has the IP address of 172.22.242.30.

Corp1#show running-config

access_list_sim_show_running.jpg

We learn that interface FastEthernet0/1 is the interface connected to Server LAN network. It is the interface we will apply our access-list (for outbound direction).

Corp1#configure terminal

Our access-list needs to allow host C – 192.168.33.3 to the Finance Web Server 172.22.242.23 via web (port 80)

Corp1(config)#access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80

Deny other hosts access to the Finance Web Server via web

Corp1(config)#access-list 100 deny tcp any host 172.22.242.23 eq 80

All other traffic is permitted

Corp1(config)#access-list 100 permit ip any any

Apply this access-list to Fa0/1 interface (outbound direction)

Corp1(config)#interface fa0/1
Corp1(config-if)#ip access-group 100 out

Notice: We have to apply the access-list to Fa0/1 interface (not Fa0/0 interface) so that the access-list can filter traffic coming from both the LAN and the Core networks. If we apply access list to the inbound interface we can only filter traffic from the LAN network.

In the exam, just click on host C to open its web browser. In the address box type http://172.22.242.23 to check if you are allowed to access Finance Web Server via HTTP or not. If your configuration is correct then you can access it.

Click on other hosts (A, B and D) and check to make sure you can’t access Finance Web Server from these hosts.

Finally, save the configuration

Corp1(config-if)#end
Corp1#copy running-config startup-config

(This configuration only prevents hosts from accessing Finance Web Server via web but if this server supports other traffic – like FTP, SMTP… then other hosts can access it, too.)

Notice: You might be asked to allow other host (A, B or D) to access the Finance Web Server so please read the requirement carefully.

Some modifications (mods):

Modification 1 (Mod 1):

permit host B from accessing finance server access-list 100 permit ip host 192.168.33.2 host 172.22.242.23
deny host B from accessing other servers (not the whole network) access-list 100 deny ip host 192.168.33.2 172.22.242.16 0.0.0.15
permit everything else access-list 100 permit ip any any

Modification 2 (Mod 2):

Only allow Host C to to access the financial server access-list 100 permit ip host 192.168.33.3 host 172.22.242.23
Not allow anyone else in any way communicate with the financial server access-list 100 deny ip any host 172.22.242.23
Allow all other traffic access-list 100 permit ip any any

Modification 3 (Mod 3):

– Host C should be able to use a web browser(HTTP)to access the Finance Web Server access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80
– Other types of access from host C to the Finance Web Server should be blocked
– All access from hosts in the Core or local LAN to the Finance Web Server should be blocked
access-list 100 deny ip any host 172.22.242.23
(because the requirement says we can not use more than 3 statements so we have to use “any” here for the hosts in the Core and hosts in local LAN)
– All hosts in the Core and local LAN should be able to access the Public Web Server * access-list 100 permit ip any host
(If the question asks this, surely it has to give you the IP of Public Web Server) but in the exam you should use “access-list 100 permit ip any any”

Modification 4 (Mod 4):

Host C should be able to use a web browser to access the financial web server access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80
Other types of access from host C to the finance web server should be blocked access-list 100 deny ip host 192.168.33.3 host 172.22.242.23
All hosts in the core and on the local LAN should be able to access the Public web server * access-list 100 permit ip any host
(The IP of Public Web Server will surely be given in this question) but in the exam you should use “access-list 100 permit ip any any”

* There are some reports about the command of “All hosts in the core and on the local LAN should be able to access the Public web server” saying that the correct command should be “access-list 100 permit ip any any”, not “access-list 100 permit ip any host (IP of Public Web Server)”. Although I believe the second command is better but maybe you should use the first command “access-list 100 permit ip any any” instead as some reports said they got 100% when using this command (even if the question gives you the IP address of Public Web Server). It is a bug in this sim.

(Note: Don’t forget to apply this access list to the suitable interface or you will lose points
interface fa0/1
ip access-group 100 out

And in the exam, they may slightly change the requirements, for example host A, host B instead of host C… so make sure you read the requirement carefully and use the access-list correctly)

I created this sim in Packet Tracer v5.2.1 so you can practice with it. You will need new version of Packet Tracer to open it (v5.1+).

accesslist_sim2_packet_tracer.jpg

Download this sim here

Notice: After typing the commands above, if you make a “ping” from other hosts (PC0, PC1, PC3) then PC4 (Finance Web Server) can still reply because we just filter HTTP traffic, not ICMP traffic. To generate HTTP traffic, select “Web Browser” in the “Desktop” tab of these PCs. When a web browser opens, type the IP address of Finance Web Server and you can see how traffic flows in Simulation Mode.

accesslist2_test_http.jpg

And notice that in the initial configuration of this sim the Core network can ping Finance Web Server. We have to create an access-list that can filter this traffic too.

Comments
Comment pages
1 93 94 95 41
  1. rhgondo
    November 7th, 2018

    People, What lab do you have in the ccna 200-125 exam?

  2. Simon
    November 27th, 2018

    hi all please send the latest dump at sopprusbarbosa at gmail dot com

  3. Ezxprt
    December 31st, 2018

    For CCNA exam preparation solved lab simulation dumps with software
    Contact

    shafqaatmehmood gmail com

  4. Costi
    January 8th, 2019

    @simon, I think here is a tricky situation because if we’ll use the syntax:
    access-list 100 permit ip any host *****, all other traffic will be blocked (the last ACE –> deny ip any any), except that comes from the ACEs we configured so far, includely to the DNS Server, for example, but the querry isn’t about blocking all other traffic, so I think it’s more suitable that we use “access-list 100 permit ip any any”

  5. Mozelle Bolinger
    January 17th, 2019

    Look at online reviews ᧐f these car ɑnd model tо understand what wⲟrks, what ԁoesn’t,and tһɑt ᴡhich уoս mɑy haᴠe а mucһ prⲟblems witһ.

    Tһey can usᥙally alplow yoս t᧐ narrow things dоwn shoᥙld yоu llet them
    кnow hatever you’re looking for. Ιf you cɑn do then looқ іnto thе credenfials in the professionals frpm tһe company.

  6. Mubashira
    January 21st, 2019

    I am planning to write CCNA routing and switching Exam , from where I will get the dumps ?
    if anybody has the dump please contact me on {email not allowed}

  7. ROBOCUPS
    January 26th, 2019

    I already pass my CCNA R&S 200-125, For you to help here’s the topic that i recieve

    LABS: VLAN
    Simlet: EIGRP Neighbor,OSPF,GRE TUNNEL, ACL
    Drag and drop: TCP/UDP and BGP

    Chinese dumps are good in my exam!!!

    TIAO

  8. Bojan
    February 8th, 2019

    Hi, where I can find that Chinese dumps? Answer here. Regards

  9. Anonymous
    February 12th, 2019

    helo friends please any one can help me latest dumps . it is very humble request send me at “asbc at hotmail dot co dot uk.

  10. VCE PLAYER LASTES VERSİON
    February 19th, 2019

    does anyone has last of VCE exam simulation setup with crack ???? could you send me mail please..

    halilalban at outlook dat com

  11. Modification 1 (Mod 1):
    March 6th, 2019

    Please can somebody please explain how they got the access-list for Modification 1 (Mod 1):

    deny host B from accessing other servers (not the whole network)
    access-list 100 deny ip host 192.168.33.2 172.22.242.16 0.0.0.15

    I’m more interested on how they summarised and came about the ip address and the wildcard (172.22.242.16 0.0.0.15) mask

    Thank you

  12. access-list 100 deny ip host
    March 9th, 2019

    access-list 100 deny ip host 192.168.33.2 172.22.242.16 0.0.0.15
    How should i know that this config block the host from accessing the 2 web server. Can you explain this? i can’t work it out?

  13. George
    March 20th, 2019

    why the number of the acl is “100”?

  14. Glenn
    March 21st, 2019

    @George,

    because you need extended ACL’s. -> 100-199 , 2000-2699

  15. jim
    March 27th, 2019

    is the web server the source?
    i know that extended acl is near to source so…
    is the reason that you put the acl near of source?

  16. Arash
    March 28th, 2019

    172.22.242.16 0.0.0.15 is the destination. It seems like all servers have IP addresses between 172.22.242.17 – 172.22.242.30. this ACL blocks all IP traffic from host 192.168.33.2 to the range of 172 IPs mentioned earlier. you will place this ACL closest to source host of 192.168.33.2

  17. bill
    April 8th, 2019

    just incase some people are not aware. in 2016, cisco revised the exam topics. the topic of frame relay has been dropped completely. so we dont have to learn that :)

  18. Access List
    April 15th, 2019

    Why the access list was set OUT on the interface FA0/1??

    EXTEND ACL shouldn’t be set closer to the source ?? For me makes more sense set it at FA0/0 IN

    Can anyone explain it

  19. Access List
    April 15th, 2019

    Ok I got it. Because of the incoming data from the CoreRouter

  20. Anonymous
    April 19th, 2019

    Why this ip address 172.22.242..23 for finance web server?
    Is this address given in question??

  21. bill
    April 23rd, 2019

    ICND2 exam next monday :( pray for me

  22. bill
    April 29th, 2019

    hi all. had my CCNA ICND2 exam today. passed.scored 866. 811 is pass mark.55 questions. i struggled and had real concerns i would fail. loads of new multiple choice questions. EIGRP troubleshoot sim was in it. exact same question and answers as far as I saw. also GRE Sim with tunnel stuff was in it. had different answers, like error within the multi link config. multi link group looked fine, except in one interface where multi link was configured, there was no ip address configured. so i just guessed and chose answer about incorrect ip address in multi link on router. question about tunnel error, had different ip configurations. guessed one or 2 answers as worried i would run out of time. there was one nasty question about AAA/TACACS+ whole page of server config, username and passwords, and asks what outcome of this config will be, user account with local server or RADIUS server?

    saw 3 drag and drops. i didnt pay much attention to drag and drops lol so it gave me trouble. saw new drag and drops that were not in dump, one about cloud service, order in which user requests services from provider. as well as one for difference between LACP and PAGP etherchannel stuff. ended up guessing. also drag and drop about the EIGRP k values, and match them to correct ones. K1, K2, K3,K4/K5 and match to answers like bandwidth, load, reliability, delay, MTU. more guess work.

    ———–

    there was ACL question, asking where to put standard ACL in diagram, if you want PC A to connect to PC c. but want to stop PC B from accessing PC. guessed more or less lol. tried following rule of placing standard ACL as close as possible to destination.

  23. Lou
    May 3rd, 2019

    To Bill,How many Questions where there as lab/sim in that IND2 exam

  24. Lou
    May 3rd, 2019

    To Bill, I meant that did you configure any labs at all

  25. bill
    May 9th, 2019

    @Lou. I did not configure anything. for the 2 sims that i had in exam, it just asked to do show commands in switch/router, then answer the questions. so i just clicked on router/switch and did show run/show ip int brief etc, to find answers.

  26. hi people
    May 11th, 2019

    Why this ip address 182.22.242..24 for finance web server?

  27. kookoo
    May 12th, 2019

    is this only in CCNA or ICND2 as well

  28. Moustafa
    May 12th, 2019

    nice man
    any one have last dump for ccna
    send me on email please

  29. bill
    May 13th, 2019

    @kookoo, it could show up in either icnd2 or combined exam. i did icnd2 but didnt get this sim.

    in ICND2, ACL’s are listed in the exam topics:

    Configure, verify, and troubleshoot IPv4 and IPv6 access list for traffic filtering

    4.4.a Standard
    4.4.b Extended
    4.4.c Named

  30. bill
    May 13th, 2019

    @Why this ip address 182.22.242..24 for finance web server?

    in the exam the ip addresses may be completely different for all the servers and networks. so just have to go with whatever your given.

  31. Hafa
    May 13th, 2019

    @Moustafa: I have lasted dump. You can contact me: cisco4career(at)gmail(dot)com

  32. Learner
    May 21st, 2019

    Hi does anyone notice that the ACL sim practice with downloaded packet tracer link https://www.9tut.com/download/9tut.com_Access-list_sim2.zip not showing no IP address configured with Fa0/0 and / Fa0/1? it is showing no IP address, duplex auto, speed auto, and port is shutdown mode. Also if I tried to check the Host C is able to access Finance web server after the configuration as above in the training and examination, but showing time out at the after type http://172.22.242.23 in the address box.

  33. Simon
    June 17th, 2019

    Hi All,

    Please can please send me the latest dump?
    sopprusbarbosa at gmail dot com

  34. Jerry
    June 22nd, 2019

    Congratulations!!!

    I passed 200-125 test with score 9xx!

    Drag and drop questions: 3, 21, 26, 36, 37, 38
    Experimental question: vlan-ts eigrp-gre acl-1

    Cisco will change in 2020, the guys who want to take the exam should hurry.

    So go to the exam as soon as possible!

    Good luck!

    P:pass
    H:hot
    at PH dooooooooot com

  35. bill
    June 24th, 2019

    just had a look, new exams seems to focus more on wireless setting, WPA2 PSK protocols etc
    5.9 Describe wireless security protocols (WPA, WPA2, and WPA3)

    5.10 Configure WLAN using WPA2 PSK using the GUI

    6.6 Recognize the capabilities of configuration management mechanisms Puppet, Chef, and Ansible.

    6.7 Interpret JSON encoded data

    lookd like they taken out EIGRP/BGP routing protocols. only have OSPF V2, IPV4/V6

Comment pages
1 93 94 95 41
Add a Comment