CCNA Access List Sim 2
Question
Answer and Explanation
(Note: If you are not sure how to use access-list, please check out my access-list tutorial at: https://www.9tut.com/access-list-tutorial, also some modifications about the access-list have been reported so you should read the “Some modifications” section at the end of this question to understand more. You can also download this sim to practice (open with Packet Tracer) here: https://www.9tut.com/download/9tut.com_Access-list_sim2.zip
Corp1>enable (you may enter “cisco” as it passwords here)
We should create an access-list and apply it to the interface which is connected to the Server LAN because it can filter out traffic from both Sw-2 and Core networks. The Server LAN network has been assigned addresses of 172.22.242.17 – 172.22.242.30 so we can guess the interface connected to them has an IP address of 172.22.242.30 (.30 is the number shown in the figure). Use the “show running-config” command to check which interface has the IP address of 172.22.242.30.
Corp1#show running-config
We learn that interface FastEthernet0/1 is the interface connected to Server LAN network. It is the interface we will apply our access-list (for outbound direction).
Corp1#configure terminal
Our access-list needs to allow host C – 192.168.33.3 to the Finance Web Server 172.22.242.23 via web (port 80)
Corp1(config)#access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80
Deny other hosts access to the Finance Web Server via web
Corp1(config)#access-list 100 deny tcp any host 172.22.242.23 eq 80
All other traffic is permitted
Corp1(config)#access-list 100 permit ip any any
Apply this access-list to Fa0/1 interface (outbound direction)
Corp1(config)#interface fa0/1
Corp1(config-if)#ip access-group 100 out
Notice: We have to apply the access-list to Fa0/1 interface (not Fa0/0 interface) so that the access-list can filter traffic coming from both the LAN and the Core networks. If we apply access list to the inbound interface we can only filter traffic from the LAN network.
In the exam, just click on host C to open its web browser. In the address box type http://172.22.242.23 to check if you are allowed to access Finance Web Server via HTTP or not. If your configuration is correct then you can access it.
Click on other hosts (A, B and D) and check to make sure you can’t access Finance Web Server from these hosts.
Finally, save the configuration
Corp1(config-if)#end
Corp1#copy running-config startup-config
(This configuration only prevents hosts from accessing Finance Web Server via web but if this server supports other traffic – like FTP, SMTP… then other hosts can access it, too.)
Notice: You might be asked to allow other host (A, B or D) to access the Finance Web Server so please read the requirement carefully.
Some modifications (mods):
Modification 1 (Mod 1):
permit host B from accessing finance server | access-list 100 permit ip host 192.168.33.2 host 172.22.242.23 |
deny host B from accessing other servers (not the whole network) | access-list 100 deny ip host 192.168.33.2 172.22.242.16 0.0.0.15 |
permit everything else | access-list 100 permit ip any any |
Modification 2 (Mod 2):
Only allow Host C to to access the financial server | access-list 100 permit ip host 192.168.33.3 host 172.22.242.23 |
Not allow anyone else in any way communicate with the financial server | access-list 100 deny ip any host 172.22.242.23 |
Allow all other traffic | access-list 100 permit ip any any |
Modification 3 (Mod 3):
– Host C should be able to use a web browser(HTTP)to access the Finance Web Server | access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80 |
– Other types of access from host C to the Finance Web Server should be blocked – All access from hosts in the Core or local LAN to the Finance Web Server should be blocked |
access-list 100 deny ip any host 172.22.242.23 (because the requirement says we can not use more than 3 statements so we have to use “any” here for the hosts in the Core and hosts in local LAN) |
– All hosts in the Core and local LAN should be able to access the Public Web Server * | access-list 100 permit ip any host (If the question asks this, surely it has to give you the IP of Public Web Server) but in the exam you should use “access-list 100 permit ip any any” |
Modification 4 (Mod 4):
Host C should be able to use a web browser to access the financial web server | access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80 |
Other types of access from host C to the finance web server should be blocked | access-list 100 deny ip host 192.168.33.3 host 172.22.242.23 |
All hosts in the core and on the local LAN should be able to access the Public web server * | access-list 100 permit ip any host (The IP of Public Web Server will surely be given in this question) but in the exam you should use “access-list 100 permit ip any any” |
* There are some reports about the command of “All hosts in the core and on the local LAN should be able to access the Public web server” saying that the correct command should be “access-list 100 permit ip any any”, not “access-list 100 permit ip any host (IP of Public Web Server)”. Although I believe the second command is better but maybe you should use the first command “access-list 100 permit ip any any” instead as some reports said they got 100% when using this command (even if the question gives you the IP address of Public Web Server). It is a bug in this sim.
(Note: Don’t forget to apply this access list to the suitable interface or you will lose points
interface fa0/1
ip access-group 100 out
And in the exam, they may slightly change the requirements, for example host A, host B instead of host C… so make sure you read the requirement carefully and use the access-list correctly)
I created this sim in Packet Tracer v5.2.1 so you can practice with it. You will need new version of Packet Tracer to open it (v5.1+).
Download this sim here
Notice: After typing the commands above, if you make a “ping” from other hosts (PC0, PC1, PC3) then PC4 (Finance Web Server) can still reply because we just filter HTTP traffic, not ICMP traffic. To generate HTTP traffic, select “Web Browser” in the “Desktop” tab of these PCs. When a web browser opens, type the IP address of Finance Web Server and you can see how traffic flows in Simulation Mode.
And notice that in the initial configuration of this sim the Core network can ping Finance Web Server. We have to create an access-list that can filter this traffic too.
People, What lab do you have in the ccna 200-125 exam?
hi all please send the latest dump at sopprusbarbosa at gmail dot com
For CCNA exam preparation solved lab simulation dumps with software
Contact
shafqaatmehmood gmail com
@simon, I think here is a tricky situation because if we’ll use the syntax:
access-list 100 permit ip any host *****, all other traffic will be blocked (the last ACE –> deny ip any any), except that comes from the ACEs we configured so far, includely to the DNS Server, for example, but the querry isn’t about blocking all other traffic, so I think it’s more suitable that we use “access-list 100 permit ip any any”
Look at online reviews ᧐f these car ɑnd model tо understand what wⲟrks, what ԁoesn’t,and tһɑt ᴡhich уoս mɑy haᴠe а mucһ prⲟblems witһ.
Tһey can usᥙally alplow yoս t᧐ narrow things dоwn shoᥙld yоu llet them
кnow hatever you’re looking for. Ιf you cɑn do then looқ іnto thе credenfials in the professionals frpm tһe company.
I am planning to write CCNA routing and switching Exam , from where I will get the dumps ?
if anybody has the dump please contact me on {email not allowed}
I already pass my CCNA R&S 200-125, For you to help here’s the topic that i recieve
LABS: VLAN
Simlet: EIGRP Neighbor,OSPF,GRE TUNNEL, ACL
Drag and drop: TCP/UDP and BGP
Chinese dumps are good in my exam!!!
TIAO
Hi, where I can find that Chinese dumps? Answer here. Regards
helo friends please any one can help me latest dumps . it is very humble request send me at “asbc at hotmail dot co dot uk.
does anyone has last of VCE exam simulation setup with crack ???? could you send me mail please..
halilalban at outlook dat com
Please can somebody please explain how they got the access-list for Modification 1 (Mod 1):
deny host B from accessing other servers (not the whole network)
access-list 100 deny ip host 192.168.33.2 172.22.242.16 0.0.0.15
I’m more interested on how they summarised and came about the ip address and the wildcard (172.22.242.16 0.0.0.15) mask
Thank you
access-list 100 deny ip host 192.168.33.2 172.22.242.16 0.0.0.15
How should i know that this config block the host from accessing the 2 web server. Can you explain this? i can’t work it out?
why the number of the acl is “100”?
@George,
because you need extended ACL’s. -> 100-199 , 2000-2699
is the web server the source?
i know that extended acl is near to source so…
is the reason that you put the acl near of source?
172.22.242.16 0.0.0.15 is the destination. It seems like all servers have IP addresses between 172.22.242.17 – 172.22.242.30. this ACL blocks all IP traffic from host 192.168.33.2 to the range of 172 IPs mentioned earlier. you will place this ACL closest to source host of 192.168.33.2
just incase some people are not aware. in 2016, cisco revised the exam topics. the topic of frame relay has been dropped completely. so we dont have to learn that :)
Why the access list was set OUT on the interface FA0/1??
EXTEND ACL shouldn’t be set closer to the source ?? For me makes more sense set it at FA0/0 IN
Can anyone explain it
Ok I got it. Because of the incoming data from the CoreRouter
Why this ip address 172.22.242..23 for finance web server?
Is this address given in question??
ICND2 exam next monday :( pray for me
hi all. had my CCNA ICND2 exam today. passed.scored 866. 811 is pass mark.55 questions. i struggled and had real concerns i would fail. loads of new multiple choice questions. EIGRP troubleshoot sim was in it. exact same question and answers as far as I saw. also GRE Sim with tunnel stuff was in it. had different answers, like error within the multi link config. multi link group looked fine, except in one interface where multi link was configured, there was no ip address configured. so i just guessed and chose answer about incorrect ip address in multi link on router. question about tunnel error, had different ip configurations. guessed one or 2 answers as worried i would run out of time. there was one nasty question about AAA/TACACS+ whole page of server config, username and passwords, and asks what outcome of this config will be, user account with local server or RADIUS server?
saw 3 drag and drops. i didnt pay much attention to drag and drops lol so it gave me trouble. saw new drag and drops that were not in dump, one about cloud service, order in which user requests services from provider. as well as one for difference between LACP and PAGP etherchannel stuff. ended up guessing. also drag and drop about the EIGRP k values, and match them to correct ones. K1, K2, K3,K4/K5 and match to answers like bandwidth, load, reliability, delay, MTU. more guess work.
———–
there was ACL question, asking where to put standard ACL in diagram, if you want PC A to connect to PC c. but want to stop PC B from accessing PC. guessed more or less lol. tried following rule of placing standard ACL as close as possible to destination.
To Bill,How many Questions where there as lab/sim in that IND2 exam
To Bill, I meant that did you configure any labs at all
@Lou. I did not configure anything. for the 2 sims that i had in exam, it just asked to do show commands in switch/router, then answer the questions. so i just clicked on router/switch and did show run/show ip int brief etc, to find answers.
Why this ip address 182.22.242..24 for finance web server?
is this only in CCNA or ICND2 as well
nice man
any one have last dump for ccna
send me on email please
@kookoo, it could show up in either icnd2 or combined exam. i did icnd2 but didnt get this sim.
in ICND2, ACL’s are listed in the exam topics:
Configure, verify, and troubleshoot IPv4 and IPv6 access list for traffic filtering
4.4.a Standard
4.4.b Extended
4.4.c Named
@Why this ip address 182.22.242..24 for finance web server?
in the exam the ip addresses may be completely different for all the servers and networks. so just have to go with whatever your given.
@Moustafa: I have lasted dump. You can contact me: cisco4career(at)gmail(dot)com
Hi does anyone notice that the ACL sim practice with downloaded packet tracer link https://www.9tut.com/download/9tut.com_Access-list_sim2.zip not showing no IP address configured with Fa0/0 and / Fa0/1? it is showing no IP address, duplex auto, speed auto, and port is shutdown mode. Also if I tried to check the Host C is able to access Finance web server after the configuration as above in the training and examination, but showing time out at the after type http://172.22.242.23 in the address box.
Hi All,
Please can please send me the latest dump?
sopprusbarbosa at gmail dot com
just had a look, new exams seems to focus more on wireless setting, WPA2 PSK protocols etc
5.9 Describe wireless security protocols (WPA, WPA2, and WPA3)
5.10 Configure WLAN using WPA2 PSK using the GUI
6.6 Recognize the capabilities of configuration management mechanisms Puppet, Chef, and Ansible.
6.7 Interpret JSON encoded data
lookd like they taken out EIGRP/BGP routing protocols. only have OSPF V2, IPV4/V6
@bill are these new topics supposed to be in the exams now or in 2020? I have my exam day after tomorrow, what exactly should i prepare for these topics if they are coming this year itself?
@Tanvi, he’s meaning about the new exams in 2020
@Tanvi, ignore my post for now, those are new topics for the new CCNA exam in 2020. you can check the cisco icnd 1 and 2 pages, lists the current exam topics
Hi everyone, please comment if anyone who give exam recently whether 9TUT site is enough to pass 200-125 please?
Modification 1 (Mod 1):
Hello, deny host B from accessing other servers (not the whole network)
access-list 100 deny ip host 192.168.33.2 172.22.242.16 0.0.0.15 –
– not quite right, it deny whole area ip address(16-31).
More true be wildcard mask – 0.0.0.7(deny 16-23 ip address) .
More more true be wildcard mask – 0.0.0.5 (deny 16,17,20,21)
Hi All,
Please can please send me the latest dump?
sopprusbarbosa at gmail dot com
Hi All,
Please can please send me the latest dump?
sopprusbarbosa at gmail dot com
If I do like this, is it ok?
access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq www
access-list 100 permit ip any host 172.22.242.24
and use implicit deny for others
Hi Guys, this was on the exam today.
passed exam
it was here
@anon can u give me latest dumps?
Hi could anyone please be so kind and send me latest dumps to timprove @ pm.me
Thank you.
My seven Students Passed the CCNA 200 125 Exam, If any one want Latest Dumps and Lab with any kind of troubleshooting service is available contact us.
networkexpert125 @ gmail dot com
I did the exam yesterday. Passed with 865. I got this simulation, “EIGRP Troubleshooting Sim” simlet,”CCNA Access List Sim” simlet and 7 Drag and Drops. Please practice al the sims and Drag & drops before the exam. other questions also much similar to the dumps.