Categories
Welcome Center
Education & Development
Discussions
Certification Preparation
Recent Posts
Groups
Free Resources
Ebooks
Free Workshops
Trending Certifications Infographic
Infosec Training
IT & Security Training
Live Boot Camps
Security Awareness Training
About Infosec Institute
Home
Certification Preparation
Cisco
CCST & CCNA (Entry-level & Associate)
where to put the access list ( source/destination issues)
x_Danny_x
for standard access list i know you put them at the destination interface and while excess access lists you put them at the source interface.
well there has been exceptions where I saw a standard list being implement at the source interface in my New Horizons Cisco book. I dont understand why it was done that way.
Are there exceptions to this rule???
Find more posts tagged with
Save $250 on 2025 certification boot camps from Infosec!
Book now with code EOY2025
Button
Comments
EdTheLad
You can place standard or extended access-lists where ever you like.
But it makes more sense to place the standard access-list as close to the destination as possible! Why?? because the standard access-list can only filter using the source ip address.If it is placed near the source you may limit this source ip address for your entire network rather than for a particular destination.So depending on what access you want to provide for the source address relates to where you place the access-list.
The extended access-list is more specific on what you filter so by placing this at the source you will only effect what you specify in the list and nothing else.By placing this as near the source as possible conserves bandwidth.So to sum up,wherever you place the access-lists depends on your network, and the rule you stated above is just a good design guide, which should make sense if you think about it!
x_Danny_x
alright man thanks. I ment to say extended and not excess. heheheh
Quick Links
All Categories
Recent Posts
Activity
Unanswered
Groups
Best Of
INFOSEC Boot Camps
$250
OFF
Use code
EOY2025
to receive $250 off your 2025 certification boot camp!
BROWSE BOOT CAMPS