Options

ACL question

froufrou123froufrou123 Member Posts: 29 ■□□□□□□□□□
Hey guys,

I'm reading Wendell Odom's ICND2 and was going over this example at page 242, figure 6-3.

He answers the example completely in Example 6-5 at pg 243. He suggested outbound ACL on Yosemite's s0 and s1 to prevent sam from reaching Bugs or Duffy.

Now, my question is: Wouldn't it be more efficient to implement an outbound ACL on Albuquerque's E0 interface? This way if the link between Yose. and Sev. goes down, Sam would still be able to reach Sev.

Also, I think I remember the author saying that when it comes to standard ACL, always apply ACLs on the nearest interface to destination, which in this case should be Albuquerque's E0 interface anyway.

I hope someone could clarify

Thanks

Comments

Sign In or Register to comment.