Soluciones integrales de TI inteligentes

dw@donewin.com.hk |

DoestheuseofextendedIPaccesscontrollists(ACL)filterregularroutingupdates(suchasOSPF)?DoIneedtoexplicitlypermitthemulticastIPsusedbyroutingprotocols(suchas224.0.0.5and224.0.0.6,inthecaseofOSPF)forupdatestoensuretheproperworkingofroutingprotocols?

Preguntas frecuentes sobre los enrutadores de CiscoPreguntas frecuentes

Does the use of extended IP access control lists (ACL) filter regular routing updates (such as OSPF)? Do I need to explicitly permit the multicast IPs used by routing protocols (such as 224.0.0.5 y 224.0.0.6, in the case of OSPF) for updates to ensure the proper working of routing protocols?

Any IP ACL on an interface is applied to any IP traffic on that interface. All IP routing updates packets are handled as regular IP packets at the interface level, y, thus, they are matched with the ACL defined at the interface using the access-listcommand. To ensure that the routing updates are not denied by ACLs, permit them using the following statements.

To permit RIP use:

lista de acceso 102 permit udp any any eq rip

To permit IGRP use:

lista de acceso 102 permit igrp any any

To permit EIGRP use:

lista de acceso 102 permit eigrp any any

To permit OSPF use:

lista de acceso 102 permit ospf any any

To permit Border Gateway Protocol (BGP) usar:

lista de acceso 102 permit tcp any any eq 179 lista de acceso 102 permit tcp any eq 179 cualquier

For more information on ACLs, refer to Configuring IP Access Listsand Configuring Commonly Used IP ACLs.

Anterior:

Próximo:

Deja una respuesta

Chat en vivo
Dejar un mensaje

    5 + 2 =