Video není dostupné.
Omlouváme se.

MicroNugget: How to Configure Extended ACLs on Cisco Routers

Sdílet
Vložit
  • čas přidán 21. 01. 2013
  • Start learning cybersecurity with CBT Nuggets. courses.cbt.gg/security
    In this video, Jeremy Cioara covers extended ACLs on Cisco routers. ACLs are powerful documents that contain lists of statements that govern which devices can and cannot access other devices. By configuring extended ACLs, you can regulate the traffic on a network and keep traffic moving fast and secure.
    One of the many things that a well-configured extended ACL can do for a network is prevent a given IP address' traffic from reaching another IP address. That's because an extended access list is really nothing more than a document with a row of statements that permit or deny traffic based on rules you can set up. That can be protocol, port number, source, destination, time range, and more.
    When it comes to configuring an extended ACL, just like driving to Disneyland only to discover it's closed would waste time and energy, the best practice is to host extended access lists as close to the source as possible. See how to write rules that identify source IP, its protocol, and the many other filters you can use to manage network traffic with extended ACLs.
    🌐 Download the Free Ultimate Networking Cert Guide: blog.cbt.gg/b942
    ⬇️ 13-Week Study Plan: CCNA (200-301): blog.cbt.gg/8lky
    Start learning with CBT Nuggets:
    • Cisco CCNA (200-301) | courses.cbt.gg/h6s

Komentáře • 98

  • @alirezaabrishami6530
    @alirezaabrishami6530 Před 10 lety +24

    Jeremy, I really love the way you teach Cisco!!!
    Thank You!

  • @mariorodas634
    @mariorodas634 Před 3 lety +3

    Jeremy, i love your videos. I'm studying for SBA for CSCO-220 AND CSCO-221. This video, and one other of yours, has been super helpful in remembering which direction to place acl. Thank you!

  • @gchlion
    @gchlion Před 11 lety

    I just want to say... AMAZING. Jeremy is the best in this of cbt ! He has the ease to explain the stuff in very cool way. NICE!!!

  • @AmazinglyAwkward
    @AmazinglyAwkward Před 5 lety +1

    I'm actually doing a comptia exam not the CCNA but this was still super super helpful, it was definetly more helpful seeing a terminal. Thanks so much!

  • @Three_Dog_Gaming
    @Three_Dog_Gaming Před 4 lety +3

    Definitely valuable! Had a co-worker leave the company that was basically master of all things Cisco and we're trying to interpret what he left us with!

  • @MrAadeyemo
    @MrAadeyemo Před 4 lety

    That was very straight to the point Jeremy and delivered in a not-boring manner.

  • @Gamelover22478
    @Gamelover22478 Před 2 lety

    Thank you so much for the video ! I’m currently in a CNT160 class and ACLS are a struggle for me, we just started implementing NAT so this will help me very much ! Thank you 😁

  • @jeremymayer9221
    @jeremymayer9221 Před 6 lety +1

    From one Jeremy to another! Thank you! Really helped!

  • @El_bigC
    @El_bigC Před 9 lety +1

    Top notch explanation, as always, Jeremy!!

  • @zwimaster
    @zwimaster Před 11 lety

    As always informative! Jeremy's nugget series are the best!

  • @libertywraith249
    @libertywraith249 Před 7 lety

    you are THE MAN Jeremy C . your instruction has been so very effective for me....and apparently everyone i talk to.
    thank you!!!

  • @chrisallen6738
    @chrisallen6738 Před 11 lety

    You are the best video instructor on the web. Keep it up, just the way you are doing it.

  • @cspell
    @cspell Před 8 lety

    well done, nice explanation of how the protocols work together!

  • @seepaknanda3397
    @seepaknanda3397 Před 4 lety

    Jeremy really your teaching method on Cisco is excellent thank you.

  • @adammohamed5757
    @adammohamed5757 Před 6 lety

    Thank you, honestly speaking, you are amazing instructor.

  • @cbtnuggets
    @cbtnuggets  Před 11 lety

    Thanks for the feedback!

  • @florentvespit960
    @florentvespit960 Před 8 lety

    am from africa, i've learned CCNA, but your videos make me understand more and more every days. thanks a lot

  • @incognituadictus2226
    @incognituadictus2226 Před 2 lety

    good and clear explanation, i like the "be the router" analogy!

  • @cbtnuggets
    @cbtnuggets  Před 11 lety

    Mahad, you are correct! This is one of Jeremy's newest MicroNuggets.

  • @robertsmooth6339
    @robertsmooth6339 Před rokem

    HI Jeremy This course on extended ACLs on Cisco routers is very . But it too late me I'm going to retire... Jeremy your awesome teacher and I want to thank you and Micro Nugget for educating
    for those who are pursuing a high advance technology career. Thanks you and even If I retired I continue to login from time to time. I'm Network Engineer

  • @jasonbrussmn
    @jasonbrussmn Před 4 lety

    Wow, just found your channel and this is awesome!

  • @SuijoART
    @SuijoART Před 2 lety

    Really helpfull. I was stuck with ACL. However after listen your explanation I'm ready to work with. Thanks 😃.

  • @Alakion
    @Alakion Před 4 lety

    Thanks for the explanation , helped me a lot ! Cheers!

  • @luizclarke1829
    @luizclarke1829 Před 9 lety +1

    Thank you Jeremy!

  • @WiseK.D
    @WiseK.D Před 3 měsíci

    Jeremy thank you so much you cleared most of my confusion.. I Don't know if you have already done this but can you make a video on acl protocoles I mean all of them and explain their use and how they work . That will be great .

  • @IgorDrozdov4
    @IgorDrozdov4 Před 2 lety +1

    Awesome explanation! Thank you!

  • @chr1smack1nnon
    @chr1smack1nnon Před 11 lety

    Love the explanations. You rock!

  • @dwade_fpv
    @dwade_fpv Před 11 lety

    Great explanation. I really appreciate your wisdom.

  • @MohammadAhmad-nh5ug
    @MohammadAhmad-nh5ug Před 3 lety

    Thanks Jeremy. This was fun.

  • @inkbythebarrelandpaperbyth6905

    Hey CBT nuggets. Jeremy is great. Thanks!

  • @muhammad.rafi2012
    @muhammad.rafi2012 Před 10 lety +3

    Jeremy as nice as ever, can we have micro nugget on applying extended access list for VTY line or console. that would be really helpful for every body i think ..

  • @robertmotz9227
    @robertmotz9227 Před 9 lety

    That was awesome. Thanks Robert P. Motz

  • @gehacktetYKzZY
    @gehacktetYKzZY Před 3 lety

    Thanks Jeremy! It was very informative.

  • @mukunddabholkar4105
    @mukunddabholkar4105 Před 3 lety

    superb!!! explain in simple way.. awsome.

  • @ajaysankar5467
    @ajaysankar5467 Před rokem

    Very Helpful. Thank you.

  • @kaguyakobe
    @kaguyakobe Před 29 dny

    We love this, thanks Jeremy

  • @bobbywaker1793
    @bobbywaker1793 Před 4 lety

    love how u explain it your the best . i wish you do a video for ssh

  • @user-jt5fw4bm4m
    @user-jt5fw4bm4m Před 4 lety

    Perfect explained 🙏

  • @nahomaseged3324
    @nahomaseged3324 Před rokem

    fantastic video. keep it up!

  • @petrithysaj4529
    @petrithysaj4529 Před 3 lety

    Thank you very much. I've my exam coming up fast and you are helping in my passing it.

    • @cbtnuggets
      @cbtnuggets  Před 3 lety +1

      You can do it, Petrit! Good luck on your exam. Thank you for learning with us!

  • @ManojKumar-1985
    @ManojKumar-1985 Před 11 lety

    Great Explanation

  • @YouSSTheMacOSXWannabe
    @YouSSTheMacOSXWannabe Před 11 lety

    thank you Jeremy

  • @ericmorey1460
    @ericmorey1460 Před 11 lety

    Great video.

  • @mlram20055
    @mlram20055 Před 10 lety

    Brilliant!!

  • @HarshvardhanParashar09
    @HarshvardhanParashar09 Před 8 lety +1

    Awesome !

  • @NoONE-bk7ud
    @NoONE-bk7ud Před 2 lety

    that was a good explanation

  • @chaospressure
    @chaospressure Před 10 lety

    This was super helpful. Thanks alot

  • @rabiej8011
    @rabiej8011 Před 3 lety

    Thank you so much, finally that explains it well

  • @AJIN0071981
    @AJIN0071981 Před 7 lety

    jeremy thanks !!!!

  • @NWWalkerMusic
    @NWWalkerMusic Před 7 lety

    Great video! Thanks for posting.
    Any Micro-Nuggets on VLSM?

  • @TheLithGH
    @TheLithGH Před 4 lety

    Thanks Jeremy!! I've always been confused as to when to start an extended access-list with "access-list 100___" or " ip access-list extended 100___" ? Thank you for your assistance!! :-)

  • @nullsemicolon
    @nullsemicolon Před 3 lety

    great video!

    • @cbtnuggets
      @cbtnuggets  Před 3 lety

      Glad you enjoyed it, thank you Sean!

  • @user-ik2ys6wq8r
    @user-ik2ys6wq8r Před 2 lety

    Amazing
    Thanks

  • @odrommouniengue2645
    @odrommouniengue2645 Před 2 lety +1

    thank you sir

  • @cbtnuggets
    @cbtnuggets  Před 11 lety

    Simon, if you would like to know a little more, feel free to request that MicroNugget in the link found in the MicroNugget description.

  • @cbtnuggets
    @cbtnuggets  Před 11 lety

    Thanks for your question! If you would like you can submit a formal request for this MicroNugget from the link above found in the description.

  • @khiderglal8245
    @khiderglal8245 Před 3 lety

    thanx your video is helpfull

  • @AhmedMahmoud-qh7oc
    @AhmedMahmoud-qh7oc Před 6 lety

    This man is great.
    I hope I discovered this channel earlier

  • @kostas8469
    @kostas8469 Před 4 lety +1

    thanks :)

  • @vianneyjean4754
    @vianneyjean4754 Před 3 lety

    Y are the best👏👏👏

  • @pouyameisamifard5804
    @pouyameisamifard5804 Před 5 lety

    you are good at teaching , i really enjoy it thank you ,say more about ip helper when there is subnets and trunking and the router that dhcp pool run on it is not directly connected to this subnets but it is conneted frome the thered router ,i don't know is that logical or possible but i am curious to know that,at ninja speed

  • @sherifflawal7131
    @sherifflawal7131 Před 10 lety

    May God bless you.

  • @ashutoshanand4717
    @ashutoshanand4717 Před 5 lety

    Pretty informative in brief.... would like to know about 1) Internet of things 2) SDN in brief

  • @MrSenicho
    @MrSenicho Před 4 lety

    Hey Jeremy , thanks for the video, I 'd love to see if you can show me how i can access my local webapp hosted locally in my local area network from the internet, i have CISCO 2900 router, and i have public IP. thanks in advance.

  • @habibkhayat1725
    @habibkhayat1725 Před 2 lety

    Thanks Jeremy. You make Networking world much easier to understand. We miss instructor like you in Cyber Security. Hope you get into that field like Kieth Barker.

  • @187MIAMIBOY
    @187MIAMIBOY Před 9 lety

    Thank you so much. I'm taking SEC450 and dealing with ACLs right now. This has helped me understand it a bit much better. The only thing I can't get around is the "3P" rule.. How would you do one protocol per access list etc..?

    • @cbtnuggets
      @cbtnuggets  Před 9 lety

      187MIAMIBOY One protocol means IP protocol (vs. IPX, Appletalk, etc...). Not one protocol as in UDP, TCP, ICMP, etc... You can handle "limitless" IP-based protocols within the access-list. We hope that helps!

  • @ikiyytours2320
    @ikiyytours2320 Před rokem

    i liked it.

  • @achrafelkhandouli
    @achrafelkhandouli Před 4 lety

    godbless

  • @Asudragon
    @Asudragon Před 2 měsíci

    quick question i am struggling to find answer to, what is the general thought on when to use standard ACL compared to extended? wouldnt a standard ACL where you deny that specific traffic and permitting the rest work as well?

  • @aniswlidi2012
    @aniswlidi2012 Před rokem

    Hi Jeremy. I uses alpha prep but there was no configuration questions, only multichoice questions. Is the new CCNA exam consisting of multichoice questions only?

  • @mihaiciobanu6804
    @mihaiciobanu6804 Před 3 lety

    How do you test the http or https ACL in packet tracer?

  • @TheSingleNotice
    @TheSingleNotice Před rokem

    Hi Jeremy, thank you for this. I am working on a problem with requires me to limit http/https traffic (as shown in your video) but only when an ip address is even. I know this would be with the use of wildcard masks, but can you give an example please? I then need to how that http does not connect but all other traffic does. How would I showcase this please?
    Many thanks

  • @tayyabali5352
    @tayyabali5352 Před 3 lety

    what if i have two routers both having a switch attached to there fa0/0 ports and those switches then have atleast two end devies(pc) connected with them. Now i want to block a single pc of 1st router for communicating with a single pc of the 2nd router. How can i do that?

  • @rakibuzzamansikdar6367

    respect

  • @GuiltySpark
    @GuiltySpark Před 11 lety

    This Nugget Good for u

  • @mahadabdilahi3958
    @mahadabdilahi3958 Před 11 lety

    i think this nugget is one of the new CCNA series produced by great instructor jeremy ciora am i right ?

  • @delson007.
    @delson007. Před 2 lety

    yo jeremy, ive been trying to figure this out but i cant find anything about it, once you apply the extended access list to the interface, is there a way to delete that?

    • @400EMP
      @400EMP Před 2 lety

      Yes, with many commands in Cisco, the best way to remove a configuration is to use the "No" command before the statement. In this case: "no access-list 150" should remove the ACL in its entirety

  • @ralph_022
    @ralph_022 Před 10 lety

    Thanks !!!!! How do you deny a network from rehashing another network using extended ??? Ex deny network 192.168.2.0 - 192.168.2.63 from pinging network 192.168.3.0. Please help

    • @cbtnuggets
      @cbtnuggets  Před 10 lety

      ralph restituyo We recommend asking these types of questions on our Forum to get other members of the CBT Nuggets community involved: community.cbtnuggets.com/forums

  • @cnxduo65
    @cnxduo65 Před 9 lety

    Hey dude;
    Have any VOD's on how to use object oriented ACL's on say Cisco 2911 routers?
    Thanks >:-}

    • @cbtnuggets
      @cbtnuggets  Před 9 lety

      cnxduo65 Thanks for the comment! We do not have a specific object oriented ACL for Cisco's 2911 routers MicroNugget but we have passed along your request for future recording possibilities.

  • @newphone3594
    @newphone3594 Před 3 lety

    I need help with advanced ACL. can someone help please?

  • @prodfc3140
    @prodfc3140 Před 3 měsíci

    Epic

  • @Johnson14207
    @Johnson14207 Před 2 měsíci

    It gets little complicated when applied in and out to a VLAN interface

  • @jasperrava5885
    @jasperrava5885 Před rokem

    Can you ping it.

  • @elliotgaulin5217
    @elliotgaulin5217 Před 3 lety

    Saving my ass for my exam toworrow

    • @cbtnuggets
      @cbtnuggets  Před 3 lety

      Best of luck, Elliot! You got this.

  • @simbadurio444
    @simbadurio444 Před 2 lety

    Why not create an actual lab and show us how it first allowed and then blocked? Still a good video, thanks.

  • @mdridoy9896
    @mdridoy9896 Před rokem

    awesome video... but it's too quick... hahaha

  • @SaigoRyu
    @SaigoRyu Před 9 lety

    Very valuable. Thank you. Try to speak a little slower please.