Skip to Content
Network Warrior
book

Network Warrior

by Gary A. Donahue
June 2007
Intermediate to advanced
600 pages
18h 19m
English
O'Reilly Media, Inc.
Content preview from Network Warrior

Chapter 23. Access Lists

The technical name for an access list is access-control list, or ACL. The individual entries in an access-control list are called access-control entries, or ACEs. The term access-control list isn't often used in practice; you'll typically hear these lists referred to simply as access lists or ACLs.

Access lists do more than just control access. They are the means whereby Cisco devices categorize and match packets in any number of interesting ways. Access lists are used as simple filters to allow traffic through interfaces. They are also used to define "interesting traffic" for ISDN dialer maps, and are used in some route maps for matching.

Designing Access Lists

This focus of this chapter will be less on the basics of access-list design, and more on making you conscious of the benefits and pitfalls of access-list design. The tips and tricks in this chapter should help you to write better, more efficient, and powerful access lists.

Tip

When creating access lists (or any configuration, for that matter), it's a good idea to create them first in a text editor, and then, once you've worked out all the details, try them in a lab environment. Any time you're working on filters, you risk causing an outage.

Wildcard Masks

Wildcard masks (also called inverse masks) can be confusing because they're the opposite, in binary, of normal subnet masks. In other words, the wildcard mask you would use to match a range that would be described with a subnet mask of 255.255.255.0 would ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Network Warrior, 2nd Edition

Network Warrior, 2nd Edition

Gary A. Donahue
Network Routing, 2nd Edition

Network Routing, 2nd Edition

Deep Medhi, Karthik Ramasamy
Cyber Security and Network Security

Cyber Security and Network Security

Sabyasachi Pramanik, Debabrata Samanta, M. Vinay, Abhijit Guha

Publisher Resources

ISBN: 9780596101510Errata Page