background image
C
H
A
P
T
E
R
7
Understanding Access List
Security
When deciding on the name of this chapter, the first title chosen was "Understanding
Network Security." Then I thought to myself (that's what you do when you spend weeks on
end in your home office writing), "You could easily write a whole book just on this topic!"
So, I changed the title to better reflect the scope of this topic in this book, which of course
reflects Cisco's expectations of CCNA candidates.
(By the way, someone already wrote the book I imagined--it's called
Designing Network
Security
, by Merike Kaeo, ISBN: 1-57870-043-4.)
Cisco expects CCNAs to understand security from the perspective of filtering traffic using
access-lists. Cisco also expects CCNAs to master the ideas and configuration behind the
Telnet, auxiliary, console, and enable passwords as well; these topics are covered in Chapter
2, "Cisco Internetwork Operating System (IOS) Fundamentals."
The reason that access lists are so important to CCNA candidates is that practically every
network uses them; to do more than basic filtering, access lists can be very tricky. In fact,
back in 1993, when I was getting certified to teach Cisco classes, the Cisco Worldwide
Training folks said that the TAC's most frequent question topic area was how to configure
access lists. Access lists are likely to remain a core-competency issue for router support
personnel for a long time. Also, several other IOS features call on access list logic to
perform packet-matching features.
When studying about access lists in this book or others, keep in mind that there are usually
many ways to configure an access list to achieve the same result. Focus on the syntax of the
commands and the nuances of the logic. If a particular example (given a set of criteria) is
configured differently than you would have configured it, do not be concerned. In this book,
I have attempted to point out in the text when a particular list could have been written a
different way.
How to Best Use This Chapter
By taking the following steps, you can make better use of your study time:
·
Keep your notes and the answers for all your work with this book in one place, for
easy reference.
ch07.fm Page 455 Monday, March 20, 2000 5:14 PM