Tutorial
Physical Layer
Data Link layer
Network Layer
Routing Algorithm
Transport Layer
Application Layer
Network Security
Misc
- Router
- OSI vs TCP/IP
- TCP vs UDP
- Transmission Control Protocol
- TCP port
- IPv4 vs IPv6
- ARP Packet Format
- ARP Table
- Working of ARP
- FTP Client
- FTP Commands
- FTP Server
- I2C Protocol
- Sliding Window Protocol
- SPI Protocol
- IP
- ARP Commands
- ARP
- Address Resolution Protocol
- ARP and its types
- TCP Retransmission
- CAN protocol
- HTTP Status Codes
- HTTP vs HTTPS
- RIP Protocol
- UDP Protocol
- ICMP Protocol
- MQTT protocol
- OSPF Protocol
- Stop and Wait Protocol
- IMAP Protocol
- POP Protocol
- CIFS
- DAS
- DIMM
- iSCSI
- NAS (Network Attached Storage)
- NFS
- NVMe
- SAN
- Border Gateway Protocol
- Go-Back-N ARQ
- RJ Cable
- Difference between Connection-Oriented and Connectionless Service
- CDMA vs. GSM
- What is MAC Address
- Modem vs. Router
- Switch Vs. Router
- USB 2.0 vs 3.0
- Difference between CSMA CA and CSMA CD
- Multiple access protocol- ALOHA, CSMA, CSMA/CA and CSMA/CD
- URI vs URL
- IMAP vs. POP3
- SSH Meaning| SSH Protocol
- UTP vs STP
- Status Code 400
- MIME Protocol
- IP address
- proxy server
- How to set up and use a proxy server
- network security
- WWW is based on which model
- Proxy Server List
- Fundamentals of Computer Networking
- IP Address Format and Table
- Bus topology and Ring topology
- Bus topology and Star topology
- Circuit Switching and Packet switching?
- Difference between star and ring topology
- Difference between Router and Bridge
- TCP Connection Termination
- Image Steganography
- Network Neutrality
- Onion Routing
- Adaptive security appliance (ASA) features
- Relabel-to-front Algorithm
- Types of Server Virtualization in Computer Network
- Access Lists (ACL)
- What is a proxy server and how does it work
- Digital Subscriber Line (DSL)
- Operating system based Virtualization
- Context based Access Control (CBAC)
- Cristian's Algorithm
- Service Set Identifier (SSID)
- Voice over Internet Protocol (VoIP)
- Challenge Response Authentication Mechanism (CRAM)
- Extended Access List
- Li-fi vs. Wi-fi
- Reflexive Access List
- Synchronous Optical Network (SONET)
- Wifi protected access (WPA)
- Wifi Protected Setup (WPS)
- Standard Access List
- Time Access List
- What is 3D Internet
- 4G Mobile Communication Technology
- Types of Wireless Transmission Media
- Best Computer Networking Courses
- Data Representation
- Network Criteria
- Classful vs Classless addressing
- Difference between BOOTP and RARP in Computer Networking
- What is AGP (Accelerated Graphics Port)
- Advantages and Disadvantages of Satellite Communication
- External IP Address
- Asynchronous Transfer Mode (ATM)
- Types of Authentication Protocols
- What is a CISCO Packet Tracer
- BOOTP work
- Subnetting in Computer Networks
- Mesh Topology Advantages and Disadvantages
- Ring Topology Advantages and Disadvantages
- Star Topology Advantages and Disadvantages
- Tree Topology Advantages and Disadvantages
- Zigbee Technology-The smart home protocol
- Network Layer in OSI Model
- Physical Layer in OSI Model
- Data Link Layer in OSI Model
- Internet explorer shortcut keys
- Network Layer Security | SSL Protocols
- Presentation Layer in OSI Model
- Session Layer in OSI Model
- SUBNET MASK
- Transport Layer Security | Secure Socket Layer (SSL) and SSL Architecture
- Functions, Advantages and Disadvantages of Network Layer
- Protocols in Noiseless and Noisy Channel
- Advantages and Disadvantages of Mesh Topology
- Cloud Networking - Managing and Optimizing Cloud-Based Networks
- Collision Domain and Broadcast Domain
- Count to Infinity Problem in Distance Vector Routing
- Difference Between Go-Back-N and Selective Repeat Protocol
- Difference between Stop and Wait, GoBackN, and Selective Repeat
- Network Function Virtualization (NFV): transforming Network Architecture with Virtualized Functions
- Network-Layer Security | IPSec Modes
- Next - Prev Network-Layer Security | IPSec Protocols and Services
- Ping vs Traceroute
- Software Defined Networking (SDN): Benefits and Challenges of Network Virtualization
- Software Defined Networking (SDN) vs. Network Function Virtualization (NFV)
- Virtual Circuits vs Datagram Networks
- BlueSmack Attack in Wireless Networks
- Bluesnarfing Attack in Wireless Networks
- Direct Sequence Spread Spectrum
- Warchalking in Wireless Networks
- WEP (Wired Equivalent Privacy)
- Wireless security encryption
- Wireless Security in an Enterprise
- Quantum Networking
- Network Automation
- Difference between MSS and MTU
- What is MTU
- Mesh Networks: A decentralized and Self-Organizing Approach to Networking
- What is Autonomous System
- What is MSS
- Cyber security & Software security
- Information security & Network security.
- Security Engineer & Security Architect
- Protection Methods for Network Security
- Trusted Systems in Network Security
- What are Authentication Tokens in Network security
- Cookies in Network Security
- Intruders in Network Security
- Network Security Toolkit (NST) in virtual box
- Pivoting-Moving Inside a Network
- Security Environment in Computer Networks
- Voice Biometric technique in Network Security
- Advantages and Disadvantages of Conventional Testing
- Difference between Kerberos and LDAP
- Cyber security and Information Security
- GraphQL Attacks and Security
- Application Layer in OSI Model
- Applications of Remote Sensing
- Seven Layers of IT Security
- What is Ad Hoc TCP
- What is Server Name Indication(SNI)
Extended Access List
The term "access-list" refers to a set of rules for controlling network traffic and reducing network attacks. ACLs are used to filter network traffic based on a set of rules defined for incoming or outgoing traffic.
Extended Access list -
This is one of the most commonly used types of access-list because it can distinguish IP traffic, so the entire traffic will not be permitted or denied as in a standard access-list. These are the ACLs that distinguish IP traffic by using both source and destination IP addresses as well as port numbers. We can also specify which IP traffic should be allowed or denied in this type of ACL. These ranges are 100-199 and 2000-2699
Features of Extended Access List -
- Extended access-list is typically used close to the source, but this is not always the case.
- Packet filtering occurs in the Extended access list based on source IP address, destination IP address, and port numbers.
- Specific services will be permitted or denied in an extended access list.
- The extended ACL range is 100 - 199, and the extended range is 2000 - 2699.
- Remember rules cannot be deleted if they are numbered with an extended Access-list. If one of the rules is removed, the entire access list is removed.
- We have the ability to delete a rule from the access list if it is named with extended Access-list.
Setting up -
Here is a simple organisational structure with three departments: sales, finance, and marketing. The networks for the marketing department are 172.16.60.0/24, the finance department is 172.16.50.0/24, and the sales department is 172.16.10.40/24. Now, we want to prevent the sales department from connecting through FTP to the finance department and the marketing and sales departments from telneting the finance department.
First, set up a numbered extended access list to block FTP connections from the sales department to the finance department.
- R1# config terminal
- R1(config)# access-list 110
- deny tcp 172.16.40.0 0.0.0.255 172.16.50.0 0.0.0.255 eq 21
Here, we first build a numbered Access-list and utilise 110 (taken from the extended access-list range) to deny the sales network's request to connect through FTP to the finance network (172.16.40.0). (172.16.50.0).
Note that TCP and port number 21 are used here since FTP. Therefore, depending on the situation, we must either specify the permit or reject the condition. Additionally, we must utilise the supplied application layer protocol's port number after eq.
Now, we must prevent the sales and marketing departments from connecting via telnet to the finance department, therefore nobody should do so. setting up for the same.
- R1(config)# access-list 110
- deny tcp any 172.16.50.0 0.0.0.255 eq 23
Here, the phrase any denotes any IP address from any subnet mask, or 0.0.0.0 0.0.0.0. We must mention port number 23 after eq since telnet uses port number 23.
- R1(config)# access-list 110 permit ip any
This is the crucial thing right now. As we are previously aware, every access list has an implicit refuse at the end, meaning that if the traffic does not comply with any of the rules of the access-list, the traffic will be discarded.
Any traffic from a source with any IP address that complies with the aforementioned requirements will not enter the finance department via the specified method. We must now apply the access-list to the router's interface:
- R1(config)# int fa0/1
- R1(config-if)# ip access-group 110 out
As we recall, the extended access-list must be applied as close to the source as possible, but in this case, we applied it too close to the destination because we need to block traffic from both the sales and marketing departments; as a result, we must apply the extended access-list close to the destination otherwise we will need to create separate access-lists for fa0/0 and fa1/0 inbound.
Standard Access-list illustration -
Now we will create a named extended access list while keeping the same topology in mind.
- R1(config)# ip access-list extended blockacl
By using this command we have made an access-list named blockacl.
- R1(config-ext-nacl)# deny tcp 172.16.40.0 0.0.0.255 172.16.50.0 0.0.0.255 eq 21
- R1(config-ext-nacl)# deny tcp any 172.16.50.0 0.0.0.255 eq 23
- R1(config-ext-nacl)# permit ip any
After that, we repeat the settings we did for the numbered access-list.
- R1(config)# int fa0/1
- R1(config-if)# ip access-group blockacl out