Tutorial
Physical Layer
Data Link layer
Network Layer
Routing Algorithm
Transport Layer
Application Layer
Network Security
Misc
- Router
- OSI vs TCP/IP
- TCP vs UDP
- Transmission Control Protocol
- TCP port
- IPv4 vs IPv6
- ARP Packet Format
- ARP Table
- Working of ARP
- FTP Client
- FTP Commands
- FTP Server
- I2C Protocol
- Sliding Window Protocol
- SPI Protocol
- IP
- ARP Commands
- ARP
- Address Resolution Protocol
- ARP and its types
- TCP Retransmission
- CAN protocol
- HTTP Status Codes
- HTTP vs HTTPS
- RIP Protocol
- UDP Protocol
- ICMP Protocol
- MQTT protocol
- OSPF Protocol
- Stop and Wait Protocol
- IMAP Protocol
- POP Protocol
- CIFS
- DAS
- DIMM
- iSCSI
- NAS (Network Attached Storage)
- NFS
- NVMe
- SAN
- Border Gateway Protocol
- Go-Back-N ARQ
- RJ Cable
- Difference between Connection-Oriented and Connectionless Service
- CDMA vs. GSM
- What is MAC Address
- Modem vs. Router
- Switch Vs. Router
- USB 2.0 vs 3.0
- Difference between CSMA CA and CSMA CD
- Multiple access protocol- ALOHA, CSMA, CSMA/CA and CSMA/CD
- URI vs URL
- IMAP vs. POP3
- SSH Meaning| SSH Protocol
- UTP vs STP
- Status Code 400
- MIME Protocol
- IP address
- proxy server
- How to set up and use a proxy server
- network security
- WWW is based on which model
- Proxy Server List
- Fundamentals of Computer Networking
- IP Address Format and Table
- Bus topology and Ring topology
- Bus topology and Star topology
- Circuit Switching and Packet switching?
- Difference between star and ring topology
- Difference between Router and Bridge
- TCP Connection Termination
- Image Steganography
- Network Neutrality
- Onion Routing
- Adaptive security appliance (ASA) features
- Relabel-to-front Algorithm
- Types of Server Virtualization in Computer Network
- Access Lists (ACL)
- What is a proxy server and how does it work
- Digital Subscriber Line (DSL)
- Operating system based Virtualization
- Context based Access Control (CBAC)
- Cristian's Algorithm
- Service Set Identifier (SSID)
- Voice over Internet Protocol (VoIP)
- Challenge Response Authentication Mechanism (CRAM)
- Extended Access List
- Li-fi vs. Wi-fi
- Reflexive Access List
- Synchronous Optical Network (SONET)
- Wifi protected access (WPA)
- Wifi Protected Setup (WPS)
- Standard Access List
- Time Access List
- What is 3D Internet
- 4G Mobile Communication Technology
- Types of Wireless Transmission Media
- Best Computer Networking Courses
- Data Representation
- Network Criteria
- Classful vs Classless addressing
- Difference between BOOTP and RARP in Computer Networking
- What is AGP (Accelerated Graphics Port)
- Advantages and Disadvantages of Satellite Communication
- External IP Address
- Asynchronous Transfer Mode (ATM)
- Types of Authentication Protocols
- What is a CISCO Packet Tracer
- BOOTP work
- Subnetting in Computer Networks
- Mesh Topology Advantages and Disadvantages
- Ring Topology Advantages and Disadvantages
- Star Topology Advantages and Disadvantages
- Tree Topology Advantages and Disadvantages
- Zigbee Technology-The smart home protocol
- Network Layer in OSI Model
- Physical Layer in OSI Model
- Data Link Layer in OSI Model
- Internet explorer shortcut keys
- Network Layer Security | SSL Protocols
- Presentation Layer in OSI Model
- Session Layer in OSI Model
- SUBNET MASK
- Transport Layer Security | Secure Socket Layer (SSL) and SSL Architecture
- Functions, Advantages and Disadvantages of Network Layer
- Protocols in Noiseless and Noisy Channel
- Advantages and Disadvantages of Mesh Topology
- Cloud Networking - Managing and Optimizing Cloud-Based Networks
- Collision Domain and Broadcast Domain
- Count to Infinity Problem in Distance Vector Routing
- Difference Between Go-Back-N and Selective Repeat Protocol
- Difference between Stop and Wait, GoBackN, and Selective Repeat
- Network Function Virtualization (NFV): transforming Network Architecture with Virtualized Functions
- Network-Layer Security | IPSec Modes
- Next - Prev Network-Layer Security | IPSec Protocols and Services
- Ping vs Traceroute
- Software Defined Networking (SDN): Benefits and Challenges of Network Virtualization
- Software Defined Networking (SDN) vs. Network Function Virtualization (NFV)
- Virtual Circuits vs Datagram Networks
- BlueSmack Attack in Wireless Networks
- Bluesnarfing Attack in Wireless Networks
- Direct Sequence Spread Spectrum
- Warchalking in Wireless Networks
- WEP (Wired Equivalent Privacy)
- Wireless security encryption
- Wireless Security in an Enterprise
- Quantum Networking
- Network Automation
- Difference between MSS and MTU
- What is MTU
- Mesh Networks: A decentralized and Self-Organizing Approach to Networking
- What is Autonomous System
- What is MSS
- Cyber security & Software security
- Information security & Network security.
- Security Engineer & Security Architect
- Protection Methods for Network Security
- Trusted Systems in Network Security
- What are Authentication Tokens in Network security
- Cookies in Network Security
- Intruders in Network Security
- Network Security Toolkit (NST) in virtual box
- Pivoting-Moving Inside a Network
- Security Environment in Computer Networks
- Voice Biometric technique in Network Security
- Advantages and Disadvantages of Conventional Testing
- Difference between Kerberos and LDAP
- Cyber security and Information Security
- GraphQL Attacks and Security
- Application Layer in OSI Model
- Applications of Remote Sensing
- Seven Layers of IT Security
- What is Ad Hoc TCP
- What is Server Name Indication(SNI)
Standard Access List
ACLs are a set of rules for regulating network traffic and minimising network threats. Using a set of rules specified for the network's incoming or outgoing traffic, ACLs are used to filter traffic. Here, we can see that the source parameter is being searched for by the standard Acess list. Therefore, they won't be concerned with the layer 2 frame header; instead, they will examine the packet header, namely the source field, and match solely based on that. Therefore, they won't delve further into the transit layer.
Standard Access list -
These are Access-lists that are created solely utilising the source IP address. These ACLs either allow or disallow the whole set of protocols. TCP, UDP, HTTPS, and other types of IP transmission are not differentiated. The router will recognise it as a regular ACL and the provided address as the source IP address if you use the numbers 1-99 or 1300-1999.
Features of Standard Access List -
- In general, standard access lists are used near to the destination ( but not always ).
- A standard access list prohibits access to the entire network or sub network.
- The range of the standard access-list is 1 to 99, and the expanded range is 1300 to 1999.
- Only the source IP address is used to implement the standard access-list.
- Remember rules cannot be deleted if numbered with a normal Access-list is used. The entire access list will be destroyed if one of the rules is removed.
- You have the option to remove a rule from the access list if named with standard Access list is used.
Note: Standard Access-lists are less commonly used than extended Access-lists since they accept or deny communication for the complete IP protocol suite because they cannot tell one IP protocol from another.
Setting up -
The sales, finance, and marketing departments are the three in this modest topology. The networks for the marketing department are 172.16.60.0/24, the finance department is 172.16.50.0/24, and the sales department is 172.16.40.0/24. In order to prevent others from accessing that network, you now wish to block connections from the sales department to the finance department.
To prevent any IP connection from the sales department to the finance department, first configure a numbered standard access list.
- R1# config terminal
- R1(config)# access-list 10 deny 172. 16. 40.0 0. 0. 0. 255
Similar to extended access-list, you cannot specify the specific IP traffic that should be allowed or blocked here. Please also note the use of the wildcard mask ( 0. 0. 0. 255 which means Subnet mask 255. 255. 255. 0). The number 10 is taken from the access-list standard range.
- R1( config )# access-list 110 permit ip any any
As you are already aware, every access list has an implicit refuse at the end, which indicates that if the traffic does not comply with any of the access list's rules, the traffic will be discarded.
Only traffic that complies with the aforementioned rules that you have specified will reach the finance department by specifying any means from a source with any IP address.
You must now apply the access list to the router's interface:
- R1(config)# int fa0/1
- R1(config-if)# ip access-group 10 out
Remembering that the standard access-list is typically applied to the destination, outbound to interface fa0/1 has been applied since it will meet our needs if it is applied close to the destination.
Standard Access-list illustration -
You will now create a named standard access list while still keeping in mind the same structure.
- R1(config)# ip access-list standard blockacl
You have created an access-list called blockacl by running this command.
- R1(config-std-nacl)# deny 172. 16. 40. 0 0. 0. 0. 255
- R1(config-std-nacl)# permit any
The identical setup that you did in the numbered access-list is then applied.
- R1(config)# int fa0/1
- R1(config-if)# ip access-group blockacl out
Example of a standard access-list for Telnet
Telnet connection can be allowed or denied using standard access-list by applying access-list on line vty lines. As you are aware, you cannot specify specific IP traffic to be prohibited in standard access-list.
Here, in the provided figure, you want to prevent telnet access from any network to the Finance department. Setting up for the same:
- R1(config)# access-list 10 deny any
- R1(config)# line vty 0 4
- R1(config-line)# access-class 10 out