CCNA Network Services and Security • Set 33
CCNA Network Services and Security Practice Test 33 — 15 questions with explanations. Free, no signup.
You are connected to R1, a branch router. Configure an extended ACL named BRANCH_IN that permits only HTTP (TCP port 80) traffic from the internal network 192.168.1.0/24 to the web server at 203.0.113.10, and permits ICMP echo-reply from any source to any destination. Apply the ACL inbound on the interface facing the internal network. Then verify that only the specified traffic is allowed.
R1# show running-config | section interface interface GigabitEthernet0/0 description Link to Internal LAN ip address 192.168.1.1 255.255.255.0 duplex auto speed auto ! interface GigabitEthernet0/1 description Link to ISP ip address 203.0.113.2 255.255.255.252 duplex auto speed auto ! ip access-list extended BRANCH_IN permit tcp 192.168.1.0 0.0.0.255 host 203.0.113.10 eq 80 permit icmp any any echo-reply
R1# show running-config | section interface interface GigabitEthernet0/0 description Link to Internal LAN ip address 192.168.1.1 255.255.255.0 duplex auto speed auto ! interface GigabitEthernet0/1 description Link to ISP ip address 203.0.113.2 255.255.255.252 duplex auto speed auto ! ip access-list extended BRANCH_IN permit tcp 192.168.1.0 0.0.0.255 host 203.0.113.10 eq 80 permit icmp any any echo-reply