Cisco ASA: All-in-One Next-Generation Firewall, IPS, and VPN Services, Third Edition by Jazib Frahim & Omar Santos & Andrew Ossipov

Cisco ASA: All-in-One Next-Generation Firewall, IPS, and VPN Services, Third Edition by Jazib Frahim & Omar Santos & Andrew Ossipov

Author:Jazib Frahim & Omar Santos & Andrew Ossipov
Language: eng
Format: epub, pdf
Publisher: Cisco Press
Published: 2014-09-22T04:00:00+00:00


Step 5: Configure Interface ACLs

As discussed in Chapter 8, “Controlling Network Access: The Traditional Way,” extended ACLs can filter out IP packets by looking at various headers. EtherType-based ACLs can be used to filter IP- and non-IP-based traffic. Because the EtherType ACLs can be employed to analyze a frame at Layer 2, they behave differently from a typical extended ACL. Consult the following guidelines when using the ACLs in your environment:

CDP packets: The security appliance does not allow Cisco Discovery Protocol (CDP) packets to traverse it, even if you allow them.

ARP packets: In its default behavior, the security appliance does not filter ARP packets You can use an EtherType ACL to block ARP traffic. All other packets, such as DHCP, RIP, OSPF, IS-IS, EIGRP, BGP, BPDU, multicast, and MPLS packets, can be controlled by the EtherType ACL entries.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.