    Classifying Traffic with Access Lists - Study Session 3 of 12 Discussion Thread

    Brett Lovins, Community Manager

      Please post your questions and conversations for André's 3rd session on Feb 7th.


      I've place the graphics from today and attached (PDF) of today's command line.


      To review recordings and register for other sessions:


      CCNA Routing and Switching Study Sessions with André Laurent






        • 1. Re: RS Study Session 3 - Post Seminar Discussion Thread

          • 2. Re: RS Study Session 3 - Post Seminar Discussion Thread

            PS: I wanted to suggest you an easier way (at least for me) for calculating wildcard mask. For example if we have /26  the mask is and Andre said that the wildcard mask is because 255-192=63. To be honest it's defficult for me to subtract 255 and 192 (or 128, 224, 240 and etc.) in my mind! It's easier for me to calculate it using the powers of 2. I know that 192(10) = 11000000(2) => we have 6 zeros so 2^6=64-1=63. If we have /28 for example:

            subnet mask = and wildcard^4-1 =>


            Hope you get my point and some of you will find it easier that way

            • 3. Re: RS Study Session 3 - Post Seminar Discussion Thread

              In today's session, I was hoping to get a firm understanding of in/out aspects of applying access-lists. I have read a lot by now and have seen several videos. I am still at the point where I feel I do not have a complete grasp of exactly why one should apply ACL to either Inbound or Outbound interface.  It gets complicated for me when the topology is compex.  The struggle is as same as initially struggling with subnetting (I can claim to have surpassed that challenge by now).


              • 4. Re: RS Study Session 3 - Post Seminar Discussion Thread
                James W. Vickery III

                I don't know about everyone else but wildcard masks give me quite a headache depending on how they are used. Firewall rules or nat, no problem, anything else and it starts to get fuzzy. I am glad we spent more time with them. I never really got what regular subnet masks were doing until I ran across something that explained that the mask and the ip address gets compared using a logical AND operation. Wildcard masks have something similar going on underneath the hood I take it? WIthout knowing "what" something is doing and "why" I tend not to have a very good foundational picture of the process which makes topics that involve that subject rocky ground.


                • 5. Re: RS Study Session 3 - Post Seminar Discussion Thread

                  • 6. Re: RS Study Session 3 - Post Seminar Discussion Thread
                    Andre Laurent, 3xCCIE/CCDE



                    • 7. Re: RS Study Session 3 - Post Seminar Discussion Thread

                      • 8. Re: RS Study Session 3 - Post Seminar Discussion Thread

                        • 9. Re: RS Study Session 3 - Post Seminar Discussion Thread
                          Andre Laurent, 3xCCIE/CCDE



                          • 10. Re: RS Study Session 3 - Post Seminar Discussion Thread

                            • 11. Re: RS Study Session 3 - Post Seminar Discussion Thread
                              James W. Vickery III

                              I somehow forgot about NAND (Not And) this is whats going on with the wildcard mask yes? Since it's the opposite of AND logic? Maybe I'll run across some nice video tutorial.

                                I missed the session but managed to review the videos!


                                Very useful information for me: I finally put the Parental Control in place in my home network (using a Cisco box of course!) by blocking all DNS (Domain) traffic to external servers and allowing only the DNS (Domain) traffic to my DNS with Parental control.


                                Until today the Parenthal Control was done in another box that was able to intercept all DNS traffic and resend it to the DNS server with Parenthal Control. (this old box is a Linksys with Tomato USB)


                                I do not know how to "force" my Cisco router to intercept and redirect all DNS trafic so I used the "deny" path: No DNS trafic get out from the hosts through router. The hosts must use the Cisco DNS service (I've started it), service that is set to use only the Parental Control DNS server.


                                Waiting next session!