ETExamTower
Q10Network Security

A network engineer needs to create an access control list on a Cisco Adaptive Security Appliance firewall that permits TCP DNS traffic from the organization’s inside network, `192.168.1.0/24`, to the internet. Which IOS command must be used to implement the access control list?

Question exhibitQuestion exhibitQuestion exhibitQuestion exhibit
← → navigate · a answer
Community votes
D
80% (8)
A
20% (2)
B
0% (0)
C
0% (0)
Discussion · 11
4
So, the syntax shown in the question is not correct for an ASA. (I work with ASA every day.)
D 3
Selected Answer: D Both A and D are correct: R9(config)#access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any R9(config)#access-list 102 permit tcp 192.168.1.0 0.0.0.255 eq 53 any R9(config)# R9(config)# R9(config)# R9(config)#do sh run | sec access-li access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any access-list 102 permit tcp 192.168.1.0 0.0.0.255 eq domain any
D 3
Selected Answer: D https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/acl_extended.html https://community.cisco.com/t5/security-blogs/cisco-asa-access-list-acl-using-network-object/ba-p/4637574 In these examples we can see what an access-list on an ASA looks like. For a network, it does not use a wild card mask like a router. Also, the destination port/service is usually placed at the end. Both eq 53 and eq domain are fine. The ASA converts port 53 to domain. https://www.cisco.com/c/en/us/td/docs/security/asa/asa912/configuration/general/asa-912-general-config/ref-ports.html#ID-2120-000002b8
A 2
Selected Answer: A b and c are missing destination ip address or 'any', so they are wrong d - the syntax is not correct. a - correct syntax https://community.cisco.com/t5/network-security/acl-for-dns-service/td-p/1553125
D 2
Selected Answer: D When I tested this on my ASA, I typed "eq 53" and when I ran a show access-list, it renamed it to "eq domain". So even though both look legitmate, I would go with 'domain'.
D 1
Selected Answer: D https://www.cisco.com/c/en/us/support/docs/ip/access-lists/26448-ACLsamples.html
D 1
Selected Answer: D The answer might be D but is wrong access-list 102 permit tcp 192.168.1.0 0.0.0.255 any eq 53
1
answer A and D are correct
D 1
Selected Answer: D tested in lab R1(config)#access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any running-config: ! access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any ! ! ! !
A 1
Selected Answer: A A and D are correct since one uses the port number (53), and the other uses the service name (domain)
D 1
Selected Answer: D R1 hostname R1 ! interface ethernet0 ip access-group 102 in ! access-list 102 permit udp any any eq domain access-list 102 permit udp any eq domain any access-list 102 permit tcp any any eq domain access-list 102 permit tcp any eq domain any https://www.cisco.com/c/en/us/support/docs/ip/access-lists/26448-ACLsamples.html#toc-hId--2055811851