Q10Network Security
A network engineer needs to create an access control list on a Cisco Adaptive Security Appliance firewall that permits TCP DNS traffic from the organization’s inside network, `192.168.1.0/24`, to the internet. Which IOS command must be used to implement the access control list?
← → navigate · a answer
Community votes
Discussion · 11
4
So, the syntax shown in the question is not correct for an ASA. (I work with ASA every day.)
D 3
Selected Answer: D
Both A and D are correct:
R9(config)#access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any
R9(config)#access-list 102 permit tcp 192.168.1.0 0.0.0.255 eq 53 any
R9(config)#
R9(config)#
R9(config)#
R9(config)#do sh run | sec access-li
access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any
access-list 102 permit tcp 192.168.1.0 0.0.0.255 eq domain any
D 3
Selected Answer: D
https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/acl_extended.html
https://community.cisco.com/t5/security-blogs/cisco-asa-access-list-acl-using-network-object/ba-p/4637574
In these examples we can see what an access-list on an ASA looks like. For a network, it does not use a wild card mask like a router. Also, the destination port/service is usually placed at the end. Both eq 53 and eq domain are fine. The ASA converts port 53 to domain.
https://www.cisco.com/c/en/us/td/docs/security/asa/asa912/configuration/general/asa-912-general-config/ref-ports.html#ID-2120-000002b8
A 2
Selected Answer: A
b and c are missing destination ip address or 'any', so they are wrong
d - the syntax is not correct.
a - correct syntax
https://community.cisco.com/t5/network-security/acl-for-dns-service/td-p/1553125
D 2
Selected Answer: D
When I tested this on my ASA, I typed "eq 53" and when I ran a show access-list, it renamed it to "eq domain". So even though both look legitmate, I would go with 'domain'.
D 1
Selected Answer: D
https://www.cisco.com/c/en/us/support/docs/ip/access-lists/26448-ACLsamples.html
D 1
Selected Answer: D
The answer might be D but is wrong
access-list 102 permit tcp 192.168.1.0 0.0.0.255 any eq 53
1
answer A and D are correct
D 1
Selected Answer: D
tested in lab
R1(config)#access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any
running-config:
!
access-list 101 permit tcp 192.168.1.0 0.0.0.255 eq domain any
!
!
!
!
A 1
Selected Answer: A
A and D are correct since one uses the port number (53), and the other uses the service name (domain)
D 1
Selected Answer: D
R1
hostname R1
!
interface ethernet0
ip access-group 102 in
!
access-list 102 permit udp any any eq domain
access-list 102 permit udp any eq domain any
access-list 102 permit tcp any any eq domain
access-list 102 permit tcp any eq domain any
https://www.cisco.com/c/en/us/support/docs/ip/access-lists/26448-ACLsamples.html#toc-hId--2055811851