Refer to the exhibit. The company CEO demands that one ACL be created to permit email traffic to the internet and deny FTP access. What is the best ACL type and placement to use in this situation?

IT Exam Items RepositoryCategory: CCNARefer to the exhibit. The company CEO demands that one ACL be created to permit email traffic to the internet and deny FTP access. What is the best ACL type and placement to use in this situation?

Refer to the exhibit. The company CEO demands that one ACL be created to permit email traffic to the internet and deny FTP access. What is the best ACL type and placement to use in this situation?

  • extended ACL outbound on R2 WAN interface towards the internet
  • standard ACL outbound on R2 S0/0/0
  • extended ACL inbound on R2 S0/0/0
  • standard ACL inbound on R2 WAN interface connecting to the internet

Explanation:

ACL Type: An extended ACL is required because the CEO's demand involves filtering traffic based on specific applications (email and FTP), which necessitates inspecting Layer 4 protocol and port information. Standard ACLs are insufficient as they only filter based on the source IPv4 address.

Placement: To satisfy the requirement of using only one ACL to control traffic from multiple internal segments (R1's LANs and R3's Server), the ACL must be placed at a common exit point. Applying the ACL outbound on the R2 WAN interface ensures that all traffic from the entire organization is inspected and filtered before it enters the internet.

Related exam: Enterprise Networking, Security, and Automation (Version 7.00) Modules 3 - 5: Network Security Exam

Related exam: CCNA Version 7.0 Final Exam Answers