RE: VACL, ACL or ???? [7:74559]

2003-09-08 Thread Radoslav Vasilev
Hi,

Unfortunelly I cannot say I fully understand yout question, but in essence,
you're wondering what type of level2/3 security to use(VACL vs ACL), right
?! Well, it's not that diffucult to chose between them, especially givven
some knowledge of their differences/usage.

ACL - layer 2/3/4 access-lists, applied on per-interface basis.
VACL - vlan access-lists, which control the traffic flow WITHIN a specified
VLAN. For example, you can specify host A is not capable of connecting host
B(both A and B in the same vlan), all other communication inside this
vlan(no layer3 routing/switching  here).

So, for instance, you have 

segment 1 internet
(layer 3 router..etc.)
segment n  servers

I don't see the need of VACL (givven that information). All you have to do
is to define your security policy and apply appropriate layer3 access-lists
to individual router interfaces(vlans on RSFC , RSM...)

Well, in curcumstanses where you've got special needs, say for example in
the server segment, you can use VACL to DEFINE THE SECURITY POLICY INSIDE
THAT GIVVEN SEGMNET(vlan).

Radoslav Vasilev
IBGC, Sofia


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74948t=74559
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: unusual BGP question. [7:54429]

2002-10-04 Thread Radoslav Vasilev

you're right MED is used for outgoing routing decisions, but...

1.as a optional nontransit path-atribute, it's only important for the
neighboring AS. as such, it determines the neighboring AS outgoing
decisions, not our own AS ones.
e.g if you change MEDs in our routing updates, it causes change only in your
neighbors.

2.what the previous posting meant, is modifying the MEDs in the updates, we
are getting /at R3? from R1 and R2. As doing that, you can force your
outgoing policy, without modifying/as in the original posting terms/ as-path
/prepending/ or local-pref  change.


-rado


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=54874t=54429
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]