200-101 · Question #160
When are packets processed by an inbound access list?
The correct answer is A. before they are routed to an outbound interface. An inbound access list filters packets as they arrive on an interface, before the routing process forwards them to an outbound interface.
Question
Exhibits
Options
- Abefore they are routed to an outbound interface
- Bafter they are routed to an outbound interface
- Cbefore and after they are routed to an outbound interface
- Dafter they are routed to an outbound interface but before being placed in the outbound queue
How the community answered
(47 responses)- A96% (45)
- B2% (1)
- D2% (1)
Why each option
An inbound access list filters packets as they arrive on an interface, before the routing process forwards them to an outbound interface.
When an ACL is applied inbound on an interface, the IOS evaluates each arriving packet against the access list before performing a routing table lookup. Packets denied by the inbound ACL are dropped immediately at the ingress interface, reducing unnecessary processing by the routing engine.
Processing after routing to an outbound interface describes the behavior of an outbound ACL, not an inbound one.
Inbound ACLs process packets only upon arrival at the inbound interface, not both before and after routing.
Placing packets in the outbound queue occurs after routing and is associated with outbound ACL processing, not inbound.
Concept tested: Inbound ACL packet processing order
Source: https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html
Topics
Community Discussion
No community discussion yet for this question.





