200-301 · Question #245
While examining excessive traffic on the network, it is noted that all incoming packets on an interface appear to be allowed even though an IPv4 ACL is applied to the interface. Which two misconfigura
The correct answer is B. A matching permit statement is too broadly defined E. A matching permit statement is too high in the access list. Traffic might be permitted if the permit statement is too braid, meaning that you are allowing more traffic than what is specifically needed, or if the matching permit statement is placed ahead of the deny traffic. Routers will look at traffic and compare it to the ACL and once a
Question
While examining excessive traffic on the network, it is noted that all incoming packets on an interface appear to be allowed even though an IPv4 ACL is applied to the interface. Which two misconfigurations cause this behavior? (Choose two.)
Options
- AThe ACL is empty
- BA matching permit statement is too broadly defined
- CThe packets fail to match any permit statement
- DA matching deny statement is too high in the access list
- EA matching permit statement is too high in the access list
How the community answered
(31 responses)- A19% (6)
- B68% (21)
- C10% (3)
- D3% (1)
Explanation
Traffic might be permitted if the permit statement is too braid, meaning that you are allowing more traffic than what is specifically needed, or if the matching permit statement is placed ahead of the deny traffic. Routers will look at traffic and compare it to the ACL and once a match is found, the router acts accordingly to that rule.
Topics
Community Discussion
No community discussion yet for this question.