nerdexam
Cisco

352-001 · Question #185

Your network operations team is deploying Access Control Lists (ACLs) across your Internet gateways. They wish to place an ACL inbound on the Internet gateway interface facing the core network (the…

The correct answer is A. inside local. An ACL applied inbound on the inside (trusted) interface of a NAT gateway evaluates packets before address translation occurs, so the source address seen by the ACL is the private inside local address of the originating host.

Designing Security

Question

Your network operations team is deploying Access Control Lists (ACLs) across your Internet gateways. They wish to place an ACL inbound on the Internet gateway interface facing the core network (the "trusted" interface). Which one of these addresses would the ACL need for traffic sourced from the inside interface, to match the source address of the traffic?

Options

  • Ainside local
  • Boutside local
  • Cinside global
  • Doutside global

How the community answered

(31 responses)
  • A
    94% (29)
  • B
    3% (1)
  • C
    3% (1)

Why each option

An ACL applied inbound on the inside (trusted) interface of a NAT gateway evaluates packets before address translation occurs, so the source address seen by the ACL is the private inside local address of the originating host.

Ainside localCorrect

The inside local address is the private IP address assigned to an internal host as seen from inside the network; because an inbound ACL on the inside interface is processed before NAT translation takes place, the source address in the packet header still holds the original private address, which is the inside local address in Cisco NAT terminology.

Boutside local

The outside local address is the IP address of an external host as seen from the inside network, which is the destination address of outbound traffic - not the source address of traffic originating from inside hosts.

Cinside global

The inside global address is the translated public IP representing an inside host as seen from the outside; this address only exists after NAT translation has been applied, which has not yet occurred when an inbound ACL on the inside interface is evaluated.

Doutside global

The outside global address is the IP address of an external host as seen from outside the network and has no relevance as the source address of traffic originating from internal hosts traversing the inside interface.

Concept tested: NAT inside local address and inbound ACL placement order

Source: https://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/8605-13.html

Topics

#NAT#inside local address#ACL#Internet gateway

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice