Cisco Systems OL-7822-06 quick start Initial IP address Wildcard bits Range

Page 33

Chapter 4 Connect the Management Interfaces and Perform Initial System Configuration

Perform the Initial System Configuration

Configuring ACLs

The SCE 1000 can be configured with Access Control Lists (ACLs), which are used to permit or deny incoming connections on any of the management interfaces.

Note ACL #0 is a pre-defined list that permits access to all IP addresses.

Configuration of access control lists is done in two stages:

1.Create the access control lists.

You may create 99 ACLs with a maximum of 20 entries per list. Each entry consists of an IP address, and an indication of whether access is permitted or denied to this IP address.

2.Assign the ACLs to the appropriate management interface. (See )

The dialog permits you to skip the creation/editing of the ACLs and go directly to assigning ACLs to the management interfaces.

Entry Formats

Each ACL may permit/deny access to any IP address, one or more ranges of IP addresses, or one or more individual IP address. Three entry formats are available to support these options:

Any IP address — Type the word “any”. Any IP address will be permitted or denied access.

Range of IP addresses — Type the beginning IP address in the desired range, then enter the wildcard bits that define the range.

This wildcard functions like a reverse mask, in that all “1” bits in the wildcard indicate the corresponding bit in the IP address should be ignored. All other bits must match the corresponding bit in the specified IP address. Refer to the table below for examples.

Each range of IP addresses can be configured to be permitted or denied access.

Individual IP address— Type the desired IP address, then enter the wildcard bits 0.0.0.0.

Each individual IP address can be configured to be permitted or denied access.

Table 4-2

IP address/Wildcard bit examples

 

 

 

 

Initial IP address

Wildcard bits

Range

 

 

 

 

10.1.1.0

 

0.0.0.255

10.1.1.0–10.1.1.255

 

 

 

 

10.1.1.0

 

0.0.0.63

10.1.1.0–10.1.1.63

 

 

 

 

10.1.1.0

 

0.0.0.0

10.1.1.0 (individual entry)

 

 

 

 

Order of Entries

The order of the entries in the list is important. The entries in the list are tested sequentially, and the action is determined by the first entry that matches the connecting IP address. Therefore, when the entry “any” appears in an Access Control List, all succeeding entries are irrelevant.

Consider two hypothetical ACLs containing the same entries in a different order.

The following list would permit access to all IP addresses, including 10.1.1.0:

permit any

deny 10.1.1.0

Note that the above list could not actually be created using the setup utility, since after the “any” entry, no other entries could be added to the list.

Cisco Service Control Engine 1000 2xGBE Quick Start Guide

 

OL-7822-06

4-13

 

 

 

Image 33
Contents Cisco Service Control Engine 1000 2xGBE Quick Start Guide Page N T E N T S Example Example 2 Installing a Service Control Application OL-7822-06 Site Preparation and Unpacking Information About Preparing for InstallationWorkbench or Tabletop Installation Prepare for Rack-Mount InstallationTools and Parts Prepare for Installation Workbench or Tabletop Installation OL-7822-06 SCE 1000 Mounting Brackets Rack-Mount the SCEAttaching the Mounting Brackets 4-post Attach the Brackets to the SCEAssemble the Crossrail Supports Installing the Crossrail Supports Four-post rack onlyAttach the Crossrail Supports to the Rack Mount the System to the RackSummary Steps Securing the SCE Platform to the Rack Connect the Chassis Ground Connect the Power Supply UnitsGrounding the Unit DC Connecting the PowerConnecting the DC Power Connect the DC-Input Power Supply UnitConnecting the AC Power Connect the AC-Input Power Supply UnitConnect the Local Console Connecting to the Local ConsoleInitial System Configuration Perform the Initial System ConfigurationSetup Command Setup Command Parameters Parameter Definition Example Configuring Initial SettingsSetting the Passwords Configuring the HostnameExample Configuring Time SettingsEnter time zone name UTC CET Enter time interval in seconds between unicast updates Configuring the DNS SettingsEnter Primary DNS IP address Configuring Access Control Lists ACLs Configuring the RDR Formatter DestinationInitial IP address Wildcard bits Range Deny Permit any Examples Configuring Snmp Enter the Snmp configuration menu Type the trap manager community string and press press Enter Enter Snmp trap manager community string About the Topology-Dependent Parameters Configuring the Topology-Dependent ParametersExample 1, Example 2, Example 3, Completing and Saving the Configuration Apply and Save this configuration? yes/no Examples Example Connect the Management InterfaceOL-7822-06 Single Link Inline Topology Information About CablingSingle Link Receive-only Topology Bump-in-the-Wire InstallationCabling the Line Interfaces Configure GigabitEthernet Auto-NegotiationConnect the GBE Line Interface Ports SCE Model Transceiver Transmit Power Receive Power DistanceCable the Line Ports Cabling the Line Interfaces OL-7822-06 Examining the LEDs Final TestsVerifying Operational Status Viewing the User Log Counters Saving the Configuration Settings Examples Following example shows the running configuration fileLoading and Activating a Service Control Application Advanced Configuration of the SCE PlatformOL-7822-06 SCE 1000 Operational Status Troubleshoot Startup ProblemsTroubleshoot Startup Problems SCE 1000 Operational Status CLI Commands for Troubleshooting Identifying Startup ProblemsTroubleshooting the link interface subsystem Page OL-7822-06

OL-7822-06 specifications

Cisco Systems OL-7822-06 is a comprehensive course offered within the Cisco Networking Academy, designed to equip students and professionals with a deep understanding of basic networking concepts and advanced networking technologies. This course primarily focuses on the required skills and knowledge needed for building, running, and maintaining networks and prepares participants for various roles in the IT and cybersecurity sectors.

One of the main features of the OL-7822-06 course is its thorough curriculum, which covers key topics such as networking fundamentals, including OSI and TCP/IP models, IPv4 and IPv6 addressing, and subnetting. It dives deep into network protocols, ensuring learners acquire a firm grasp of how data flows across networks, as well as the role of routers and switches in maintaining efficient network operations.

The course also emphasizes hands-on learning, leveraging various simulation tools and virtual labs that provide students with real-world scenarios to apply their knowledge practically. These labs are integral in helping learners understand the configuration and troubleshooting of network devices, enhancing their problem-solving skills in a controlled environment.

Another significant aspect of OL-7822-06 is its focus on emerging technologies. The course introduces students to concepts such as network security, cloud computing, wireless networking, and IoT (Internet of Things). This inclusion reflects the ever-evolving landscape of technology and prepares participants to be adaptable in the face of rapid change within the industry.

Additionally, the OL-7822-06 course promotes collaboration and peer engagement through group projects and discussions. This not only fosters a sense of community among learners but also enhances their communication skills, which are essential in modern IT environments.

The course is structured to accommodate various learning styles, offering a blend of theoretical knowledge and practical exercises. It provides assessments and quizzes that help gauge understanding and retention of information, ensuring students are well-prepared for certification exams and real-world applications.

In summary, Cisco Systems OL-7822-06 stands out as a robust educational offering that combines foundational networking principles with advanced technologies. Its focus on hands-on experience, collaboration, and the introduction of current industry trends makes it an invaluable resource for aspiring networking professionals, ultimately paving the way for a successful career in the tech industry.