Re: Subnet mask vs. wild card mask when using an access-list
I usually use wildcard masks for access-lists all the time, because if offers you much greater granularity in the control you have over traffic.
With subnet masks all of the ones and zeroes must be contiguous, as you know, and so you can permit or deny traffic in groups of 2, 4, 8, 16, 32, etc. only. With wildcard masks, you can permit or deny in groups of 1, 2, 3, 4, 5, odd numbers only, even numbers only, every other Thursday...Ok, so maybe not every other Thursday, but just about any other combination you can think of. The control is so much greater because the ones and zeroes do NOT have to be contiguous.
For example, the network 172.16.0.0 with a wildcard mask of 0.0.0.254 will match all of the even numbered IP address from 172.16.0.0 to 172.16.0.254. Try that with a subnet mask. And if you just want to allow, say the first four IP address in the same subnet, use the wildcard mask 0.0.0.3. Finally, assume you want to match the IP addresses 172.16.0.0 through 172.16.31.255 (the private class b's), use 0.15.255.255.
This document gives several answers on frequently asked questions for PFRv3 channel state behavior.
Q1: What are all the channel operational states from a BR (border role) perspective and what are the rules/conditions to be in each st...
The need was to reach an host inside a LAN through a VPN connection managed by the LAN gateway (Cisco 1921).
The LAN gateway performs NAT and there was a dedicate nat rule for the host i wanted to reach through VPN.
I couldn't connect to the hos...
We have 3 identical switches configured by someone else and would like to claim some of the Gigabit ports(G1/G2/G3/G4) for use on servers. When we try to change the wiring and configuration, we run in to connectivity issues. Attached is a des...