What is the difference between a standard ACL and an extended ACL?

Study for the ITS Networking Test. Prepare with flashcards and multiple-choice questions. Each question includes hints and explanations. Get ready to excel in your exam!

Multiple Choice

What is the difference between a standard ACL and an extended ACL?

Explanation:
Standard ACLs filter traffic based only on where it comes from—the source IP address. They don’t consider where it’s going, what protocol is used, or what service is requested. Extended ACLs add granularity by allowing filtering on both source and destination IP addresses, the transport protocol (such as TCP, UDP, or ICMP), and even specific port numbers. This lets you permit or deny particular services between particular hosts or subnets, not just general access from a network. For example, you can allow HTTP from one subnet to another while denying other protocols, something a standard ACL can’t express. In practice, use standard ACLs when you only need to restrict by who can access resources, and use extended ACLs when you need to control access by both endpoints and the specific services.

Standard ACLs filter traffic based only on where it comes from—the source IP address. They don’t consider where it’s going, what protocol is used, or what service is requested. Extended ACLs add granularity by allowing filtering on both source and destination IP addresses, the transport protocol (such as TCP, UDP, or ICMP), and even specific port numbers. This lets you permit or deny particular services between particular hosts or subnets, not just general access from a network. For example, you can allow HTTP from one subnet to another while denying other protocols, something a standard ACL can’t express. In practice, use standard ACLs when you only need to restrict by who can access resources, and use extended ACLs when you need to control access by both endpoints and the specific services.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy