Frequently Asked Questions of NAT & PAT
Got questions? We've got the answers quick, clear, and hassle-free as per mentioned FAQ
FAQ Execution
An ACL is a rule set used on routers/firewalls to permit or deny traffic based on defined criteria.
To control traffic flow and enhance network security.
On routers, Layer 3 switches, and firewalls.
Source IP, destination IP, protocol, and ports (depending on type).
Implicit deny all at the end.
An ACE (Access Control Entry).
No, traditional ACLs are stateless.
The packet is denied.
Yes, with logging options.
Yes, especially if very large or poorly ordered.
Filters traffic based only on source IP.
Filters using source, destination, protocol, and ports.
ACL identified by a number.
ACL identified by a name.
ACL entries created temporarily for authenticated users.
Creates temporary entries for return traffic.
ACL active during specified time ranges.
ACL designed for IPv6 traffic.
Filters based on MAC addresses (Layer 2).
VLAN Access Control List applied within VLANs.
Top to bottom, first match wins.
Because processing stops at the first match.
Inverse mask used to match IP ranges.
Match exactly one IP.
Match any IP.
any.
Subnet mask defines network; wildcard defines matching range.
Yes, extended ACLs can.
Yes (TCP, UDP, ICMP, etc.).
deny ip any any.
Close to the destination.
Close to the source.
Filters traffic entering an interface.
Filters traffic leaving an interface.
Yes, per direction and protocol.
Yes, to restrict Telnet/SSH access.
Yes, with distribute-lists.
Yes, to define traffic for translation.
Yes, to classify traffic.
Indirectly, by blocking IP/ports (not URLs).
Traffic may be unintentionally blocked.
By deleting it from the interface and configuration.
Show ACL counters/statistics.
Allows editing entries without deleting ACL.
Yes, especially named ACLs with sequence numbers.
To monitor denied/allowed traffic.
No.
They are stateless and basic compared to firewalls.
Yes, widely used in networking.
To control and secure network traffic flow.