Home > Ticket 5 – R1 ACL

Ticket 5 – R1 ACL

May 2nd, 2018 in TSHOOT v2 Go to comments

Configuration on R1
interface Serial0/0/1
description Link to ISP
ip address
ip nat outside
ip access-group edge_security in
ip access-list extended edge_security
deny ip any
deny ip any
deny ip any
deny any
permit ip host any


Ans1) R1
Ans2) IPv4 layer 3 security
Ans3) Under the ‘ip access-list extended edge_security’ configuration add the ‘permit ip any’ command.

+ This is the only ticket the extended access-list edge_security exists. In other tickets, the access-list 30 is applied to the inbound direction of S0/0/1 of R1.
+ Although host is permitted to go through the access-list (permit ip host any) but clients cannot ping the web server because R1 cannot establish BGP session with neighbor

Comments (10) Comments
Comment pages
1 6 7 8 26
  1. ChillBaba
    August 7th, 2018

    CAn any one tell what is the question/issue/problem of this new sim? if we dont know the issue how will we be able to identify it or compare it with answers.

  2. jirehccnp
    August 8th, 2018


    Could you please don’t totally remove the old scenario? how could I revise and have look on those old scenario? we don’t know maybe old scenario might appear again right.

  3. jirehccnp
    August 8th, 2018

    hi all,
    just for sharing.
    old scenario:

    ip access-list standard nat_traffic

    it is not permit, and ACL end with explicit deny,
    so, the traffic of could not get through.

  4. Please help me.Please for god sake
    August 8th, 2018

    @Network Tut
    Dear Team,
    My account is going to expire and I have 5 tickets left
    4 , 8 , 9 , 11 and 17 does not have a problem question.How will I be able to identify if no question is stated.

    Problem: Client 1 is able to ping but can’t ping the Web Server

  5. CCNP switching Exam
    August 8th, 2018

    Hello All,

    I am renewing the CCNP certification.

    Has anyone got those exams lately?

    where do I get the dumps?
    where do I get some T-shooting simulations?

    Thank you.


  6. jirehccnp
    August 11th, 2018

    @CCNP switching Exam

    sign up for premium account for networktut then u will get

  7. new
    August 15th, 2018

    Hi everyone,

    After we enter the answers, are we required to test for resolution

  8. @new
    August 20th, 2018

    dont think so, under tshoot exam we only can find the issues and propose solution

  9. Igor
    August 27th, 2018

    Hi admin,
    Please change ip address on s0/0/1 from x.x.x.224 to x.x.x.225

  10. Anonymous
    September 1st, 2018

    Hello jirehccnp,

    thank you for the reply. I have signed up with the premium.

    Do you know if the tickets are still valid?



Comment pages
1 6 7 8 26