Section 6.0: IOS Firewall Configuration (6 points)

6.1. Context-Based Access Control (CBAC) (3 points)

  1. Configure CBAC on R2 to protect VLAN4.

  2. Inspect all common connection-oriented protocols.

  3. Apply egress ACL on unprotected interface(s) only.

  4. Allow ICMP explicitly.

6.2. Advanced Context-Based Access Control (CBAC) (3 points)

  1. Configure CBAC to allow Java applets from 164.0.0.0/8 and 165.0.0.0/8 networks only.

  2. Servers in protected zones should not exceed 200 concurrent embryonic connections. Offending hosts should be blocked for 1 hour.

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.