CCIE Wireless Written Exam: Minimum Number of Rules for CPU ACL | VLAN Management Access

Minimum Number of Rules for CPU ACL

Question

What is the minimum number of rules that is necessary in a CPU ACL to allow all access from a single VLAN to the management interface, yet prevent management access from all other VLANs while permitting all other traffic?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B.

To allow all access from a single VLAN to the management interface, while preventing management access from all other VLANs, a CPU Access Control List (ACL) needs to be configured.

The CPU ACL is applied to traffic destined to the management interface, and it is used to filter traffic that is not allowed to reach the management interface.

To achieve the required functionality, the following rules need to be configured in the CPU ACL:

  1. Permit all traffic from the management VLAN to the management interface.
  2. Permit all traffic from the management interface to the management VLAN.
  3. Deny all traffic from all other VLANs to the management interface.
  4. Deny all traffic from the management interface to all other VLANs.
  5. Permit all other traffic.

Therefore, the minimum number of rules necessary in a CPU ACL to allow all access from a single VLAN to the management interface, yet prevent management access from all other VLANs while permitting all other traffic is five.

Therefore, the correct answer is A. five.