Creating wildcard masks for ACL's...

Paunchy

Member
Sep 19, 2001
126
0
0
Hey all... I'm trying to get my brain around wildcard masking for ACL's and I'm having some trouble... I've gone through a few examples and I understand about half of them, so I'm apparently missing some part of the puzzle... if anyone has time to work out an example based on the information I provided (with some sort of detail), I'd greatly appreciate it...

Say you want to create an ACL to filter traffic from subnet 172.12.45.0 - 172.12.100.0 What would the wildcard mask look like, and how do you do the math to create it? I understand from simpler examples that you find a common bit pattern in whatever octet(s) you're filtering, but I can't reproduce the wildcard mask every time.

This is what I understand:

45 = 00101101
100 = 01100100

So is the wildcard mask 0.0.178.255 OR 0.0.128.255 OR am I completely wrong?

Once again, any help would be appreciated... thanks in advance...

--Paunchy
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
Wildcard masks only work if the start and end addresses are whatever power of two is associated with the mask. That is to say, you can easily create a mask for .128 to .191:

128 = 10000000
191 = 10111111

So clearly, if you create a mask that says the first two bits are the same and the last six bits are wildcarded, you're in good shape.

In order to do arbitrary ranges, you will have to have multiple rules with multiple masks.

Here's a tool that will compute it for you:

http://www.csc.fi/english/funet/calc/laskin2.html

For your range, it says you need: (I'm just copying the rightmost column, which is in CIDR notation):
172.12.45.0/24
172.12.46.0/23
172.12.48.0/20
172.12.64.0/19
172.12.96.0/22
172.12.100.0/32

This is a lot uglier than what I think you were hoping to find, but it still beats listing every subnet out.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |