If any of you are stuck, remember applying the ACL to an interface is case sensitive, maybe Jeremy mentioned that but it got me this video!
@mrbanaly2 жыл бұрын
I am practicing your labs and then validating with your videos. I feel like I am accomplished a significant progress on the CCNA material. THANK U VERY MUCH!!
@Gelimarr6 ай бұрын
do you have your CCNA by now?
@iamsteezze3 жыл бұрын
Thanks for all you do for the community. Your effort is not going unnoticed
@JeremysITLab3 жыл бұрын
Thanks, I appreciate it :)
@paulroberts85422 жыл бұрын
As a suggestion - an alternative way to show that DNS is blocked is to use the 'nslookup' command from the PC. That way, you don't need to know the host names that the DNS server has configured.
@iamjoycheee Жыл бұрын
Thank you sir! I got stuck on the wildcard mask block used in 15:40 which means my subnetting knowledge is not yet that strong:( . I know you mentioned regarding this on the lecture vid but i need to practice more. Once again sir thank you very much.
@Alberto.813 жыл бұрын
Thank you jeremy for another great video. Looking forward for more!
@JeremysITLab3 жыл бұрын
Thanks Alberto!
@hotmail48236202 жыл бұрын
We must atleast like and subscriber to thank Jeremy for the intelligent and hardwork he has done
@vauxhallchevette58583 жыл бұрын
Happy new year Jeremy. I hope you will finish this course soon and start another one.
@JeremysITLab3 жыл бұрын
Thanks, happy new year!
@NetworkingwithHamza6 ай бұрын
I forgot permit ip any any on R1 g0/0 so my pings were failing even when I was using ip address of svr 2 to ping, and I was wondering why is it pinging for you in your video and failing in my lab. I figured it out.
@racheldecastro4551Ай бұрын
I did the same exact thing lol! I think we got so focused on the more complicated ACEs that we completely overlooked the stuff about implicit deny.
@MosesRms3 жыл бұрын
you have realy been doing a great job and you know how to bring up the lessons, bunch of thanks
@JeremysITLab3 жыл бұрын
Thank you, glad you like it :)
@HemanthJabalpuri Жыл бұрын
Your lab is great as usual. But today's Boson lab is very interesting.
@Madmark50484 Жыл бұрын
After a Monmouth 2 1/2 days and 15 of your days of lessons. I’ve realised not going to be able to complete the course in a week as I planned. I calculate I would be 7 of your days short. Still going to push through and learn it but at a milder pace. When I’m off in March maybe then I can go mad and finish it.
@Reason_over_Dogma3 жыл бұрын
Thanks for the video. I put it on each interface of R1. I had it going out of s0/0/0 inbound but this is much cleaner.
@LeeDowney5 ай бұрын
The ACL name mode is case sensitive!!! Just FYI incase you can't figure out why yours isn't working! 🙂
@-b777ljq33 жыл бұрын
this lab is very helpful to understand extended ACL, very good, thank Jeremy very much for the hard work.
@samirsamir77793 жыл бұрын
Hello Jeremy + Happy new year !!! thank you for your awesome courses about CCNA . All the Best..
@JeremysITLab3 жыл бұрын
Thanks, happy new year!
@mohammedimranali84773 жыл бұрын
Thanks a billion times for your videos. Can you please let me know when WIFI SDN & NETWORK PROGRAMABILITY STARTS PLEASE UPDATE THANKS
@JeremysITLab3 жыл бұрын
I'll cover them at the end of the course
@VeryBigBang133 жыл бұрын
Awesome video, as always ! I spent way too much time trying to pick an appropriate name for my ACLs... i hate myself for that 😂
@JeremysITLab3 жыл бұрын
Better than totally random names that don't help at all! ;)
@ross91883 жыл бұрын
Really good work Jeremy, much appreciated! Your videos in conjunction with ITproTV has put me on a really good track :)
@JeremysITLab3 жыл бұрын
Thanks Ross :)
@vhomotlatsi4866 ай бұрын
Very helpful. Thank you, Jeremy.
@konefine36263 жыл бұрын
Always great video with a perfect explanation thank you Jeremy
@JeremysITLab3 жыл бұрын
Thanks Kone!
@jacquepackage5 ай бұрын
What is a simple way of remembering if the rule should be inbound or outbound? its the only thing getting me mixed up with ACLs
@yawziddah8494 ай бұрын
If you're using standard ACL use outbound on the destination interface and if using Extended ACL use inbound on the source ACL.. This tip might help
@jacquepackage4 ай бұрын
@@yawziddah849thank you! I’ll keep that in mind.
@syedyousafbukhari221324 күн бұрын
yes got me confused too earlier, simple way is to understand IN would be to the router through that interface. OUT would be out of the router through that interface and accordingly you can judge, like the other guy said as well. Standard close to destinations and Extended close to Source!
@nicholassattaur99643 жыл бұрын
Great video Jeremy, loved the topic! Thank you
@JeremysITLab3 жыл бұрын
Thanks Nicholas :)
@ZkinLarz2 ай бұрын
Can i also do it as "ip access-list 101 extended"?
@syedyousafbukhari221324 күн бұрын
yes but the word "extended" comes before the numbers
@MiguelHernandez-zd7kr3 жыл бұрын
Great lab! thank you once again
@JeremysITLab3 жыл бұрын
Thanks Miguel!
@obwizy3 жыл бұрын
oh no, I have caught up. looking forward to more videos.
@JeremysITLab3 жыл бұрын
Glad you like the videos :) Next one coming in about an hour!
@olaniyi010 ай бұрын
Day 35, I can't afford the exam... However, I'm learning and improving my networking knowledge... Thank you Jeremy
@abelornet90172 жыл бұрын
Thank you so much. it's easy to understand
@MohammedAbdalla-d5g3 жыл бұрын
greetings jermey , keep up the good work
@JeremysITLab3 жыл бұрын
Thanks :)
@onewaydrive_3 жыл бұрын
I think I got this :) ACLs at least lol by the way, youre originally from Canada right? I hear the "aboot" ;)
@JeremysITLab3 жыл бұрын
Haha yep, good ear! (or maybe my accent is stronger than I thought lol)
@Alex-jh8pj3 жыл бұрын
Hello Jeremy, your course about CCNA is the best in the internet. and the flashcards are extremely helpful. Thank you for that all. I have a question about boson ExSim, Is the access lifetime or is the access limited? sorry if you already mentioned it. my english is not good.
@JeremysITLab3 жыл бұрын
Access is lifetime! :)
@pissedputin77383 жыл бұрын
If you double click on the devices in Boson, it would open the console. Rather than clicking once on the device and then the "console" button.
@JeremysITLab3 жыл бұрын
Thanks for the tip 👍
@Abiymokve3 жыл бұрын
Thank you very much for the courses .how many courses are there to finish? at least as an estimate
@JeremysITLab3 жыл бұрын
The course is about 70% complete I think
@yashchellani58553 жыл бұрын
Thanks for the consistent videos. I just had a small doubt. When we are asked to create one rule to include both the PCs, how did you determine the IP address of 10.10.2.0 and Wildcard mask of 0.0.1.255 respectively. Thank you!!
@JeremysITLab3 жыл бұрын
Hi, what time in the video?
@yashchellani58553 жыл бұрын
@@JeremysITLab 15:40
@gerryvalenzuela91583 жыл бұрын
I have the same question as Yash
@syedyousafbukhari221324 күн бұрын
i'm someone who is pretty weak with these too but all i understood is it's /23 wildcard mask, meaning the 3rd octet isn't fixed. so it will have a range of 2 and 3? not so sure. so in that way it will cover both those ip addresses, im guessing
@spectrumanalyzer30932 жыл бұрын
Once again, a superb video. Really great detail and very useful examples and quiz questions.
@youssefsalama6633 жыл бұрын
You are the best! Thanks!!!
@JeremysITLab3 жыл бұрын
Thanks Youssef :)
@rayyanshaikh34423 жыл бұрын
good work sir jeremy appreciated
@JeremysITLab3 жыл бұрын
Thank you :)
@yoriichiT9 ай бұрын
thanks for the course i still have a doubt about how you decided to use the /23 prefix on 15:40
@desmondchung13958 ай бұрын
I don't know if you still need this.. But I think it's as below. Write out PC2/PC3 IP in binary: 10.10.2.102 = 00001010.00001010.00000010.01100110 10.10.3.103 = 00001010.00001010.00000011.01100111 First 23bits are the same. Rewrite the subnet mask /23. 11111111.11111111.11111110.00000000 Invert them to get the wildcard mask. 00000000.00000000.00000001.11111111 and you'll get 0.0.1.255 All the best with your CCNA!
@syedyousafbukhari221324 күн бұрын
i'm someone who is pretty weak with these too but all i understood is it's /23 wildcard mask, meaning the 3rd octet isn't fixed. so it will have a range of 2 and 3? not so sure. so in that way it will cover both those ip addresses, im guessing
@zarados23 жыл бұрын
Hello Jeremy great video as always! Thank you for creating such a comprehensive video on CCNA. I just want to ask how did you decide to use a /23 prefix on 15:50. Can't a /24 prefix be used on this scenario since they both have a /24 prefix? Thank you!
@JeremysITLab3 жыл бұрын
You could use /24, but then you'd need to use two permit statements, one for each /24 network.
@zarados23 жыл бұрын
@@JeremysITLab Thank you for answering! This will surely help me in my learnings.
@syedyousafbukhari221324 күн бұрын
7:30 can we make this command with "range 80 - 443" ? or would it block a lot of other protocols which we might need like ospf eigrp?
@DevOpsPulse3 жыл бұрын
thank you thank you
@Moss23233 жыл бұрын
Great job
@racheldecastro4551Ай бұрын
Was scratching my head for a while on why more traffic was being blocked than there should've been after applying the ACLs, until I realized in the process of creating the more thought out ACEs I completely forgot slap on a simple "permit ip any any" afterwards to prevent the implicit deny! That felt really silly.
@Idea3655.3 жыл бұрын
hello sir i have some problem if try dns like ping pc1 then say -----Ping request could not find host pc3. Please check the name and try again.---- whats that mean still i didn't config any acl
@hanimazen57172 жыл бұрын
Thank you jeremy for sharing your knowledge with us i hope people reward/support you for your hard work. Quick question CCNA 200-301 exam has no labs in it just multiple choices is that correct ? Thanks
@tejas39683 жыл бұрын
Hello Sir, Your videos are easy to understand and fun to learn. Is this course enough to pass the official CCNA exam? Thanks for your efforts to teach us! It means a lot
@JeremysITLab3 жыл бұрын
Hello! The course isn't complete at the moment, so it won't be enough. I recommend reading the official cert guides by Wendell Odom to fill in the gaps.
@maksudmuzaffarov6652 жыл бұрын
HOnestly, I wanted smash more like buttons, UNfortunately, i am not able. Amazing content, thank you Jeremy
@faridgulum12262 жыл бұрын
You merged 1st and 3nd one into ACL-id 101. What if I create another ACL for the 3rd requirement ? 100 and 101 for the first 2 requirements and 102 for the third one where we have to block http/s traffic.
@mg76705 ай бұрын
Thanks!
@FuryRushBe3 жыл бұрын
спасибо большое
@JeremysITLab3 жыл бұрын
Thanks for watching ;)
@Ahmed-TOUMI Жыл бұрын
Hi Jeremy, many thanks for your awesome courses, I wan just to ask you if I can use "permit IP host 10.0.1.1 host 10.0.2.1 eq 80" command in place of "permit TCP host 10.0.1.1 host 10.0.2.1 eq 80" that means using "IP" and no "TCP" in the first ACE
@syedyousafbukhari221324 күн бұрын
no cuz tcp is only needed to be blocked!
@worldofhind6233 жыл бұрын
Hello thank you very much I want to ask about where I can take online classes and have the certification of CCNA 1 2 3 and 4 please thank you
@JeremysITLab3 жыл бұрын
There is only one CCNA certification, not 4
@worldofhind6233 жыл бұрын
How i can have it online please thank you for your answer
@rohailbukhari26873 жыл бұрын
@5:04 why is it that when u configured acl to deny traffic to SRV1 from 172.16.1.0/24, you decided to ping SRV2 instead? and y did it affect SRV2 when we only denied traffic to SRV1?
@JeremysITLab3 жыл бұрын
I pinged srv2 by host name to test if PC1 is able to access the DNS service on host 1. It couldn't ping srv2 by host name, meaning it couldn't access the DNS service on srv1.
@utshavb Жыл бұрын
5:09 Why arent we able to ping SRV2? We blocked SRV1 for PC1 to access DNS service for SRV1 and not SRV2? Any insight?
@JeremysITLab Жыл бұрын
Because SRV1 is the DNS server, so DNS doesn't work (PC1 can't learn SRV2's IP).
@vikashranjan12163 жыл бұрын
When will the course will complete?? Any estimated date??
@JeremysITLab3 жыл бұрын
Probably the first half of this year!
@pieleanumihai92810 ай бұрын
thanks
@nedatuaconta2431 Жыл бұрын
tysm
@fragiskosbatis3 жыл бұрын
happy new year to everyone i have a question from what i can see, the ip access-list resequence command is not working in packet tracer am i right?
@JeremysITLab3 жыл бұрын
Not sure, I haven't tried it in packet tracer. But there are many commands that aren't available in packet tracer, so perhaps 'ip acecss-list resequence' is one of them!
@TiTo_SPB3 жыл бұрын
I just want to thank you for the great effort you did , the way your explaning its really amazing ,,, now i just finished your videos ,, and really excited to finish it , but i am really afraid to lose motivation unill you finsih it,, so i dont know what to do ,,any advice ? also i have another question )) ,, i am working in communication company (transit company) which deal with voice over ip using SIP protocol ,, most of our work on cisco routers but i am still in the beginnrer level so i dont deal with the routers direct. thats why i am really intersted now to finish the CCNA.. my question is if you know any course related to SIP protocol. i just found SIP school certified associate but i never heared about this certificate , just need your opinion and advice and for the CCNA course do you recomend cisco-ccna-gold-bootcamp-course from Neil Anderson or David Bombal thank you in advance
@JeremysITLab3 жыл бұрын
Unfortunately it will be a while before I finish the course, so I think it's best to get another course and a book! For the book, I recommend the official cert guides (vol 1 and 2) by Wendell Odom, and for the course I like Neil Anderson's. I'm sure David Bombal's is great too, but I didn't use it myself. Not really sure about SIP courses. I don't use it in my work and have never studied it.
@prathameshgaikwad92813 жыл бұрын
i downloaded packet tracer files from your website but it is showing incompatible with current version Is bosonnetsi, free software?
@JeremysITLab3 жыл бұрын
My files are all compatible with the current version. What version are you using? NetSim isn't free, it's a product made by Boson Software.
@TRERERA3 жыл бұрын
I need to pass my exam. i want to prepare myself with your courses. After all this, Can you help me to aply to a plateform fir the ccna test?
@JeremysITLab3 жыл бұрын
Do a Google search for 'Pearson VUE Cisco', you can apply for the exam there :)
@TRERERA3 жыл бұрын
@@JeremysITLab Thank you !
@sumitsingh-ys6ew3 жыл бұрын
jeremy, one little doubt at 5:27 How PC1 is able to perform ARP process as the ARP request uses destination ip= FFFF-FFFF-FFFF which can't be routed between routers R1 and R2. then how PC1 is able to ping SRV2 succesfully??
@sumitsingh-ys6ew3 жыл бұрын
@@JeremysITLab that means, as the PC1 will send an ARP request then in reply to that request the R1 will respond with its MAC in that ARP response and then PC1 will send that ping packet of SRV to R1(def. gateway) and later the R1 will use its routing table to forward the ping to SRV1. RIGHT???
@deepbaban68643 жыл бұрын
How many more videos will be there to complete course?
@JeremysITLab3 жыл бұрын
The course is about 70% complete
@benoitwaziri2004 Жыл бұрын
very good merci bcp
@rekharanibehera81303 жыл бұрын
I know you have already posted the progress a while back. But what's the present progress, what do u think how much percentage have we completed so far?
@JeremysITLab3 жыл бұрын
It's probably about 70% complete at the moment.
@rekharanibehera81303 жыл бұрын
Thanks for everything and your effort too. . .
@rekharanibehera81303 жыл бұрын
Btw Happy New Year 😺 Jeremy.... Have a great year ahead.....😃👍
@Zlarg8 ай бұрын
Are there any benefits to making seperate entries in the ACL for blocking TCP & UDP connections to the DNS service, instead of just denying "IP"? UPDATE: after testing I can answer my own question haha. Denying IP wil block all IP traffic without allowing a specific port/service to be configured. So if you want to target specific ports/services, you will need to use TCP or UDP in the command.
@VladimirGKovalev6 ай бұрын
For DNS service first I tried an inverse logic, to permit all tcp/udp traffic from 172.16.1.0/24 to SRV1 except port 53 in SRV1. Here is the excerpt from PT's CLI: Extended IP access list 105 5 permit udp 172.16.1.0 0.0.0.255 host 192.168.1.100 neq domain 10 permit tcp 172.16.1.0 0.0.0.255 host 192.168.1.100 neq domain 15 permit ip any any ACL 105 was applied same way to R1's G0/0 inbound. However this solution doesn't work and I cannot understand why?
@syedyousafbukhari221324 күн бұрын
hey! i checked ur question with chat gpt, it's pretty hard to understand but basically the ACL continues reading the other entries even when it's port 53 (DNS) and when it finally reaches permit ip any any.. it doesn't block and ur DNS traffic goes through.. u can check it out too for further understanding!
@juliocesarmoreno92723 жыл бұрын
hey jeremi thank for your videos if i join the chanel what I get ?
@JeremysITLab3 жыл бұрын
Click the 'join' button under the video, it says what you get.
@sujoenilshahi97153 жыл бұрын
Sir, i have one problem to solve ...there is one switch in school and that switch is working fine its a 24 port switch but when i replaced with 16 port switch it was not working and even light was glowing do i need to configure ..so what are the measure steps should i take to resolve ... This is a real world problem when i learn your lecture it seems easy but when real world problem comes its really difficult to understand ...so while placing new switch what r the things we need to know
@65gtotrips3 жыл бұрын
🔰 It’s not remotely fair to ask Jeremy to troubleshoot a device for you; A device he has no access to, has no direct connection, no model #, IOS level, situational background, etc... > Have you searched the internet for information on your replacement switch❓ > Have you backed up and reviewed the old switches configuration❓ > Have you made sure your cables or correct❓ > Have you gone into the new switches configuration and looked at how it’s configured❓ > Have you referred to the new switches manual❓ > Have you looked at the new switches manufacturer website knowledge base❓ These are the things that your expected to do as a competent network technician
@JeremysITLab3 жыл бұрын
Thanks @CiscoLadder for helping out! Yeah, I can't really help out with questions like this, I need more info than can be easily conveyed over KZbin comments.
@pelisclips31533 жыл бұрын
Hi Jeremy, I have a question for you. I tried to experiment in the lab a bit and tried to deny DNS to server using the same commands from this lab but for SRV2. However, when I ping srv2, I get a ping back every time. I applied it to the ACL to g0/0 interface inbound. R1(config)#ip access-list extended NEW R1(config-ext-nacl)#deny udp 172.16.1.0 0.0.0.255 host 192.168.2.100 eq 53 R1(config-ext-nacl)#deny tcp 172.16.1.0 0.0.0.255 host 192.168.2.100 eq 53 R1(config-ext-nacl)#permit ip any any R1(config-ext-nacl)#int g0/0 R1(config-if)#ip access-group NEW in
@pelisclips31533 жыл бұрын
ah, I see now. You configured DNS for both Srv1 and Srv2. My mistake. Thanks again for the resources! This is very helpful in helping me understand the concept
@syedyousafbukhari221324 күн бұрын
@@pelisclips3153 yea the DNS server was supposed to be Server 1 not 2. and i guess u can still ping but just not by the names the ones u denied..
@twanaahmedbrno62043 жыл бұрын
thank you a lot I have written to you before and again I'm saying that we don't know how to thank you sir you are the best in my networking career I just wanna ask you to advise me and tell me the name of the best programming language for networking just give me the name, please java or python or which one do you recommend is the best?? I have been confused about this question a lot thanks for everything
@JeremysITLab3 жыл бұрын
For networking, Python 100%!
@twanaahmedbrno62043 жыл бұрын
Thank you so much bro 💚💛🧡💙❤️
@modassirjamal53783 жыл бұрын
How many videos still left to upload
@cloaksorg3 жыл бұрын
I think he said there will be about 50 total.
@JeremysITLab3 жыл бұрын
Yeah about 50 days to 60 days in total, we'll see.
@modassirjamal53783 жыл бұрын
@@JeremysITLab there are two sections of ur videos other one is full of practical is it for new CCNA and is there any other video still left to upload there also.
@NathanAlpern Жыл бұрын
Hi. if you apply the deny ip for pc1 you could still ping pcq because its ICMP. am i correct?
@syedyousafbukhari221324 күн бұрын
ip includes all traffic though.. depends if ur destination is different, then it would allow icmp i guess
@susmitamazumder83903 жыл бұрын
for 1 line extended numbered acl we dont need to use ip at the begining of the command? I have tried using multiline command without using ip that wont work.
@JeremysITLab3 жыл бұрын
Sorry, I don't understand the question. Are you asking about 1 line or multiline?
@susmitamazumder83903 жыл бұрын
@@JeremysITLab hi Jeremy In Odom's book p63 have extended (num) acl cmd , those are 1 line (I mean everything covered in 1 line) . e.g. access-list 101 permit tcp host 10.1.1.1 10.1.2.0 0.0.0.255 eq www The command is like that.
@syedyousafbukhari221324 күн бұрын
i think i know what you mean.. u use ip cuz ur blocking all traffic, not certain type of traffic
@65gtotrips3 жыл бұрын
🔰 Hiya Jeremy, I think I’ve asked this before but...I don’t see any ‘JOIN’ button i.e. as I do in other content provider channels... Is it something particular to an iPhone not seeing it❓ I know what it looks like, it’s a blue ‘JOIN’ button, but I never see it under any of your superb videos... I’d like to join...as I’m a loyal follower and I always recommend you to other CCNA candidates... Best Regards, Dave - CiscoLadder
@JeremysITLab3 жыл бұрын
Hi Dave! Thanks so much for offering your support. In the iPhone app it should be right next to the subscribe button, I can see it on my videos. If you can't see it, I have no idea what the problem could be. Maybe check it out on PC?
@TiTo_SPB3 жыл бұрын
Hi Jeremy ,,, just want to know if the course on your website is complete or not and if not how long will it take you to complete it ?
@JeremysITLab3 жыл бұрын
Nope, many more videos to come. I'll finish it this year.
@ipada95 Жыл бұрын
Is it an error on CCNA to create 2 different ACLs for request 1 and 3?
@syedyousafbukhari221324 күн бұрын
not unless you're told to, whatever's the requirement, you should do it accordingly
@markganus10852 жыл бұрын
is there a free open source alternative to netsim?
@JeremysITLab2 жыл бұрын
Packet Tracer is the only free alternative.
@al-tahirali27533 жыл бұрын
how many videos left ?
@JeremysITLab3 жыл бұрын
The course is about 70% complete
@SergioValenzuela-bo1ig10 ай бұрын
Why /23 ?
@desmondchung13958 ай бұрын
I don't know if you still need this.. But I think it's as below. Write out PC2/PC3 IP in binary: 10.10.2.102 = 00001010.00001010.00000010.01100110 10.10.3.103 = 00001010.00001010.00000011.01100111 First 23bits are the same. Rewrite the subnet mask /23. 11111111.11111111.11111110.00000000 Invert them to get the wildcard mask. 00000000.00000000.00000001.11111111 and you'll get 0.0.1.255
@syedyousafbukhari221324 күн бұрын
because this covers both 10.10.2.102 and 10.10.3.103.. as that step required us to only use 1 ACL entry, that's why he used /23.
@norwellsgn2853 жыл бұрын
🇵🇭🇵🇭🇵🇭
@JeremysITLab3 жыл бұрын
Thanks for watching!
@SAMSAM-up5nd2 жыл бұрын
this lab is very helpful to understand extended ACL, very good, thank Jeremy very much for the hard work.