Configure and verify numbered or named IPv4 ACLs using ordered ACEs, wildcard masks and correct placement.
Standard ACLExtended ACLWildcardImplicit denyPlacement
01 // Mental model
Start with the big picture.
Entries are checked top-down; the first match decides and processing stops.
CCNA focus: Translate the requirement into protocol, source, destination and service; order specific entries before broad ones; apply once per protocol, direction and interface; then inspect counters.
02 // Building blocks
Know what each part does.
01
ACE processing
Entries are checked top-down; the first match decides and processing stops.
02
Implicit deny
Every ACL ends with an unseen deny any, so traffic not explicitly permitted is denied.
03
Standard ACL
Matches source IPv4 address only and is generally placed near the destination.
04
Extended ACL
Can match protocol, source, destination and ports and is generally placed near the source.
03 // Compare and recognise
Read the clues.
Item
What to remember
Wildcard 0
Corresponding address bit must match.
Wildcard 1
Corresponding address bit is ignored.
Inbound
Checked as a packet enters an interface, before the routing decision.
Outbound
Checked after routing, as a packet leaves an interface.
04 // Extended named ACL
Extended named ACL.
R1(config)# ip access-list extended USERS-INR1(config-ext-nacl)# permit tcp 10.10.10.0 0.0.0.255 host 10.20.20.10 eq 443R1(config-ext-nacl)# permit udp 10.10.10.0 0.0.0.255 host 10.20.20.53 eq 53R1(config-ext-nacl)# deny ip any any logR1(config)# interface gigabitEthernet 0/0R1(config-if)# ip access-group USERS-IN inR1# show access-listsR1# show ip interface gigabitEthernet 0/0
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
Corresponding address bit must match.
Corresponding address bit is ignored.
Checked as a packet enters an interface, before the routing decision.
Checked after routing, as a packet leaves an interface.
Exam checkpoint: Translate the requirement into protocol, source, destination and service; order specific entries before broad ones; apply once per protocol, direction and interface; then inspect counters.
06 // Check yourself
Access Control Lists quiz.
1. How are ACL entries evaluated?
2. What happens when no ACE matches?
3. What does a wildcard-mask bit of 0 mean?
4. Where are extended ACLs generally placed?
5. Which command applies an IPv4 ACL to an interface?