Security Fundamentals // Lesson 06

Access Control Lists.

Configure and verify numbered or named IPv4 ACLs using ordered ACEs, wildcard masks and correct placement.

Standard ACLExtended ACLWildcardImplicit denyPlacement
01 // Mental model

Start with the big picture.

Entries are checked top-down; the first match decides and processing stops.

CCNA focus: Translate the requirement into protocol, source, destination and service; order specific entries before broad ones; apply once per protocol, direction and interface; then inspect counters.
02 // Building blocks

Know what each part does.

01

ACE processing

Entries are checked top-down; the first match decides and processing stops.

02

Implicit deny

Every ACL ends with an unseen deny any, so traffic not explicitly permitted is denied.

03

Standard ACL

Matches source IPv4 address only and is generally placed near the destination.

04

Extended ACL

Can match protocol, source, destination and ports and is generally placed near the source.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
Wildcard 0Corresponding address bit must match.
Wildcard 1Corresponding address bit is ignored.
InboundChecked as a packet enters an interface, before the routing decision.
OutboundChecked after routing, as a packet leaves an interface.
04 // Extended named ACL

Extended named ACL.

R1(config)# ip access-list extended USERS-IN
R1(config-ext-nacl)# permit tcp 10.10.10.0 0.0.0.255 host 10.20.20.10 eq 443
R1(config-ext-nacl)# permit udp 10.10.10.0 0.0.0.255 host 10.20.20.53 eq 53
R1(config-ext-nacl)# deny ip any any log
R1(config)# interface gigabitEthernet 0/0
R1(config-if)# ip access-group USERS-IN in
R1# show access-lists
R1# show ip interface gigabitEthernet 0/0

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Corresponding address bit must match.
  • Corresponding address bit is ignored.
  • Checked as a packet enters an interface, before the routing decision.
  • Checked after routing, as a packet leaves an interface.
Exam checkpoint: Translate the requirement into protocol, source, destination and service; order specific entries before broad ones; apply once per protocol, direction and interface; then inspect counters.
06 // Check yourself

Access Control Lists quiz.

1. How are ACL entries evaluated?

2. What happens when no ACE matches?

3. What does a wildcard-mask bit of 0 mean?

4. Where are extended ACLs generally placed?

5. Which command applies an IPv4 ACL to an interface?

Score: 0 / 5