Routelearn.net
Course menu

Course 13: Security FundamentalsLesson 4.3 (9 of 10 in this course)98 of 104 in the CCNA series

Lab: writing and placing ACLs

Turn a written policy into an extended ACL and a VTY access-class, predict what each test packet meets, and fix three classic mistakes.

Intermediate · 20 min read

After this lesson, you can turn a written policy into ACLs, place each one where it filters the right traffic, and prove it with the match counters.

Access control list (ACL) is an ordered list of permit and deny statements that a router checks against packets, top to bottom, until one matches. A packet that matches nothing is denied by the implicit deny at the end.

In simple terms: A checklist the router reads from the top for every packet. The first line that fits decides; if nothing fits, the packet is dropped.

The policy

The network is the one from the ACL lessons: Sales (192.168.10.0/24) and Admin (192.168.20.0/24) behind R1, the web server SRV1 (192.168.30.10) behind R2. Routing works and nothing is filtered yet. The security team writes:

  1. Sales may use the website on SRV1 (HTTP and HTTPS) and ping it. Nothing else from Sales may reach SRV1.
  2. Sales may reach every other destination as before.
  3. Only the Admin PC (192.168.20.10) may SSH to R1 and R2.
  4. The Admin LAN is not restricted.

Task 1: plan it

For each rule: standard or extended ACL, which router, which interface or line, and which direction?

Show the plan
RulesACLWhereWhy there
1 and 2Extended, named SALES-INR1 Gi0/0, inboundIt matches source, destination and port, so it can go next to the source and drop unwanted traffic before it crosses the network.
3Standard, named VTY-ADMINVTY lines on R1 and R2, access-class inIt only needs the source address, and it protects the routers' own logins.
4None–No ACL on Gi0/2 means nothing from the Admin LAN is filtered.

Task 2: write and apply the ACLs

Show the configuration
ip access-list extended SALES-IN 10 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80 20 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443 30 permit icmp 192.168.10.0 0.0.0.255 host 192.168.30.10 echo 40 deny ip 192.168.10.0 0.0.0.255 host 192.168.30.10 50 permit ip 192.168.10.0 0.0.0.255 any ! interface GigabitEthernet0/0 ip access-group SALES-IN in

R1. The order matters: the specific permits to SRV1 come before the deny for SRV1, and the general permit comes last. Line 50 is what keeps rule 2 working.

ip access-list standard VTY-ADMIN permit host 192.168.20.10 ! line vty 0 15 access-class VTY-ADMIN in

R1 and R2. access-class filters logins to the router itself; ip access-group would filter traffic passing through an interface.

What about DHCP for the Sales PCs?

If R1 is the DHCP server or relay for Sales, a DHCPDISCOVER arrives on Gi0/0 from 0.0.0.0 to 255.255.255.255. It matches no line of SALES-IN, so the implicit deny drops it and new PCs get no address. Add a line before the end: 45 permit udp any any eq bootps.

Task 3: predict, then watch

For each test, decide which line of SALES-IN matches (or whether the ACL is involved at all) before you watch.

Test:
Gi0/0192.168.10.0/24Gi0/2192.168.20.0/24Gi0/1Gi0/110.0.12.0/30Gi0/0PC1 (Sales)192.168.10.10Admin PC192.168.20.10R1R2SRV1 (web)192.168.30.10/24
  1. 1. Checked on the way in: line 10 doesn't match (port 80); line 20 matches: permit.
  2. 2. Delivered: the page loads. The replies come back through Gi0/0 outbound, which has no ACL.
An inbound ACL checks each packet once, as it enters the interface, and the first matching line decides.

Task 4: read the counters

Example output written for this lab, based on Cisco IOS documentation
R1#show access-lists SALES-IN
Extended IP access list SALES-IN
    10 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq www (152 matches)
    20 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443 (1208 matches)
    30 permit icmp 192.168.10.0 0.0.0.255 host 192.168.30.10 echo (8 matches)
    40 deny ip 192.168.10.0 0.0.0.255 host 192.168.30.10 (4 matches)
    50 permit ip 192.168.10.0 0.0.0.255 any (377 matches)
IOS shows port 80 as www. Counters only rise when a line matches, so they show which lines are actually doing something. Line 40's 4 matches are the blocked SSH attempts.

Task 5: find the mistakes

Predict · scenario 1

A colleague applied SALES-IN with ip access-group SALES-IN out on R1 Gi0/0 instead of in. What happens to Sales?

Predict · scenario 2

Someone moved line 40 (deny ip … host 192.168.30.10) to sequence 5. What breaks?

Predict · scenario 3

New Sales PCs get no IP address after SALES-IN is applied. R1 is their DHCP server. What is the fix?