← All labs Lab 12 · Packet Tracer

Named extended ACL

Filter by protocol and port and apply close to the source

Level: Advanced Time: 30 min Domain 5.0 Security Fundamentals

Scenario

SRV1 (192.168.30.10) is a web server. LAN 192.168.10.0/24 must not open its website (TCP 80), but it can still ping it and reach the other networks. LAN 192.168.20.0/24 can do everything.

Create the named extended ACL BLOQUEO_WEB and apply it where an extended ACL belongs: as close as possible to the source. Test it from PC1 with curl 192.168.30.10 (it should fail) and from PC3 (it should work).

Topology

PC1PC2SW1R1PC3SRV1Gi0/0Gi0/1Fa0Fa0/1Fa0Fa0/2Gi0/1Fa0Gi0/2Fa0

Devices and cabling

FromToCable
R1 Gi0/0SW1 Gi0/1Straight-through
PC1 Fa0SW1 Fa0/1Straight-through
PC2 Fa0SW1 Fa0/2Straight-through
R1 Gi0/1PC3 Fa0Crossover
R1 Gi0/2SRV1 Fa0Crossover

If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.

Addressing

DeviceInterfaceAddressMaskDefault gateway
R1G0/0192.168.10.1255.255.255.0—
R1G0/1192.168.20.1255.255.255.0—
R1G0/2192.168.30.1255.255.255.0—
PC1NIC192.168.10.10255.255.255.0192.168.10.1
PC2NIC192.168.10.11255.255.255.0192.168.10.1
PC3NIC192.168.20.10255.255.255.0192.168.20.1
SRV1NIC192.168.30.10255.255.255.0192.168.30.1

Starting configuration

In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.

R1hostname R1 no ip domain-lookup interface g0/0 ip address 192.168.10.1 255.255.255.0 no shutdown interface g0/1 ip address 192.168.20.1 255.255.255.0 no shutdown interface g0/2 ip address 192.168.30.1 255.255.255.0 no shutdown
SW1hostname SW1 no ip domain-lookup

PCs and servers (Desktop › IP Configuration)

Tasks

What must end up working. In the app, each one ticks itself off as soon as you get it.

  1. Extended ACL BLOQUEO_WEB exists
  2. PC1 can't open the server's website
  3. PC1 can still ping the server
  4. PC3 can open the website
  5. Applied inbound on G0/0, next to the source
  6. PC1 still reaches PC3
  7. Tested with curl from PC1
In Packet Tracer
  • Same topology as the standard ACL lab. The Server-PT has HTTP on (Services tab).
  • To test the website, on PC1 go to Desktop › Web Browser and open http://192.168.30.10: it shouldn't load. From PC3, it should.
Hints
  • Extended ACL BLOQUEO_WEB exists: ip access-list extended BLOQUEO_WEB
  • PC1 can't open the server's website: deny tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80
  • PC1 can still ping the server: After the deny, permit ip any any; otherwise the implicit deny blocks everything
  • PC3 can open the website: The ACL must only affect LAN 192.168.10.0/24
  • Applied inbound on G0/0, next to the source: interface g0/0 → ip access-group BLOQUEO_WEB in
  • PC1 still reaches PC3: From PC1: ping 192.168.20.10
  • Tested with curl from PC1: On PC1's console: curl 192.168.30.10

Step-by-step solution

Try it on your own first: you learn much more by typing the commands yourself.

Show the solution

1Create the named extended ACL R1

An extended ACL filters by source, destination, protocol and port. eq 80 is HTTP (IOS shows it as www).

R1enable configure terminal ip access-list extended BLOQUEO_WEB deny tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80 permit ip any any exit

2Apply it close to the source R1

Since it filters so precisely, it goes as early as possible so the network doesn't carry traffic that will be dropped.

R1interface g0/0 ip access-group BLOQUEO_WEB in end

Verification

PC1's ping to the server still works: only port 80 is blocked.

PC1C:\>ping 192.168.30.10 Pinging 192.168.30.10 with 32 bytes of data: Reply from 192.168.30.10: bytes=32 time<1ms TTL=127 Reply from 192.168.30.10: bytes=32 time<1ms TTL=127 Reply from 192.168.30.10: bytes=32 time<1ms TTL=127 Reply from 192.168.30.10: bytes=32 time<1ms TTL=127 Ping statistics for 192.168.30.10: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms

The deny line adds matches when PC1 tries to open the website.

R1R1#show access-lists Extended IP access list BLOQUEO_WEB 10 deny tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq www (1 match(es)) 20 permit ip any any (8 match(es))

G0/0 has BLOQUEO_WEB inbound.

R1R1#show ip interface g0/0 | include access list Outgoing access list is not set Inbound access list is BLOQUEO_WEB

Common mistakes

Practice this lab on your phone

RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.

Get RoutingLab