SRV1 (192.168.30.10) is a web server. LAN 192.168.10.0/24 must not open its website (TCP 80), but it can still ping it and reach the other networks. LAN 192.168.20.0/24 can do everything.
Create the named extended ACL BLOQUEO_WEB and apply it where an extended ACL belongs: as close as possible to the source. Test it from PC1 with curl 192.168.30.10 (it should fail) and from PC3 (it should work).
Topology
Devices and cabling
R1·2911
SW1·2960-24TT
PC1, PC2, PC3·PC-PT
SRV1·Server-PT
From
To
Cable
R1Gi0/0
SW1Gi0/1
Straight-through
PC1Fa0
SW1Fa0/1
Straight-through
PC2Fa0
SW1Fa0/2
Straight-through
R1Gi0/1
PC3Fa0
Crossover
R1Gi0/2
SRV1Fa0
Crossover
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
R1
G0/0
192.168.10.1
255.255.255.0
—
R1
G0/1
192.168.20.1
255.255.255.0
—
R1
G0/2
192.168.30.1
255.255.255.0
—
PC1
NIC
192.168.10.10
255.255.255.0
192.168.10.1
PC2
NIC
192.168.10.11
255.255.255.0
192.168.10.1
PC3
NIC
192.168.20.10
255.255.255.0
192.168.20.1
SRV1
NIC
192.168.30.10
255.255.255.0
192.168.30.1
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
R1hostname R1
no ip domain-lookup
interface g0/0
ip address 192.168.10.1 255.255.255.0
no shutdown
interface g0/1
ip address 192.168.20.1 255.255.255.0
no shutdown
interface g0/2
ip address 192.168.30.1 255.255.255.0
no shutdown
SW1hostname SW1
no ip domain-lookup
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.10.10, mask 255.255.255.0, gateway 192.168.10.1
PC2: IP 192.168.10.11, mask 255.255.255.0, gateway 192.168.10.1
PC3: IP 192.168.20.10, mask 255.255.255.0, gateway 192.168.20.1
SRV1: IP 192.168.30.10, mask 255.255.255.0, gateway 192.168.30.1 (with the HTTP service on)
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
Extended ACL BLOQUEO_WEB exists
PC1 can't open the server's website
PC1 can still ping the server
PC3 can open the website
Applied inbound on G0/0, next to the source
PC1 still reaches PC3
Tested with curl from PC1
In Packet Tracer
Same topology as the standard ACL lab. The Server-PT has HTTP on (Services tab).
To test the website, on PC1 go to Desktop › Web Browser and open http://192.168.30.10: it shouldn't load. From PC3, it should.
Hints
Extended ACL BLOQUEO_WEB exists: ip access-list extended BLOQUEO_WEB
PC1 can't open the server's website: deny tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80
PC1 can still ping the server: After the deny, permit ip any any; otherwise the implicit deny blocks everything
PC3 can open the website: The ACL must only affect LAN 192.168.10.0/24
Applied inbound on G0/0, next to the source: interface g0/0 → ip access-group BLOQUEO_WEB in
PC1 still reaches PC3: From PC1: ping 192.168.20.10
Tested with curl from PC1: On PC1's console: curl 192.168.30.10
Step-by-step solution
Try it on your own first: you learn much more by typing the commands yourself.
Show the solution
1Create the named extended ACL R1
An extended ACL filters by source, destination, protocol and port. eq 80 is HTTP (IOS shows it as www).
R1enable
configure terminal
ip access-list extended BLOQUEO_WEB
deny tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80
permit ip any any
exit
2Apply it close to the source R1
Since it filters so precisely, it goes as early as possible so the network doesn't carry traffic that will be dropped.
R1interface g0/0
ip access-group BLOQUEO_WEB in
end
Verification
PC1's ping to the server still works: only port 80 is blocked.
PC1C:\>ping 192.168.30.10
Pinging 192.168.30.10 with 32 bytes of data:
Reply from 192.168.30.10: bytes=32 time<1ms TTL=127
Reply from 192.168.30.10: bytes=32 time<1ms TTL=127
Reply from 192.168.30.10: bytes=32 time<1ms TTL=127
Reply from 192.168.30.10: bytes=32 time<1ms TTL=127
Ping statistics for 192.168.30.10:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
The deny line adds matches when PC1 tries to open the website.
R1R1#show access-lists
Extended IP access list BLOQUEO_WEB
10 deny tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq www (1 match(es))
20 permit ip any any (8 match(es))
G0/0 has BLOQUEO_WEB inbound.
R1R1#show ip interface g0/0 | include access list
Outgoing access list is not set
Inbound access list is BLOQUEO_WEB
Common mistakes
Forgetting permit ip any any: the implicit deny also cuts the ping and everything else.
Swapping source and destination in the deny line.
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.