PC1 (192.168.10.10) must not reach the server network (192.168.30.0/24). Every other device should, and PC1 must still reach everything else.
Create numbered standard ACL 10 that denies that host and permits the rest, and apply it where a standard ACL belongs: as close as possible to the destination. Check each line's matches with show access-lists after a few pings.
Topology
Devices and cabling
R1·2911
SW1·2960-24TT
PC1, PC2, PC3·PC-PT
SRV1·Server-PT
From
To
Cable
R1Gi0/0
SW1Gi0/1
Straight-through
PC1Fa0
SW1Fa0/1
Straight-through
PC2Fa0
SW1Fa0/2
Straight-through
R1Gi0/1
PC3Fa0
Crossover
R1Gi0/2
SRV1Fa0
Crossover
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
R1
G0/0
192.168.10.1
255.255.255.0
—
R1
G0/1
192.168.20.1
255.255.255.0
—
R1
G0/2
192.168.30.1
255.255.255.0
—
PC1
NIC
192.168.10.10
255.255.255.0
192.168.10.1
PC2
NIC
192.168.10.11
255.255.255.0
192.168.10.1
PC3
NIC
192.168.20.10
255.255.255.0
192.168.20.1
SRV1
NIC
192.168.30.10
255.255.255.0
192.168.30.1
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
R1hostname R1
no ip domain-lookup
interface g0/0
ip address 192.168.10.1 255.255.255.0
no shutdown
interface g0/1
ip address 192.168.20.1 255.255.255.0
no shutdown
interface g0/2
ip address 192.168.30.1 255.255.255.0
no shutdown
SW1hostname SW1
no ip domain-lookup
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.10.10, mask 255.255.255.0, gateway 192.168.10.1
PC2: IP 192.168.10.11, mask 255.255.255.0, gateway 192.168.10.1
PC3: IP 192.168.20.10, mask 255.255.255.0, gateway 192.168.20.1
SRV1: IP 192.168.30.10, mask 255.255.255.0, gateway 192.168.30.1
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
ACL 10 denies 192.168.10.10
ACL 10 permits everything else
Applied outbound on G0/2, next to the server
PC1 no longer reaches the server
PC2 and PC3 still reach the server
PC1 still reaches PC3
Checked with show access-lists
In Packet Tracer
PC3 and the server connect straight to the router with crossover cables; PC1 and PC2 to the switch with straight-through cables.
A standard ACL only looks at the source. If you put it inbound on G0/0, PC1 couldn't reach anywhere.
R1interface g0/2
ip access-group 10 out
end
Verification
From PC1 the router replies "Destination host unreachable": the ACL drops it.
PC1C:\>ping 192.168.30.10
Pinging 192.168.30.10 with 32 bytes of data:
Reply from 192.168.10.1: Destination host unreachable.
Reply from 192.168.10.1: Destination host unreachable.
Reply from 192.168.10.1: Destination host unreachable.
Reply from 192.168.10.1: Destination host unreachable.
Ping statistics for 192.168.30.10:
Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
From PC2, the ping gets through.
PC2C:\>ping 192.168.30.10
Pinging 192.168.30.10 with 32 bytes of data:
Request timed out.
Reply from 192.168.30.10: bytes=32 time<1ms TTL=127
Reply from 192.168.30.10: bytes=32 time<1ms TTL=127
Reply from 192.168.30.10: bytes=32 time<1ms TTL=127
Ping statistics for 192.168.30.10:
Packets: Sent = 4, Received = 3, Lost = 1 (25% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Each line's counters ("match(es)") show which traffic matched it.
R1R1#show access-lists
Standard IP access list 10
10 deny host 192.168.10.10 (8 match(es))
20 permit any (4 match(es))
Common mistakes
Forgetting the final permit any: the implicit deny blocks everyone.
Applying it in the wrong direction (in instead of out).
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.