← All labs Lab 11 · Packet Tracer

Standard ACL

Block one host and apply the ACL close to the destination

Level: Intermediate Time: 25 min Domain 5.0 Security Fundamentals

Scenario

PC1 (192.168.10.10) must not reach the server network (192.168.30.0/24). Every other device should, and PC1 must still reach everything else.

Create numbered standard ACL 10 that denies that host and permits the rest, and apply it where a standard ACL belongs: as close as possible to the destination. Check each line's matches with show access-lists after a few pings.

Topology

PC1PC2SW1R1PC3SRV1Gi0/0Gi0/1Fa0Fa0/1Fa0Fa0/2Gi0/1Fa0Gi0/2Fa0

Devices and cabling

FromToCable
R1 Gi0/0SW1 Gi0/1Straight-through
PC1 Fa0SW1 Fa0/1Straight-through
PC2 Fa0SW1 Fa0/2Straight-through
R1 Gi0/1PC3 Fa0Crossover
R1 Gi0/2SRV1 Fa0Crossover

If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.

Addressing

DeviceInterfaceAddressMaskDefault gateway
R1G0/0192.168.10.1255.255.255.0—
R1G0/1192.168.20.1255.255.255.0—
R1G0/2192.168.30.1255.255.255.0—
PC1NIC192.168.10.10255.255.255.0192.168.10.1
PC2NIC192.168.10.11255.255.255.0192.168.10.1
PC3NIC192.168.20.10255.255.255.0192.168.20.1
SRV1NIC192.168.30.10255.255.255.0192.168.30.1

Starting configuration

In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.

R1hostname R1 no ip domain-lookup interface g0/0 ip address 192.168.10.1 255.255.255.0 no shutdown interface g0/1 ip address 192.168.20.1 255.255.255.0 no shutdown interface g0/2 ip address 192.168.30.1 255.255.255.0 no shutdown
SW1hostname SW1 no ip domain-lookup

PCs and servers (Desktop › IP Configuration)

Tasks

What must end up working. In the app, each one ticks itself off as soon as you get it.

  1. ACL 10 denies 192.168.10.10
  2. ACL 10 permits everything else
  3. Applied outbound on G0/2, next to the server
  4. PC1 no longer reaches the server
  5. PC2 and PC3 still reach the server
  6. PC1 still reaches PC3
  7. Checked with show access-lists
In Packet Tracer
  • PC3 and the server connect straight to the router with crossover cables; PC1 and PC2 to the switch with straight-through cables.
Hints
  • ACL 10 denies 192.168.10.10: access-list 10 deny host 192.168.10.10
  • ACL 10 permits everything else: Every ACL ends with an implicit deny any: add access-list 10 permit any
  • Applied outbound on G0/2, next to the server: interface g0/2 → ip access-group 10 out
  • PC1 no longer reaches the server: From PC1: ping 192.168.30.10 should fail
  • PC2 and PC3 still reach the server: If they fail, the permit any is missing
  • PC1 still reaches PC3: If it fails, you applied the ACL inbound on G0/0: a standard ACL there cuts PC1 off from everywhere
  • Checked with show access-lists: show access-lists

Step-by-step solution

Try it on your own first: you learn much more by typing the commands yourself.

Show the solution

1Create the ACL R1

ACLs are read top to bottom and end with an implicit deny any: without the permit any, everything would be blocked.

R1enable configure terminal access-list 10 deny host 192.168.10.10 access-list 10 permit any

2Apply it close to the destination R1

A standard ACL only looks at the source. If you put it inbound on G0/0, PC1 couldn't reach anywhere.

R1interface g0/2 ip access-group 10 out end

Verification

From PC1 the router replies "Destination host unreachable": the ACL drops it.

PC1C:\>ping 192.168.30.10 Pinging 192.168.30.10 with 32 bytes of data: Reply from 192.168.10.1: Destination host unreachable. Reply from 192.168.10.1: Destination host unreachable. Reply from 192.168.10.1: Destination host unreachable. Reply from 192.168.10.1: Destination host unreachable. Ping statistics for 192.168.30.10: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

From PC2, the ping gets through.

PC2C:\>ping 192.168.30.10 Pinging 192.168.30.10 with 32 bytes of data: Request timed out. Reply from 192.168.30.10: bytes=32 time<1ms TTL=127 Reply from 192.168.30.10: bytes=32 time<1ms TTL=127 Reply from 192.168.30.10: bytes=32 time<1ms TTL=127 Ping statistics for 192.168.30.10: Packets: Sent = 4, Received = 3, Lost = 1 (25% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms

Each line's counters ("match(es)") show which traffic matched it.

R1R1#show access-lists Standard IP access list 10 10 deny host 192.168.10.10 (8 match(es)) 20 permit any (4 match(es))

Common mistakes

Practice this lab on your phone

RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.

Get RoutingLab