Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

README.md


⬅️ Back to Table of Contents

Lab 18: Standard ACL - Enterprise Traffic Engineering & Security Baseline

Objective

This lab demonstrates the implementation of Standard Access Control Lists (ACLs) to regulate traffic in a multi-zone Enterprise environment. We focus on the "Specific Deny -> Global Permit" strategy and analyze why Outbound placement at the destination is the optimal choice for Standard ACLs.

Topology & Network Design

The infrastructure is devided into three distinct zones to simulate a corporate hierarchy. Traffic must traverse the OSPF-enabled backbone to reach the protected Server Farm.

Zone Subnet Key Devices Permitted Denied
VLAN 10 (IT) 192.168.1.0/24 Kali Server VLAN 30
VLAN 20 (HR) 192.168.2.0/24 Window VLAN 30 Server
VLAN 30 (CLIENT) 192.168.100.0/24 Router Server VLAN 10
Server 1.1.1.0/24 Kali VLAN 10, 30 VLAN 20

📸 Screenshot

Screenshot 2026-02-10 211339
  • To understanding the concept more briefly this is the picture how the packet will be permitted or denied:

📸 Screenshot

Screenshot 2026-02-10 211339
(Windows Traffic)
Screenshot 2026-02-10 224657
(Kali IT Traffic)
Screenshot 2026-02-10 225001

(Client Traffic)

Screenshot 2026-02-10 225252

(Server Traffic)

Important

Make sure that all devices has fully reachability

📸 Screenshot

Screenshot 2026-02-10 200346 Screenshot 2026-02-10 201543 Screenshot 2026-02-10 201640

Execution Phase: The "Smart" Standard ACL (Cisco Best Practice)

To protect the Server, and VLAN 30 without causing a "Blackhole" for Internet traffic, we apply the ACL Outbound on the interface closest to the destination.

1. Wildcard Mask Calculation

For a /24 subnet, we calculate the wildcard mask as follows:

$$Wildcard = 255.255.255.255 - 255.255.255.0 = 0.0.0.255$$

2. Router Configuration (ISP - The Gateway to Server and VLAN 30)

  • VLAN 30
ISP(config)# access-list 1 deny 192.168.1.0 0.0.0.255
ISP(config)# access-list 1 permit any
ISP(config)# interface e0/2
ISP(config-if)# ip access-group 1 out
  • Server
ISP(config)# access-list 2 deny 192.168.2.0 0.0.0.255
ISP(config)# access-list 2 permit any
ISP(config)# interface e0/1
ISP(config-if)# ip access-group 2 out

📸 Screenshot

Screenshot 2026-02-10 231639 Screenshot 2026-02-10 231633

Verification & Packet Walk Analysis

Scenario A: Permitted Access (VLAN 20) - Denied Access (VLAN 10) to VLAN 30

📸 Screenshot

Screenshot 2026-02-10 201810

(Kali IT → Client: As expected in the outputs the packets has been filtered)

  • Result: Destination Host Unreachable. / Packet Filtered.
  • Mechanism: The Router identifies the source IP 192.168.1.x, matches the first line of the ACL, and drops the packet before it exits the e0/2 interface.
Screenshot 2026-02-10 201836

(Windows → Client: Windows can still ping the Client)

Screenshot 2026-02-10 201938

(and vice versa)

  • Result: Success. Traffic matches the permit any rule.

  • Observation: show ip access-lists 1 indicates incrementing hit counts for the permit statement.

Screenshot 2026-02-10 230332

Scenario B: Permitted Access (VLAN 10, 30) - Denied Access (VLAN 20) to Server

📸 Screenshot

Screenshot 2026-02-10 205139

(Same as Scenario A)

Screenshot 2026-02-10 210731 Screenshot 2026-02-10 205445

(Both VLAN 10, 30 can still ping the Server and vice versa)

  • Observation: show ip access-lists 2 indicates incrementing hit counts for the permit statement.
Screenshot 2026-02-10 233502

Caution

🛑 The "Implicit Deny" Trap: Analysis of a Failed Configuration

A common pitfall in ACL design is forgetting the Implicit Deny All rule. Even when attempting to "permit normally," as seen in our initial configuration, the lack of a final catch-all statement can paralyze external connectivity.

📸 Screenshot

Screenshot 2026-02-10 202701

(Manually permitted both VLAN 10, 30 to access the Server and denied VLAN 20 as normal but with no permit any command)

Screenshot 2026-02-10 202811 Screenshot 2026-02-10 202816

(Even the name resolution and ping does not work for both VLAN 10, 30 & you can see the encounters increment show access-list command but the ping sill not works)

1. The Invisible Rule

Every Cisco ACL ends with an invisible deny any command. If a packet does not match an explicit permit statement, it is discarded immediately.

2. Evidence from the Lab

As shown in our setup, ACL 2 only permits traffic from source subnets 192.168.1.0 and 192.168.100.0:

  • DNS Resolution Failure: When a client sends a DNS query to 1.1.1.1, the return packet (Reply) has a source IP of 1.1.1.1. Since this IP is not explicitly permitted in ACL 2, the Router drops the reply. This results in the error: Temporary failure in name resolution.

  • Total Internet Loss: Similarly, pings to 1.1.1.1 show 100% packet loss. The outbound request succeeds, but the return traffic is "murdered" by the implicit deny rule before it can reach the client.

3. The Golden Rule

"To block specific hosts while maintaining global connectivity, you MUST end the ACL with permit any."

Without this final statement, your Router acts as a total blackhole for any traffic originating from outside your defined internal subnets.

  • The Fix:

📸 Screenshot

Screenshot 2026-02-11 001303

Note

Key Takeaways:

  • Placement Logic: Standard ACLs should be placed Outbound at the Destination. Placing them at the Source would indiscriminately block the user from accessing any network resource, not just the target server.
  • Stateless Nature: Standard ACLs are "dumb"—they only look at the Source IP. They cannot distinguish between an "Echo Request" and an "Echo Reply."
  • The Golden Rule: Always end a "Deny" list with a permit any to ensure return traffic (like DNS 1.1.1.1 or Web replies) isn't accidentally dropped.

Tip

  • Instead of manually permitted just specify the subnet or host you want to denied then configure the ip deny and after that is the permit any command to reduce errors when writing code.
  • Because ACL have many different way to write so try to configure it with most efficient.

📸 Screenshot

Screenshot 2026-02-11 002803

(Configured 1)

Screenshot 2026-02-11 002602

(Configured 2)

  • Both are corrects but 1 is more fewer than 2.

Efficiency: The "Single Gatekeeper" Principle

In professional networking, we only need one ACL at the right place to secure a connection.

📸 Screenshot

image

(Example topology)

Why one Outbound ACL at the Destination is enough:

  • Kill the Request: If you place an Outbound ACL on R2 (near PC2) to block PC1, the "Ping Request" is dropped before it reaches PC2.

  • No Reply Needed: Since PC2 never receives the request, it never sends a "Reply." The conversation is dead.

  • No Redundancy: You don't need a second ACL on R1 to block PC2. Placing a single ACL at the destination gate is 100% effective.

The Benefits:

  1. Saves CPU: Routers only have to check the packet once, not twice.

  2. Clean Config: Easier to manage and troubleshoot.

  3. Flexibility: PC1 is only blocked from PC2, but can still reach the Internet or other departments via R1.


Rules of ACL Processing

To wrap up Lab 18, we must respect the internal logic of the Cisco IOS:

Important

1. Top-to-Bottom: The "First Match" Rule

ACLs are processed sequentially. Once a packet matches a line, the search stops immediately.

  • The Trap: If you have deny 192.168.1.1 at Line 10 and permit 192.168.1.1 at Line 20, the packet is DROPPED.
  • The Lesson: Always place your most specific rules (Host/Subnet) at the top and general rules (permit any) at the bottom.

2. Packet Flow: Inbound vs. Outbound

The Router follows a strict order of operations when a packet arrives at an interface:

  • INBOUND ACL: 1. Packet arrives. 2. Check ACL first. (If denied, drop now to save CPU). 3. If permitted, look at the Routing Table.
  • OUTBOUND ACL: 1. Router finds the destination in the Routing Table. 2. Pushes packet toward the exit interface. 3. Check ACL last. (If denied, drop before it hits the wire).

Final Verdict

Lab 18 successfully validates that while Standard ACLs are a blunt instrument, they are highly effective when deployed with Strategic Placement and Implicit Deny Awareness.

Understanding this sequence allows you to troubleshoot exactly where a packet is being killed. In this lab, we successfully utilized Routing first, Filtering last by using an Outbound ACL at the destination.

⬅️ Previous Lab 🏠 Main Menu Next Lab ➡️