| ⬅️ Back to Table of Contents |
|---|
This lab demonstrates the implementation of Standard Access Control Lists (ACLs) to regulate traffic in a multi-zone Enterprise environment. We focus on the "Specific Deny -> Global Permit" strategy and analyze why Outbound placement at the destination is the optimal choice for Standard ACLs.
The infrastructure is devided into three distinct zones to simulate a corporate hierarchy. Traffic must traverse the OSPF-enabled backbone to reach the protected Server Farm.
| Zone | Subnet | Key Devices | Permitted | Denied |
|---|---|---|---|---|
| VLAN 10 (IT) | 192.168.1.0/24 |
Kali | Server | VLAN 30 |
| VLAN 20 (HR) | 192.168.2.0/24 |
Window | VLAN 30 | Server |
| VLAN 30 (CLIENT) | 192.168.100.0/24 |
Router | Server | VLAN 10 |
| Server | 1.1.1.0/24 |
Kali | VLAN 10, 30 | VLAN 20 |
📸 Screenshot
- To understanding the concept more briefly this is the picture how the packet will be permitted or denied:
📸 Screenshot
To protect the Server, and VLAN 30 without causing a "Blackhole" for Internet traffic, we apply the ACL Outbound on the interface closest to the destination.
1. Wildcard Mask Calculation
For a /24 subnet, we calculate the wildcard mask as follows:
2. Router Configuration (ISP - The Gateway to Server and VLAN 30)
- VLAN 30
ISP(config)# access-list 1 deny 192.168.1.0 0.0.0.255
ISP(config)# access-list 1 permit any
ISP(config)# interface e0/2
ISP(config-if)# ip access-group 1 out- Server
ISP(config)# access-list 2 deny 192.168.2.0 0.0.0.255
ISP(config)# access-list 2 permit any
ISP(config)# interface e0/1
ISP(config-if)# ip access-group 2 out📸 Screenshot
📸 Screenshot
(Kali IT → Client: As expected in the outputs the packets has been filtered)
- Result: Destination Host Unreachable. / Packet Filtered.
- Mechanism: The Router identifies the source IP
192.168.1.x, matches the first line of the ACL, and drops the packet before it exits thee0/2interface.
(Windows → Client: Windows can still ping the Client)
(and vice versa)
-
Result: Success. Traffic matches the
permit anyrule. -
Observation:
show ip access-lists 1indicates incrementing hit counts for the permit statement.
📸 Screenshot
(Same as Scenario A)
(Both VLAN 10, 30 can still ping the Server and vice versa)
- Observation:
show ip access-lists 2indicates incrementing hit counts for the permit statement.
Caution
A common pitfall in ACL design is forgetting the Implicit Deny All rule. Even when attempting to "permit normally," as seen in our initial configuration, the lack of a final catch-all statement can paralyze external connectivity.
📸 Screenshot
(Manually permitted both VLAN 10, 30 to access the Server and denied VLAN 20 as normal but with no permit any command)
(Even the name resolution and ping does not work for both VLAN 10, 30 & you can see the encounters increment show access-list command but the ping sill not works)
Every Cisco ACL ends with an invisible deny any command. If a packet does not match an explicit permit statement, it is discarded immediately.
As shown in our setup, ACL 2 only permits traffic from source subnets 192.168.1.0 and 192.168.100.0:
-
DNS Resolution Failure: When a client sends a DNS query to
1.1.1.1, the return packet (Reply) has a source IP of1.1.1.1. Since this IP is not explicitly permitted in ACL 2, the Router drops the reply. This results in the error:Temporary failure in name resolution. -
Total Internet Loss: Similarly, pings to
1.1.1.1show100% packet loss. The outbound request succeeds, but the return traffic is "murdered" by the implicit deny rule before it can reach the client.
"To block specific hosts while maintaining global connectivity, you MUST end the ACL with permit any."
Without this final statement, your Router acts as a total blackhole for any traffic originating from outside your defined internal subnets.
- The Fix:
📸 Screenshot
Note
- Placement Logic: Standard ACLs should be placed Outbound at the Destination. Placing them at the Source would indiscriminately block the user from accessing any network resource, not just the target server.
- Stateless Nature: Standard ACLs are "dumb"—they only look at the Source IP. They cannot distinguish between an "Echo Request" and an "Echo Reply."
- The Golden Rule: Always end a "Deny" list with a
permit anyto ensure return traffic (like DNS 1.1.1.1 or Web replies) isn't accidentally dropped.
Tip
- Instead of manually permitted just specify the subnet or host you want to denied then configure the
ip denyand after that is thepermit anycommand to reduce errors when writing code. - Because ACL have many different way to write so try to configure it with most efficient.
📸 Screenshot
(Configured 1)
(Configured 2)
- Both are corrects but 1 is more fewer than 2.
In professional networking, we only need one ACL at the right place to secure a connection.
📸 Screenshot
(Example topology)
-
Kill the Request: If you place an Outbound ACL on R2 (near PC2) to block PC1, the "Ping Request" is dropped before it reaches PC2.
-
No Reply Needed: Since PC2 never receives the request, it never sends a "Reply." The conversation is dead.
-
No Redundancy: You don't need a second ACL on R1 to block PC2. Placing a single ACL at the destination gate is 100% effective.
-
Saves CPU: Routers only have to check the packet once, not twice.
-
Clean Config: Easier to manage and troubleshoot.
-
Flexibility: PC1 is only blocked from PC2, but can still reach the Internet or other departments via R1.
To wrap up Lab 18, we must respect the internal logic of the Cisco IOS:
Important
ACLs are processed sequentially. Once a packet matches a line, the search stops immediately.
- The Trap: If you have deny
192.168.1.1at Line 10 andpermit 192.168.1.1at Line 20, the packet is DROPPED. - The Lesson: Always place your most specific rules (Host/Subnet) at the top and general rules (
permit any) at the bottom.
The Router follows a strict order of operations when a packet arrives at an interface:
- INBOUND ACL: 1. Packet arrives. 2. Check ACL first. (If denied, drop now to save CPU). 3. If permitted, look at the Routing Table.
- OUTBOUND ACL: 1. Router finds the destination in the Routing Table. 2. Pushes packet toward the exit interface. 3. Check ACL last. (If denied, drop before it hits the wire).
Lab 18 successfully validates that while Standard ACLs are a blunt instrument, they are highly effective when deployed with Strategic Placement and Implicit Deny Awareness.
Understanding this sequence allows you to troubleshoot exactly where a packet is being killed. In this lab, we successfully utilized Routing first, Filtering last by using an Outbound ACL at the destination.
| ⬅️ Previous Lab | 🏠 Main Menu | Next Lab ➡️ |
|---|


