6.6.2. ACL Configuration
Understanding Wildcard Masks: ACLs use wildcard masks (the inverse of subnet masks). A 0 means "must match," a 255 means "don't care."
| Wildcard | Meaning | Example |
|---|---|---|
0.0.0.0 | Match this exact IP | Single host (shorthand: host 10.1.1.5) |
0.0.0.255 | Match the first 3 octets | /24 network |
0.0.255.255 | Match the first 2 octets | /16 network |
For any prefix length, the wildcard is 255.255.255.255 minus the subnet mask: /21 = 255.255.248.0, so the wildcard is 0.0.7.255. The keyword any is shorthand for 0.0.0.0 255.255.255.255.
Scenario 1: Block a subnet from reaching a server The finance VLAN (10.10.10.0/24) shouldn't reach the guest wireless segment. Use a standard ACL applied outbound on the interface facing guests:
Router(config)# access-list 10 deny 10.10.10.0 0.0.0.255
Router(config)# access-list 10 permit any ! Don't forget this!
Router(config)# interface GigabitEthernet0/1
Router(config-if)# ip access-group 10 out
What happens if you forget permit any? The implicit deny blocks everyone, not just finance. Always end with an explicit permit for traffic you want to allow.
Scenario 2: Allow only web traffic from users Users on 192.168.1.0/24 should only reach the internet via HTTP (80) and HTTPS (443). Everything else gets blocked and logged:
Router(config)# access-list 110 permit tcp 192.168.1.0 0.0.0.255 any eq 80
Router(config)# access-list 110 permit tcp 192.168.1.0 0.0.0.255 any eq 443
Router(config)# access-list 110 deny ip any any log ! Log blocked attempts
Router(config)# interface GigabitEthernet0/0
Router(config-if)# ip access-group 110 in
Scenario 3: Named ACL for readability Named ACLs are easier to read and you can insert/delete lines without recreating the whole ACL:
Router(config)# ip access-list extended GUEST-INTERNET
Router(config-ext-nacl)# permit tcp any any eq 80
Router(config-ext-nacl)# permit tcp any any eq 443
Router(config-ext-nacl)# permit udp any any eq 53 ! Allow DNS
Router(config-ext-nacl)# deny ip any any log
Router(config)# interface GigabitEthernet0/2
Router(config-if)# ip access-group GUEST-INTERNET in
Scenario 4: Restrict who can reach the VTY lines
A standard ACL can protect management access too. On VTY lines it is applied with access-class, not ip access-group (that command is interface-only and rejected in line mode):
Router(config)# access-list 5 permit 172.16.50.0 0.0.0.255 ! Management subnet
Router(config)# line vty 0 15
Router(config-line)# access-class 5 in
Rules worth knowing:
- An interface takes one ACL per direction per protocol (one IPv4 in, one IPv4 out, and the same again for IPv6). Applying a second ACL in the same direction replaces the first.
established(TCP only) matches segments with the ACK or RST bit set—return traffic for sessions opened from the inside. It is a static flag check, not stateful inspection, and does nothing for UDP.
Verification:
Router# show access-lists ! See ACL contents and hit counters
Router# show ip interface GigabitEthernet0/0 ! Confirm ACL is applied
Troubleshooting tip: The hit counters in show access-lists tell you which rules are matching traffic. If your "permit" line has zero hits, traffic isn't reaching that rule—check the rules above it.
⚠️ Exam Trap: ACL placement is heavily tested. Standard ACLs close to destination, extended ACLs close to source. The reasoning: standard ACLs would block the source from reaching anything if placed at the source, so you place them where they only affect the specific destination.