On this page 23 sections
- What an ACL does
- Standard versus extended ACLs
- Wildcard masks
- host and any keywords
- Standard numbered ACL syntax
- Standard named ACL syntax
- Extended numbered ACL syntax
- Extended named ACL syntax
- Common protocols and port operators
- Apply an ACL to an interface
- Understand direction correctly
- Edit ACL entries with sequence numbers
- Remove an ACL safely
- Verify ACLs
- Lab 1 topology — standard ACL
- Lab 1 — configure connectivity
- Lab 1 — configure and test the standard ACL
- Lab 2 topology — extended ACL
- Lab 2 — configure the extended ACL
- Lab 3 — protect router VTY access
- Logging denied traffic
- Common ACL mistakes
- ACL troubleshooting workflow
What an ACL does
An access control list, or ACL, is an ordered set of permit and deny statements. Cisco IOS compares a packet with the entries from top to bottom and stops at the first match.
Every ACL ends with an invisible deny any or deny ip any any. If no explicit statement matches, the packet is discarded. Add the required permit statements before applying the ACL.
ACLs filter traffic; they do not create routes. The network must already have working Layer 3 connectivity.
Standard versus extended ACLs
A standard IPv4 ACL matches only the source IPv4 address. An extended IPv4 ACL can match protocol, source, destination and Layer 4 ports.
- Standard numbered ACLs:
1–99and1300–1999. - Extended numbered ACLs:
100–199and2000–2699. - Named ACLs use a descriptive name instead of a number.
As a general placement rule, put standard ACLs near the destination and extended ACLs near the source. The final location must still reflect exactly which traffic should be filtered.
Wildcard masks
ACLs use wildcard masks. A 0 bit means the corresponding address bit must match; a 1 bit means it is ignored.
For common subnet masks, subtract each octet from 255.
Subnet mask 255.255.255.0
Subtract from 255.255.255.255
Wildcard 0.0.0.255/32 0.0.0.0
/30 0.0.0.3
/29 0.0.0.7
/28 0.0.0.15
/27 0.0.0.31
/26 0.0.0.63
/25 0.0.0.127
/24 0.0.0.255
/16 0.0.255.255
/8 0.255.255.255host and any keywords
host represents one exact address and is equivalent to a wildcard of 0.0.0.0. any represents every IPv4 address and is equivalent to 0.0.0.0 255.255.255.255.
access-list 10 permit host 192.168.10.25
access-list 10 permit 192.168.10.25 0.0.0.0access-list 10 permit any
access-list 10 permit 0.0.0.0 255.255.255.255Standard numbered ACL syntax
The second statement is essential when all other sources should continue to pass.
access-list 10 deny 192.168.10.0 0.0.0.255
access-list 10 permit anyStandard named ACL syntax
Named ACLs make the purpose easier to understand and allow sequence-based editing.
ip access-list standard BLOCK-LAN10
10 deny 192.168.10.0 0.0.0.255
20 permit anyExtended numbered ACL syntax
DNS primarily uses UDP 53 but can also use TCP 53, so real policies may need both.
access-list 110 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443access-list 110 permit udp 192.168.10.0 0.0.0.255 host 192.168.30.53 eq 53
access-list 110 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.53 eq 53Extended named ACL syntax
The explicit deny blocks other traffic from LAN 10 to LAN 30. The final permit allows traffic not covered by that restriction to continue normally.
ip access-list extended WEB-POLICY
10 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80
20 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443
30 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
40 permit ip any anyCommon protocols and port operators
established only checks the TCP ACK or RST flags. It is not a stateful firewall and does not track a complete connection.
permit tcp any host 192.168.30.10 eq 22
permit tcp any host 192.168.30.10 range 80 443
permit udp any host 192.168.30.53 eq domain
permit tcp any any establishedApply an ACL to an interface
An interface supports one IPv4 ACL per direction and per protocol. One inbound and one outbound IPv4 ACL can coexist.
interface GigabitEthernet0/0
ip access-group WEB-POLICY ininterface GigabitEthernet0/1
ip access-group 10 outUnderstand direction correctly
Direction is always from the router interface's point of view.
- Traffic arriving from a PC into the router is inbound on the LAN interface.
- The same traffic leaving toward another router is outbound on the transit interface.
- Return traffic arrives inbound on the transit interface and leaves outbound on the LAN interface.
Trace the packet hop by hop before selecting an interface and direction.
Edit ACL entries with sequence numbers
Named ACLs can be edited without deleting the entire list.
ip access-list extended WEB-POLICY
15 permit tcp host 192.168.10.50 host 192.168.30.10 eq 22ip access-list extended WEB-POLICY
no 15ip access-list resequence WEB-POLICY 10 10Remove an ACL safely
On classic numbered ACLs, no access-list 110 removes the complete list.
interface GigabitEthernet0/0
no ip access-group WEB-POLICY in
exit
no ip access-list extended WEB-POLICYno access-list 110Verify ACLs
Use hit counters to confirm which entries match actual traffic. Clear counters before a controlled test when necessary.
show ip access-listsshow ip access-lists WEB-POLICYshow ip interface GigabitEthernet0/0clear access-list counters WEB-POLICYLab 1 topology — standard ACL
The objective is to stop LAN 10 from reaching LAN 30 while allowing other source networks. Because a standard ACL cannot select a destination, place it close to LAN 30.
PC1 --- LAN 10 --- R1 -------- R2 --- LAN 30 --- Server
192.168.10.0/24 10.0.12.0/30 192.168.30.0/24
R1 G0/0 192.168.10.1/24
R1 G0/1 10.0.12.1/30
R2 G0/0 10.0.12.2/30
R2 G0/1 192.168.30.1/24
Server 192.168.30.10/24, gateway 192.168.30.1Lab 1 — configure connectivity
Verify that PC1 can reach the server before adding the ACL.
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
no shutdown
interface GigabitEthernet0/1
ip address 10.0.12.1 255.255.255.252
no shutdown
ip route 192.168.30.0 255.255.255.0 10.0.12.2interface GigabitEthernet0/0
ip address 10.0.12.2 255.255.255.252
no shutdown
interface GigabitEthernet0/1
ip address 192.168.30.1 255.255.255.0
no shutdown
ip route 192.168.10.0 255.255.255.0 10.0.12.1Lab 1 — configure and test the standard ACL
Expected result: traffic sourced from 192.168.10.0/24 cannot exit R2 G0/1 toward LAN 30. Other permitted sources can still reach LAN 30.
ip access-list standard BLOCK-LAN10
10 deny 192.168.10.0 0.0.0.255
20 permit any
interface GigabitEthernet0/1
ip access-group BLOCK-LAN10 outshow ip access-lists BLOCK-LAN10
show ip interface GigabitEthernet0/1Lab 2 topology — extended ACL
The objective is to allow LAN 10 to use HTTP and HTTPS on one server, block all other LAN 10 traffic to LAN 30, and leave unrelated traffic unaffected. An extended ACL belongs close to the source, so apply it inbound on R1 G0/0.
PC1 192.168.10.10 --- R1 -------- R2 --- Server 192.168.30.10
same addressing as Lab 1Lab 2 — configure the extended ACL
Expected result: HTTP and HTTPS to 192.168.30.10 are permitted. ICMP, SSH and other IP traffic from LAN 10 to LAN 30 are denied. Traffic from LAN 10 to other destinations reaches the final permit statement.
ip access-list extended WEB-ONLY
10 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80
20 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443
30 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
40 permit ip any any
interface GigabitEthernet0/0
ip access-group WEB-ONLY inshow ip access-lists WEB-ONLY
show ip interface GigabitEthernet0/0Lab 3 — protect router VTY access
Test from the allowed administrator host before closing the existing management session. A mistake can lock out remote administration.
ip access-list standard VTY-MANAGEMENT
10 permit host 192.168.10.50
20 deny any log
line vty 0 4
access-class VTY-MANAGEMENT in
transport input sshLogging denied traffic
The log keyword generates messages for matching packets. It is useful for testing but can consume CPU and produce many logs on a busy interface.
ip access-list extended WEB-ONLY
30 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255 logCommon ACL mistakes
- Forgetting the implicit deny at the end.
- Placing a broad statement before a more specific one.
- Using a subnet mask instead of a wildcard mask.
- Applying the ACL to the wrong interface or direction.
- Expecting a standard ACL to filter by destination or port.
- Forgetting that ACLs are stateless packet filters.
- Testing before routing and addressing work correctly.
- Editing a numbered ACL without checking whether the full list was removed.
ACL troubleshooting workflow
First verify addressing and routes without the ACL. Then inspect the ACL entries, interface assignment, direction and match counters. Generate one controlled test flow and check which counter increases.
show ip interface brief
show ip route
show ip access-lists
show ip interface GigabitEthernet0/0
show running-config | section access-list
show running-config | section interface