On this page 23 sections
  1. What an ACL does
  2. Standard versus extended ACLs
  3. Wildcard masks
  4. host and any keywords
  5. Standard numbered ACL syntax
  6. Standard named ACL syntax
  7. Extended numbered ACL syntax
  8. Extended named ACL syntax
  9. Common protocols and port operators
  10. Apply an ACL to an interface
  11. Understand direction correctly
  12. Edit ACL entries with sequence numbers
  13. Remove an ACL safely
  14. Verify ACLs
  15. Lab 1 topology — standard ACL
  16. Lab 1 — configure connectivity
  17. Lab 1 — configure and test the standard ACL
  18. Lab 2 topology — extended ACL
  19. Lab 2 — configure the extended ACL
  20. Lab 3 — protect router VTY access
  21. Logging denied traffic
  22. Common ACL mistakes
  23. ACL troubleshooting workflow
01

What an ACL does

An access control list, or ACL, is an ordered set of permit and deny statements. Cisco IOS compares a packet with the entries from top to bottom and stops at the first match.

Every ACL ends with an invisible deny any or deny ip any any. If no explicit statement matches, the packet is discarded. Add the required permit statements before applying the ACL.

ACLs filter traffic; they do not create routes. The network must already have working Layer 3 connectivity.

02

Standard versus extended ACLs

A standard IPv4 ACL matches only the source IPv4 address. An extended IPv4 ACL can match protocol, source, destination and Layer 4 ports.

  • Standard numbered ACLs: 1–99 and 1300–1999.
  • Extended numbered ACLs: 100–199 and 2000–2699.
  • Named ACLs use a descriptive name instead of a number.

As a general placement rule, put standard ACLs near the destination and extended ACLs near the source. The final location must still reflect exactly which traffic should be filtered.

03

Wildcard masks

ACLs use wildcard masks. A 0 bit means the corresponding address bit must match; a 1 bit means it is ignored.

For common subnet masks, subtract each octet from 255.

Calculate a /24 wildcard
Subnet mask    255.255.255.0
Subtract from  255.255.255.255
Wildcard       0.0.0.255
Common wildcard masks
/32  0.0.0.0
/30  0.0.0.3
/29  0.0.0.7
/28  0.0.0.15
/27  0.0.0.31
/26  0.0.0.63
/25  0.0.0.127
/24  0.0.0.255
/16  0.0.255.255
/8   0.255.255.255
04

host and any keywords

host represents one exact address and is equivalent to a wildcard of 0.0.0.0. any represents every IPv4 address and is equivalent to 0.0.0.0 255.255.255.255.

Equivalent host statements
access-list 10 permit host 192.168.10.25
access-list 10 permit 192.168.10.25 0.0.0.0
Equivalent any statements
access-list 10 permit any
access-list 10 permit 0.0.0.0 255.255.255.255
05

Standard numbered ACL syntax

The second statement is essential when all other sources should continue to pass.

Standard numbered ACL
access-list 10 deny 192.168.10.0 0.0.0.255
access-list 10 permit any
06

Standard named ACL syntax

Named ACLs make the purpose easier to understand and allow sequence-based editing.

Standard named ACL
ip access-list standard BLOCK-LAN10
 10 deny 192.168.10.0 0.0.0.255
 20 permit any
07

Extended numbered ACL syntax

DNS primarily uses UDP 53 but can also use TCP 53, so real policies may need both.

Permit HTTPS from one subnet to one server
access-list 110 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443
Permit DNS queries to one server
access-list 110 permit udp 192.168.10.0 0.0.0.255 host 192.168.30.53 eq 53
access-list 110 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.53 eq 53
08

Extended named ACL syntax

The explicit deny blocks other traffic from LAN 10 to LAN 30. The final permit allows traffic not covered by that restriction to continue normally.

Named web access policy
ip access-list extended WEB-POLICY
 10 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80
 20 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443
 30 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
 40 permit ip any any
09

Common protocols and port operators

established only checks the TCP ACK or RST flags. It is not a stateful firewall and does not track a complete connection.

Common port examples
permit tcp any host 192.168.30.10 eq 22
permit tcp any host 192.168.30.10 range 80 443
permit udp any host 192.168.30.53 eq domain
permit tcp any any established
10

Apply an ACL to an interface

An interface supports one IPv4 ACL per direction and per protocol. One inbound and one outbound IPv4 ACL can coexist.

Apply inbound
interface GigabitEthernet0/0
 ip access-group WEB-POLICY in
Apply outbound
interface GigabitEthernet0/1
 ip access-group 10 out
11

Understand direction correctly

Direction is always from the router interface's point of view.

  • Traffic arriving from a PC into the router is inbound on the LAN interface.
  • The same traffic leaving toward another router is outbound on the transit interface.
  • Return traffic arrives inbound on the transit interface and leaves outbound on the LAN interface.

Trace the packet hop by hop before selecting an interface and direction.

12

Edit ACL entries with sequence numbers

Named ACLs can be edited without deleting the entire list.

Insert a new entry
ip access-list extended WEB-POLICY
 15 permit tcp host 192.168.10.50 host 192.168.30.10 eq 22
Remove one entry
ip access-list extended WEB-POLICY
 no 15
Resequence an ACL
ip access-list resequence WEB-POLICY 10 10
13

Remove an ACL safely

On classic numbered ACLs, no access-list 110 removes the complete list.

Detach and delete a named ACL
interface GigabitEthernet0/0
 no ip access-group WEB-POLICY in
exit
no ip access-list extended WEB-POLICY
Delete a numbered ACL
no access-list 110
14

Verify ACLs

Use hit counters to confirm which entries match actual traffic. Clear counters before a controlled test when necessary.

Display all IPv4 ACLs
show ip access-lists
Display one named ACL
show ip access-lists WEB-POLICY
Check interface assignments
show ip interface GigabitEthernet0/0
Clear match counters
clear access-list counters WEB-POLICY
15

Lab 1 topology — standard ACL

The objective is to stop LAN 10 from reaching LAN 30 while allowing other source networks. Because a standard ACL cannot select a destination, place it close to LAN 30.

Lab 1 topology and addressing
PC1 --- LAN 10 --- R1 -------- R2 --- LAN 30 --- Server
       192.168.10.0/24  10.0.12.0/30  192.168.30.0/24

R1 G0/0  192.168.10.1/24
R1 G0/1  10.0.12.1/30
R2 G0/0  10.0.12.2/30
R2 G0/1  192.168.30.1/24
Server   192.168.30.10/24, gateway 192.168.30.1
16

Lab 1 — configure connectivity

Verify that PC1 can reach the server before adding the ACL.

Configure R1
interface GigabitEthernet0/0
 ip address 192.168.10.1 255.255.255.0
 no shutdown
interface GigabitEthernet0/1
 ip address 10.0.12.1 255.255.255.252
 no shutdown
ip route 192.168.30.0 255.255.255.0 10.0.12.2
Configure R2
interface GigabitEthernet0/0
 ip address 10.0.12.2 255.255.255.252
 no shutdown
interface GigabitEthernet0/1
 ip address 192.168.30.1 255.255.255.0
 no shutdown
ip route 192.168.10.0 255.255.255.0 10.0.12.1
17

Lab 1 — configure and test the standard ACL

Expected result: traffic sourced from 192.168.10.0/24 cannot exit R2 G0/1 toward LAN 30. Other permitted sources can still reach LAN 30.

Configure the standard ACL on R2
ip access-list standard BLOCK-LAN10
 10 deny 192.168.10.0 0.0.0.255
 20 permit any
interface GigabitEthernet0/1
 ip access-group BLOCK-LAN10 out
Verify the result
show ip access-lists BLOCK-LAN10
show ip interface GigabitEthernet0/1
18

Lab 2 topology — extended ACL

The objective is to allow LAN 10 to use HTTP and HTTPS on one server, block all other LAN 10 traffic to LAN 30, and leave unrelated traffic unaffected. An extended ACL belongs close to the source, so apply it inbound on R1 G0/0.

Lab 2 topology
PC1 192.168.10.10 --- R1 -------- R2 --- Server 192.168.30.10
                       same addressing as Lab 1
19

Lab 2 — configure the extended ACL

Expected result: HTTP and HTTPS to 192.168.30.10 are permitted. ICMP, SSH and other IP traffic from LAN 10 to LAN 30 are denied. Traffic from LAN 10 to other destinations reaches the final permit statement.

Configure WEB-ONLY on R1
ip access-list extended WEB-ONLY
 10 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 80
 20 permit tcp 192.168.10.0 0.0.0.255 host 192.168.30.10 eq 443
 30 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
 40 permit ip any any
interface GigabitEthernet0/0
 ip access-group WEB-ONLY in
Verify the policy
show ip access-lists WEB-ONLY
show ip interface GigabitEthernet0/0
20

Lab 3 — protect router VTY access

Test from the allowed administrator host before closing the existing management session. A mistake can lock out remote administration.

Permit only the administrator host
ip access-list standard VTY-MANAGEMENT
 10 permit host 192.168.10.50
 20 deny any log
line vty 0 4
 access-class VTY-MANAGEMENT in
 transport input ssh
21

Logging denied traffic

The log keyword generates messages for matching packets. It is useful for testing but can consume CPU and produce many logs on a busy interface.

Log a deny statement
ip access-list extended WEB-ONLY
 30 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255 log
22

Common ACL mistakes

  • Forgetting the implicit deny at the end.
  • Placing a broad statement before a more specific one.
  • Using a subnet mask instead of a wildcard mask.
  • Applying the ACL to the wrong interface or direction.
  • Expecting a standard ACL to filter by destination or port.
  • Forgetting that ACLs are stateless packet filters.
  • Testing before routing and addressing work correctly.
  • Editing a numbered ACL without checking whether the full list was removed.
23

ACL troubleshooting workflow

First verify addressing and routes without the ACL. Then inspect the ACL entries, interface assignment, direction and match counters. Generate one controlled test flow and check which counter increases.

Useful troubleshooting commands
show ip interface brief
show ip route
show ip access-lists
show ip interface GigabitEthernet0/0
show running-config | section access-list
show running-config | section interface