Writers' Community!
Home News Business Science & Technology Life
Front Page Page Two Columnists Submit an Article FAQs Contact Author Login
Article Submission
We Need YOUR Articles!
We'll Promote Them for FREE!

Author Login

New Authors
Register Here


Now Serving 5,539 Authors
48,401 Quality Articles
& 6,486 Current Users Online!
Featured Authors
Avis Ward (12,701)
Richard Nicastro (2,545)
Dianne Lehmann (3,016)
Mogama (12,129)
Mike Fak (7,094)
Robert Melaccio, Sr. (6,658)
David Pekrul (613)
Terry Mitchell (2,761)
Sara O'Rourke (392)
Joel Hendon (4,797)
Susan Thom (9,073)
Laura Trahan (32,764)
Abigail Richards (6,279)
Peggy Butler (3,497)

View All Featured Authors
Most Recent
Windows Vista Sidebar, Gadgets, Easy Wireless Networking and Improved Back Features

CompTIA A+, Security+, Network+ Tutorial Ethernet Card Troubleshooting

CCNA, CCENT, CCNP Tutorial on Routers and Routing

CompTIA Security+ Article on Firewall Security Advantages and Firewall Functions

Microsoft Training Certifications

CCNA Security Exam Tutorial: When It's Good To Add Salt

Why Switch to Windows Vista

Free Cisco CCNA, CCENT, CCNP Certification Tutorial

Why People should get Network+, CCNA, CCNP or CCIE Network Based Certifications

Cisco CCNA And CCNP Practice Exam Questions: Frame Relay, Uplinkfast, And More!

Home » Categories » Computers & Networking » Technical Certification » Cisco CCNA Exam Tutorial: Configuring Standard Access Lists » Printer Friendly

Cisco CCNA Exam Tutorial: Configuring Standard Access Lists

Rated 3.5 out of 5
No Reader Ratings Available ?
Rate It  /  View Comments  /  View All Articles submitted by Chris Bryant CCIE 12933
Submitted Wednesday, April 05, 2006
Chris Bryant CCIE 12933 (13,682)
The Bryant Advantage
Log in to become a member of Chris Bryant CCIE 12933's Fan Club!


Access Control Lists (ACLs) allow a router to permit or deny packets based on a variety of criteria. The ACL is configured in global mode, but is applied at the interface level. An ACL does not take effect until it is expressly applied to an interface with the ip access-group command. Packets can be filtered as they enter or exit an interface.

If a packet enters or exits an interface with an ACL applied, the packet is compared against the criteria of the ACL. If the packet matches the first line of the ACL, the appropriate “permit" or “deny" action is taken. If there is no match, the second line is examined. Again, if there is a match, the appropriate action is taken. If there is no match, the third line of the ACL is compared to the packet.

This process continues until a match is found, at which time the ACL stops running. If no match is found, a default “deny" takes place, and the packet will not be processed. When an ACL is configured, if a packet is not expressly permitted, it will be subject to the implicit deny at the end of every ACL. This is the default behavior of an ACL and cannot be changed.

A standard ACL is concerned with only one factor, the source IP address of the packet. The destination is not considered. Extended ACLs consider both the source and destination of the packet, and can consider the port number as well. The numerical range used for each is different: standard ACLs use the ranges 1-99 and 1300-1399 extended lists use 100-199 and 2000 to 2699.

There are several points worth repeating before beginning to configure standard ACLs.

Standard ACLs consider only the source IP address for matches.

The ACL lines are run from top to bottom. If there is no match on the first line, the second is run if no match on the second, the third is run, and so on until there is a match, or the end of the ACL is reached. This top-to-bottom process places special importance on the order of the lines.

There is an implicit deny at the end of every ACL. If packets are not expressly permitted, they are implicitly denied.

If Router 3’s Ethernet interface should only accept packets with a source network of 172.12.12.0, the ACL will be configured like this:

R3#conf t

R3(config)#access-list 5 permit 172.12.12.0 0.0.0.255

The ACL consists of only one explicit line, one that permits packets from source IP address 172.12.12.0 /24. The implicit deny, which is not configured or seen in the running configuration, will deny all packets not matching the first line.

The ACL is then applied to the Ethernet0 interface:

R3#conf t

R3(config)#interface e0

R3(config-if)#ip access-group 5 in

But before you write any ACLs, it's a really good idea to see what other ACLs are already running on the router! To see the ACLs running on the router, use the command show access-list.

R1#show access-list
Standard IP access list 1
permit 0.0.0.0
Standard IP access list 5
permit 172.1.1.1
Standard IP access list 7
permit 23.3.3.3
Extended IP access list 100
permit tcp any any lt www (26 matches)
permit tcp any any neq telnet (12 matches)
deny ip any any
Extended IP access list 105
deny tcp any any eq www
deny tcp any any eq telnet

You're going to use ACLs all the way up the Cisco certification ladder, and throughout your career. The importance of knowing how to write and apply ACLs is paramount, and it all starts with mastering the fundamentals!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of free CCNA and CCNP tutorials, The Ultimate CCNA Study Package, and Ultimate CCNP Study Packages.

You can also join his RSS feed and visit his blog, which is updated several times daily with new Cisco certification articles, free tutorials, and daily CCNA / CCNP exam questions! Details are on the website.

For a FREE copy of his latest e-books, “How To Pass The CCNA" and “How To Pass The CCNP", visit the website and download your free copies. You can also get FREE CCNA and CCNP exam questions every day! Get your CCNA study guide from The Bryant Advantage!






Reprint Rights

Log in to become a member of Chris Bryant CCIE 12933's Fan Club!

Comments on this article:
No comments yet.


Was this article helpful to you? Leave a Public Comment or Question:

 

This Article has been viewed 512 times.
Article added to SearchWarp.com on Wednesday, April 05, 2006
View other articles written by Chris Bryant CCIE 12933 (13,682)


If you found this article interesting, you may want to check out:

Disclaimer:  All information on this site is provided for informational purposes only! By no means is any information presented herein intended to substitute for the advice provided to you by any health care or other professional or organization.


Today's Most Popular
Cisco Certification: The Definitive Guide To ARP, RARP, IARP, and Proxy ARP

Cisco CCNA Exam Tutorial: What's A Collision Domain?

Cisco CCNA Exam Tutorial: Five OSPF Details You Must Know!

Cisco CCNA Certification: Showdown At The Transport Layer... TCP vs. UDP !

Cisco CCNA Certification Exam Tutorial: Route Summarization

Cisco CCENT / CCNA Certification Exam Tutorial: Logging Synchronous And Exec-Timeout Commands

Cisco CCNA / CCNP Certification: Deciphering PING Returns

How To Become A CCNA (Cisco Certified Network Associate)

Cisco CCNA / CCNP Home Lab Tutorial: How To Build A Frame Relay Switch

CCNA / CCNP / BCMSN Exam Tutorial: VLAN Trunking Basics

Home  |  Page Two  |  FAQ's  |  Contact  |  Terms of Service  |  Article Submission Guidelines  |  Writers' Contests  |  Privacy  |  Mission / About
Copyright © 1999-2008 SearchWarp.com, All Rights Reserved - SearchWarp.com is an IcoLogic, Inc. Company