Home > Access List Tutorial

Access List Tutorial

February 13th, 2011 Go to comments

In this tutorial we will learn about access list.

Access control lists (ACLs) provide a means to filter packets by allowing a user to permit or deny IP packets from crossing specified interfaces. Just imagine you come to a fair and see the guardian checking tickets. He only allows people with suitable tickets to enter. Well, an access list’s function is same as that guardian.

Access lists filter network traffic by controlling whether packets are forwarded or blocked at the router’s interfaces based on the criteria you specified within the access list.

To use ACLs, the system administrator must first configure ACLs and then apply them to specific interfaces. There are 3 popular types of ACL: Standard, Extended and Named ACLs.

Standard IP Access List

Standard IP lists (1-99) only check source addresses of all IP packets.

Configuration Syntax

access-list access-list-number {permit | deny} source {source-mask}

Apply ACL to an interface

ip access-group access-list-number {in | out}

Example of Standard IP Access List

Standard_ACL_Example1.jpg

Configuration:

In this example we will define a standard access list that will only allow network 10.0.0.0/8 to access the server (located on the Fa0/1 interface)

Define which source is allowed to pass:

Router(config)#access-list 1 permit 10.0.0.0 0.255.255.255

(there is always an implicit deny all other traffic at the end of each ACL so we don’t need to define forbidden traffic)

Apply this ACL to an interface:

Router(config)#interface Fa0/1

Router(config-if)#ip access-group 1 out

The ACL 1 is applied to permit only packets from 10.0.0.0/8 to go out of Fa0/1 interface while deny all other traffic. So can we apply this ACL to other interface, Fa0/2 for example? Well we can but shouldn’t do it because users can access to the server from other interface (s0 interface, for example). So we can understand why an standard access list should be applied close to the destination.

Note: The “0.255.255.255″ is the wildcard mask part of network “10.0.0.0″. We will learn how to use wildcard mask later.

Extended IP Access List

Extended IP lists (100-199) check both source and destination addresses, specific UDP/TCP/IP protocols, and destination ports.

Configuration Syntax

access-list access-list-number {permit | deny} protocol source {source-mask} destination {destination-mask} [eq destination-port]

Example of Extended IP Access List

Extended_ACL_Example1.jpg

In this example we will create an extended ACL that will deny FTP traffic from network 10.0.0.0/8 but allow other traffic to go through.

Note: FTP uses TCP on port 20 & 21.

Define which protocol, source, destination and port are denied:

Router(config)#access-list 101 deny tcp 10.0.0.0 0.255.255.255 187.100.1.6 0.0.0.0 eq 21

Router(config)#access-list 101 deny tcp 10.0.0.0 0.255.255.255 187.100.1.6 0.0.0.0 eq 20

Router(config)#access-list 101 permit ip any any

Apply this ACL to an interface:

Router(config)#interface Fa0/1

Router(config-if)#ip access-group 101 out

Notice that we have to explicit allow other traffic (access-list 101 permit ip any any) as there is an “deny all” command at the end of each ACL.

As we can see, the destination of above access list is “187.100.1.6 0.0.0.0″ which specifies a host. We can use “host 187.100.1.6″ instead. We will discuss wildcard mask later.

In summary, below is the range of standard and extended access list

Access list type Range
Standard 1-99, 1300-1999
Extended 100-199, 2000-2699

Comments (378) Comments
Comment pages
1 4 5 6 7 8 458
  1. Praveen Das PV
    May 13th, 2014

    Please send me the latest dump. praveendaspv@gmail.com

    Thanks to you

  2. ibrahim imad
    May 14th, 2014

    Please send me the latest dump. barhoum_55@hotmail.com

  3. Aftab Ahmed
    May 27th, 2014

    Can anyone Please send me the latest Dump at aftabahmed105@gmail.com

  4. Anonymous
    May 31st, 2014

    Hi, May I ask request for the latest CCNA dump? My email is bios27@gmail.com. Thanks!

  5. please could you send me the latest dumps..colette.mcgovern@gmail.com
    June 4th, 2014

    please could you sent me the latest dumps…colette.mcgovern@gmail.com

  6. Please could you sent me the latest CCNA dump? My email is hwmb@hotmail.es. Thanks
    June 8th, 2014

    Please could you sent me the latest CCNA dump? My email is hwmb@hotmail.es. Thanks

  7. maazoud
    June 9th, 2014

    please dears if any one have latest dump please please my exam next week , maazoud90@gmail.com..

  8. Leslie
    June 11th, 2014

    Please send me the latest dump. chikuruwol@gmail.com

  9. Paul
    June 12th, 2014

    Please send me the latest dump.
    skill.82@tiscali.it
    Thanks

  10. ayus
    June 13th, 2014

    Could i please get the latest dump? Taking exam next week. Send to Anarchytays@gmail.com

    thanks

  11. mahatsacky
    June 16th, 2014

    hi guys i need to do ccna exam by tomorrow plz latest dums @ mahad422@gmail.com

  12. eliud kitime
    June 17th, 2014

    please send me latest dump . i plan to do ccna next week eliud732001@yahoo.com

  13. Sarah
    June 17th, 2014

    hi guys, can anyone please send me the latest dump. my e-mail is mostvn@hotmail.com

  14. Arnab
    June 18th, 2014

    can anyone please send me the latest dump. my e-mail is arnabkanrar@yahoo.com

  15. Muhammad Ramzan Qamar
    June 19th, 2014

    Please send me the latest dump.muhammadramzan.qamar@yahoo.com

    Thanks to you

  16. Constantine Rigas
    June 19th, 2014

    Please anyone send me the latest dump gusrigas69@gmail.com
    Thanks tons!!!

  17. Anonymous
    June 23rd, 2014

    Please send me the latest dump ambet0505@gmail.com

  18. Anonymous
    June 23rd, 2014

    Please send me the latest dump r_coroza@yahoo.com

  19. Michael Troso
    June 24th, 2014

    Please send me the latest dump michael.troso@yahoo.com

  20. Apropos
    June 25th, 2014

    Please send me the latest dumps. I plan to take the ccna 200-120 exam next week.
    THANKS!!!! aproposchpt2@gmail.com

  21. Israr
    June 26th, 2014

    Please send me the latest dump buttisrar@hotmail.com

  22. temidayo
    June 26th, 2014

    please kindly send me the latest dumps.. i have planned to write my exam in the next few weeks… my e-mail is temidayoolanipekun@gmail.com .. thanks ! ! !

  23. Rambabu Kosuru
    June 27th, 2014

    Please send me the latest dump. I have exam on coming Monday. Please Send updated Dump at rambabuk424@gmail.com

  24. pit
    July 5th, 2014

    can you please send me the latest dump. taking exam in next month . please sapikness@gmail.com

  25. Anonymous
    July 6th, 2014

    could anyone please send me latest dumps,farhanrocking001@gmail.com

  26. san Barack
    July 9th, 2014

    can anybody make me understand more on ACL IN and OUT bound thing is killing me.

  27. vimal
    July 11th, 2014

    Please send me the latest dumps. check4vimalmohan@gmail.com

  28. tawin
    July 14th, 2014

    Please send me the latest dump. to tawin_7@hotmail.com
    Thanks to you
    ขอบคุณครับ

  29. siraj
    July 16th, 2014

    please send me the latest dumps. sirajer@live.com

  30. Salahuddin Shaikh
    July 16th, 2014

    Please Send me latest dumps. sshaikh385@gmail.com

  31. Zak
    July 18th, 2014

    Hi,i want to take ccna exam soon can some body send me latest ccna dumps please..my email id is zak0019@yahoo.co.uk

  32. Antonio
    July 19th, 2014

    Im also about to the the CCNA examen, please help with the dumps. THanks so much gta18_q_f360@hotmail.com

  33. Ken
    July 23rd, 2014

    Anyone, please send me the latest dump.I plan to take the test on next month. rmk01750@gmail.com
    Thank you so much

  34. Kash
    July 25th, 2014

    Thanks for this knowledge on access list kindly send me some lastest dumps kelvinallday@gmail.com

  35. Jake
    July 29th, 2014

    Want to take test next month

    Please send latest VCE reader and DUMPS

    wesseljake@gmail.com

    Thanks

  36. News
    July 29th, 2014

    Want to take the exam in next month please send latest dump. element@mweb.co.zw

  37. Diego
    August 2nd, 2014

    Please, send me lastest dumps and VCE reader, diegopuertaramos@gmail.com

  38. Razi
    August 4th, 2014

    Want to take the exam in next week please send me latest dump razeul@gmail.com

  39. Maverick
    August 6th, 2014

    I want to take the exam around the 23 August 2014 please send me latest dump naicker@intekom.co.za

  40. Hasnain Ali
    August 9th, 2014

    I want to take the exam around the 22 August 2014 please send me latest dump engr.husni@gmail.com

  41. prakash prasanna
    August 12th, 2014

    please send latest dump . prakashdooms@gmail.com

  42. Besher Allahham
    August 14th, 2014

    its very simple topology

  43. Pako
    August 15th, 2014

    please send latest dump peter.gabor.pakozdi@gmail.com

  44. oguz han
    August 15th, 2014

    please sent me :)

  45. oguz han
    August 15th, 2014
  46. Anonymous
    August 20th, 2014

    can you send me dumps too? onebur@aol.com

  47. sagar
    August 20th, 2014

    can some1 send me the lastest dumps sgrwaghmare010@yahoo.in

  48. ray
    August 20th, 2014

    can you sent me the latest dumps? adonai_o7@yahoo.com God bless…

  49. osita
    August 26th, 2014

    can someone please send latest dumps ositaonwe@gmail.com

  50. Anonymous
    August 27th, 2014

    Please send me the latest dumps anonym875@gmail.com

Comment pages
1 4 5 6 7 8 458
Add a Comment