Blocking Web Access to a Specific Server Using an Extended ACL
Experiment: Blocking Web Access to a Specific Server Using an Extended ACL
Problem Statement
You are the network administrator of a college. The college is assigned the network address:
140.80.0.0
The college has 20 subnets.
The Central Computing Facility (CCF) is located in the 4th subnet. The CSE department's hackathon registration website is hosted on a server assigned the 7th host address in the 16th subnet.
The registration has now closed. Therefore, students in the CCF must be prevented from accessing the hackathon website.
However:
The server provides services other than web hosting. Only HTTP/HTTPS access to the server from CCF must be blocked. Other services such as ping, FTP, DNS, etc., must continue to work.
This experiment demonstrates the use of an Extended Access Control List (Extended ACL) in Cisco Packet Tracer.
1. Aim
To design and configure a subnetted college network in Cisco Packet Tracer and use an extended IPv4 ACL to block HTTP/HTTPS access from the CCF subnet to a specific web server while allowing other services to remain accessible.
2. Objectives
After completing this experiment, students should be able to:
- Subnet a Class B network to create at least 20 subnets.
- Determine the subnet address of the CCF.
- Determine the subnet containing the hackathon server.
- Assign IP addresses to routers, PCs, and the server.
- Configure a web server in Cisco Packet Tracer.
- Configure HTTP/HTTPS services on a server.
- Configure an Extended ACL.
-
Block traffic based on:
- Source IP address
- Destination IP address
- Transport protocol
- Destination port number
- Allow non-web services to continue working.
-
Verify ACL operation using
pingand web access. - Understand why an extended ACL is required instead of a standard ACL.
3. Background Theory
The college has been assigned:
140.80.0.0
Since 140 belongs to the Class B range, the default network mask is:
255.255.0.0
or:
/16
We need at least 20 subnets.
To create 20 or more subnets:
2^n ≥ 20
The smallest value of n satisfying this is:
2^5 = 32
Therefore, we borrow 5 bits from the host portion.
Original:
/16
After borrowing 5 bits:
/21
Therefore, the subnet mask is:
255.255.248.0
This gives:
2^5 = 32 subnets
which is sufficient for the required 20 subnets.
4. Subnet Calculation
The subnet mask is:
255.255.248.0
The interesting octet is the third octet.
The block size is:
256 - 248 = 8
Therefore, the subnet addresses are:
| Subnet No. | Network Address | Usable Host Range |
|---|---|---|
| 1 | 140.80.0.0/21 | 140.80.0.1 – 140.80.7.254 |
| 2 | 140.80.8.0/21 | 140.80.8.1 – 140.80.15.254 |
| 3 | 140.80.16.0/21 | 140.80.16.1 – 140.80.23.254 |
| 4 | 140.80.24.0/21 | 140.80.24.1 – 140.80.31.254 |
| 5 | 140.80.32.0/21 | 140.80.32.1 – 140.80.39.254 |
| 6 | 140.80.40.0/21 | 140.80.40.1 – 140.80.47.254 |
| 7 | 140.80.48.0/21 | 140.80.48.1 – 140.80.55.254 |
| 8 | 140.80.56.0/21 | 140.80.56.1 – 140.80.63.254 |
| 9 | 140.80.64.0/21 | 140.80.64.1 – 140.80.71.254 |
| 10 | 140.80.72.0/21 | 140.80.72.1 – 140.80.79.254 |
| 11 | 140.80.80.0/21 | 140.80.80.1 – 140.80.87.254 |
| 12 | 140.80.88.0/21 | 140.80.88.1 – 140.80.95.254 |
| 13 | 140.80.96.0/21 | 140.80.96.1 – 140.80.103.254 |
| 14 | 140.80.104.0/21 | 140.80.104.1 – 140.80.111.254 |
| 15 | 140.80.112.0/21 | 140.80.112.1 – 140.80.119.254 |
| 16 | 140.80.120.0/21 | 140.80.120.1 – 140.80.127.254 |
| 17 | 140.80.128.0/21 | 140.80.128.1 – 140.80.135.254 |
| 18 | 140.80.136.0/21 | 140.80.136.1 – 140.80.143.254 |
| 19 | 140.80.144.0/21 | 140.80.144.1 – 140.80.151.254 |
| 20 | 140.80.152.0/21 | 140.80.152.1 – 140.80.159.254 |
5. Identify the CCF Network
The CCF is in the 4th subnet.
Therefore:
CCF Network = 140.80.24.0/21
Usable addresses:
140.80.24.1 to 140.80.31.254
We will use:
Router CCF interface = 140.80.24.1
and assign PCs addresses such as:
PC0 = 140.80.24.10 PC1 = 140.80.24.11 PC2 = 140.80.24.12
6. Identify the Hackathon Server Network
The server is in the 16th subnet.
Therefore:
16th subnet = 140.80.120.0/21
Usable range:
140.80.120.1 to 140.80.127.254
The problem states that the server is assigned the 7th address.
For this experiment, we interpret "7th address" as the 7th usable host address:
140.80.120.7
Therefore:
Hackathon Server IP = 140.80.120.7
Note for students: Some questions use "7th address" to mean counting the network address as address 1, which would produce
.6. In this experiment we use the conventional networking interpretation of the 7th usable host address = 140.80.120.7.
7. Final Addressing Scheme
| Device | Interface | IP Address | Subnet Mask |
|---|---|---|---|
| Router | G0/0 | 140.80.24.1 | 255.255.248.0 |
| Router | G0/1 | 140.80.120.1 | 255.255.248.0 |
| CCF PC0 | Fa0 | 140.80.24.10 | 255.255.248.0 |
| CCF PC1 | Fa0 | 140.80.24.11 | 255.255.248.0 |
| CCF PC2 | Fa0 | 140.80.24.12 | 255.255.248.0 |
| Hackathon Server | Fa0 | 140.80.120.7 | 255.255.248.0 |
Default gateways:
CCF PCs → 140.80.24.1 Server → 140.80.120.1
8. Network Topology
For Packet Tracer, we can represent the required networks with two LANs connected by a router.
COLLEGE NETWORK CCF - 4th Subnet 140.80.24.0/21 | +-----------+ | Switch0 | +-----------+ | | | PC0 PC1 PC2 | | G0/0 140.80.24.1 +---------+ | ROUTER | +---------+ G0/1 140.80.120.1 | | +-----------+ | Switch1 | +-----------+ | | Hackathon Server 140.80.120.7
The router connects:
CCF network 140.80.24.0/21
to:
9. Devices Required
| Device | Quantity |
|---|---|
| Cisco Router | 1 |
| Cisco 2960 Switch | 2 |
| PCs | 3 |
| Server | 1 |
| Copper Straight-Through Cables | 5 |
10. Why Do We Need an Extended ACL?
The requirement is:
Block only the website.
We cannot simply block the server's IP address.
For example, if we use:
deny ip 140.80.24.0 0.0.7.255 host 140.80.120.7
then all IP communication from CCF to the server would be blocked.
That could prevent:
- HTTP
- HTTPS
- FTP
- ICMP/ping
- other TCP services
- other UDP services
This violates the requirement.
Therefore, we need an Extended ACL.
An Extended ACL can examine:
Source IP Destination IP Protocol Source port Destination port
Therefore, we can specifically say:
CCF → Hackathon Server → TCP → port 80
and:
CCF → Hackathon Server → TCP → port 443
should be denied.
Everything else can be permitted.
11. Ports Used by Web Services
| Service | Protocol | Port |
|---|---|---|
| HTTP | TCP | 80 |
| HTTPS | TCP | 443 |
| FTP | TCP | 21 |
| DNS | UDP/TCP | 53 |
| SSH | TCP | 22 |
| Telnet | TCP | 23 |
Therefore, to block only web access, we need to block:
TCP port 80 TCP port 443
while allowing other traffic.
12. Procedure
Task 1: Open Cisco Packet Tracer
- Open Cisco Packet Tracer.
- Create a new workspace.
Task 2: Place the Router
- Select Network Devices → Routers.
- Select a router with at least two Ethernet/GigabitEthernet interfaces.
- Place the router in the workspace.
For example:
Router0
Task 3: Place Two Switches
Place two 2960 switches.
Switch0 → CCF LAN Switch1 → Server LAN
Task 4: Place Three PCs
Place:
PC0 PC1 PC2
These represent students accessing the network from CCF.
Task 5: Place the Server
From End Devices, place one server.
Rename it conceptually:
Hackathon-Web-Server
Task 6: Connect the CCF LAN
Use Copper Straight-Through cables.
Connect:
PC0 → Switch0 PC1 → Switch0 PC2 → Switch0 Switch0 → Router G0/0
Task 7: Connect the Server LAN
Connect:
Router G0/1 → Switch1 Switch1 → Server
The topology should look like:
PC0 | PC1 |\ PC2 \ Switch0 | | G0/0 140.80.24.1 Router 140.80.120.1 G0/1 | Switch1 | | Server 140.80.120.7
13. Configure the Router
Task 8: Configure G0/0
Open:
Router → CLI
Enter:
enable configure terminal interface gigabitEthernet 0/0 ip address 140.80.24.1 255.255.248.0 no shutdown exit
Task 9: Configure G0/1
Enter:
interface gigabitEthernet 0/1 ip address 140.80.120.1 255.255.248.0 no shutdown exit end
14. Verify Router Interfaces
Task 10
Enter:
show ip interface brief
Expected:
| Interface | IP Address | Status | Protocol |
|---|---|---|---|
| G0/0 | 140.80.24.1 | up | up |
| G0/1 | 140.80.120.1 | up | up |
Both interfaces should ideally show:
up up
15. Configure CCF PCs
Task 11: Configure PC0
Go to:
PC0 → Desktop → IP Configuration
Enter:
IP Address: 140.80.24.10 Subnet Mask: 255.255.248.0 Default Gateway: 140.80.24.1
Task 12: Configure PC1
IP Address: 140.80.24.11 Subnet Mask: 255.255.248.0 Default Gateway: 140.80.24.1
Task 13: Configure PC2
IP Address: 140.80.24.12 Subnet Mask: 255.255.248.0 Default Gateway: 140.80.24.1
16. Configure the Hackathon Server
Task 14
Go to:
Server → Desktop → IP Configuration
Enter:
IP Address: 140.80.120.7 Subnet Mask: 255.255.248.0 Default Gateway: 140.80.120.1
17. Configure the Web Server
Task 15: Enable HTTP
Go to:
Server → Services → HTTP
Make sure:
HTTP: ON
You can edit the default web page if desired.
For example, use:
HACKATHON REGISTRATION Registration is now CLOSED.
This makes the experiment visually clear when students access the website.
18. Enable HTTPS
If your Packet Tracer version provides HTTPS under the HTTP service:
HTTPS: ON
This allows us to demonstrate blocking both:
HTTP → TCP 80 HTTPS → TCP 443
19. Test Connectivity Before Applying ACL
This is an important step.
Before configuring the ACL, verify that everything works.
Task 16: Ping the Router
From PC0:
ping 140.80.24.1
Expected:
Successful
Task 17: Ping the Server
From PC0:
ping 140.80.120.7
Expected:
Successful
Do the same from PC1:
ping 140.80.120.7
and PC2:
ping 140.80.120.7
All should succeed.
20. Test the Website Before Applying ACL
Task 18
On PC0:
Desktop → Web Browser
Enter:
http://140.80.120.7
The server's web page should open.
Repeat from PC1 and PC2.
Therefore, before the ACL:
CCF → HTTP → Server
is working.
21. Important Observation Before ACL
Students should record:
| Test | Expected Result |
|---|---|
| PC0 → Router ping | Success |
| PC0 → Server ping | Success |
| PC1 → Server ping | Success |
| PC2 → Server ping | Success |
| PC0 → HTTP website | Success |
| PC1 → HTTP website | Success |
| PC2 → HTTP website | Success |
This establishes the baseline.
22. Configure the Extended ACL
Now we implement the actual requirement.
We will create an ACL called:
CCF_WEB_BLOCK
The ACL will:
- Deny HTTP from CCF to the server.
- Deny HTTPS from CCF to the server.
- Permit everything else.
23. Task 19: Enter ACL Configuration Mode
On the router:
enable configure terminal
Create the extended named ACL:
ip access-list extended CCF_WEB_BLOCK
The prompt becomes:
Router(config-ext-nacl)#
24. Task 20: Block HTTP
Enter:
deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 80
Let's understand this command:
deny
Block the traffic.
tcp
Only TCP traffic.
140.80.24.0 0.0.7.255
Source = entire CCF subnet.
host 140.80.120.7
Destination = only the hackathon server.
eq 80
Destination TCP port 80 = HTTP.
25. Task 21: Block HTTPS
Enter:
deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443
This blocks HTTPS.
26. Task 22: Permit All Other Traffic
This line is very important.
Enter:
permit ip any any
Why?
Because ACLs have an implicit:
deny ip any any
at the end.
If we don't explicitly permit other traffic, the ACL could unintentionally block other communications.
Therefore:
deny HTTP deny HTTPS permit everything else
is exactly what we need.
27. Complete ACL Configuration
The complete configuration is:
Router(config)# ip access-list extended CCF_WEB_BLOCK Router(config-ext-nacl)# deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 80 Router(config-ext-nacl)# deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443 Router(config-ext-nacl)# permit ip any any Router(config-ext-nacl)# exit
28. Task 23: Apply the ACL to the Correct Interface
Now we have to decide where to apply the ACL.
We want to filter traffic coming from CCF.
Therefore, we can apply the ACL inbound on G0/0, the interface connected to CCF.
Enter:
interface gigabitEthernet 0/0 ip access-group CCF_WEB_BLOCK in exit end
The complete command is:
Router(config)# interface gigabitEthernet 0/0 Router(config-if)# ip access-group CCF_WEB_BLOCK in Router(config-if)# exit Router(config)# end
29. Why Apply the ACL on G0/0 Inbound?
The traffic flow is:
CCF PC | ↓ Switch | ↓ G0/0 | ↓ Router | ↓ G0/1 | ↓ Server
By applying the ACL inbound on G0/0, traffic from CCF is examined as soon as it enters the router.
This is efficient because unwanted HTTP/HTTPS traffic is stopped before the router forwards it toward the server.
30. Test the ACL
Now repeat the tests.
Task 24: Ping the Server
From PC0:
ping 140.80.120.7
Expected:
SUCCESS
This is very important.
The ping should still work because:
ping = ICMP
and we only blocked:
TCP port 80 TCP port 443
31. Test HTTP Access
Task 25
From PC0:
Desktop → Web Browser
Enter:
http://140.80.120.7
Expected result:
Website access should fail.
Repeat from:
PC1 PC2
The website should be inaccessible from all CCF PCs.
32. Test HTTPS Access
If HTTPS is enabled:
https://140.80.120.7
Expected:
Blocked
This verifies that both web protocols are blocked.
33. Verify That Other Services Are Not Blocked
This is a critical part of the experiment.
The problem specifically states:
Other services provided by the server should not be denied.
Therefore, we must demonstrate that non-web traffic still works.
34. Test ICMP
From PC0:
ping 140.80.120.7
Expected:
SUCCESS
Therefore:
ICMP → Allowed
35. Test FTP
If you enable FTP on the server:
Go to:
Server → Services → FTP
Set:
FTP: ON
Create a test FTP user if required by your Packet Tracer version.
Then from PC0, use:
Desktop → Command Prompt
Try:
ftp 140.80.120.7
Expected:
FTP access should continue to work.
This demonstrates that:
TCP port 21
has not been blocked.
36. Test Other Services
You can similarly test other services available on the Packet Tracer server.
For example:
HTTP → BLOCKED HTTPS → BLOCKED FTP → ALLOWED ICMP → ALLOWED
This demonstrates that the ACL is service-specific rather than server-specific.
37. Verify ACL Statistics
On the router:
show access-lists
You should see something similar to:
Extended IP access list CCF_WEB_BLOCK deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq www deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443 permit ip any any
The ACL entries may display hit counts.
For example:
deny tcp ... eq 80 (5 matches) deny tcp ... eq 443 (2 matches) permit ip any any (15 matches)
The exact counts will depend on how many tests were performed.
38. Task 26: Observe ACL Hit Counts
Perform:
show access-lists
before and after attempting to access:
http://140.80.120.7
Students should observe that the match count of the HTTP deny rule increases.
This provides evidence that the ACL is actually processing the web traffic.
39. Verify ACL Applied to Interface
Use:
show ip interface gigabitEthernet 0/0
Look for information indicating:
Inbound access list is CCF_WEB_BLOCK
This confirms that the ACL is applied in the intended direction.
40. Complete ACL Configuration
Students should record this in their lab record:
enable configure terminal ip access-list extended CCF_WEB_BLOCK deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 80 deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443 permit ip any any exit interface gigabitEthernet 0/0 ip access-group CCF_WEB_BLOCK in exit end
41. Understanding the Wildcard Mask
Students should understand:
CCF network: 140.80.24.0/21
Subnet mask:
255.255.248.0
Wildcard mask:
0.0.7.255
because:
255.255.255.255 - 255.255.248.0 ---------------- 0.0.7.255
Therefore:
140.80.24.0 0.0.7.255
represents the entire CCF subnet:
140.80.24.0 through 140.80.31.255
with usable hosts:
140.80.24.1 through 140.80.31.254
42. Why We Used host for the Server
The ACL contains:
host 140.80.120.7
This means:
Match exactly one destination IP address.
We do not want to block the entire server subnet.
If we used:
140.80.120.0 0.0.7.255
we would potentially block web access to all servers in that subnet.
The requirement is only about one particular server.
Therefore:
host 140.80.120.7
is appropriate.
43. Why We Used eq 80
The command:
eq 80
means:
equal to destination port 80
Port 80 is HTTP.
Similarly:
eq 443
means HTTPS.
Thus:
deny tcp ... host 140.80.120.7 eq 80
means:
Block TCP traffic from CCF to the hackathon server when the destination port is 80.
44. Why We Did Not Use deny ip
Consider this ACL:
deny ip 140.80.24.0 0.0.7.255 host 140.80.120.7
This would block all IP traffic from CCF to the server.
That would potentially prevent:
HTTP HTTPS FTP ICMP DNS SSH etc.
But the problem specifically says:
Other services must not be denied.
Therefore, deny ip is not appropriate.
The correct approach is to use:
deny tcp ... eq 80 deny tcp ... eq 443 permit ip any any
45. Observation Table
Students should complete this table.
| Test | Protocol/Port | Expected Result | Actual Result |
|---|---|---|---|
| PC0 → Server ping | ICMP | Allowed | ______ |
| PC1 → Server ping | ICMP | Allowed | ______ |
| PC2 → Server ping | ICMP | Allowed | ______ |
| PC0 → Server HTTP | TCP/80 | Blocked | ______ |
| PC1 → Server HTTP | TCP/80 | Blocked | ______ |
| PC2 → Server HTTP | TCP/80 | Blocked | ______ |
| PC0 → Server HTTPS | TCP/443 | Blocked | ______ |
| PC0 → Server FTP | TCP/21 | Allowed | ______ |
46. Before and After ACL
This comparison is useful for students.
| Service | Before ACL | After ACL |
|---|---|---|
| Ping | Allowed | Allowed |
| HTTP | Allowed | Blocked |
| HTTPS | Allowed | Blocked |
| FTP | Allowed | Allowed |
| Other IP traffic | Allowed | Allowed |
Therefore, the ACL achieves the required objective.
47. Troubleshooting Exercise
Task 27: Check What Happens if the ACL Is Removed
Remove the ACL from G0/0:
configure terminal interface gigabitEthernet 0/0 no ip access-group CCF_WEB_BLOCK in exit end
Now test:
http://140.80.120.7
The website should become accessible again.
This demonstrates that the ACL was responsible for blocking the web traffic.
Reapply it:
configure terminal interface gigabitEthernet 0/0 ip access-group CCF_WEB_BLOCK in exit end
Test again.
The website should again be blocked.
48. Task 28: Save the Configuration
Once the experiment is working:
copy running-config startup-config
Press Enter when prompted.
49. Important Commands Used
| Purpose | Command |
|---|---|
| Enter privileged mode | enable |
| Enter global configuration | configure terminal |
| Create extended ACL | ip access-list extended NAME |
| Deny HTTP | deny tcp SOURCE DESTINATION eq 80 |
| Deny HTTPS | deny tcp SOURCE DESTINATION eq 443 |
| Permit other traffic | permit ip any any |
| Apply ACL | ip access-group NAME in |
| View ACL | show access-lists |
| View interface ACL | show ip interface |
| Test connectivity | ping IP |
| Save configuration | copy running-config startup-config |
50. Result
The college network was subnetted using a /21 subnet mask to create 32 subnets. The CCF was identified as the 4th subnet, 140.80.24.0/21, and the hackathon server was assigned the 7th usable host address of the 16th subnet, 140.80.120.7. An extended ACL was configured on the router to block HTTP and HTTPS traffic from the CCF subnet to the hackathon server. Other services, including ICMP and FTP, were permitted, thereby satisfying the requirement to block only website access.
Comments
Post a Comment