Blocking Web Access to a Specific Server Using an Extended ACL

 

Experiment: Blocking Web Access to a Specific Server Using an Extended ACL

Problem Statement

You are the network administrator of a college. The college is assigned the network address:

140.80.0.0

The college has 20 subnets.

The Central Computing Facility (CCF) is located in the 4th subnet. The CSE department's hackathon registration website is hosted on a server assigned the 7th host address in the 16th subnet.

The registration has now closed. Therefore, students in the CCF must be prevented from accessing the hackathon website.

However:

The server provides services other than web hosting. Only HTTP/HTTPS access to the server from CCF must be blocked. Other services such as ping, FTP, DNS, etc., must continue to work.

This experiment demonstrates the use of an Extended Access Control List (Extended ACL) in Cisco Packet Tracer.


1. Aim

To design and configure a subnetted college network in Cisco Packet Tracer and use an extended IPv4 ACL to block HTTP/HTTPS access from the CCF subnet to a specific web server while allowing other services to remain accessible.


2. Objectives

After completing this experiment, students should be able to:

  1. Subnet a Class B network to create at least 20 subnets.
  2. Determine the subnet address of the CCF.
  3. Determine the subnet containing the hackathon server.
  4. Assign IP addresses to routers, PCs, and the server.
  5. Configure a web server in Cisco Packet Tracer.
  6. Configure HTTP/HTTPS services on a server.
  7. Configure an Extended ACL.
  8. Block traffic based on:
    • Source IP address
    • Destination IP address
    • Transport protocol
    • Destination port number
  9. Allow non-web services to continue working.
  10. Verify ACL operation using ping and web access.
  11. Understand why an extended ACL is required instead of a standard ACL.

3. Background Theory

The college has been assigned:

140.80.0.0

Since 140 belongs to the Class B range, the default network mask is:

255.255.0.0

or:

/16

We need at least 20 subnets.

To create 20 or more subnets:

2^n ≥ 20

The smallest value of n satisfying this is:

2^5 = 32

Therefore, we borrow 5 bits from the host portion.

Original:

/16

After borrowing 5 bits:

/21

Therefore, the subnet mask is:

255.255.248.0

This gives:

2^5 = 32 subnets

which is sufficient for the required 20 subnets.


4. Subnet Calculation

The subnet mask is:

255.255.248.0

The interesting octet is the third octet.

The block size is:

256 - 248 = 8

Therefore, the subnet addresses are:

Subnet No.Network AddressUsable Host Range
1140.80.0.0/21140.80.0.1 – 140.80.7.254
2140.80.8.0/21140.80.8.1 – 140.80.15.254
3140.80.16.0/21140.80.16.1 – 140.80.23.254
4140.80.24.0/21140.80.24.1 – 140.80.31.254
5140.80.32.0/21140.80.32.1 – 140.80.39.254
6140.80.40.0/21140.80.40.1 – 140.80.47.254
7140.80.48.0/21140.80.48.1 – 140.80.55.254
8140.80.56.0/21140.80.56.1 – 140.80.63.254
9140.80.64.0/21140.80.64.1 – 140.80.71.254
10140.80.72.0/21140.80.72.1 – 140.80.79.254
11140.80.80.0/21140.80.80.1 – 140.80.87.254
12140.80.88.0/21140.80.88.1 – 140.80.95.254
13140.80.96.0/21140.80.96.1 – 140.80.103.254
14140.80.104.0/21140.80.104.1 – 140.80.111.254
15140.80.112.0/21140.80.112.1 – 140.80.119.254
16140.80.120.0/21140.80.120.1 – 140.80.127.254
17140.80.128.0/21140.80.128.1 – 140.80.135.254
18140.80.136.0/21140.80.136.1 – 140.80.143.254
19140.80.144.0/21140.80.144.1 – 140.80.151.254
20140.80.152.0/21140.80.152.1 – 140.80.159.254

5. Identify the CCF Network

The CCF is in the 4th subnet.

Therefore:

CCF Network = 140.80.24.0/21

Usable addresses:

140.80.24.1
       to
140.80.31.254

We will use:

Router CCF interface = 140.80.24.1

and assign PCs addresses such as:

PC0 = 140.80.24.10
PC1 = 140.80.24.11
PC2 = 140.80.24.12

6. Identify the Hackathon Server Network

The server is in the 16th subnet.

Therefore:

16th subnet = 140.80.120.0/21

Usable range:

140.80.120.1
        to
140.80.127.254

The problem states that the server is assigned the 7th address.

For this experiment, we interpret "7th address" as the 7th usable host address:

140.80.120.7

Therefore:

Hackathon Server IP = 140.80.120.7

Note for students: Some questions use "7th address" to mean counting the network address as address 1, which would produce .6. In this experiment we use the conventional networking interpretation of the 7th usable host address = 140.80.120.7.


7. Final Addressing Scheme

DeviceInterfaceIP Address    Subnet Mask
RouterG0/0140.80.24.1    255.255.248.0
RouterG0/1140.80.120.1    255.255.248.0
CCF PC0Fa0140.80.24.10    255.255.248.0
CCF PC1Fa0140.80.24.11    255.255.248.0
CCF PC2Fa0140.80.24.12    255.255.248.0
Hackathon ServerFa0140.80.120.7    255.255.248.0

Default gateways:

CCF PCs → 140.80.24.1
Server  → 140.80.120.1

8. Network Topology

For Packet Tracer, we can represent the required networks with two LANs connected by a router.

                  COLLEGE NETWORK

        CCF - 4th Subnet
        140.80.24.0/21
               |
         +-----------+
         |  Switch0  |
         +-----------+
          |    |    |
         PC0  PC1  PC2
          |
          |
       G0/0
    140.80.24.1
        +---------+
        | ROUTER  |
        +---------+
       G0/1
   140.80.120.1
          |
          |
     +-----------+
     |  Switch1  |
     +-----------+
          |
          |
    Hackathon Server
    140.80.120.7

The router connects:

CCF network
140.80.24.0/21

to:

Server network
140.80.120.0/21




9. Devices Required

DeviceQuantity
Cisco Router    1
Cisco 2960 Switch    2
PCs    3
Server    1
Copper Straight-Through Cables    5

10. Why Do We Need an Extended ACL?

The requirement is:

Block only the website.

We cannot simply block the server's IP address.

For example, if we use:

deny ip 140.80.24.0 0.0.7.255 host 140.80.120.7

then all IP communication from CCF to the server would be blocked.

That could prevent:

  • HTTP
  • HTTPS
  • FTP
  • ICMP/ping
  • other TCP services
  • other UDP services

This violates the requirement.

Therefore, we need an Extended ACL.

An Extended ACL can examine:

Source IP
Destination IP
Protocol
Source port
Destination port

Therefore, we can specifically say:

CCF → Hackathon Server → TCP → port 80

and:

CCF → Hackathon Server → TCP → port 443

should be denied.

Everything else can be permitted.


11. Ports Used by Web Services

Service    Protocol    Port
HTTP    TCP    80
HTTPS    TCP    443
FTP    TCP    21
DNS    UDP/TCP    53
SSH    TCP    22
Telnet    TCP    23

Therefore, to block only web access, we need to block:

TCP port 80
TCP port 443

while allowing other traffic.


12. Procedure

Task 1: Open Cisco Packet Tracer

  1. Open Cisco Packet Tracer.
  2. Create a new workspace.

Task 2: Place the Router

  1. Select Network Devices → Routers.
  2. Select a router with at least two Ethernet/GigabitEthernet interfaces.
  3. Place the router in the workspace.

For example:

Router0

Task 3: Place Two Switches

Place two 2960 switches.

Switch0 → CCF LAN
Switch1 → Server LAN

Task 4: Place Three PCs

Place:

PC0
PC1
PC2

These represent students accessing the network from CCF.


Task 5: Place the Server

From End Devices, place one server.

Rename it conceptually:

Hackathon-Web-Server

Task 6: Connect the CCF LAN

Use Copper Straight-Through cables.

Connect:

PC0 → Switch0
PC1 → Switch0
PC2 → Switch0
Switch0 → Router G0/0

Task 7: Connect the Server LAN

Connect:

Router G0/1 → Switch1
Switch1 → Server

The topology should look like:

 PC0
  |
 PC1
  |\
 PC2 \
      Switch0
         |
         |
       G0/0
    140.80.24.1
       Router
    140.80.120.1
       G0/1
         |
      Switch1
         |
         |
   Server
140.80.120.7

13. Configure the Router

Task 8: Configure G0/0

Open:

Router → CLI

Enter:

enable
configure terminal
interface gigabitEthernet 0/0
ip address 140.80.24.1 255.255.248.0
no shutdown
exit

Task 9: Configure G0/1

Enter:

interface gigabitEthernet 0/1
ip address 140.80.120.1 255.255.248.0
no shutdown
exit
end

14. Verify Router Interfaces

Task 10

Enter:

show ip interface brief

Expected:

Interface    IP Address    Status    Protocol
G0/0    140.80.24.1    up    up
G0/1    140.80.120.1    up            up

Both interfaces should ideally show:

up
up

15. Configure CCF PCs

Task 11: Configure PC0

Go to:

PC0 → Desktop → IP Configuration

Enter:

IP Address:       140.80.24.10
Subnet Mask:      255.255.248.0
Default Gateway:  140.80.24.1

Task 12: Configure PC1

IP Address:       140.80.24.11
Subnet Mask:      255.255.248.0
Default Gateway:  140.80.24.1

Task 13: Configure PC2

IP Address:       140.80.24.12
Subnet Mask:      255.255.248.0
Default Gateway:  140.80.24.1

16. Configure the Hackathon Server

Task 14

Go to:

Server → Desktop → IP Configuration

Enter:

IP Address:       140.80.120.7
Subnet Mask:      255.255.248.0
Default Gateway:  140.80.120.1

17. Configure the Web Server

Task 15: Enable HTTP

Go to:

Server → Services → HTTP

Make sure:

HTTP: ON

You can edit the default web page if desired.

For example, use:

HACKATHON REGISTRATION

Registration is now CLOSED.

This makes the experiment visually clear when students access the website.


18. Enable HTTPS

If your Packet Tracer version provides HTTPS under the HTTP service:

HTTPS: ON

This allows us to demonstrate blocking both:

HTTP → TCP 80
HTTPS → TCP 443

19. Test Connectivity Before Applying ACL

This is an important step.

Before configuring the ACL, verify that everything works.


Task 16: Ping the Router

From PC0:

ping 140.80.24.1

Expected:

Successful


Task 17: Ping the Server

From PC0:

ping 140.80.120.7

Expected:

Successful

Do the same from PC1:

ping 140.80.120.7

and PC2:

ping 140.80.120.7

All should succeed.


20. Test the Website Before Applying ACL

Task 18

On PC0:

Desktop → Web Browser

Enter:

http://140.80.120.7

The server's web page should open.

Repeat from PC1 and PC2.

Therefore, before the ACL:

CCF → HTTP → Server

is working.


21. Important Observation Before ACL

Students should record:

Test    Expected Result
PC0 → Router ping    Success
PC0 → Server ping    Success
PC1 → Server ping    Success
PC2 → Server ping    Success
PC0 → HTTP website    Success
PC1 → HTTP website    Success
PC2 → HTTP website    Success

This establishes the baseline.


22. Configure the Extended ACL

Now we implement the actual requirement.

We will create an ACL called:

CCF_WEB_BLOCK

The ACL will:

  1. Deny HTTP from CCF to the server.
  2. Deny HTTPS from CCF to the server.
  3. Permit everything else.

23. Task 19: Enter ACL Configuration Mode

On the router:

enable
configure terminal

Create the extended named ACL:

ip access-list extended CCF_WEB_BLOCK

The prompt becomes:

Router(config-ext-nacl)#

24. Task 20: Block HTTP

Enter:

deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 80

Let's understand this command:

deny

Block the traffic.

tcp

Only TCP traffic.

140.80.24.0 0.0.7.255

Source = entire CCF subnet.

host 140.80.120.7

Destination = only the hackathon server.

eq 80

Destination TCP port 80 = HTTP.


25. Task 21: Block HTTPS

Enter:

deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443

This blocks HTTPS.


26. Task 22: Permit All Other Traffic

This line is very important.

Enter:

permit ip any any

Why?

Because ACLs have an implicit:

deny ip any any

at the end.

If we don't explicitly permit other traffic, the ACL could unintentionally block other communications.

Therefore:

deny HTTP
deny HTTPS
permit everything else

is exactly what we need.


27. Complete ACL Configuration

The complete configuration is:

Router(config)# ip access-list extended CCF_WEB_BLOCK

Router(config-ext-nacl)# deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 80

Router(config-ext-nacl)# deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443

Router(config-ext-nacl)# permit ip any any

Router(config-ext-nacl)# exit

28. Task 23: Apply the ACL to the Correct Interface

Now we have to decide where to apply the ACL.

We want to filter traffic coming from CCF.

Therefore, we can apply the ACL inbound on G0/0, the interface connected to CCF.

Enter:

interface gigabitEthernet 0/0
ip access-group CCF_WEB_BLOCK in
exit
end

The complete command is:

Router(config)# interface gigabitEthernet 0/0
Router(config-if)# ip access-group CCF_WEB_BLOCK in
Router(config-if)# exit
Router(config)# end

29. Why Apply the ACL on G0/0 Inbound?

The traffic flow is:

CCF PC
   |
   ↓
Switch
   |
   ↓
G0/0
   |
   ↓
Router
   |
   ↓
G0/1
   |
   ↓
Server

By applying the ACL inbound on G0/0, traffic from CCF is examined as soon as it enters the router.

This is efficient because unwanted HTTP/HTTPS traffic is stopped before the router forwards it toward the server.


30. Test the ACL

Now repeat the tests.

Task 24: Ping the Server

From PC0:

ping 140.80.120.7

Expected:

SUCCESS

This is very important.

The ping should still work because:

ping = ICMP

and we only blocked:

TCP port 80
TCP port 443

31. Test HTTP Access

Task 25

From PC0:

Desktop → Web Browser

Enter:

http://140.80.120.7

Expected result:

Website access should fail.

Repeat from:

PC1
PC2

The website should be inaccessible from all CCF PCs.


32. Test HTTPS Access

If HTTPS is enabled:

https://140.80.120.7

Expected:

Blocked

This verifies that both web protocols are blocked.


33. Verify That Other Services Are Not Blocked

This is a critical part of the experiment.

The problem specifically states:

Other services provided by the server should not be denied.

Therefore, we must demonstrate that non-web traffic still works.


34. Test ICMP

From PC0:

ping 140.80.120.7

Expected:

SUCCESS

Therefore:

ICMP → Allowed

35. Test FTP

If you enable FTP on the server:

Go to:

Server → Services → FTP

Set:

FTP: ON

Create a test FTP user if required by your Packet Tracer version.

Then from PC0, use:

Desktop → Command Prompt

Try:

ftp 140.80.120.7

Expected:

FTP access should continue to work.

This demonstrates that:

TCP port 21

has not been blocked.


36. Test Other Services

You can similarly test other services available on the Packet Tracer server.

For example:

HTTP  → BLOCKED
HTTPS → BLOCKED
FTP   → ALLOWED
ICMP  → ALLOWED

This demonstrates that the ACL is service-specific rather than server-specific.


37. Verify ACL Statistics

On the router:

show access-lists

You should see something similar to:

Extended IP access list CCF_WEB_BLOCK

deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq www
deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443
permit ip any any

The ACL entries may display hit counts.

For example:

deny tcp ... eq 80 (5 matches)
deny tcp ... eq 443 (2 matches)
permit ip any any (15 matches)

The exact counts will depend on how many tests were performed.


38. Task 26: Observe ACL Hit Counts

Perform:

show access-lists

before and after attempting to access:

http://140.80.120.7

Students should observe that the match count of the HTTP deny rule increases.

This provides evidence that the ACL is actually processing the web traffic.


39. Verify ACL Applied to Interface

Use:

show ip interface gigabitEthernet 0/0

Look for information indicating:

Inbound access list is CCF_WEB_BLOCK

This confirms that the ACL is applied in the intended direction.


40. Complete ACL Configuration

Students should record this in their lab record:

enable
configure terminal

ip access-list extended CCF_WEB_BLOCK

deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 80

deny tcp 140.80.24.0 0.0.7.255 host 140.80.120.7 eq 443

permit ip any any

exit

interface gigabitEthernet 0/0

ip access-group CCF_WEB_BLOCK in

exit
end

41. Understanding the Wildcard Mask

Students should understand:

CCF network:
140.80.24.0/21

Subnet mask:

255.255.248.0

Wildcard mask:

0.0.7.255

because:

255.255.255.255
-
255.255.248.0
----------------
0.0.7.255

Therefore:

140.80.24.0 0.0.7.255

represents the entire CCF subnet:

140.80.24.0
through
140.80.31.255

with usable hosts:

140.80.24.1
through
140.80.31.254

42. Why We Used host for the Server

The ACL contains:

host 140.80.120.7

This means:

Match exactly one destination IP address.

We do not want to block the entire server subnet.

If we used:

140.80.120.0 0.0.7.255

we would potentially block web access to all servers in that subnet.

The requirement is only about one particular server.

Therefore:

host 140.80.120.7

is appropriate.


43. Why We Used eq 80

The command:

eq 80

means:

equal to destination port 80

Port 80 is HTTP.

Similarly:

eq 443

means HTTPS.

Thus:

deny tcp ... host 140.80.120.7 eq 80

means:

Block TCP traffic from CCF to the hackathon server when the destination port is 80.


44. Why We Did Not Use deny ip

Consider this ACL:

deny ip 140.80.24.0 0.0.7.255 host 140.80.120.7

This would block all IP traffic from CCF to the server.

That would potentially prevent:

HTTP
HTTPS
FTP
ICMP
DNS
SSH
etc.

But the problem specifically says:

Other services must not be denied.

Therefore, deny ip is not appropriate.

The correct approach is to use:

deny tcp ... eq 80
deny tcp ... eq 443
permit ip any any

45. Observation Table

Students should complete this table.

TestProtocol/Port    Expected Result    Actual Result
PC0 → Server pingICMP    Allowed    ______
PC1 → Server pingICMP    Allowed    ______
PC2 → Server pingICMP    Allowed        ______
PC0 → Server HTTPTCP/80    Blocked    ______
PC1 → Server HTTPTCP/80    Blocked    ______
PC2 → Server HTTPTCP/80    Blocked    ______
PC0 → Server HTTPSTCP/443    Blocked    ______
PC0 → Server FTPTCP/21    Allowed    ______

46. Before and After ACL

This comparison is useful for students.

ServiceBefore ACLAfter ACL
PingAllowedAllowed
HTTPAllowedBlocked
HTTPSAllowedBlocked
FTPAllowedAllowed
Other IP trafficAllowedAllowed

Therefore, the ACL achieves the required objective.


47. Troubleshooting Exercise

Task 27: Check What Happens if the ACL Is Removed

Remove the ACL from G0/0:

configure terminal
interface gigabitEthernet 0/0
no ip access-group CCF_WEB_BLOCK in
exit
end

Now test:

http://140.80.120.7

The website should become accessible again.

This demonstrates that the ACL was responsible for blocking the web traffic.

Reapply it:

configure terminal
interface gigabitEthernet 0/0
ip access-group CCF_WEB_BLOCK in
exit
end

Test again.

The website should again be blocked.


48. Task 28: Save the Configuration

Once the experiment is working:

copy running-config startup-config

Press Enter when prompted.


49. Important Commands Used

PurposeCommand
Enter privileged mode    enable
Enter global configuration    configure terminal
Create extended ACL    ip access-list extended NAME
Deny HTTP    deny tcp SOURCE DESTINATION eq 80
Deny HTTPS    deny tcp SOURCE DESTINATION eq 443
Permit other traffic    permit ip any any
Apply ACL    ip access-group NAME in
View ACL    show access-lists
View interface ACL    show ip interface
Test connectivity    ping IP
Save configuration    copy running-config startup-config

50. Result

The college network was subnetted using a /21 subnet mask to create 32 subnets. The CCF was identified as the 4th subnet, 140.80.24.0/21, and the hackathon server was assigned the 7th usable host address of the 16th subnet, 140.80.120.7. An extended ACL was configured on the router to block HTTP and HTTPS traffic from the CCF subnet to the hackathon server. Other services, including ICMP and FTP, were permitted, thereby satisfying the requirement to block only website access.

Comments

Popular posts from this blog

Networks Lab PCCSL507 Semester 5 KTU CS 2024 Scheme - Dr Binu V P

Study of whois Command

Study and Use of ifconfig Command