Configuring a Standard ACL to Restrict Access to a Specific IP Address

 

Experiment: Configuring a Standard ACL to Restrict Access to a Specific IP Address

The experiment will block one specific PC from accessing another network while allowing other PCs to access it.


1. Aim

To configure a standard IPv4 Access Control List (ACL) on a Cisco router using Packet Tracer to restrict a specific IP address from accessing a destination network.


2. Objectives

After completing this experiment, students will be able to:

  1. Understand the purpose of an ACL.
  2. Configure a standard ACL on a Cisco router.
  3. Deny traffic from a specific source IP address.
  4. Permit traffic from other IP addresses.
  5. Apply an ACL to a router interface.
  6. Verify an ACL using show access-lists.
  7. Test the ACL using ping.
  8. Understand the concept of implicit deny.

3. Theory

What is an ACL?

An Access Control List (ACL) is a collection of rules configured on a router to control network traffic.

An ACL can be used to:

  • Permit traffic
  • Deny traffic
  • Restrict specific hosts
  • Restrict specific networks
  • Control access to services
  • Improve network security

For this first experiment, we will use a standard ACL.

Standard ACL

A standard ACL makes decisions based primarily on the source IP address.

For example:

access-list 10 deny host 192.168.1.20

means:

Deny traffic coming from 192.168.1.20.

And:

access-list 10 permit any

means:

Allow traffic from all other sources.


4. Network Topology

We will use the following simple topology:

                    Router0
                  ┌─────────┐
                  │  2911   │
                  └────┬────┘
                       │
          ┌────────────┴────────────┐
          │                         │
        G0/0                       G0/1
          │                         │
      192.168.1.1              192.168.2.1
          │                         │
       Switch0                  Switch1
       /     \                     |
      /       \                    |
    PC0       PC1                 PC2
    .10       .20                  .10

We want to achieve:

PC0  ─────────────→ PC2    ALLOW
PC1  ─────────────→ PC2    DENY

Policy

PC1 should not be allowed to access PC2, while PC0 should continue to have access to PC2.


5. IP Addressing Scheme

We will use two IPv4 networks.

LAN 1

192.168.1.0/24

LAN 2

192.168.2.0/24
Device    InterfaceIP Address    Subnet MaskGateway
Router0    G0/0192.168.1.1    255.255.255.0        —
PC0    NIC192.168.1.10    255.255.255.0    192.168.1.1
PC1    NIC192.168.1.20    255.255.255.0    192.168.1.1
Router0    G0/1192.168.2.1    255.255.255.0        —
PC2    NIC192.168.2.10    255.255.255.0    192.168.2.1

6. Devices Required

DeviceQuantity
Cisco 2911 Router    1
Cisco 2960 Switch    2
PC-PT    3
Copper Straight-Through Cable    5

7. Construct the Network

In Cisco Packet Tracer, place:

  • 1 × Router0
  • 2 × Switches
  • 3 × PCs

Connect:

PC0 ── Switch0 ──┐
                 │
PC1 ── Switch0 ──┤
                 │
               G0/0
              Router0
               G0/1
                 │
              Switch1
                 │
                PC2




8. Configure Router0

Open:

Router0 → CLI

Enter:

enable
configure terminal

Task 1 – Configure G0/0

interface gigabitEthernet 0/0
ip address 192.168.1.1 255.255.255.0
no shutdown
exit

Task 2 – Configure G0/1

interface gigabitEthernet 0/1
ip address 192.168.2.1 255.255.255.0
no shutdown
exit

Task 3 – Save the configuration

end
copy running-config startup-config

Press Enter when prompted.


9. Configure PC0

Go to:

PC0 → Desktop → IP Configuration

Enter:

IP Address:
192.168.1.10

Subnet Mask:
255.255.255.0

Default Gateway:
192.168.1.1

10. Configure PC1

Go to:

PC1 → Desktop → IP Configuration

Enter:

IP Address:
192.168.1.20

Subnet Mask:
255.255.255.0

Default Gateway:
192.168.1.1

11. Configure PC2

Go to:

PC2 → Desktop → IP Configuration

Enter:

IP Address:
192.168.2.10

Subnet Mask:
255.255.255.0

Default Gateway:
192.168.2.1

12. Test the Network Before Applying ACL

This is an important step.

Before configuring the ACL, make sure that all PCs can communicate.

Test PC0 → PC2

On PC0:

Desktop → Command Prompt

ping 192.168.2.10

Expected:

Reply from 192.168.2.10

Test PC1 → PC2

On PC1:

ping 192.168.2.10

Expected:

Reply from 192.168.2.10

At this stage:

PC0 → PC2     ALLOWED
PC1 → PC2     ALLOWED

This confirms that the basic network is working before the ACL is introduced.


13. Create the ACL

Now we will create an ACL that blocks:

192.168.1.20

which is the address of PC1.

The ACL will allow all other source addresses.


14. Configure Standard ACL

On Router0:

enable
configure terminal

Enter:

access-list 10 deny host 192.168.1.20

This means:

Deny traffic originating from PC1.

Now enter:

access-list 10 permit any

This means:

Permit all other source addresses.

The complete ACL is:

access-list 10 deny host 192.168.1.20
access-list 10 permit any

15. Apply the ACL to the Interface

We want to restrict access towards the second LAN.

Therefore, apply the ACL to the interface connected to LAN 2.

That is:

G0/1

We will apply it in the outbound direction.

Enter:

interface gigabitEthernet 0/1
ip access-group 10 out
exit

Then:

end

Save:

copy running-config startup-config

16. Understand Where the ACL Is Applied

The packet from PC1 travels:

PC1
 ↓
Switch0
 ↓
R0 G0/0
 ↓
R0 G0/1
 ↓
Switch1
 ↓
PC2

The ACL is applied:

                 ACL 10
                   ↓
PC1 → R0 G0/0 → R0 G0/1 → PC2
                   OUT

Therefore, when the packet is about to leave R0 through G0/1, the router checks ACL 10.

Since PC1's source address is:

192.168.1.20

the first rule matches:

deny host 192.168.1.20

and the packet is dropped.


17. Test the ACL

Test 1 – PC1 → PC2

From PC1:

ping 192.168.2.10

The ping should now fail.

You may see:

Request timed out.

or:

Destination host unreachable.

The important result is:

PC1 → PC2 = BLOCKED

18. Test PC0 → PC2

Now go to PC0:

ping 192.168.2.10

This should still succeed.

PC0 → PC2 = ALLOWED

This demonstrates that the ACL is blocking only PC1, not the entire LAN.


19. Test PC0 → PC1

PC0 and PC1 are on the same LAN:

192.168.1.0/24

Try:

ping 192.168.1.20

This should succeed.

Why?

Because the packet between PC0 and PC1 does not pass through Router0. Therefore, the ACL on Router0 G0/1 does not affect it.

This is an important observation for students.


20. Test PC1 → Router0

From PC1:

ping 192.168.1.1

This should normally succeed because the ACL was applied outbound on G0/1, not inbound on G0/0.

This helps students understand that an ACL affects traffic according to where and in which direction it is applied.


21. Verify the ACL

On Router0:

show access-lists

You should see something similar to:

Standard IP access list 10
    10 deny host 192.168.1.20
    20 permit any

You may also see packet counters, for example:

10 deny host 192.168.1.20 (5 matches)
20 permit any (5 matches)

The match counts increase as traffic passes through the ACL.


22. Check the Interface Configuration

Use:

show ip interface gigabitEthernet 0/1

Look for:

Outgoing access list is 10

This confirms that ACL 10 has been applied outbound on G0/1.


23. Understand the permit any

Students must understand why we used:

access-list 10 permit any

Suppose we only configured:

access-list 10 deny host 192.168.1.20

Cisco ACLs have an implicit deny all at the end.

Conceptually, the ACL would be:

deny 192.168.1.20
deny everything else

Therefore, PC0 would also be blocked.

By adding:

permit any

we get:

PC1       → DENY
Everything else → PERMIT

This is a very important ACL concept.


24. ACL Processing Order

Cisco processes ACL entries from top to bottom.

Our ACL is:

access-list 10 deny host 192.168.1.20
access-list 10 permit any

For a packet from PC1:

Source = 192.168.1.20
        ↓
First rule matches
        ↓
DENY

For a packet from PC0:

Source = 192.168.1.10
        ↓
First rule does not match
        ↓
Second rule matches
        ↓
PERMIT

25. Observation Table

Students can record their observations:

TestSourceDestination    Expected ResultActual Result
1PC0PC2    Permit
2PC1PC2    Deny
3PC0PC1    Permit
4PC1Router0 G0/0    Permit
5PC0Router0 G0/1    Permit

26. Complete ACL Configuration

For student reference:

enable
configure terminal

access-list 10 deny host 192.168.1.20
access-list 10 permit any

interface gigabitEthernet 0/1
ip access-group 10 out
exit

end
copy running-config startup-config

27. Removing the ACL

If students want to remove the ACL from the interface:

configure terminal
interface gigabitEthernet 0/1
no ip access-group 10 out
exit

To delete the ACL itself:

no access-list 10

After removing it, test again:

PC1 → PC2

The ping should work again.

This is a useful demonstration of the effect of the ACL.


28. Alternative: Use a Named Standard ACL

For teaching, I actually recommend introducing named ACLs after students understand numbered ACLs.

Instead of:

access-list 10 deny host 192.168.1.20
access-list 10 permit any

we can use:

ip access-list standard BLOCK_PC1
deny host 192.168.1.20
permit any
exit

Then:

interface gigabitEthernet 0/1
ip access-group BLOCK_PC1 out
exit

The advantage is that:

BLOCK_PC1

is much easier for students and administrators to understand than:

ACL 10

For your first ACL laboratory, however, I suggest students first learn the numbered standard ACL.


29. Troubleshooting

Problem 1: PC0 is also blocked

Check whether you entered:

access-list 10 permit any

Without this statement, the implicit deny will block all other traffic.


Problem 2: PC1 can still access PC2

Check:

show access-lists

and:

show ip interface gigabitEthernet 0/1

Make sure you see:

Outgoing access list is 10

Also verify that PC1 really has:

192.168.1.20

Problem 3: ACL is applied in the wrong direction

Our topology uses:

ip access-group 10 out

on:

G0/1

If you instead apply it to G0/0 inbound, the behavior is different.

This is why students should always identify:

  1. Where the traffic enters the router
  2. Where it leaves the router
  3. Whether the ACL should be applied inbound or outbound

30. Important ACL Rule

Students should remember:

Standard ACLs examine the source IP address.

For this experiment:

PC1
192.168.1.20

is the source that we want to block.

Therefore:

deny host 192.168.1.20

is sufficient.


31. Result

A standard IPv4 ACL was successfully configured on Router0 in Cisco Packet Tracer to restrict PC1 (192.168.1.20) from accessing PC2 (192.168.2.10). Access from PC0 was permitted, demonstrating selective traffic control using a standard ACL. The ACL operation was verified using show access-lists, show ip interface, and connectivity tests.

Comments

Popular posts from this blog

Networks Lab PCCSL507 Semester 5 KTU CS 2024 Scheme - Dr Binu V P

Study of whois Command

Study and Use of ifconfig Command