Configuring a Standard ACL to Restrict Access to a Specific IP Address
Experiment: Configuring a Standard ACL to Restrict Access to a Specific IP Address
The experiment will block one specific PC from accessing another network while allowing other PCs to access it.
1. Aim
To configure a standard IPv4 Access Control List (ACL) on a Cisco router using Packet Tracer to restrict a specific IP address from accessing a destination network.
2. Objectives
After completing this experiment, students will be able to:
- Understand the purpose of an ACL.
- Configure a standard ACL on a Cisco router.
- Deny traffic from a specific source IP address.
- Permit traffic from other IP addresses.
- Apply an ACL to a router interface.
-
Verify an ACL using
show access-lists. -
Test the ACL using
ping. - Understand the concept of implicit deny.
3. Theory
What is an ACL?
An Access Control List (ACL) is a collection of rules configured on a router to control network traffic.
An ACL can be used to:
- Permit traffic
- Deny traffic
- Restrict specific hosts
- Restrict specific networks
- Control access to services
- Improve network security
For this first experiment, we will use a standard ACL.
Standard ACL
A standard ACL makes decisions based primarily on the source IP address.
For example:
access-list 10 deny host 192.168.1.20
means:
Deny traffic coming from
192.168.1.20.
And:
access-list 10 permit any
means:
Allow traffic from all other sources.
4. Network Topology
We will use the following simple topology:
Router0 ┌─────────┐ │ 2911 │ └────┬────┘ │ ┌────────────┴────────────┐ │ │ G0/0 G0/1 │ │ 192.168.1.1 192.168.2.1 │ │ Switch0 Switch1 / \ | / \ | PC0 PC1 PC2 .10 .20 .10
We want to achieve:
PC0 ─────────────→ PC2 ALLOW PC1 ─────────────→ PC2 DENY
Policy
PC1 should not be allowed to access PC2, while PC0 should continue to have access to PC2.
5. IP Addressing Scheme
We will use two IPv4 networks.
LAN 1
192.168.1.0/24
LAN 2
192.168.2.0/24
| Device | Interface | IP Address | Subnet Mask | Gateway |
|---|---|---|---|---|
| Router0 | G0/0 | 192.168.1.1 | 255.255.255.0 | — |
| PC0 | NIC | 192.168.1.10 | 255.255.255.0 | 192.168.1.1 |
| PC1 | NIC | 192.168.1.20 | 255.255.255.0 | 192.168.1.1 |
| Router0 | G0/1 | 192.168.2.1 | 255.255.255.0 | — |
| PC2 | NIC | 192.168.2.10 | 255.255.255.0 | 192.168.2.1 |
6. Devices Required
| Device | Quantity |
|---|---|
| Cisco 2911 Router | 1 |
| Cisco 2960 Switch | 2 |
| PC-PT | 3 |
| Copper Straight-Through Cable | 5 |
7. Construct the Network
In Cisco Packet Tracer, place:
- 1 × Router0
- 2 × Switches
- 3 × PCs
Connect:
8. Configure Router0
Open:
Router0 → CLI
Enter:
enable configure terminal
Task 1 – Configure G0/0
interface gigabitEthernet 0/0 ip address 192.168.1.1 255.255.255.0 no shutdown exit
Task 2 – Configure G0/1
interface gigabitEthernet 0/1 ip address 192.168.2.1 255.255.255.0 no shutdown exit
Task 3 – Save the configuration
end copy running-config startup-config
Press Enter when prompted.
9. Configure PC0
Go to:
PC0 → Desktop → IP Configuration
Enter:
IP Address: 192.168.1.10 Subnet Mask: 255.255.255.0 Default Gateway: 192.168.1.1
10. Configure PC1
Go to:
PC1 → Desktop → IP Configuration
Enter:
IP Address: 192.168.1.20 Subnet Mask: 255.255.255.0 Default Gateway: 192.168.1.1
11. Configure PC2
Go to:
PC2 → Desktop → IP Configuration
Enter:
IP Address: 192.168.2.10 Subnet Mask: 255.255.255.0 Default Gateway: 192.168.2.1
12. Test the Network Before Applying ACL
This is an important step.
Before configuring the ACL, make sure that all PCs can communicate.
Test PC0 → PC2
On PC0:
Desktop → Command Prompt
ping 192.168.2.10
Expected:
Reply from 192.168.2.10
Test PC1 → PC2
On PC1:
ping 192.168.2.10
Expected:
Reply from 192.168.2.10
At this stage:
PC0 → PC2 ALLOWED PC1 → PC2 ALLOWED
This confirms that the basic network is working before the ACL is introduced.
13. Create the ACL
Now we will create an ACL that blocks:
192.168.1.20
which is the address of PC1.
The ACL will allow all other source addresses.
14. Configure Standard ACL
On Router0:
enable configure terminal
Enter:
access-list 10 deny host 192.168.1.20
This means:
Deny traffic originating from PC1.
Now enter:
access-list 10 permit any
This means:
Permit all other source addresses.
The complete ACL is:
access-list 10 deny host 192.168.1.20 access-list 10 permit any
15. Apply the ACL to the Interface
We want to restrict access towards the second LAN.
Therefore, apply the ACL to the interface connected to LAN 2.
That is:
G0/1
We will apply it in the outbound direction.
Enter:
interface gigabitEthernet 0/1 ip access-group 10 out exit
Then:
end
Save:
copy running-config startup-config
16. Understand Where the ACL Is Applied
The packet from PC1 travels:
PC1 ↓ Switch0 ↓ R0 G0/0 ↓ R0 G0/1 ↓ Switch1 ↓ PC2
The ACL is applied:
ACL 10 ↓ PC1 → R0 G0/0 → R0 G0/1 → PC2 OUT
Therefore, when the packet is about to leave R0 through G0/1, the router checks ACL 10.
Since PC1's source address is:
192.168.1.20
the first rule matches:
deny host 192.168.1.20
and the packet is dropped.
17. Test the ACL
Test 1 – PC1 → PC2
From PC1:
ping 192.168.2.10
The ping should now fail.
You may see:
Request timed out.
or:
Destination host unreachable.
The important result is:
PC1 → PC2 = BLOCKED
18. Test PC0 → PC2
Now go to PC0:
ping 192.168.2.10
This should still succeed.
PC0 → PC2 = ALLOWED
This demonstrates that the ACL is blocking only PC1, not the entire LAN.
19. Test PC0 → PC1
PC0 and PC1 are on the same LAN:
192.168.1.0/24
Try:
ping 192.168.1.20
This should succeed.
Why?
Because the packet between PC0 and PC1 does not pass through Router0. Therefore, the ACL on Router0 G0/1 does not affect it.
This is an important observation for students.
20. Test PC1 → Router0
From PC1:
ping 192.168.1.1
This should normally succeed because the ACL was applied outbound on G0/1, not inbound on G0/0.
This helps students understand that an ACL affects traffic according to where and in which direction it is applied.
21. Verify the ACL
On Router0:
show access-lists
You should see something similar to:
Standard IP access list 10 10 deny host 192.168.1.20 20 permit any
You may also see packet counters, for example:
10 deny host 192.168.1.20 (5 matches) 20 permit any (5 matches)
The match counts increase as traffic passes through the ACL.
22. Check the Interface Configuration
Use:
show ip interface gigabitEthernet 0/1
Look for:
Outgoing access list is 10
This confirms that ACL 10 has been applied outbound on G0/1.
23. Understand the permit any
Students must understand why we used:
access-list 10 permit any
Suppose we only configured:
access-list 10 deny host 192.168.1.20
Cisco ACLs have an implicit deny all at the end.
Conceptually, the ACL would be:
deny 192.168.1.20 deny everything else
Therefore, PC0 would also be blocked.
By adding:
permit any
we get:
PC1 → DENY Everything else → PERMIT
This is a very important ACL concept.
24. ACL Processing Order
Cisco processes ACL entries from top to bottom.
Our ACL is:
access-list 10 deny host 192.168.1.20 access-list 10 permit any
For a packet from PC1:
Source = 192.168.1.20 ↓ First rule matches ↓ DENY
For a packet from PC0:
Source = 192.168.1.10 ↓ First rule does not match ↓ Second rule matches ↓ PERMIT
25. Observation Table
Students can record their observations:
| Test | Source | Destination | Expected Result | Actual Result |
|---|---|---|---|---|
| 1 | PC0 | PC2 | Permit | |
| 2 | PC1 | PC2 | Deny | |
| 3 | PC0 | PC1 | Permit | |
| 4 | PC1 | Router0 G0/0 | Permit | |
| 5 | PC0 | Router0 G0/1 | Permit |
26. Complete ACL Configuration
For student reference:
enable configure terminal access-list 10 deny host 192.168.1.20 access-list 10 permit any interface gigabitEthernet 0/1 ip access-group 10 out exit end copy running-config startup-config
27. Removing the ACL
If students want to remove the ACL from the interface:
configure terminal interface gigabitEthernet 0/1 no ip access-group 10 out exit
To delete the ACL itself:
no access-list 10
After removing it, test again:
PC1 → PC2
The ping should work again.
This is a useful demonstration of the effect of the ACL.
28. Alternative: Use a Named Standard ACL
For teaching, I actually recommend introducing named ACLs after students understand numbered ACLs.
Instead of:
access-list 10 deny host 192.168.1.20 access-list 10 permit any
we can use:
ip access-list standard BLOCK_PC1 deny host 192.168.1.20 permit any exit
Then:
interface gigabitEthernet 0/1 ip access-group BLOCK_PC1 out exit
The advantage is that:
BLOCK_PC1
is much easier for students and administrators to understand than:
ACL 10
For your first ACL laboratory, however, I suggest students first learn the numbered standard ACL.
29. Troubleshooting
Problem 1: PC0 is also blocked
Check whether you entered:
access-list 10 permit any
Without this statement, the implicit deny will block all other traffic.
Problem 2: PC1 can still access PC2
Check:
show access-lists
and:
show ip interface gigabitEthernet 0/1
Make sure you see:
Outgoing access list is 10
Also verify that PC1 really has:
192.168.1.20
Problem 3: ACL is applied in the wrong direction
Our topology uses:
ip access-group 10 out
on:
G0/1
If you instead apply it to G0/0 inbound, the behavior is different.
This is why students should always identify:
- Where the traffic enters the router
- Where it leaves the router
- Whether the ACL should be applied inbound or outbound
30. Important ACL Rule
Students should remember:
Standard ACLs examine the source IP address.
For this experiment:
PC1 192.168.1.20
is the source that we want to block.
Therefore:
deny host 192.168.1.20
is sufficient.
31. Result
A standard IPv4 ACL was successfully configured on Router0 in Cisco Packet Tracer to restrict PC1 (192.168.1.20) from accessing PC2 (192.168.2.10). Access from PC0 was permitted, demonstrating selective traffic control using a standard ACL. The ACL operation was verified using show access-lists, show ip interface, and connectivity tests.
Comments
Post a Comment