5.5.1 Packet Tracer - IPv4 ACL Implementation Challenge (Instructor Version)
Instructor Note: Red font color or gray highlights indicate text that appears in the instructor copy only.

5.5.1 Packet Tracer - IPv4 ACL Implementation Challenge
Addressing Table
| Device | Interface | IP Address |
|---|---|---|
| HQ | G0/0/0 | 192.168.1.1/26 |
| G0/0/1 | 192.168.1.65/29 | |
| S0/1/0 | 192.0.2.1/30 | |
| S0/1/1 | 192.168.3.1/30 | |
| Branch | G0/0/0 | 192.168.2.1/27 |
| G0/0/1 | 192.168.2.33/28 | |
| S0/1/1 | 192.168.3.2/30 | |
| PC-1 | NIC | 192.168.1.10/26 |
| PC-2 | NIC | 192.168.1.20/26 |
| PC-3 | NIC | 192.168.1.30/26 |
| Admin | NIC | 192.168.1.67/29 |
| Enterprise Web Server | NIC | 192.168.1.70/29 |
| Branch PC | NIC | 192.168.2.17/27 |
| Branch Server | NIC | 192.168.2.45/28 |
| Internet User | NIC | 198.51.100.218/24 |
| External Web Server | NIC | 203.0.113.73/24 |
Objectives
- Configure a router with standard named ACLs.
- Configure a router with extended named ACLs.
- Configure a router with extended ACLs to meet specific communication requirements.
- Configure an ACL to control access to network device terminal lines.
- Configure the appropriate router interfaces with ACLs in the appropriate direction.
- Verify the operation of the configured ACLs.
Background / Scenario
In this activity you will configure extended, standard named, and extended named ACLs to meet specified communication requirements.
Instructions
Step 1: Verify Connectivity in the New Company Network
First, test connectivity on the network as it is before configuring the ACLs. All hosts should be able to ping all other hosts.
Step 2: Configure Standard and Extended ACLs per Requirements.
Configure ACLs to meet the following requirements:
Important guidelines:
- Do not use explicit deny any statements at the end of your ACLs.
- Use shorthand (host and any) whenever possible.
- Write your ACL statements to address the requirements in the order that they are specified here.
- Place your ACLs in the most efficient location and direction.
ACL 1 Requirements
- Create ACL 101.
- Explicitly block FTP access to the Enterprise Web Server from the internet.
- No ICMP traffic from the internet should be allowed to any hosts on HQ LAN 1
- Allow all other traffic.
HQ(config)#access-list 101 deny tcp any host 192.168.1.70 eq ftp
HQ(config)#access-list 101 deny icmp any 192.168.1.0 0.0.0.63
HQ(config)#access-list 101 permit ip any any
HQ(config)#interface Serial0/1/0
HQ(config-if)#ip access-group 101 inACL 2 Requirements
- Use ACL number 111
- No hosts on HQ LAN 1 should be able to access the Branch Server.
- All other traffic should be permitted.
HQ(config)#access-list 111 deny ip any host 192.168.2.45
HQ(config)#access-list 111 permit ip any any
HQ(config)#interface GigabitEthernet0/0/0
HQ(config-if)#ip access-group 111 inACL 3: Requirements
- Create a named standard ACL. Use the name vty_block. The name of your ACL must match this name exactly.
- Only addresses from the HQ LAN 2 network should be able to access the VTY lines of the HQ router.
HQ(config)#ip access-list standard vty_block
HQ(config-std-nacl)#permit 192.168.1.64 0.0.0.7
HQ(config-std-nacl)#line vty 0 4
HQ(config-line)#access-class vty_block inACL 4: Requirements
- Create a named extended ACL called branch_to_hq. The name of your ACL must match this name exactly.
- No hosts on either of the Branch LANs should be allowed to access HQ LAN 1. Use one access list statement for each of the Branch LANs.
- All other traffic should be allowed.
Branch(config)#ip access-list extended branch_to_hq
Branch(config-ext-nacl)#deny ip 192.168.2.0 0.0.0.31 192.168.1.0 0.0.0.63
Branch(config-ext-nacl)#deny ip 192.168.2.32 0.0.0.15 192.168.1.0 0.0.0.63
Branch(config-ext-nacl)#permit ip any any
Branch(config-ext-nacl)#interface Serial0/1/1
Branch(config-if)#ip access-group branch_to_hq outStep 3: Verify ACL Operation.
a. Perform the following connectivity tests between devices in the topology. Note whether or not they are successful.
Note: Use the show ip access-lists command to verify ACL operation. Use the clear access list counters command to reset the match counters.
Send a ping request from Branch PC to the Enterprise Web Server. Was it successful? Explain.
Which ACL statement permitted or denied the ping between these two devices? List the access list name or number, the router on which it was applied, and the specific line that the traffic matched.
Attempt to ping from PC-1 on the HQ LAN 1 to the Branch Server. Was it successful? Explain.
Which ACL statement permitted or denied the ping between these two devices?
Open a web browser on the External Server and attempt to bring up a web page stored on the Enterprise Web Server. Is it successful? Explain.
Which ACL statement permitted or denied the ping between these two devices?
b. Test connections to an internal server from the internet.
From the command line on the Internet User PC, attempt to make an FTP connection to the Branch Server. Is the FTP connection successful?
Which access list should be modified to prevent users from the Internet to make FTP connections to the Branch Server?
Which statement(s) should be added to the access list to deny this traffic?
Device Configs - Final
Router HQ
! ============================================================== !--- 5.5.1 Packet Tracer - IPv4 ACL Implementation Challenge !--- ANSWER SCRIPT FOR ROUTER HQ !--- Usage: from the console (or CLI tab) on HQ, enter privileged EXEC mode with "enable", !--- then paste this whole file. Every line beginning with "!" is a comment; IOS ignores it. !--- Per this lab's own guidelines: no explicit "deny any" at the end of any ACL (rely on !--- the implicit one), use "host"/"any" shorthand wherever the traffic is a single address, !--- and place each ACL on the most efficient interface/direction (closest to the source !--- of the traffic each ACL is meant to catch). ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- ACL 101 requirements: block FTP to the Enterprise Web Server from the internet; block !--- all ICMP from the internet to HQ LAN 1; allow everything else. Placed inbound on !--- Serial0/1/0 - the interface closest to "the internet", the source of both rules. ! -------------------------------------------------------------- access-list 101 deny tcp any host 192.168.1.70 eq ftp access-list 101 deny icmp any 192.168.1.0 0.0.0.63 access-list 101 permit ip any any ! -------------------------------------------------------------- !--- ACL 111 requirements: no host on HQ LAN 1 may reach the Branch Server; allow everything !--- else. Placed inbound on GigabitEthernet0/0/0 - HQ LAN 1's own interface, the closest !--- possible point to the source of this traffic. ! -------------------------------------------------------------- access-list 111 deny ip any host 192.168.2.45 access-list 111 permit ip any any ! -------------------------------------------------------------- !--- ACL 3 requirements: named standard ACL "vty_block" - only HQ LAN 2 (192.168.1.64/29, !--- the Admin/Enterprise-Server network) may reach the router's own VTY lines. ! -------------------------------------------------------------- ip access-list standard vty_block permit 192.168.1.64 0.0.0.7 ! -------------------------------------------------------------- !--- Apply ACL 111 inbound on HQ LAN 1's own interface. ! -------------------------------------------------------------- interface GigabitEthernet0/0/0 ip access-group 111 in exit ! -------------------------------------------------------------- !--- Apply ACL 101 inbound on the internet-facing interface. ! -------------------------------------------------------------- interface Serial0/1/0 ip access-group 101 in exit ! -------------------------------------------------------------- !--- Standard ACLs controlling terminal access use "access-class", not "ip access-group". ! -------------------------------------------------------------- line vty 0 4 access-class vty_block in end ! ============================================================== !--- Verification (from HQ and the hosts): !--- HQ# show ip access-lists -> confirms ACL 101, 111, and vty_block, each with the two !--- or three lines above (no explicit deny lines - implicit deny is relied on throughout) !--- External Web Server > browse to 192.168.1.70 (Enterprise Web Server) -> succeeds !--- (matches ACL 101's final "permit ip any any" - only FTP and ICMP are blocked) !--- Internet User > ftp to 192.168.1.70 -> fails !--- Internet User > ping any host on HQ LAN 1 (192.168.1.0/26) -> fails !--- PC-1 (HQ LAN 1) > ping 192.168.2.45 (Branch Server) -> fails (matches !--- ACL 111 line 10 on HQ) !--- Only hosts on 192.168.1.64/29 (Admin, Enterprise Web Server) can Telnet/SSH into HQ !--- !--- Follow-up question in the lab (not part of the graded ACL 1-4 requirements above): !--- the Internet User can still FTP into the Branch Server successfully, because nothing !--- above blocks it. The lab's own suggested fix is to extend ACL 101 with: !--- access-list 101 deny tcp any host 192.168.2.45 eq 21 !--- placed BEFORE the existing "permit ip any any" line (so it would need re-entering as !--- a numbered/sequenced insert, or the whole ACL rebuilt in the right order) - left out !--- of the base script above since it's presented as a discussion question, not one of !--- the four required ACLs. ! ==============================================================
Router Branch
! ============================================================== !--- 5.5.1 Packet Tracer - IPv4 ACL Implementation Challenge !--- ANSWER SCRIPT FOR ROUTER BRANCH !--- Usage: from the console (or CLI tab) on Branch, enter privileged EXEC mode with !--- "enable", then paste this whole file. Every line beginning with "!" is a comment; IOS !--- ignores it. !--- Branch's own interfaces are G0/0/0 (192.168.2.1/27, Branch LAN 1), G0/0/1 !--- (192.168.2.33/28, Branch LAN 2), and S0/1/1 (192.168.3.2/30, the link to HQ). ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- ACL 4 requirements: named extended ACL "branch_to_hq" - neither Branch LAN may reach !--- HQ LAN 1 (192.168.1.0/26); allow everything else, including access to HQ's other !--- network (Admin/Enterprise Web Server, 192.168.1.64/29 - a different subnet, untouched !--- by these two rules). ! -------------------------------------------------------------- ip access-list extended branch_to_hq deny ip 192.168.2.0 0.0.0.31 192.168.1.0 0.0.0.63 deny ip 192.168.2.32 0.0.0.15 192.168.1.0 0.0.0.63 permit ip any any ! -------------------------------------------------------------- !--- Applied OUTBOUND on the WAN link to HQ (Serial0/1/1), not inbound on each Branch LAN !--- interface separately - this single choke point is the most efficient place to catch !--- traffic sourced from EITHER Branch LAN on its way to HQ, since one ACL already covers !--- both source networks with its two deny lines. ! -------------------------------------------------------------- interface Serial0/1/1 ip access-group branch_to_hq out end ! ============================================================== !--- Verification (from Branch and the hosts): !--- Branch# show ip access-lists -> confirms branch_to_hq's two deny lines plus the !--- trailing permit (no explicit deny any - implicit deny relied on) !--- Branch PC > ping 192.168.1.70 (Enterprise Web Server, on HQ LAN 2) -> succeeds !--- (EntServer is on 192.168.1.64/29, NOT part of the 192.168.1.0/26 HQ LAN 1 range these !--- deny lines target, so it falls through to the final "permit ip any any") !--- Branch PC > ping any host on 192.168.1.0/26 (HQ LAN 1) -> fails !--- Branch Server > ping any host on 192.168.1.0/26 (HQ LAN 1) -> fails ! ==============================================================




