SlideShare a Scribd company logo
ACL Principle
V1.1
Objectives
Understand the basic function of ACL
Know when and how to use ACL
Contents
ACL conception and function
ACL types
ACL working principle
ACL rule
FDDI
172.16.0.0
172.17.0.0
Token
Ring
Internet
Why Use Access Lists?
Manage IP traffic as network access grows
Filter packets as they pass through the router
Access List Applications
Permit or deny packets moving through the
router
Permit or deny telnet access to or from the
router
Without access lists all packets could be
transmitted onto all parts of your network
telnet access (IP)
Transmission of packets on an interface
ACL Configuration Procedure
Define trigger condition
Define packet matching rules
Bind to interface or service
Packet outgoing
interfacePacket incoming
interface
ACL process
permit?
Source IP、
Destination IP
protocol
Contents
ACL conception and function
ACL types
ACL working principle
ACL rule
Dest Address
Source Address
Protocol
Port number
Segment Header
(TCP Header) Data
Packet Header
(IP Header )
Frame Header
(e.g. HDLC)
Use ACL to check
data
Deny Permit
ACL Types and Matching Conditions
Standard ACL
Use source address as filtering standard
Can generally restrict a kind of protocol
Extend ACL
Use five elements to filter packets
Can restrict a concrete protocol accurately
ACL Types and Matching Conditions
IPv6 ACL Command Structure
Command structure for standard ACL
Command structure for extend ACL
Contents
ACL conception and function
ACL types
ACL working principle
ACL rule
Inbound
Interface
Packets
N
Y
Packet Discard Bucket
Choose
Interface
NAccess
List
?
Routing
Table
Entry
?
Y
Outbound
Interface
Packets
S0
Outbound Access Lists
Outbound
Interface
Packets
N
Y
Packet Discard Bucket
Choose
Interface
Routing
Table
Entry
?
N
Packets
Test
Access List
Statements
Permit
?
Y
Outbound Access Lists
Access
List
?
Y
S0
E0
Inbound
Interface
Packets
Notify Sender
Outbound Access Lists
If no access list statement matches then discard the packet
N
Y
Packet Discard Bucket
Choose
Interface
Routing
Table
Entry
?
N
Y
Test
Access List
Statements
Permit
?
Y
Access
List
?
Discard Packet
N
Outbound
Interface
Packets
Packets
S0
E0
Inbound
Interface
Packets
Contents
ACL conception and function
ACL types
ACL working principle
ACL rule
A List of Tests: Deny or Permit
Packets to Interface(s)
in the access group
Packet
Discard
Bucket
Y
Interface(s)
Destination
Deny
Deny
Y
Match
First
Rule
?
Permit
A List of Tests: Deny or Permit
Packets to Interface(s)
in the Access Group
Packet
Discard
Bucket
Y
Interface(s)
Destination
Deny
Deny
Y
Match
First
Rule
?
Permit
N
Deny Permit
Match
Next
Rule(s)
?
YY
A List of Tests: Deny or Permit
Packets to Interface(s)
in the Access Group
Packet
Discard
Bucket
Y
Interface(s)
Destination
Deny
Deny
Y
Match
First
Rule
?
Permit
N
Deny Permit
Match
Next
Rule(s)
?
Deny
Match
Last
Rule
?
YY
N
YY
Permit
A List of Tests: Deny or Permit
Packets to Interface(s)
in the Access Group
Packet
Discard
Bucket
Y
Interface(s)
Destination
Deny
Y
Match
First
Rule
?
Permit
N
Deny Permit
Match
Next
Rule(s)
?
Deny
Match
Last
Rule
?
YY
N
YY
Permit
Implicit
Deny
If no match
deny all
Deny
N
ACL Rule Conclusion
Q:How to arrange
the sequence of rules
when configuring
ACL
ACL matching execute from top to bottom, if one statement
match the packets, it will execute the corresponding rule (permit
or deny) and then jump out of ACL.
There is an implicit rule “Deny all” at the end of each ACL.
ACL can be applied to inbound or outbound direction of a
concrete IP interface
ACL can be applied to a specific system service (e.g. Telnet
service on device)
Before applying ACL, we should create it
We can set only one ACL for a specific protocol on one direction
of an interface at one time
Where to apply ACL?
Standard ACL: near the destination
Extend ACL: near the source
E0
E0
E1
S0
To0
S1
S0
S1
E0
E0Token
Ring
BB
AA
DD
PC_A
PC_B
Content Review
ACL conception and usage
ACL working principle
ACL types
ACL rule
Questions
Where to place standard ACL in the network?
Where to place extend ACL?
What will be done to the packet if there are no
matches in the ACL?
How to arrange the sequence of rules when
configuring ACL?
What will happen if a data packet pass an
interface that no ACL is defined?
04 zxr10 bc-en-acl principle and configuration (acl principle)-1-ppt-201105 24

More Related Content

Similar to 04 zxr10 bc-en-acl principle and configuration (acl principle)-1-ppt-201105 24

Chapter 08 - Acl
Chapter 08 - AclChapter 08 - Acl
Chapter 08 - Aclphanleson
 
Access Control List & its Types
Access Control List & its TypesAccess Control List & its Types
Access Control List & its Types
Netwax Lab
 
Chapter10ccna
Chapter10ccnaChapter10ccna
Chapter10ccnarobertoxe
 
acl configuration
acl configurationacl configuration
acl configuration
RandyDookheran1
 
Modul 5 access control list
Modul 5 access control listModul 5 access control list
Modul 5 access control list
diah risqiwati
 
10 module
10  module10  module
10 moduleAsif
 
Network Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptxNetwork Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptx
Zalmaanabdi
 
Network Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptxNetwork Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptx
Zalmaanabdi
 
CCNP 642-732 Training
CCNP 642-732 TrainingCCNP 642-732 Training
CCNP 642-732 Training
saenaetr
 
5 ip security aaa and acl
5 ip security aaa and acl5 ip security aaa and acl
5 ip security aaa and acl
SagarR24
 
5 ip security dataplace security
5 ip security dataplace security5 ip security dataplace security
5 ip security dataplace security
SagarR24
 
Ip Access Lists
Ip Access ListsIp Access Lists
Ip Access Lists
CCNAResources
 
5 ip security ipsec gre
5 ip security ipsec gre5 ip security ipsec gre
5 ip security ipsec gre
SagarR24
 
Access Control List (ACL)
Access Control List (ACL)Access Control List (ACL)
Access Control List (ACL)
ISMT College
 
Uccn1003 -may09_-_lect09_-_access_control_list_acl_
Uccn1003  -may09_-_lect09_-_access_control_list_acl_Uccn1003  -may09_-_lect09_-_access_control_list_acl_
Uccn1003 -may09_-_lect09_-_access_control_list_acl_Shu Shin
 
Uccn1003 -may09_-_lect09_-_access_control_list_acl_
Uccn1003  -may09_-_lect09_-_access_control_list_acl_Uccn1003  -may09_-_lect09_-_access_control_list_acl_
Uccn1003 -may09_-_lect09_-_access_control_list_acl_Shu Shin
 
SwOS (MikroTik Switch OS) Administration Guide
SwOS (MikroTik Switch OS) Administration GuideSwOS (MikroTik Switch OS) Administration Guide
SwOS (MikroTik Switch OS) Administration Guide
Tũi Wichets
 

Similar to 04 zxr10 bc-en-acl principle and configuration (acl principle)-1-ppt-201105 24 (20)

Acl
AclAcl
Acl
 
Chapter 08 - Acl
Chapter 08 - AclChapter 08 - Acl
Chapter 08 - Acl
 
Access Control List & its Types
Access Control List & its TypesAccess Control List & its Types
Access Control List & its Types
 
Chapter10ccna
Chapter10ccnaChapter10ccna
Chapter10ccna
 
Chapter10ccna
Chapter10ccnaChapter10ccna
Chapter10ccna
 
acl configuration
acl configurationacl configuration
acl configuration
 
Modul 5 access control list
Modul 5 access control listModul 5 access control list
Modul 5 access control list
 
10 module
10  module10  module
10 module
 
CCNA Access Lists
CCNA Access ListsCCNA Access Lists
CCNA Access Lists
 
Network Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptxNetwork Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptx
 
Network Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptxNetwork Security p7 ACL with Established Option.pptx
Network Security p7 ACL with Established Option.pptx
 
CCNP 642-732 Training
CCNP 642-732 TrainingCCNP 642-732 Training
CCNP 642-732 Training
 
5 ip security aaa and acl
5 ip security aaa and acl5 ip security aaa and acl
5 ip security aaa and acl
 
5 ip security dataplace security
5 ip security dataplace security5 ip security dataplace security
5 ip security dataplace security
 
Ip Access Lists
Ip Access ListsIp Access Lists
Ip Access Lists
 
5 ip security ipsec gre
5 ip security ipsec gre5 ip security ipsec gre
5 ip security ipsec gre
 
Access Control List (ACL)
Access Control List (ACL)Access Control List (ACL)
Access Control List (ACL)
 
Uccn1003 -may09_-_lect09_-_access_control_list_acl_
Uccn1003  -may09_-_lect09_-_access_control_list_acl_Uccn1003  -may09_-_lect09_-_access_control_list_acl_
Uccn1003 -may09_-_lect09_-_access_control_list_acl_
 
Uccn1003 -may09_-_lect09_-_access_control_list_acl_
Uccn1003  -may09_-_lect09_-_access_control_list_acl_Uccn1003  -may09_-_lect09_-_access_control_list_acl_
Uccn1003 -may09_-_lect09_-_access_control_list_acl_
 
SwOS (MikroTik Switch OS) Administration Guide
SwOS (MikroTik Switch OS) Administration GuideSwOS (MikroTik Switch OS) Administration Guide
SwOS (MikroTik Switch OS) Administration Guide
 

Recently uploaded

6th International Conference on Machine Learning & Applications (CMLA 2024)
6th International Conference on Machine Learning & Applications (CMLA 2024)6th International Conference on Machine Learning & Applications (CMLA 2024)
6th International Conference on Machine Learning & Applications (CMLA 2024)
ClaraZara1
 
DfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributionsDfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributions
gestioneergodomus
 
AP LAB PPT.pdf ap lab ppt no title specific
AP LAB PPT.pdf ap lab ppt no title specificAP LAB PPT.pdf ap lab ppt no title specific
AP LAB PPT.pdf ap lab ppt no title specific
BrazilAccount1
 
Final project report on grocery store management system..pdf
Final project report on grocery store management system..pdfFinal project report on grocery store management system..pdf
Final project report on grocery store management system..pdf
Kamal Acharya
 
NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...
NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...
NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...
Amil Baba Dawood bangali
 
Water Industry Process Automation and Control Monthly - May 2024.pdf
Water Industry Process Automation and Control Monthly - May 2024.pdfWater Industry Process Automation and Control Monthly - May 2024.pdf
Water Industry Process Automation and Control Monthly - May 2024.pdf
Water Industry Process Automation & Control
 
Fundamentals of Electric Drives and its applications.pptx
Fundamentals of Electric Drives and its applications.pptxFundamentals of Electric Drives and its applications.pptx
Fundamentals of Electric Drives and its applications.pptx
manasideore6
 
CME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional ElectiveCME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional Elective
karthi keyan
 
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdfAKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
SamSarthak3
 
Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)
Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)
Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)
MdTanvirMahtab2
 
Recycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part IIIRecycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part III
Aditya Rajan Patra
 
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTSHeap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Soumen Santra
 
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdfTop 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Teleport Manpower Consultant
 
Tutorial for 16S rRNA Gene Analysis with QIIME2.pdf
Tutorial for 16S rRNA Gene Analysis with QIIME2.pdfTutorial for 16S rRNA Gene Analysis with QIIME2.pdf
Tutorial for 16S rRNA Gene Analysis with QIIME2.pdf
aqil azizi
 
Student information management system project report ii.pdf
Student information management system project report ii.pdfStudent information management system project report ii.pdf
Student information management system project report ii.pdf
Kamal Acharya
 
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
bakpo1
 
DESIGN A COTTON SEED SEPARATION MACHINE.docx
DESIGN A COTTON SEED SEPARATION MACHINE.docxDESIGN A COTTON SEED SEPARATION MACHINE.docx
DESIGN A COTTON SEED SEPARATION MACHINE.docx
FluxPrime1
 
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
obonagu
 
Hierarchical Digital Twin of a Naval Power System
Hierarchical Digital Twin of a Naval Power SystemHierarchical Digital Twin of a Naval Power System
Hierarchical Digital Twin of a Naval Power System
Kerry Sado
 
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Dr.Costas Sachpazis
 

Recently uploaded (20)

6th International Conference on Machine Learning & Applications (CMLA 2024)
6th International Conference on Machine Learning & Applications (CMLA 2024)6th International Conference on Machine Learning & Applications (CMLA 2024)
6th International Conference on Machine Learning & Applications (CMLA 2024)
 
DfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributionsDfMAy 2024 - key insights and contributions
DfMAy 2024 - key insights and contributions
 
AP LAB PPT.pdf ap lab ppt no title specific
AP LAB PPT.pdf ap lab ppt no title specificAP LAB PPT.pdf ap lab ppt no title specific
AP LAB PPT.pdf ap lab ppt no title specific
 
Final project report on grocery store management system..pdf
Final project report on grocery store management system..pdfFinal project report on grocery store management system..pdf
Final project report on grocery store management system..pdf
 
NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...
NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...
NO1 Uk best vashikaran specialist in delhi vashikaran baba near me online vas...
 
Water Industry Process Automation and Control Monthly - May 2024.pdf
Water Industry Process Automation and Control Monthly - May 2024.pdfWater Industry Process Automation and Control Monthly - May 2024.pdf
Water Industry Process Automation and Control Monthly - May 2024.pdf
 
Fundamentals of Electric Drives and its applications.pptx
Fundamentals of Electric Drives and its applications.pptxFundamentals of Electric Drives and its applications.pptx
Fundamentals of Electric Drives and its applications.pptx
 
CME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional ElectiveCME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional Elective
 
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdfAKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
 
Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)
Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)
Industrial Training at Shahjalal Fertilizer Company Limited (SFCL)
 
Recycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part IIIRecycled Concrete Aggregate in Construction Part III
Recycled Concrete Aggregate in Construction Part III
 
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTSHeap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
Heap Sort (SS).ppt FOR ENGINEERING GRADUATES, BCA, MCA, MTECH, BSC STUDENTS
 
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdfTop 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
 
Tutorial for 16S rRNA Gene Analysis with QIIME2.pdf
Tutorial for 16S rRNA Gene Analysis with QIIME2.pdfTutorial for 16S rRNA Gene Analysis with QIIME2.pdf
Tutorial for 16S rRNA Gene Analysis with QIIME2.pdf
 
Student information management system project report ii.pdf
Student information management system project report ii.pdfStudent information management system project report ii.pdf
Student information management system project report ii.pdf
 
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
 
DESIGN A COTTON SEED SEPARATION MACHINE.docx
DESIGN A COTTON SEED SEPARATION MACHINE.docxDESIGN A COTTON SEED SEPARATION MACHINE.docx
DESIGN A COTTON SEED SEPARATION MACHINE.docx
 
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
 
Hierarchical Digital Twin of a Naval Power System
Hierarchical Digital Twin of a Naval Power SystemHierarchical Digital Twin of a Naval Power System
Hierarchical Digital Twin of a Naval Power System
 
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
 

04 zxr10 bc-en-acl principle and configuration (acl principle)-1-ppt-201105 24

  • 2. Objectives Understand the basic function of ACL Know when and how to use ACL
  • 3. Contents ACL conception and function ACL types ACL working principle ACL rule
  • 4. FDDI 172.16.0.0 172.17.0.0 Token Ring Internet Why Use Access Lists? Manage IP traffic as network access grows Filter packets as they pass through the router
  • 5. Access List Applications Permit or deny packets moving through the router Permit or deny telnet access to or from the router Without access lists all packets could be transmitted onto all parts of your network telnet access (IP) Transmission of packets on an interface
  • 6. ACL Configuration Procedure Define trigger condition Define packet matching rules Bind to interface or service Packet outgoing interfacePacket incoming interface ACL process permit? Source IP、 Destination IP protocol
  • 7. Contents ACL conception and function ACL types ACL working principle ACL rule
  • 8. Dest Address Source Address Protocol Port number Segment Header (TCP Header) Data Packet Header (IP Header ) Frame Header (e.g. HDLC) Use ACL to check data Deny Permit ACL Types and Matching Conditions Standard ACL Use source address as filtering standard Can generally restrict a kind of protocol Extend ACL Use five elements to filter packets Can restrict a concrete protocol accurately
  • 9. ACL Types and Matching Conditions
  • 10. IPv6 ACL Command Structure Command structure for standard ACL Command structure for extend ACL
  • 11. Contents ACL conception and function ACL types ACL working principle ACL rule
  • 13. Outbound Interface Packets N Y Packet Discard Bucket Choose Interface Routing Table Entry ? N Packets Test Access List Statements Permit ? Y Outbound Access Lists Access List ? Y S0 E0 Inbound Interface Packets
  • 14. Notify Sender Outbound Access Lists If no access list statement matches then discard the packet N Y Packet Discard Bucket Choose Interface Routing Table Entry ? N Y Test Access List Statements Permit ? Y Access List ? Discard Packet N Outbound Interface Packets Packets S0 E0 Inbound Interface Packets
  • 15. Contents ACL conception and function ACL types ACL working principle ACL rule
  • 16. A List of Tests: Deny or Permit Packets to Interface(s) in the access group Packet Discard Bucket Y Interface(s) Destination Deny Deny Y Match First Rule ? Permit
  • 17. A List of Tests: Deny or Permit Packets to Interface(s) in the Access Group Packet Discard Bucket Y Interface(s) Destination Deny Deny Y Match First Rule ? Permit N Deny Permit Match Next Rule(s) ? YY
  • 18. A List of Tests: Deny or Permit Packets to Interface(s) in the Access Group Packet Discard Bucket Y Interface(s) Destination Deny Deny Y Match First Rule ? Permit N Deny Permit Match Next Rule(s) ? Deny Match Last Rule ? YY N YY Permit
  • 19. A List of Tests: Deny or Permit Packets to Interface(s) in the Access Group Packet Discard Bucket Y Interface(s) Destination Deny Y Match First Rule ? Permit N Deny Permit Match Next Rule(s) ? Deny Match Last Rule ? YY N YY Permit Implicit Deny If no match deny all Deny N
  • 20. ACL Rule Conclusion Q:How to arrange the sequence of rules when configuring ACL ACL matching execute from top to bottom, if one statement match the packets, it will execute the corresponding rule (permit or deny) and then jump out of ACL. There is an implicit rule “Deny all” at the end of each ACL. ACL can be applied to inbound or outbound direction of a concrete IP interface ACL can be applied to a specific system service (e.g. Telnet service on device) Before applying ACL, we should create it We can set only one ACL for a specific protocol on one direction of an interface at one time
  • 21. Where to apply ACL? Standard ACL: near the destination Extend ACL: near the source E0 E0 E1 S0 To0 S1 S0 S1 E0 E0Token Ring BB AA DD PC_A PC_B
  • 22. Content Review ACL conception and usage ACL working principle ACL types ACL rule
  • 23. Questions Where to place standard ACL in the network? Where to place extend ACL? What will be done to the packet if there are no matches in the ACL? How to arrange the sequence of rules when configuring ACL? What will happen if a data packet pass an interface that no ACL is defined?