An Access Control List (ACL) is a sequential set of permit or deny statements (Access Control Entries - ACEs) applied to router interfaces to filter network traffic. ACLs inspect IP packet headers to permit authorized communications while blocking malicious or unwanted network traffic.
Standard vs Extended Access Control Lists
Standard ACLs (1–99, 1300–1999): Filters traffic based exclusively on Source IP Address. Should generally be placed as close to the destination as possible.
Extended ACLs (100–199, 2000–2699): Filters traffic based on Source IP, Destination IP, IP Protocol (TCP/UDP/ICMP), and Port Numbers (e.g., Port 80 HTTP, Port 443 HTTPS). Should be placed as close to the source as possible.
Critical ACL Rules & Processing Engine
Top-Down Execution: Routers evaluate packet headers sequentially against ACL rules starting from rule line 10 downward.
First Match Rule: Once a packet matches an ACE, processing stops immediately and the action (Permit or Deny) is taken.
Implicit Deny All: Every Cisco ACL ends with an invisible default rule: deny ip any any. If traffic does not match any explicit permit rule, it is dropped.
Inbound vs Outbound Interface Direction
Inbound ACLs: Packets are processed and filtered BEFORE the router performs routing table lookups.
Outbound ACLs: Packets are routed first, then filtered BEFORE being queued out the exit interface.
Where to Implement ACL Security?
Perimeter Network Firewalls: Restricting internet traffic entering local enterprise LANs.
VLAN & Subnet Segregation: Blocking unauthorized user subnets from accessing critical enterprise Database Servers.
Administrative VTY Line Security: Restricting SSH/Telnet management access exclusively to IT Admin workstations.