Skip to main content
AD Academy
CCNA — Cisco Networking Fundamentals
Intermediate14 minLast updated: Topic 11 of 12

ACL: Standard vs. Extended and Rule Order

Where to place an access list, why order is critical, and what the implicit deny any is.

Not read

What you will learn here

  • Standard vs Extended ACLs
  • Why rule order matters
  • What the implicit deny any is

Worth reading first:OSPFv2: Router ID, Hello and DR/BDR

Analogy: An ACL is a security guard at the entrance with a list of names. He reads from top to bottom and stops at the first matching line — and whoever didn't appear on the list at all, simply doesn't enter.

The packet is checked top-down and the first matching line wins. Line 10 denies SMB from the guest network to the servers, line 20 permits HTTPS, line 30 permits DNS, and everything else is dropped by the implicit deny at the end. Standard ACLs match the source only and belong close to the destination; extended ACLs match address, protocol and port and belong close to the source.

Standard vs. Extended

  • Standard (1–99) — checks only source address. Place close to the destination, otherwise too much is blocked.
  • Extended (100–199) — checks source, destination, protocol, and port. Place close to the source to save unnecessary traffic.
  • Named ACL — names instead of numbers, allows editing by line numbers. Always recommended.
  • At the end of every ACL there is an implicit deny any — what is not explicitly permitted, is blocked.
  • One ACL per direction per interface (in / out) is possible.
! Extended ACL: Allow HTTPS and DNS, block SMB from guest network
Router(config)# ip access-list extended GUEST-IN
Router(config-ext-nacl)# 10 deny tcp 192.168.99.0 0.0.0.255 192.168.50.0 0.0.0.255 eq 445
Router(config-ext-nacl)# 20 permit tcp 192.168.99.0 0.0.0.255 any eq 443
Router(config-ext-nacl)# 30 permit udp 192.168.99.0 0.0.0.255 any eq 53
Router(config-ext-nacl)# 40 deny ip any any log
Router(config)# interface gi0/1
Router(config-if)# ip access-group GUEST-IN in

! Tests
Router# show access-lists
Router# show ip interface gi0/1 | include access list
bash
Architecture and theory — Under the hood

ACLs are checked line by line from top to bottom; once there is a match — the check stops. At the end of every ACL there is an implicit deny any that is not visible in the config.

Packet -> line 10 permit? -> match? YES -> PERMIT (stop)
                 |NO
             line 20 deny? ...
                 |NO
             [implicit deny any]  <-- Everything is dropped here
text
  • Standard (1-99): Filters only by source address — place close to the destination.
  • Wildcard Mask is the inverse of Subnet Mask: 0 = must match, 1 = don't care. /26 → 0.0.0.63, single host → 0.0.0.0, any address → any.
  • ACL on an interface only applies to traffic passing through the router (transit) — traffic generated by the router itself is not checked, so a ping from the router can succeed while users are blocked.
  • ACL on VTY protects access to equipment management.
Practical configuration (CLI)
! Extended named ACL
R(config)# ip access-list extended BRANCH-IN
R(config-ext-nacl)# 10 permit tcp 192.168.10.0 0.0.0.255 host 10.0.0.50 eq 443
R(config-ext-nacl)# 20 permit udp any host 10.0.0.10 eq 53
R(config-ext-nacl)# 30 deny ip 192.168.10.0 0.0.0.255 10.0.20.0 0.0.0.255 log
R(config-ext-nacl)# 40 permit ip any any
R(config)# interface gi0/0
R(config-if)# ip access-group BRANCH-IN in

! Management protection
R(config)# access-list 10 permit 192.168.99.0 0.0.0.255
R(config)# line vty 0 15
R(config-line)# access-class 10 in
bash
Real-world Scenarios in the Organization
  • Guest VLAN isolation: Internet allowed, internal network blocked.
  • Access to servers only from the management VLAN and only on required ports.
  • Blocking known problematic traffic (SMB between branches) to reduce ransomware spread.
Troubleshooting
R# show access-lists
R# show ip access-lists BRANCH-IN     ! matches counter for each line
R# show ip interface gi0/0 | include access list
R# clear access-list counters
bash
  • Everything is blocked → Forgot `permit` at the end, and the `implicit deny` caught everything.
  • The rule is not enforced → The ACL was not applied to the interface, or was applied in the opposite direction (in/out).
  • The line's counter remains 0 → Traffic does not reach it at all, or an earlier line caught it.
  • DNS/DHCP broke → Forgot to allow UDP 53 and 67/68.
Glossary and Quick Command Line
  • Standard = Close to destination | Extended = Close to source
  • ip access-group <name> in|out — on the interface
  • At the end, always `implicit deny any`
  • Wildcard: host = 0.0.0.0, any = 255.255.255.255

Check yourself

Where do you place a Standard ACL?

What happens to traffic that does not match any line in the ACL?

Was this page helpful?