Analogy: An ACL is a security guard at the entrance with a list of names. He reads from top to bottom and stops at the first matching line — and whoever didn't appear on the list at all, simply doesn't enter.
The packet is checked top-down and the first matching line wins. Line 10 denies SMB from the guest network to the servers, line 20 permits HTTPS, line 30 permits DNS, and everything else is dropped by the implicit deny at the end. Standard ACLs match the source only and belong close to the destination; extended ACLs match address, protocol and port and belong close to the source.
Standard vs. Extended
- Standard (1–99) — checks only source address. Place close to the destination, otherwise too much is blocked.
- Extended (100–199) — checks source, destination, protocol, and port. Place close to the source to save unnecessary traffic.
- Named ACL — names instead of numbers, allows editing by line numbers. Always recommended.
- At the end of every ACL there is an implicit deny any — what is not explicitly permitted, is blocked.
- One ACL per direction per interface (in / out) is possible.