CCNA Access Lists (ACLs)
CCNA 200-301 exam notes · Updated 2026-10-06
Access lists are the CCNA's favourite way to test whether you can control traffic precisely — which list type, which order, which direction, which interface. This guide to CCNA access lists covers standard ACLs, extended ACLs, and the rules on order, direction and placement. Drill it, then prove it with our free CCNA mock test.
Standard ACLs
Standard ACLs (numbered 1–99, or 1300–1999 expanded) filter on source IP address only — nothing else. That limitation dictates their placement: put them as close to the destination as possible, because filtering near the source would block that source's traffic to everywhere. The syntax is simple: access-list 10 permit 192.168.1.0 0.0.0.255 — note the wildcard mask (inverse mask: 0 = must match, 255 = don't care), and the keyword any as shorthand for 0.0.0.0 255.255.255.255.
Apply with ip access-group 10 out on the interface, choosing in (traffic entering the interface, toward the router) or out (traffic leaving the interface) carefully — direction is relative to the interface, and it's the single most tested ACL concept. Verify with show access-lists (watch the match counters to see which lines are hitting) and show ip interface g0/0 (shows applied ACLs).
Named standard ACLs (ip access-list standard NAME) work identically but let you edit individual lines — numbered ACLs can only be rebuilt wholesale. Either way, the implicit deny all at the end blocks everything not explicitly permitted, so a standard ACL with only deny statements blocks the entire universe.
Key exam points
- Standard ACLs (1–99): source IP only. Place close to the DESTINATION.
- Wildcard masks: 0 = match, 255 = ignore. any = 0.0.0.0 255.255.255.255.
- Direction (in/out) is relative to the interface — the most tested ACL concept.
- Named ACLs allow line editing; numbered ones must be rebuilt. Implicit deny all ends every ACL.
Extended ACLs
Extended ACLs (100–199, or 2000–2699 expanded) filter on protocol, source, destination, and ports — the precision tool. Because they're precise, place them as close to the source as possible so unwanted traffic is dropped before it consumes bandwidth. A typical line: access-list 100 permit tcp 192.168.1.0 0.0.0.255 any eq 80 — protocol first, then source, then destination, then port operators (eq, neq, lt, gt, range).
The named form is what you'll actually configure: ip access-list extended WEB-ONLY, then sequence-numbered lines like 10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 and 20 permit tcp 192.168.1.0 0.0.0.255 any eq 443. Sequence numbers let you insert lines later (15 deny … slots between 10 and 20) — a favourite exam detail. Remember established for permitting return TCP traffic, and that filtering "web traffic" usually means both 80 and 443.
Port-number fluency from the fundamentals tables pays off directly here: an ACL permitting DNS needs permit udp any any eq 53 (and TCP 53 for zone transfers), SSH is eq 22, and blocking Telnet while allowing SSH is a two-line exercise. Always finish by applying with ip access-group — an ACL that exists but isn't applied filters nothing, the exam's cruellest trap.
Key exam points
- Extended ACLs (100–199): protocol + source + destination + ports. Place close to the SOURCE.
- Syntax order: access-list <n> <permit|deny> <protocol> <src> <dst> [eq <port>].
- Named ACLs use sequence numbers — insert lines without rebuilding.
- An ACL filters nothing until applied with ip access-group <name> <in|out>.
ACL Rules: Order, Direction and Placement
Three rules govern every ACL question. Rule 1 — top-down, first match wins. A packet is compared against each line in order and the first match decides; later lines never see it. A broad permit ip any any above a specific deny makes the deny dead text. Rule 2 — implicit deny all. Every ACL ends with an invisible deny ip any any; if you only wrote permits, everything else is blocked — including routing-protocol hellos and return traffic you forgot. Rule 3 — one ACL per interface per direction per protocol. You can't stack two inbound IPv4 ACLs on one interface.
Direction trips up more candidates than anything else in this domain. Inbound = traffic entering the interface (before routing); outbound = traffic leaving the interface (after routing). To block internet hosts from reaching your LAN server, filter inbound on the outside interface or outbound on the inside interface — both work, but the exam wants you to see the equivalence and pick the efficient one.
Placement summarised: standard ACLs near the destination (they're too blunt for the source side), extended ACLs near the source (drop junk early). And the golden troubleshooting step: show access-lists match counters tell you which line is actually catching the traffic — if the deny counter climbs when your test traffic flows, you've found your culprit.
Key exam points
- First match wins, processed top-down. Order lines most-specific first.
- Implicit deny ip any any ends every ACL — explicitly permit what you need, including return traffic.
- One ACL per interface per direction per protocol. Direction is relative to the interface.
- Standard → near destination. Extended → near source. Use show access-lists counters to diagnose.
Related CCNA study guides
Frequently asked questions
What are the key CCNA exam points for Standard ACLs?
For the CCNA 200-301 exam, remember: Standard ACLs (1–99): source IP only. Place close to the DESTINATION. Wildcard masks: 0 = match, 255 = ignore. any = 0.0.0.0 255.255.255.255. Direction (in/out) is relative to the interface — the most tested ACL concept. Named ACLs allow line editing; numbered ones must be rebuilt. Implicit deny all ends every ACL.
What are the key CCNA exam points for Extended ACLs?
For the CCNA 200-301 exam, remember: Extended ACLs (100–199): protocol + source + destination + ports. Place close to the SOURCE. Syntax order: access-list <n> <permit|deny> <protocol> <src> <dst> [eq <port>]. Named ACLs use sequence numbers — insert lines without rebuilding. An ACL filters nothing until applied with ip access-group <name> <in|out>.
What are the key CCNA exam points for ACL Rules?
For the CCNA 200-301 exam, remember: First match wins, processed top-down. Order lines most-specific first. Implicit deny ip any any ends every ACL — explicitly permit what you need, including return traffic. One ACL per interface per direction per protocol. Direction is relative to the interface. Standard → near destination. Extended → near source. Use show access-lists counters to diagnose.
Which key detail about Standard ACLs should you memorise for the CCNA 200-301 exam?
Wildcard masks: 0 = match, 255 = ignore. any = 0.0.0.0 255.255.255.255.
Which key detail about Extended ACLs should you memorise for the CCNA 200-301 exam?
Syntax order: access-list <n> <permit|deny> <protocol> <src> <dst> [eq <port>].