Access lists: the order, the implicit deny, and where to put one
An ACL is read top to bottom and stops at the first match. Two consequences follow, and they account for most of the ACLs that do not do what their author meant.
An access list is a list of permit and deny statements read top to bottom, stopping at the first match. Two consequences follow from that sentence and almost every ACL mistake is one of them.
Consequence one: order is meaning
R1(config)# ip access-list extended GUEST
R1(config-ext-nacl)# permit ip 10.0.0.0 0.0.0.255 any
R1(config-ext-nacl)# deny ip 10.0.0.50 0.0.0.0 any
The second line never runs. 10.0.0.50 matched the first line, the list
stopped, and the packet was permitted. Specific entries go above general
ones, always.
Consequence two: there is a deny at the end you did not type
Every ACL ends with an invisible deny ip any any. An ACL that only permits
one thing denies everything else — which is usually what you wanted, and is
occasionally a very long afternoon when you applied it to the interface you
are telnetted in through.
> If an ACL exists and matches nothing you wrote, it still matches. Silently, > and as a deny.
Wildcard masks
ACLs take a wildcard, which is the inverse of a subnet mask: 0 means match
this bit, 1 means ignore it. 0.0.0.255 matches a /24. 0.0.0.0 matches
one host — and host 10.0.0.50 means the same thing and reads better.
any is 0.0.0.0 255.255.255.255.
Where to put it
The old rule — standard ACLs near the destination, extended near the source — exists because a standard ACL can only match the source address, so placing one near the source blocks that source from reaching everything. An extended ACL names both ends, so it can be placed where the traffic enters and dropped before it crosses the network.
R1(config)# interface GigabitEthernet0/0
R1(config-if)# ip access-group GUEST in
in and out are from the router's point of view: in is traffic arriving
on that interface. Getting this backwards is common and the symptom is an ACL
that appears to do nothing.
Prove it before you trust it
show access-lists prints a match count per line. A line with zero matches is
either unnecessary or unreachable, and the difference matters:
R1# show access-lists GUEST
Extended IP access list GUEST
10 permit tcp 10.0.0.0 0.0.0.255 any eq 443 (1842 matches)
20 deny ip 10.0.0.0 0.0.0.255 any (37 matches)
Counters are the only honest answer to "is this rule doing anything".
Join the discussion
Replies, likes and bookmarks live in the community half, which needs a free account. Writing here is free too, and everything is reviewed before it is published.
Open this in the communityEverything publishedHow this works