Back to Learning
CCNA · 200-301FreeIntermediate

Extended ACL: Direction and Placement

ACLs are evaluated in one direction on one interface. This lab reinforces the CCNA rule of placing extended ACLs close to the source while validating the actual packet path.

SecurityACL

The problem

An extended ACL intended to block one client subnet from a server is applied outbound on the server-facing interface, unintentionally blocking reply traffic instead of the original request.

What you'll practice

  • Trace a packet path
  • Read ACL attachment direction
  • Apply extended ACL placement guidance
  • Use ACL counters to verify matches

The topology

A client VLAN reaches a server VLAN through one router; the policy should affect only the selected client traffic.

Commands to run yourself

The real diagnostic commands for this lab, copy-paste ready. Run these in the same order to reproduce the investigation on your own session.

Inspect ACL attachment
show ip interface
Read ACL entries and counters
show access-lists
Inspect routing path
show ip route

Topology diagram

Frequently asked

Is this aligned to CCNA practice?

Yes. It focuses on configuration, verification, and troubleshooting skills covered by the CCNA-level technology domain named on this lab.

Ready to run this lab yourself?

No setup, no image sourcing. Book a session or ask for a live demo.