Extended ACL: Direction and Placement
ACLs are evaluated in one direction on one interface. This lab reinforces the CCNA rule of placing extended ACLs close to the source while validating the actual packet path.
The problem
An extended ACL intended to block one client subnet from a server is applied outbound on the server-facing interface, unintentionally blocking reply traffic instead of the original request.
What you'll practice
- Trace a packet path
- Read ACL attachment direction
- Apply extended ACL placement guidance
- Use ACL counters to verify matches
The topology
A client VLAN reaches a server VLAN through one router; the policy should affect only the selected client traffic.
Commands to run yourself
The real diagnostic commands for this lab, copy-paste ready. Run these in the same order to reproduce the investigation on your own session.
show ip interfaceshow access-listsshow ip routeTopology diagram
Frequently asked
Is this aligned to CCNA practice?
Yes. It focuses on configuration, verification, and troubleshooting skills covered by the CCNA-level technology domain named on this lab.
Ready to run this lab yourself?
No setup, no image sourcing. Book a session or ask for a live demo.