ACL Segmentation Policy on Multi-LAN Router
Bundle lab
Deploy and verify multiple IPv4 ACLs on a single router that terminates three distinct LANs (Client, Server, and Management). You will place an extended ACL inbound on the Client interface to allow only specific services to the Server and block access to Management, a standard ACL outbound on the Management interface to enforce destination-side protection by source, and a VTY access-class to restrict router SSH to the Management subnet only. Validate with end-host tests that permitted flows succeed while denied flows are provably blocked, and use ACL hit counts and logs to troubleshoot.
Learning objectives
- Configure and apply multiple ACLs on different router interfaces and directions.
- Enforce segmentation between client, server, and management networks using IPv4 ACLs.
- Verify policy from end hosts and interpret ACL hit counts and log outputs.
- Diagnose direction/placement mistakes and implicit deny behavior.
- Validate operational impact on critical services (SSH, HTTP, ICMP).
Troubleshooting focus
- Why does permitted traffic work one way but not the other?
- How do ACL hit counts and log messages expose the blocked flow?
- What changes when the same ACL is placed inbound vs. outbound?
- Which flows fail due to the implicit deny?
- How does a VTY access-class differ from an interface access-group?
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.