IntermediatePublished 2026-07-14
CCNA: Extended ACLs — Match Protocol, Port, Destination
Archive lab
Deploy an extended ACL inbound near the source to allow HTTP from a client VLAN to a server while blocking ICMP to that same server. The lab uses router-on-a-stick over a hardened access switch with a routed transit to a core router hosting the server VLAN. You will implement, verify from endpoints, and troubleshoot matching by protocol, port, destination, and placement/direction.
Learning objectives
- Design and place an extended ACL inbound close to the source
- Match source network, destination host, protocol, and TCP port in a single ACL
- Order ACEs correctly with an explicit final permit
- Bind an ACL to the correct interface and direction
- Verify allowed HTTP succeeds while ICMP to the server is blocked from the client
Troubleshooting focus
- Verify the ACL applies to the correct interface and inbound direction near the source
- Confirm ACE ordering: specific permits before denies and an explicit final permit
- Check the exact destination host IP and TCP port match
- Ensure trunks carry the correct VLANs so packets actually hit the filtered interface
- Validate static routes on both routers so the HTTP flow returns successfully
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.