IntermediatePublished 2026-07-15
CCNA Foundations: Named ACLs — Readable Rules & Editing by Sequence
Archive lab
Intermediate CCNA lab focused on named extended ACLs. You will permit a specific business flow (HTTP from the branch client to a data center web server) while denying ICMP to that server, apply the ACL inbound on the branch LAN interface, and validate from real endpoints. The baseline provides static routing and full connectivity; your task is to implement a readable, ordered named extended ACL with a remark and bind it correctly so the intended policy is enforced.
Learning objectives
- Design a readable named extended ACL with an intent-focused remark
- Order ACEs correctly and understand the implicit deny
- Apply an extended ACL inbound near the source on the correct interface
- Verify policy from endpoints and interpret ACL hit counters
- Edit ACLs by sequence to insert or adjust rules without rewriting the list
Troubleshooting focus
- Identify incorrect ACL placement or direction and its impact on observed traffic
- Differentiate routing failures from ACL drops using traceroute, ping, and show commands
- Recognize the effect of ACE ordering and missing explicit permits (implicit deny)
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.