BeginnerPublished 2026-07-13
CCNA Foundations: Standard ACLs — Filter Traffic by Source
Archive lab
Build a compact two-router, three-host topology. Implement a numbered standard ACL on the destination router to permit Client-A and deny Client-B from reaching a protected server based solely on source subnet. Verify from the end hosts that permitted traffic succeeds and denied traffic fails, and practice correct ACL placement and direction.
Learning objectives
- Author a numbered standard ACL (1–99) that matches traffic by source network only
- Place a standard ACL on the interface closest to the destination in the correct direction
- Verify ACL behavior from end hosts and interpret counters
- Differentiate standard vs. extended ACL use cases and placement
Troubleshooting focus
- CLIENT-B still gets replies from 10.30.30.10: the ACL is on the wrong interface or the wrong direction.
- The deny line in
show access-lists 10never increments while CLIENT-B pings: check the wildcard mask — for a /24 it is 0.0.0.255, not a subnet mask — and that the permit and deny lines are not reversed. - This lab includes it deliberately.
- Both clients behave inconsistently and the ACL looks right: fix routing first.
show ip routeon both routers must list all three LANs; ACLs should never mask a routing problem.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.