All guided builds

Guided buildcore7 steps~20 min5 devices

Guard the server with an ACL

Let one workstation reach the server, stop the guest laptop, and learn what the implicit deny does to everyone else.

What you'll be able to do: A router that forwards the office LAN to the server segment for the staff workstation and silently drops the guest laptop's packets — with a filter you can read top to bottom and predict, instead of one you hope is right.

Topics: ACLs · Traffic filtering · Implicit deny · Network security

What you'll build

Step by step

  1. 1. Place the router and address the office side

    Drag a router onto the canvas, name it, and put 192.168.10.1 on Gi0/0 — that address is the gateway every office host will point at. A router's ports ship shut, so `no shutdown` is part of the job: forget it and the address sits on a port that is administratively down and carries nothing.

    On Edge — Name the router and give the office-facing port its gateway address

    enable
    configure terminal
    hostname Edge
    interface Gi0/0
    ip address 192.168.10.1 255.255.255.0
    no shutdown
    exit
    end

    Check: run show ip interface brief on Edge and look for Gi0/0 192.168.10.1 YES manual down down.

    Why: A router can only filter traffic that passes through it, so where the router sits decides what you will be able to protect. Edge is about to become the only path between the office and the server segment, and that position — not any command — is what makes the filter in this build possible.

  2. 2. Cable the office switch to the router

    Drop a switch in and run a cable from the router's Gi0/0 to the switch's Gi0/1. Nothing is configured on that switch port and nothing needs to be: an out-of-the-box switch port is an access port in VLAN 1, which is exactly right for a flat office LAN. Watch Gi0/0's Protocol column go up once the cable lands.

    • Cable Edge Gi0/0 ↔ SW-Office Gi0/1

    On SW-Office — Name the switch so its console prompt tells you where you are typing

    enable
    configure terminal
    hostname SW-Office
    end

    Check: run show interfaces status on SW-Office and look for Gi0/1 connected 1 auto 1000 gigabit.

    Why: A link needs a live, enabled port at both ends: Gi0/0 was already enabled, so it came up the moment the switch answered on the other end of the cable. Reading the state from both sides — `show ip interface brief` on the router, `show interfaces status` on the switch — is how you tell which end of a dead link is at fault.

  3. 3. Plug in the two workstations

    Add both PCs on Fa0/1 and Fa0/2, and give each one an address in 192.168.10.0/24 plus the router as its default gateway. They share a subnet and a switch, so they can already talk to each other without the router being involved at all — remember that, because the ACL you write later will not change it.

    • Cable PC-Staff Eth0 ↔ SW-Office Fa0/1
    • Cable PC-Guest Eth0 ↔ SW-Office Fa0/2

    On PC-Staff — Name the staff workstation and address it

    hostname PC-Staff
    ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1

    On PC-Guest — Name the visitor laptop and address it

    hostname PC-Guest
    ipconfig Eth0 192.168.10.30 255.255.255.0 192.168.10.1

    Check: run ip -br a on PC-Staff and look for Eth0 UP 192.168.10.10/24.

    Why: Both workstations point at 192.168.10.1, so every packet they send to another subnet enters Edge through Gi0/0 — one door for all office traffic. That single entry point is what will later let one interface ACL judge every office host's traffic on its way in.

  4. 4. Hang the server off the router's second port

    Put the server on its own segment: cable it straight to Gi0/1, address that port 192.168.20.1, and give WEB1 192.168.20.100 with the router as its gateway. A server on the far side of a router is the whole reason this lab has a filter to write — traffic between the two subnets has to pass through Edge, and anything that passes through a router can be inspected there.

    • Cable Edge Gi0/1 ↔ WEB1 Eth0

    On Edge — Address the server-facing port

    enable
    configure terminal
    interface Gi0/1
    ip address 192.168.20.1 255.255.255.0
    no shutdown
    exit
    end

    On WEB1 — Name the server and put it on the server subnet

    hostname WEB1
    ipconfig Eth0 192.168.20.100 255.255.255.0 192.168.20.1

    On PC-Guest — Prove the problem: the visitor laptop can reach the server today

    ping 192.168.20.100

    Check: run show ip route on Edge and look for C 192.168.20.0/24 is directly connected, Gi0/1.

    Why: Each router interface can check traffic in two directions — inbound as packets arrive, outbound as they leave — so this router now offers four places a filter could go: in or out on Gi0/0, in or out on Gi0/1. Choosing the interface and the direction is half of writing any ACL, because the same list can protect, do nothing or cut off everyone depending on where it is bound.

  5. 5. Write the deny — and lock everybody out

    Here is the rule you want: PC-Guest may not reach the server segment. Write it as one line, bind it to the direction traffic leaves toward the server, and then ping the server from PC-Staff. It fails. So does everything else. An ACL is an ordered list that ends in an invisible `deny any` you never typed, so a list containing one deny denies the entire world.

    On Edge — One deny line, applied outbound on the server-facing port

    enable
    configure terminal
    access-list 10 deny host 192.168.10.30
    interface Gi0/1
    ip access-group 10 out
    exit
    end

    On PC-Staff — The ping that should have kept working

    ping 192.168.20.100

    Check: run show access-lists on Edge and look for 10 deny host 192.168.10.30.

    Why: An ACL is read top to bottom and the first line that matches decides; a packet that matches none of them meets the implicit deny at the end. Numbered lists from 1 to 99 are standard lists, which match on the source address alone — which is why this line can name the guest but has no way to say what the guest was trying to reach.

  6. 6. Add the permit that makes the list mean what you meant

    Fix it by putting an explicit `permit any` after the deny. Order is everything: the router reads top to bottom and stops at the first line that matches, so the deny gets its say before the permit sweeps up everyone else. Swap the two lines and the permit would match first and the deny would never run.

    On Edge — Delete the broken list, rewrite it in the right order, and re-apply it

    enable
    configure terminal
    no access-list 10
    access-list 10 deny host 192.168.10.30
    access-list 10 permit any
    interface Gi0/1
    ip access-group 10 out
    exit
    end

    On PC-Staff — Confirm the staff workstation is back

    ping 192.168.20.100

    Check: run show access-lists on Edge and look for 20 permit any.

    Why: A standard ACL belongs as close to the destination as possible, because it can only name sources: bound outbound on Gi0/1 it judges only traffic heading into the server segment, so the guest keeps everything else — its own gateway, the other desk, the rest of the network.

  7. 7. Close the gap only an extended ACL can close

    Ping 192.168.20.1 from PC-Guest and it answers, even though the guest is supposedly fenced off — an outbound ACL never filters traffic that stops at the router itself. Moving list 10 inbound would fix that and break the guest's own gateway with it, because a standard ACL matches on source and nothing else. An extended ACL names source, destination and protocol, so it can deny this one host to this one address and let everything else past.

    On Edge — Deny the guest's management and probe traffic to the router's server-side address

    enable
    configure terminal
    ip access-list extended GUEST-GUARD
    deny tcp host 192.168.10.30 host 192.168.20.1 eq 23
    deny icmp host 192.168.10.30 host 192.168.20.1
    permit ip any any
    exit
    interface Gi0/0
    ip access-group GUEST-GUARD in
    exit
    end

    On PC-Guest — The probe that used to work

    ping 192.168.20.1

    Check: run show ip interface Gi0/0 on Edge and look for Inbound access list is GUEST-GUARD.

    Why: An extended ACL names source, destination, protocol and port, which makes it precise enough to sit close to the source: bound inbound on Gi0/0, it judges the guest's packets the moment they arrive, before the router does any routing work for them, and it leaves every other host and every other destination alone.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Guard the server with an ACL — step-by-step network lab · NetForge-AI