Guided buildcore7 steps~20 min5 devices
Guard the server with an ACL
Let one workstation reach the server, stop the guest laptop, and learn what the implicit deny does to everyone else.
What you'll be able to do: A router that forwards the office LAN to the server segment for the staff workstation and silently drops the guest laptop's packets — with a filter you can read top to bottom and predict, instead of one you hope is right.
Topics: ACLs · Traffic filtering · Implicit deny · Network security
What you'll build
- Edge — a router, the router between the office and the server segment
- SW-Office — a switch, the access switch both workstations plug into
- PC-Staff — a pc, the staff workstation, which must keep working
- PC-Guest — a pc, the visitor laptop you are going to fence off
- WEB1 — a server, the application server being protected
Step by step
1. Place the router and address the office side
Drag a router onto the canvas, name it, and put 192.168.10.1 on Gi0/0 — that address is the gateway every office host will point at. A router's ports ship shut, so `no shutdown` is part of the job: forget it and the address sits on a port that is administratively down and carries nothing.
On Edge — Name the router and give the office-facing port its gateway address
enable configure terminal hostname Edge interface Gi0/0 ip address 192.168.10.1 255.255.255.0 no shutdown exit endCheck: run
show ip interface briefon Edge and look forGi0/0 192.168.10.1 YES manual down down.Why: A router can only filter traffic that passes through it, so where the router sits decides what you will be able to protect. Edge is about to become the only path between the office and the server segment, and that position — not any command — is what makes the filter in this build possible.
2. Cable the office switch to the router
Drop a switch in and run a cable from the router's Gi0/0 to the switch's Gi0/1. Nothing is configured on that switch port and nothing needs to be: an out-of-the-box switch port is an access port in VLAN 1, which is exactly right for a flat office LAN. Watch Gi0/0's Protocol column go up once the cable lands.
- Cable Edge Gi0/0 ↔ SW-Office Gi0/1
On SW-Office — Name the switch so its console prompt tells you where you are typing
enable configure terminal hostname SW-Office endCheck: run
show interfaces statuson SW-Office and look forGi0/1 connected 1 auto 1000 gigabit.Why: A link needs a live, enabled port at both ends: Gi0/0 was already enabled, so it came up the moment the switch answered on the other end of the cable. Reading the state from both sides — `show ip interface brief` on the router, `show interfaces status` on the switch — is how you tell which end of a dead link is at fault.
3. Plug in the two workstations
Add both PCs on Fa0/1 and Fa0/2, and give each one an address in 192.168.10.0/24 plus the router as its default gateway. They share a subnet and a switch, so they can already talk to each other without the router being involved at all — remember that, because the ACL you write later will not change it.
- Cable PC-Staff Eth0 ↔ SW-Office Fa0/1
- Cable PC-Guest Eth0 ↔ SW-Office Fa0/2
On PC-Staff — Name the staff workstation and address it
hostname PC-Staff ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1On PC-Guest — Name the visitor laptop and address it
hostname PC-Guest ipconfig Eth0 192.168.10.30 255.255.255.0 192.168.10.1Check: run
ip -br aon PC-Staff and look forEth0 UP 192.168.10.10/24.Why: Both workstations point at 192.168.10.1, so every packet they send to another subnet enters Edge through Gi0/0 — one door for all office traffic. That single entry point is what will later let one interface ACL judge every office host's traffic on its way in.
4. Hang the server off the router's second port
Put the server on its own segment: cable it straight to Gi0/1, address that port 192.168.20.1, and give WEB1 192.168.20.100 with the router as its gateway. A server on the far side of a router is the whole reason this lab has a filter to write — traffic between the two subnets has to pass through Edge, and anything that passes through a router can be inspected there.
- Cable Edge Gi0/1 ↔ WEB1 Eth0
On Edge — Address the server-facing port
enable configure terminal interface Gi0/1 ip address 192.168.20.1 255.255.255.0 no shutdown exit endOn WEB1 — Name the server and put it on the server subnet
hostname WEB1 ipconfig Eth0 192.168.20.100 255.255.255.0 192.168.20.1On PC-Guest — Prove the problem: the visitor laptop can reach the server today
ping 192.168.20.100Check: run
show ip routeon Edge and look forC 192.168.20.0/24 is directly connected, Gi0/1.Why: Each router interface can check traffic in two directions — inbound as packets arrive, outbound as they leave — so this router now offers four places a filter could go: in or out on Gi0/0, in or out on Gi0/1. Choosing the interface and the direction is half of writing any ACL, because the same list can protect, do nothing or cut off everyone depending on where it is bound.
5. Write the deny — and lock everybody out
Here is the rule you want: PC-Guest may not reach the server segment. Write it as one line, bind it to the direction traffic leaves toward the server, and then ping the server from PC-Staff. It fails. So does everything else. An ACL is an ordered list that ends in an invisible `deny any` you never typed, so a list containing one deny denies the entire world.
On Edge — One deny line, applied outbound on the server-facing port
enable configure terminal access-list 10 deny host 192.168.10.30 interface Gi0/1 ip access-group 10 out exit endOn PC-Staff — The ping that should have kept working
ping 192.168.20.100Check: run
show access-listson Edge and look for10 deny host 192.168.10.30.Why: An ACL is read top to bottom and the first line that matches decides; a packet that matches none of them meets the implicit deny at the end. Numbered lists from 1 to 99 are standard lists, which match on the source address alone — which is why this line can name the guest but has no way to say what the guest was trying to reach.
6. Add the permit that makes the list mean what you meant
Fix it by putting an explicit `permit any` after the deny. Order is everything: the router reads top to bottom and stops at the first line that matches, so the deny gets its say before the permit sweeps up everyone else. Swap the two lines and the permit would match first and the deny would never run.
On Edge — Delete the broken list, rewrite it in the right order, and re-apply it
enable configure terminal no access-list 10 access-list 10 deny host 192.168.10.30 access-list 10 permit any interface Gi0/1 ip access-group 10 out exit endOn PC-Staff — Confirm the staff workstation is back
ping 192.168.20.100Check: run
show access-listson Edge and look for20 permit any.Why: A standard ACL belongs as close to the destination as possible, because it can only name sources: bound outbound on Gi0/1 it judges only traffic heading into the server segment, so the guest keeps everything else — its own gateway, the other desk, the rest of the network.
7. Close the gap only an extended ACL can close
Ping 192.168.20.1 from PC-Guest and it answers, even though the guest is supposedly fenced off — an outbound ACL never filters traffic that stops at the router itself. Moving list 10 inbound would fix that and break the guest's own gateway with it, because a standard ACL matches on source and nothing else. An extended ACL names source, destination and protocol, so it can deny this one host to this one address and let everything else past.
On Edge — Deny the guest's management and probe traffic to the router's server-side address
enable configure terminal ip access-list extended GUEST-GUARD deny tcp host 192.168.10.30 host 192.168.20.1 eq 23 deny icmp host 192.168.10.30 host 192.168.20.1 permit ip any any exit interface Gi0/0 ip access-group GUEST-GUARD in exit endOn PC-Guest — The probe that used to work
ping 192.168.20.1Check: run
show ip interface Gi0/0on Edge and look forInbound access list is GUEST-GUARD.Why: An extended ACL names source, destination, protocol and port, which makes it precise enough to sit close to the source: bound inbound on Gi0/0, it judges the guest's packets the moment they arrive, before the router does any routing work for them, and it leaves every other host and every other destination alone.
The theory behind it
More in Security & resilience
- One jack, one PC: port security — Lock the reception wall jack to one PC with sticky port security, watch a visitor's laptop err-disable it, recover the port, then switch to restrict so the next intruder is dropped without taking reception offline.
- A DMZ behind a firewall — Stand a firewall between three zones so the public reaches one server and nothing else.
- Two routers, one gateway — Give a LAN a gateway that survives a router failure: two routers share one virtual address with VRRP, and the hosts never notice the handover.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab