Cisco CCNA (200-301)Security FundamentalsHard
A switch's running configuration shows the following access list applied inbound on interface GigabitEthernet0/1: access-list 110 deny tcp 192.168.5.0 0.0.0.255 any eq 23 access-list 110 permit ip any any A host at 192.168.5.10 attempts an SSH session (TCP port 22) to a remote server. What is the result?
- AThe SSH session is permitted because it does not match the deny statement's port 23 condition
- BThe SSH session is denied because the source subnet matches the first line
- CThe SSH session is denied because there is no explicit permit for port 22
- DThe SSH session is denied due to the implicit deny at the end of the ACL
Show answer & explanationAnswer & explanation
Correct answer: A. The SSH session is permitted because it does not match the deny statement's port 23 condition
The first line only denies TCP traffic from 192.168.5.0/24 destined to port 23 (Telnet). SSH uses port 22, so it does not match the deny line; it falls through to the second line, 'permit ip any any', which allows it.
Why the other options are wrong
- B. The deny line only applies to port 23 (Telnet), not port 22 (SSH).
- C. An explicit permit is not needed for port 22 because 'permit ip any any' covers all remaining traffic.
- D. The implicit deny never triggers here because the second explicit line permits all remaining IP traffic.
ACL Line-by-Line Evaluation
Cisco ACLs are processed top-down; the first matching line determines the action, and remaining lines (including implicit deny) are only evaluated if no prior match occurs.
- Match is based on protocol, source/destination, and port together
- A deny for one specific port does not affect other ports/protocols
- Explicit 'permit ip any any' catches everything not explicitly denied above it
Memory trick: First Match Wins, then Move On