Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A network security engineer is designing a new firewall policy for a corporate network. The policy needs to permit HTTP and HTTPS traffic from the internal network to the internet, block all other outbound traffic, and allow only SSH access from a specific management subnet to internal servers. Which ordered set of Access Control List (ACL) entries would achieve this, assuming a default implicit deny at the end?

  1. A1. permit tcp internal_net any eq 80; 2. permit tcp internal_net any eq 443; 3. deny ip any any; 4. permit tcp management_subnet internal_servers eq 22
  2. B1. permit tcp any host 80 eq 443; 2. permit tcp any host 22 eq 22; 3. deny ip any any
  3. C1. permit tcp any any eq 80; 2. permit tcp any any eq 443; 3. permit tcp management_subnet internal_servers eq 22
  4. D1. permit tcp internal_net any eq 80; 2. permit tcp internal_net any eq 443; 3. permit tcp management_subnet internal_servers eq 22
Show answer & explanation

Correct answer: D. 1. permit tcp internal_net any eq 80; 2. permit tcp internal_net any eq 443; 3. permit tcp management_subnet internal_servers eq 22

Option B correctly orders the permit statements to allow HTTP/HTTPS outbound and then SSH for management, relying on the implicit deny for all other traffic. Option A incorrecty specifies 'host 80 eq 443' and 'host 22 eq 22'. Option C places a 'deny ip any any' before the SSH rule, which would block SSH. Option D uses 'any any' for HTTP/HTTPS, which is too broad and doesn't restrict to the internal network.

Why the other options are wrong

  • A. This option includes a 'deny ip any any' statement before the SSH permit rule, which would prevent SSH access from the management subnet.
  • B. This option uses incorrect syntax for port specification and source/destination match, making it invalid.
  • C. This option allows HTTP/HTTPS from 'any' source to 'any' destination, which is not restricted to the internal network as required, and could allow inbound HTTP/HTTPS.

ACL Implicit Deny

At the end of every Access Control List (ACL), there is an implicit 'deny any any' statement that blocks all traffic not explicitly permitted by preceding statements.

  • Not explicitly visible in the configuration.
  • Ensures all unpermitted traffic is dropped.
  • Requires careful ordering of permit/deny rules.

Memory trick: Rules are read in order, first match wins, then the silent 'NO'.

More Network Security questions