A network engineer is configuring an access control list (ACL) on a router to permit HTTP and HTTPS traffic from the subnet 192.168.10.0/24 to a web server at 10.0.0.5. All other traffic from this subnet should be denied. Which two ACL entries, when placed in the correct order, achieve this goal?
- Aaccess-list 101 permit ip 192.168.10.0 0.0.0.255 host 10.0.0.5 eq 80 access-list 101 permit ip 192.168.10.0 0.0.0.255 host 10.0.0.5 eq 443
- Baccess-list 101 permit tcp any host 10.0.0.5 eq 80 access-list 101 permit tcp any host 10.0.0.5 eq 443
- Caccess-list 101 permit tcp 192.168.10.0 0.0.0.255 host 10.0.0.5 eq www access-list 101 permit tcp 192.168.10.0 0.0.0.255 host 10.0.0.5 eq https
- Daccess-list 101 permit tcp 192.168.10.0 0.0.0.255 host 10.0.0.5 eq 80 access-list 101 permit tcp 192.168.10.0 0.0.0.255 host 10.0.0.5 eq 443
Show answer & explanationAnswer & explanation
Correct answer: C. access-list 101 permit tcp 192.168.10.0 0.0.0.255 host 10.0.0.5 eq www access-list 101 permit tcp 192.168.10.0 0.0.0.255 host 10.0.0.5 eq https
The correct ACL entries use the 'permit tcp' protocol, specify the source subnet with its wildcard mask (192.168.10.0 0.0.0.255), the destination host (host 10.0.0.5), and the correct destination port numbers for HTTP (www or 80) and HTTPS (https or 443). Using 'www' and 'https' are valid aliases for ports 80 and 443 respectively. The implicit deny all at the end of every ACL will deny all other traffic.
Why the other options are wrong
- A. Uses 'permit ip' instead of 'permit tcp'. HTTP and HTTPS are TCP-based protocols, so 'permit tcp' is required to specify port numbers. 'permit ip' would permit all IP traffic, not just specific ports.
- B. Uses 'any' for the source, which would permit traffic from any source, not just the 192.168.10.0/24 subnet, violating the requirement.
- D. Uses numeric ports 80 and 443, which is correct, but 'www' and 'https' are also valid and commonly used aliases. This option is technically correct, but B uses the named ports which are often preferred for readability.
Standard IP ACL Syntax
Cisco Access Control List (ACL) syntax for filtering IP traffic based on source IP address, destination IP address, protocol, and port numbers.
- ACLs are processed top-down, first match wins.
- An implicit 'deny any any' is at the end of every ACL.
- Wildcard masks are used with source/destination IP addresses.
Memory trick: Access Control Lists: like bouncers for network packets, checking IDs and destinations.