> For the complete documentation index, see [llms.txt](https://netsec.nerd-cafe.ir/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://netsec.nerd-cafe.ir/network-engineering/ccna/configuring-standard-acls-in-cisco-routers.md).

# Configuring Standard ACLs in Cisco Routers

Nerd cafe

### <mark style="color:blue;">**Introduction to Standard ACLs**</mark>

Access Control Lists (ACLs) in Cisco routers are used to filter traffic based on defined rules. A <mark style="color:red;">**Standard ACL**</mark> is a simple form of ACL that <mark style="color:red;">**filters traffic based on source IP addresses only**</mark>. It does <mark style="color:red;">**not**</mark> consider destination IP or other criteria.

In this guide, we will:

1. **Understand the concept of Standard ACLs**
2. **Set up a practical GNS3 lab scenario**
3. **Configure Standard ACLs step by step**
4. **Test and verify the configuration**

### <mark style="color:blue;">**Step 1: Lab Topology in GNS3**</mark>

We will simulate a small network using <mark style="color:red;">**1 router, 1 switch and 2 PCs**</mark>.

#### **Network Topology:**

<figure><img src="https://2804731566-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOszSitBb46QATDLUtW4%2Fuploads%2FUy1gsE6jJUemwaxFhYO4%2F0488-standard-acl-topology.png?alt=media&amp;token=bfb3d91c-c7a7-4db7-9dc5-a32ab2c121a7" alt=""><figcaption><p>Topology</p></figcaption></figure>

**Objective:**

* <mark style="color:red;">**Allow**</mark> PC1 (192.168.1.100) to access Router (R1).
* <mark style="color:red;">**Deny**</mark> PC2 (192.168.1.200) from reaching Router (R1).

### <mark style="color:blue;">**Step 2: GNS3 Device Configuration**</mark>

**Assign IP addresses to the interfaces of Router (R1)**

```
R1#configure terminal
R1(config)#interface fastEthernet 0/0
R1(config-if)#ip address 192.168.1.1 255.255.255.0
R1(config-if)#no shutdown
```

### <mark style="color:blue;">**Step 3: Configuring Standard ACL on Router1**</mark>

**Create an ACL to allow PC1 and deny PC2**

```
R1(config)#access-list 10 permit 192.168.1.100 0.0.0.0
R1(config)#access-list 10 deny 192.168.1.200 0.0.0.0
R1(config)#access-list 10 permit any
```

**Explanation:**

* `access-list 10 permit 192.168.1.100 0.0.0.0` → Allows PC1 to communicate
* `access-list 10 deny 192.168.1.200 0.0.0.0` → Blocks PC2 from communication
* `access-list 10 permit any` → Ensures all other traffic is allowed

#### Apply the ACL to the interface

```
R1(config)#interface fastEthernet 0/0
R1(config-if)#ip access-group 10 in
```

**Explanation:**

* `ip access-group 10 in` → Applies ACL 10 to incoming traffic on FastEthernet0/0.

### <mark style="color:blue;">**Step 4: Verifying the Configuration**</mark>

**Check the ACL**

```
R1#show access-lists
Standard IP access list 10
    10 permit 192.168.1.100
    20 deny   192.168.1.200
    30 permit any
R1#
```

**Test connectivity**

* PC1 should be able to PING Router (R1)

```
PC1> ping 192.168.1.1

84 bytes from 192.168.1.1 icmp_seq=1 ttl=255 time=9.702 ms
84 bytes from 192.168.1.1 icmp_seq=2 ttl=255 time=9.840 ms
^C
PC1>
```

* PC2 should NOT be able to PING Router1

```
PC2> ping 192.168.1.1

*192.168.1.1 icmp_seq=1 ttl=255 time=11.651 ms (ICMP type:3, code:13, Communication administratively prohibited)
*192.168.1.1 icmp_seq=2 ttl=255 time=5.817 ms (ICMP type:3, code:13, Communication administratively prohibited)
*192.168.1.1 icmp_seq=3 ttl=255 time=3.315 ms (ICMP type:3, code:13, Communication administratively prohibited)
^C
PC2>
```

### <mark style="color:blue;">Keywords</mark>

`Standard ACL`, `Cisco ACL`, `Access Control List`, `Cisco Router`, `IP filtering`, `network security`, `CCNA`, `GNS3 simulation`, `ACL configuration`, `permit IP`, `deny IP`, `Cisco commands`, `access-list 10`, `router security`, `packet filtering`, `subnet ACL`, `IP access-group`, `inbound ACL`, `network filtering`, `ACL verification`, `سیسکو`
