Standard & Extended ACLs
CCNA 200-301 v2.0 · Live Feb 3, 2027 (v1.1 valid through Feb 2, 2027) Cisco Packet Tracer
مقصدObjectiveObjective
اس لیب میں آپ Access Control Lists سیکھیں گے — standard اور extended (named) ACLs بنانا اور interfaces پر لگانا۔Is lab mein aap Access Control Lists seekhenge — standard aur extended (named) ACLs banana aur interfaces par lagana.In this lab you'll learn Access Control Lists — building standard and extended (named) ACLs and applying them to interfaces.
آسان مثالSimple AnalogySimple Analogy
آفس کے دروازے پر گارڈ کے پاس دو lists ہیں۔ پہلی list صرف کہتی ہے 'اس محلے والے اندر آ سکتے ہیں' (standard ACL — صرف source دیکھتا ہے)۔ دوسری list تفصیل میں کہتی ہے 'اس بندے کو اس کمرے میں اس وقت جانے دو، لیکن اس کمرے میں نہیں' (extended ACL — source, destination, protocol, port سب دیکھتا ہے)۔ ACLs network کے دربان ہیں۔Office ke darwaze par guard ke paas do lists hain. Pehli list sirf kehti hai 'is mohalle wale andar aa sakte hain' (standard ACL — sirf source dekhta hai). Doosri list detail mein kehti hai 'is bande ko is kamre mein is waqt jane do, lekin us kamre mein nahi' (extended ACL — source, destination, protocol, port sab dekhta hai). ACLs network ke darban hain.The guard at the office door has two lists. The first says only 'people from this neighborhood may enter' (standard ACL — looks at source only). The second says in detail 'let this person into this room at this time, but not that room' (extended ACL — checks source, destination, protocol, and port). ACLs are the network's gatekeepers.
سیٹ اپLab SetupLab Setup
R1 کے G0/0 پر 192.168.10.0/24، G0/1 پر 192.168.20.0/24۔ ایک web server بھی 192.168.20.0 میں لگاؤ۔ Devices: 1x Router 2911 (R1), 1x Switch, 3x PC۔ PC1: 192.168.10.10/24، PC2: 192.168.10.11/24 (گیٹ وے .1)۔ PC3: 192.168.20.10/24 (گیٹ وے 192.168.20.1)۔R1 ke G0/0 par 192.168.10.0/24, G0/1 par 192.168.20.0/24. Ek web server bhi 192.168.20.0 mein lagao. Devices: 1x Router 2911 (R1), 1x Switch, 3x PC PC1: 192.168.10.10/24, PC2: 192.168.10.11/24 (gateway .1). PC3: 192.168.20.10/24 (gateway 192.168.20.1).R1's G0/0 has 192.168.10.0/24, G0/1 has 192.168.20.0/24. Also place a web server in 192.168.20.0. Devices: 1x Router 2911 (R1), 1x Switch, 3x PC. PC1: 192.168.10.10/24, PC2: 192.168.10.11/24 (gateway .1). PC3: 192.168.20.10/24 (gateway 192.168.20.1).
اقداماتStepsSteps
Step 1
R1 پر Standard ACL۔ ACL 10: 192.168.20.0 network کو deny، باقی سب کو permit۔R1 par Standard ACL. ACL 10: 192.168.20.0 network ko deny, baqi sab ko permit.Standard ACL on R1. ACL 10: deny the 192.168.20.0 network, permit everything else.
enable configure terminal access-list 10 deny 192.168.20.0 0.0.0.255 access-list 10 permit any
Step 2
پھر اسے G0/0 پر 'in' direction میں لگاؤ — مطلب اندر آنے والے traffic پر چیک ہوگا۔Phir isay G0/0 par 'in' direction mein lagao — matlab andar aane wale traffic par check hogaThen apply it on G0/0 in the 'in' direction — meaning incoming traffic gets checked.
interface g0/0 ip access-group 10 in exit
Step 3
Extended Named ACL۔ Named ACL میں نام ہوتا ہے (BLOCK-WEB)۔Extended Named ACL. Named ACL mein naam hota hai (BLOCK-WEB).Extended named ACL. A named ACL has a name (BLOCK-WEB).
ip access-list extended BLOCK-WEB deny tcp 192.168.10.0 0.0.0.255 any eq 80 deny tcp 192.168.10.0 0.0.0.255 any eq 443
Step 4
یہ کہتی ہے: 192.168.10.0 والوں کو web (port 80/443) پر نہیں جانے دینا، باقی سب allow۔ آخر میں permit ip any any ضروری — ورنہ implicit deny سب روک دے گا۔Ye kehti hai: 192.168.10.0 walon ko web (port 80/443) par nahi jane dena, baqi sab allow. Aakhir mein permit ip any any zaroori — warna implicit deny sab rok degaIt says: don't let 192.168.10.0 reach the web (ports 80/443), allow everything else. A final permit ip any any is required — otherwise the implicit deny blocks everything.
permit ip any any exit interface g0/0 ip access-group BLOCK-WEB in exit
Step 5
Testing: Standard ACL کے بعد PC3 سے ping کرو — fail ہونا چاہیے۔Testing: Standard ACL ke baad PC3 se ping karo — fail hona chahiye.Testing: after the standard ACL, ping from PC3 — it should fail.
Step 6
Extended ACL کے بعد PC1 سے web server کھولو — fail، لیکن ping pass ہونا چاہیے۔Extended ACL ke baad PC1 se web server kholo — fail, lekin ping pass hona chahiye.After the extended ACL, open the web server from PC1 — it should fail, but ping should pass.
تصدیقVerifyVerify
show access-lists سے matches دیکھو — کونسی line کتنی دفعہ لگی۔ show ip interface g0/0 سے لگی ہوئی ACL دیکھو۔show access-lists se matches dekho — kaunsi line kitni dafa lagi. show ip interface g0/0 se lagi hui ACL dekho.Check matches with show access-lists — how many times each line hit. See the applied ACL with show ip interface g0/0.
show access-lists show ip interface g0/0
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ ACL لگاتے ہی سب کچھ بند ہو گیا۔ACL lagate hi sab kuch band ho gaya.Everything stopped working as soon as I applied the ACL.
✅ ہر ACL کے آخر میں چھپا ہوا 'deny any' ہوتا ہے۔ ہمیشہ آخر میں permit ip any any (یا ضروری permits) لکھو۔Har ACL ke aakhir mein chhupa hua 'deny any' hota hai. Hamesha aakhir mein permit ip any any (ya zaroori permits) likho.Every ACL ends with a hidden 'deny any'. Always write permit ip any any (or the needed permits) at the end.
⚠️ ACL کام نہیں کر رہی، traffic گزر رہا ہے۔ACL kaam nahi kar rahi, traffic guzar raha hai.The ACL isn't working — traffic is passing through.
✅ 'in' کا مطلب interface میں داخل ہونے والا traffic۔ غلط direction پر ACL لگانے سے الٹا اثر ہوتا ہے۔'in' ka matlab interface mein dakhil hone wala traffic. Ghalat direction par ACL lagane se ulta asar hota hai.'in' means traffic entering the interface. Applying the ACL in the wrong direction gives the opposite result.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Standard اور Extended ACL میں فرق؟Standard aur Extended ACL mein farq?What's the difference between standard and extended ACLs?
Standard ACL (1-99) صرف source IP دیکھتی ہے۔ Extended ACL (100-199 یا named) source, destination, protocol اور port سب دیکھتی ہے۔Standard ACL (1-99) sirf source IP dekhti hai. Extended ACL (100-199 ya named) source, destination, protocol aur port sab dekhti hai.A standard ACL (1-99) looks only at the source IP. An extended ACL (100-199 or named) checks source, destination, protocol, and port.