Overview
In this chapter, you will learn how to create and apply access lists to control both traffic
flow and network security. In the process, you will review the use and rules of access lists.
The chapter introduces the creation of standard and extended IP access lists and explains
how to apply them to router interfaces. This chapter also describes how to monitor and
verify access lists, create named access lists, and configure access lists via Security Device
Manager.
Chapter Objectives
• Describe the usage and rules of access lists
• Establish standard IP access lists
• Produce extended IP access lists
• Apply access lists to interfaces
• Monitor and verify access lists
• Create named access lists
• Use Security Device Manager to create standard and extended IP access lists
• Use Security Device Manager to create a router firewall
Teaching Tips
Access Lists: Usage and Rules
1. Define access lists as permit or deny statements that filter traffic based on the source
address, destination address, protocol type, and port number of a packet.
2. Mention that access lists are available for IP, IPX, AppleTalk, and many other
protocols.
Access List Usage
1. Explain that you can create a standard access list that examines a packet for the packet’s
2. Mention that with careful planning, you can create access lists that control which traffic
crosses particular links, and which segments of your network will have access to others.