Memory hook: Match the packet before you apply the rule.
Must remember
An ACL processes entries in order and normally stops on the first match, with an implicit deny at the end. Standard IPv4 ACLs primarily match source address; extended ACLs can match source, destination, protocol and ports. Interpret inbound/outbound relative to the interface, not to a vague “Internet direction.”
Wildcard masks use zero bits for comparison and one bits for “ignore.” 0.0.0.255 matches the varying last octet of a /24 pattern. Host/any shortcuts still express match scope. Test intended permitted and denied flows, including return traffic and essential DNS/DHCP/management paths.
Port security constrains learned/allowed source MAC addresses with configured violation behavior. It is not strong cryptographic device identity. DHCP snooping distinguishes trusted server paths and builds bindings; dynamic ARP inspection can use trustworthy bindings to reject invalid ARP claims. Configuration must account for static-address devices and legitimate infrastructure paths.
AAA separates authentication, authorization and accounting. Local accounts can support fallback; centralized RADIUS/TACACS+ improves policy consistency and attribution. Protect administrator sessions, store secrets appropriately and avoid locking out the recovery path when changing AAA.
IPsec site-to-site VPNs protect network-to-network tunnels; remote-access VPNs connect users/devices. Identity, routing and access policy remain required. Wireless WPA2/WPA3 and enterprise authentication protect different aspects from a web captive portal. Physical access controls, secure defaults and user awareness complete the picture.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Permit web from one subnet to one server | A correctly ordered extended ACL matching source, destination and port. |
| Reject rogue DHCP servers | Snooping with only legitimate server-facing paths trusted. |
| Record per-command device administration | Appropriate centralized AAA and accounting policy. |
Traps
- The implicit deny can block necessary traffic you forgot to allow.
- A permitted MAC address can be spoofed; it is not equivalent to certificate identity.
Active recall
1. What happens after the first ACL match?
The corresponding action is taken; later entries are not used for that packet.
2. What does wildcard bit 1 mean?
Ignore that bit for matching.
3. Inbound on an interface means what?
The packet is entering the device through that interface.
4. Why can ARP inspection break static clients?
They may lack expected dynamic bindings unless explicitly accommodated.
5. What should precede a risky AAA change?
A tested access/recovery plan and a controlled change procedure.