- 01Getting Started
- 02Understanding the Operating Modes of Network Devices
- 03Entering Privileged EXEC Mode with enable
- 04Entering Configuration Mode with configure terminal
- 05Renaming the Switch with hostname
- 06Moving Between Modes with exit and end
- 07Entering Port Configuration with interface
- 08Enabling a Port with no shutdown
- 09Assigning an IP Address with ip address
- 10Labeling a Port with description
- 11Viewing the Configuration with show running-config
- 12Listing Interfaces with show ip interface brief
- 13What Is a VLAN? Splitting a Network Logically
- 14Creating a VLAN with vlan
- 15Naming a VLAN with name
- 16Setting the Port Type with switchport mode
- 17Assigning a Port to a VLAN with switchport access vlan
- 18Listing VLANs with show vlan brief
- 19Adding a Static Route with ip route
- 20Viewing the Routing Table with show ip route
- 21Testing Reachability with ping
- 22Tracing the Path with traceroute
- 23Checking OS Information with show version
- 24Checking the Time with show clock
- 25Saving the Configuration with copy running-config startup-config
- 26Saving with write memory (the Short Form)
- 27Setting a Login Message with banner motd
- 28Configuring the Console Line with line console 0
- 29Setting a Password with password
- 30Requiring the Password at Login with login
- 31Configuring Remote Access with line vty 0 4
- 32Creating an Access List with access-list
- 33Checking Access Lists with show access-lists
- 34Viewing the MAC Address Table with show mac address-table
- 35Discovering Neighbors with show cdp neighbors
- 36Viewing the ARP Table with show arp
- 37Understanding Loop Prevention with spanning-tree mode
- 38Rebooting the Device with reload
- 39Hands-On: Configure a Small Office Network
Creating an Access List with access-list
When you want to allow or block traffic from specific networks only, use access-list. It defines rules — known as an ACL (access control list) — that permit or deny traffic.
The syntax is access-list number permit/deny source-ip. The number decides the ACL type (standard, extended, and so on), and rules are evaluated top to bottom.
Running access-list 10 permit 192.168.1.0 adds one rule to ACL number 10: permit traffic from the 192.168.1.0 network.
A common stumble is forgetting that creating an ACL by itself does nothing — it only takes effect once applied to an interface or vty line with access-group or similar.
In real work, ACLs are the core of security control: restricting management access to specific administrator IPs, limiting traffic between departments, and more.
🧑💻 You can type this command into the Networking pseudo terminal to try it yourself (this page itself has no interactive terminal).
