Default ACL Action

The default action when no ACLs are configured on a device is to permit all traffic. However, once you configure an ACL and apply it to a port or VLAN, the default action for that port or VLAN is to deny all traffic that is not explicitly permitted. Given these defaults, follow these guidelines for configuring and applying ACLs:

  • If you want to control access, configure ACLs consisting of permit entries for the access you want to permit. The ACLs implicitly deny all other access.
  • If you want to secure access in environments with many users, you may want to configure ACLs that consist of explicit deny entries and then add an entry to permit all access to the end of each ACL so that the software permits packets that are not denied by the deny entries.

Because by default traffic is restricted unless explicitly allowed once an ACL is applied to an interface or VLAN, an ACL can block packets switched between members of the same VLAN or subnet over a virtual interface with an ACL applied to the VLAN or a port in it. To overcome this issue, you must add explicit rules to the ACL allowing traffic from the sources you want to include.

Consider the following example.

vlan 200 by port
 untagged ethe 1/1/1 to 1/1/2 
 router-interface ve 200
!
interface ve 200
 ip address 192.168.1.1 255.255.255.0
!
ip access-list extended acl101
permit ip host 1.1.1.1 host 2.2.2.2 
!
ip access-list extended acl102
permit ip host 1.1.1.1 host 2.2.2.2 
permit ip 192.168.1.0 0.0.0.255 192.168.1.0 0.0.0.255 
!

host1 (192.168.1.10/24) is connected to 1/1/1 and host2 (192.168.1.11/24) is connected to 1/1/2.

If access-list acl101 is applied to VLAN 200, the hosts in it will not be able to communicate with each other. This is because acl101 includes an implicit deny filter at the end by default.

However, if access-list acl102 is applied to VLAN 200, the hosts in it will be able to communicate with each other. This is because the second statement of the ACL explicitly permits traffic within the subnet 192.168.1.0/24, to which the hosts belong.