Skip to main content
PacketMentor logo
Open menu
← All simulators
Security Fundamentals Simulator

Standard ACL Simulator

Build a numbered or named standard ACL on R1. Send packets from PC-A/B/C to the server zone, watch them get permitted or denied. Implicit deny, shadow detection, and 6 exam scenarios baked in.

SOURCE ZONEDESTINATION ZONE — ACL APPLIED OUTBOUND HERE (close to destination)192.168.x.0/2410.0.0.0/24PC-ASales Dept192.168.1.10PC-BHR Dept192.168.2.10PC-CIT Dept · 192.168.3.10R1▶ ACL 10Gi0/1 outboundGi0/0Gi0/1FILE-SRV10.0.0.10File sharesMGMT-SRV10.0.0.20ManagementIP
0Sent
0Permitted
0Denied
0Rules
0Shadowed
📡 Send Test Packet
Source
To
Speed
⚙️ ACL 10 — Rule Builder
📍 Standard ACL Placement Rule: Standard ACLs filter SOURCE IP only — they cannot see the destination. Always apply them as close to the destination as possible to avoid accidentally blocking traffic to other networks. This ACL is applied outbound on Gi0/1 (toward the server zone).
Remark
Action
Src IP
⚠️ Shadow detected: these rules can never be reached:
    SeqActionSource IP / WildcardHitsOrder
    📋 Scenario:

    Practice — ACL fundamentals & edge cases

    Score: 0 / 0

    Mixed questions about ACL syntax, placement, wildcards, and exam traps. Next button on right and wrong.

    Question
    Drill this into reflex

    When a 'deny any' lands two rules too high

    1:1 mentorship with real ACL debug scenarios, lab reviews, and US interview prep. Free first session. No card on file.

    Claim my free session →