ACL Drill Set 3 – Answers

By certskills October 19, 2015 09:05

This post makes no sense without the questions from the previous post, so check those out if you’ve not done so already. The questions list ACLs that were typed in a text editor, so they could list an IP address parameter that IOS will change, depending on the wildcard mask. Look below the fold to check your answers, and ask questions if you have them.

First, the repeated original 5 ACLs:

  1. access-list 1 permit
  2. access-list 2 permit
  3. access-list 3 permit
  4. access-list 4 permit
  5. access-list 5 permit

And now the answers. Note that of these, only the 5th ACL changes when copied into config mode on a router.

  1.  –
  2. –
  3. –
  4. –
  5. –
ACL Drill Set 3
Answers: OSPF Interface Config 1
By certskills October 19, 2015 09:05
Notify of

Your e-mail address will not be published.
Required fields are marked*


Newest Most Voted
Inline Feedbacks
View all comments
Taylor B
Taylor B
June 14, 2017 11:02 pm

Is answer 5 a mistake?
I got and that it would not change when added to the running config?

Did I do something wrong here?

Jesus D
Jesus D
Reply to  Taylor B
July 14, 2017 7:38 pm is not a Network, it’s an IP Address. means a range from a /21 network, which means jumps of 8 in the third octect (subnetting) -> -> … -> -> -> … ->

So the correct range for that network is: –

Reply to  Taylor B
July 21, 2017 9:36 am

Jesus summed it up nicely.
On your answer, you may have followed the process to just add the wildcard mask to the IP address/subnet listed to get the end of the range. However, the problem statement mentioned that the commands were in a text editor, to be pasted. IOS will take an access-list command, do the math like Jesus described, do the math to determine the range of IP addresses implied by the combined number and wildcard, and then change the first number if it’s not the first number in the range.

To do that math:
Invert the wildcard mask to turn it into a wildcard mask.
Do the same old subnetting math on the two numbers as IP address and SUBNET mask to find the range of addresses in the subnet
If the calculated “subnet number” isn’t the same number that was in the access-list command, IOS will change it to that value ( in this case).
Hope this helps…

December 10, 2021 10:36 am

Hello Wendell
I appreciate your great work. The concepts you have covered are very applicable and you covered them such a way that give me a sense of great understanding of the material…