An Access Control List (ACL) is used to filter incoming or outgoing network traffic of an interface, whether it’s on a Cisco Router or Adaptive Security Appliance (ASA). Without Access Control List (ACL) any type of network traffic will be allowed to flow freely between networks/interfaces and this can be a security flaw.
Access Control List is a hierarchical set of statements that have matching criteria and an action that is triggered once the matching criteria are fulfilled. If the packet's detail does not match the first line, it moves to the second line, and so on until it gets a match. If none of the lines matches the packet's detail, the packet gets dropped. This is because of the inherent characteristic of an ACL, which is called implicit deny.
Ideally, an Access Control List would be configured on Layer 3 devices and would be applied...