← CCNA: networking and production troubleshooting
06 / 7 · 25 MIN

Policy, identity, and secure management

Evaluate rules in order and validate identity before administration.

Concept and mechanism

A sequential ACL applies the first matching entry. A specific permit after a broad denial does not automatically take priority. Test relevant fields, direction, and interface; without a match, implicit denial can also block management. Before applying, define recovery access and examples of allowed and prohibited traffic. Counters help confirm which entry handled the request when the test window is known. Do not confuse ACL processing with routing’s longest prefix match: they are different mechanisms.

Guided application

DAI checks ARP information against trusted bindings according to configuration. A static server without a binding may need an explicit supported exception; trusting every port broadly removes protection. AAA also requires distinct functions: authentication identifies, authorization controls actions, and accounting records activity. In SSH, a key change following device replacement requires independent fingerprint confirmation and correlation with the approved change. Deleting every known association does not establish trust in the new key. Recovery should restore necessary access while preserving the ability to establish who did what.

IN PRACTICE

A /16 deny before a TCP/443 permit for a host in that block prevents the exception. Review order and also prove other flows remain blocked.

Common pitfalls

Using specificity as ACL priority; opening everything for diagnosis; confusing authentication with authorization; accepting unconfirmed keys.

Related topics: APIs, data, and AI-assisted decisions · Addressing, transport, and evidence

Take this idea with you

An access correction should preserve policy and identity evidence.

Create account

Reference: IP ACL overview · 200-301 CCNA v1.1