networker050184 wrote: » What are you not understanding exactly? If the traffic you want to block with your ACL is coming into an interface then use an inbound ACL. If the traffic you want to block is going out an interface use an outbound ACL. It makes more sense usually to block inbound as close to the source as possible so the traffic doesn't have to traverse the network just to be dropped. I don't know if it's still taught this way, but the old rule of thumb for CCNA was standard ACL close to the destination as possible and extended close to the source. Not the biggest fan of that though as it always just depends on your network setup and goals.
Beany wrote: » can anyone point me to some ACL practice questions with answers? I think I'll get the hang of it with some testing questions.