Access control lists (ACLs) can filter or classify network traffic passing through a router. Standard ACLs check only the source IP address while extended ACLs check both source and destination addresses and specific protocols. ACLs can permit or deny traffic passing through the router, control virtual terminal access, and provide special handling of classified traffic. They are configured globally and applied to interfaces to filter inbound or outbound traffic.