当前位置:网站首页>Standard ACL and extended ACL
Standard ACL and extended ACL
2022-07-07 18:38:00 【Chen chacha__】
standard ACL
R0 Basic configuration
int f0/0
ip add 192.168.10.254 255.255.255.0
no shutdown
int f0/1
ip add 76.12.16.133 255.255.255.252
no shut
R1 Basic configuration
int f0/0
ip add 76.12.32.254 255.255.255.0
no shut
int f0/1
ip add 76.12.16.134 255.255.255.252
no shut
Then give them to R1、R2 Configure the default route
R1
ip route 0.0.0.0 0.0.0.0 76.12.16.133 #76.12.16.133 It is the next hop address connected to this router , It can also be written as the next hop port number connected to this router
R2
ip route 0.0.0.0 0.0.0.0 76.12.16.134 # ditto
standard ACL On the router near the destination address
stay R1 Upper configuration standard ACL
standard ACL The number of 1-99
ip access-list 1 permit host 192.168.10.100
ip access-list 1 deny host 192.168.10.1
interface f0/1
ip access-group 1 in
Expand ACL
R0 Basic configuration
int f0/0
ip add 192.168.10.254 255.255.255.0
no shutdown
int f0/1
ip add 76.12.16.133 255.255.255.252
no shut
R1 Basic configuration
int f0/0
ip add 76.12.32.254 255.255.255.0
no shut
int f0/1
ip add 76.12.16.134 255.255.255.252
no shut
Then give them to R1、R2 Configure the default route
R1
ip route 0.0.0.0 0.0.0.0 76.12.16.133 #76.12.16.133 It is the next hop address connected to this router , It can also be written as the next hop port number connected to this router
R2
ip route 0.0.0.0 0.0.0.0 76.12.16.134 # ditto
Expand ACL It is configured on the router close to the source address
stay R0 Configure extensions on ACL
Expand ACL The number of 100-199
You need an agreement 、 Source IP、 Source port 、 Purpose IP、 The destination ports match
ip access-list 100 deny icmp host 192.168.10.1 host 76.12.32.1 # Reject from 192.168.10.1 The host goes to 76.12.32.1 The host ping package
ip access-list 100 permit ip any any # Allow all
interface f0/1
ip access-group 100 out # take ACL Apply to the out interface
边栏推荐
猜你喜欢
元宇宙带来的创意性改变
Taffydb open source JS database
将模型的记忆保存下来!Meta&UC Berkeley提出MeMViT,建模时间支持比现有模型长30倍,计算量仅增加4.5%...
Chapter 3 business function development (user login)
保证接口数据安全的10种方案
万字保姆级长文——Linkedin元数据管理平台Datahub离线安装指南
Some key points in the analysis of spot Silver
小试牛刀之NunJucks模板引擎
4种常见的缓存模式,你都知道吗?
持续测试(CT)实战经验分享
随机推荐
卖空、加印、保库存,东方甄选居然一个月在抖音卖了266万单书
More than 10000 units were offline within ten days of listing, and the strength of Auchan Z6 products was highly praised
Rules for filling in volunteers for college entrance examination
RIP和OSPF的区别和配置命令
Kirk Borne的本周学习资源精选【点击标题直接下载】
What skills can you master to be a "master tester" when doing software testing?
2021年全国平均工资出炉,你达标了吗?
String type, constant type and container type of go language
回归测试的分类
Tips for short-term operation of spot silver that cannot be ignored
Sports Federation: resume offline sports events in a safe and orderly manner, and strive to do everything possible for domestic events
【Unity Shader】插入Pass实现模型遮挡X光透视效果
Afghan interim government security forces launched military operations against a hideout of the extremist organization "Islamic state"
Will domestic software testing be biased
Five network IO models
CVPR 2022丨学习用于小样本语义分割的非目标知识
【蓝桥杯集训100题】scratch从小到大排序 蓝桥杯scratch比赛专项预测编程题 集训模拟练习题第17题
Live broadcast software construction, canvas Text Bold
golang 客户端服务端登录
行业案例|数字化经营底座助力寿险行业转型