当前位置:网站首页>ACL实验演示(Huawei路由器设备配置)
ACL实验演示(Huawei路由器设备配置)
2022-07-26 16:53:00 【51CTO】
一、ACL介绍
ACL(Access Control List)访问控制列表,其目的是为了对某种访问进行控制,使用包过滤技术,在路由器上读取第三层及第四层包头中的信息如源地址、目的地址、源端口、目的端口等,根据预先定义好的规则对包进行过滤,从而达到访问控制的目的。
ps:华为默认允许通过数据包,思科默认拒绝通过。
二、ACL实验目的
允许技术部(192.168.3.0网段)访问服务器;
不允许事业部和外网访问服务器;
三、实验拓扑

四、实验配置
(1)R1配置
<Huawei>system-view
[Huawei]sysname R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.2.254 24
[R1-GigabitEthernet0/0/0]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 192.168.3.254 24
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]ip add 192.168.4.254 24
[R1-GigabitEthernet0/0/2]int g4/0/0
[R1-GigabitEthernet4/0/0]ip add 12.1.1.1 24
[R1-GigabitEthernet4/0/0]q
[R1]acl 3000
[R1-acl-adv-3000]rule 10 permit ip source 192.168.3.0 0.0.0.255 destination 192. 168.4.4 0
[R1-acl-adv-3000]rule 20 deny ip source 192.168.2.0 0.0.0.255 destination 192.16.4.4 0
[R1-acl-adv-3000]rule 30 deny ip source 12.1.1.0 0.0.0.255 destination 192.168.4.4 0
[R1-acl-adv-3000]q
[R1]int g0/0/2
[R1-GigabitEthernet0/0/2]traffic-filter outbound acl 3000
(2)R2配置
<Huawei>sys
[Huawei]sys R2
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.1.1.2 24
[R2]ip route-static 0.0.0.0 0 12.1.1.1
(3)用PC1 PC2 R2 ping Server1验证



用PC1 和 R2 ping Server1不通,PC2可以,实验验证成功。
边栏推荐
- 大家下午好,请教一个问题:如何从保存点启动一个之前以SQL提交的作业?问题描述:用SQL在cl
- 6-19漏洞利用-nsf获取目标密码文件
- leetcode:1206. 设计跳表【跳表板子】
- Summer Challenge openharmony greedy snake based on JS
- Definition of graph traversal and depth first search and breadth first search (I)
- Just this time! Talk about the technical solutions of distributed system in detail
- TD database syntax
- 性能调优bug层出不穷?这3份文档轻松搞定JVM调优
- Is it safe for Huishang futures to open an account online? What is the account opening process?
- Performance tuning bugs emerge in endlessly? These three documents can easily handle JVM tuning
猜你喜欢

我们被一个 kong 的性能 bug 折腾了一个通宵

图的遍历的定义以及深度优先搜索和广度优先搜索(一)

#夏日挑战赛# OpenHarmony基于JS实现的贪吃蛇

跨站点请求伪造(CSRF)

Method and voltage setting of exciting vibrating wire sensor with hand-held vibrating wire collector

Pay attention to the traffic safety warning of tourism passenger transport issued by the Ministry of public security

Ascend target detection and recognition - customize your own AI application

天翼云Web应用防火墙(边缘云版)支持检测和拦截Apache Spark shell命令注入漏洞

Definition of graph traversal and depth first search and breadth first search (I)

2019普及组总结
随机推荐
我们被一个 kong 的性能 bug 折腾了一个通宵
leetcode:1206. 设计跳表【跳表板子】
【机器学习】Mean Shift原理及代码
Eureka Registry - from entry to application
Redis persistence - detailed analysis of RDB source code | nanny level analysis! The most complete network
TD database syntax
常用超好用正则表达式!
A collection of commonly used shortcut keys for office software
Use replace regexp to add a sequence number at the beginning of a line
What are the popular technologies in 2022?
The user experience center of Analysys Qianfan bank was established to help upgrade the user experience of the banking industry
【云原生之kubernetes实战】安装kubeopertor教程
Everything is available Cassandra: the fairy database behind Huawei tag
浅析接口测试
[300 opencv routines] 240. Shi Tomas corner detection in opencv
Crazy God redis notes 02
SQL中去去重的三种方式
Summer Challenge openharmony greedy snake based on JS
JS 函数作用域 变量声明提升 作用域链 不加var的变量,是全局变量
the loss outweighs the gain! Doctors cheated 2.1 million yuan and masters cheated 30000 yuan of talent subsidies, all of which were sentenced!