Ä¿¡¡Â¼
1.8 ÅäÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©
1.15.7 »ùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨ÅäÖþÙÀý
1.15.9 ACL±¨ÎļÆÊýͳ¼ÆÅäÖþÙÀý
ACL£¨Access Control List£¬½Ó¼û½ÚÔìÁÐ±í£©Ò²³ÆÎª½Ó¼ûÁÐ±í£¬ÓеÄÎĵµÖл¹³ÆÖ®Îª°ü¹ýÂË¡£ACLͨ¹ý½ç˵һϵÁÐÔ̺¬¡°ÔÊÐí¡±»ò¡°»Ø¾ø¡±µÄ¹æ¶¨Óï¾ä£¬²¢½«ÕâЩ¹æ¶¨ÀûÓõ½É豸½Ó¿ÚÉÏ£¬¶Ô½ø³ö½Ó¿ÚµÄÊý¾Ý°ü½øÐнÚÔ죬´Ó¶øÌáÉýÍøÂçÉ豸µÄ°²È«ÐÔ¡£
ÅäÖÃACL¿ÉÄܱ£ÏÕÍøÂ簲ȫ¡¢¿¿µÃסºÍ²»±ä£¬ÀýÈ磺
l Ô¤·À±¨ÎĹ¥»÷£ºÕë¶ÔIP¡¢TCP»òÕßICMP±¨ÎĵĹ¥»÷£¬¶ÔÕâЩ¹¥»÷±¨ÎÄ×ö¡°»Ø¾ø¡±´¦Öá£
l ÍøÂç½Ó¼û½ÚÔ죺ÏÞ¶Å×û§½Ó¼û·þÎñ£¬ÀýÈçÖ»ÔÊÐí½Ó¼ûWWWºÍµç×ÓÓʼþ·þÎñ£¬ÆäËû·þÎñÈçTelnetÔò²»ÈÝ¡£»òÕßÖ»ÔÊÐíÔÚ¸ø¶¨µÄ¹¦·ò¶ÎÄÚ½Ó¼û£¬»òÕßÖ»ÔÊÐíÌØ¶¨Ö÷»ú½Ó¼ûÍøÂçµÈ¡£
l ÍøÂçÁ÷Á¿½ÚÔ죺½áºÏQoS¿ÉÒÔΪ³ÁÒªµÄÊý¾ÝÁ÷½øÐÐÓÅÏÈ·þÎñ±£ÕÏ¡£¹ØÓÚQoSµÄÅäÖÃÇë°Ý¼û¡°QoS¡±¡£
l ½Ó¼ûÁбí
½Ó¼ûÁбíÓУº¸ù»ù½Ó¼ûÁбíºÍ¶¯Ì¬½Ó¼ûÁÐ±í¡£
Óû§Äܹ»Æ¾¾Ý±ØÒªÑ¡Ôñ¸ù»ù½Ó¼ûÁбí»ò¶¯Ì¬½Ó¼ûÁÐ±í¡£Í¨³£Çé¿öÏ£¬Ê¹Óøù»ù½Ó¼ûÁбíÒѾ¿ÉÄÜÂú×㰲ȫ±ØÒª¡£µ«¹¥»÷Õß¿ÉÄÜͨ¹ýÈí¼þ¼ÙðԴµØÖ·ºýŪÉ豸£¬´Ó¶ø½Ó¼ûÍøÂç¡£¶ø¶¯Ì¬½Ó¼ûÁбíÔÚÓû§½Ó¼ûÍøÂçÒÔǰ£¬ÒªÇóͨ¹ýÉí·ÝÈÏÖ¤£¬Ê¹¹¥»÷ÕßÄÑÒÔ½Ó¼ûÍøÂç¡£ÔÚÃô¸ÐÇøÓòÄܹ»Ê¹Óö¯Ì¬½Ó¼ûÁÐ±í±£ÕÏÍøÂ簲ȫ¡£
×¢Ã÷
ͨ¹ý¼ÙðԴµØÖ·ºýŪÉ豸¼´µç×ÓºýŪÊÇËùÓнӼûÁбí¹ÌÓеÄÎÊÌ⣬ʹÓö¯Ì¬ÁбíÒ²»áÔâ·êµç×ÓºýŪÎÊÌ⣺¹¥»÷Õß¿ÉÄÜÔÚÓû§Í¨¹ýÉí·ÝÈÏÖ¤µÄÓÐЧ½Ó¼ûÆÚ¼ä£¬¼ÙðÓû§µÄµØÖ·½Ó¼ûÍøÂç¡£½â¾ö¸ÃÎÊÌâµÄ²½ÖèÓÐÁ½ÖÖ£¬Ò»ÖÖÊǾ¡Á¿ÉèÖøü¶ÌµÄÓû§½Ó¼û¿ÕÏй¦·ò£»ÁíÒ»ÖÖÊÇʹÓÃIPsec¼ÓÃܺÍ̸¶ÔÍøÂçÊý¾Ý½øÐмÓÃÜ£¬È·±£½øÈëÉ豸ʱ£¬ËùÓеÄÊý¾Ý¶¼ÊǼÓÃܵġ£
½Ó¼ûÁбíͨ³£ÅäÖÃÔÚÒÔϵØÎ»µÄÍøÂçÉ豸ÉÏ£º
¡ð ÄÚ²¿ÍøºÍ±í²¿Íø£¨ÈçInternet£©Ö®¼äµÄÉ豸
¡ð Á½¸öÍøÂç½ÓÈÀ²¿ÃŵÄÉ豸
¡ð ½ÓÈë½ÚÔì¶Ë¿ÚµÄÉ豸
ACE£¨Access Control Entry£¬½Ó¼û½ÚÔìÌõ¿î£©ÊÇÔ̺¬¡°ÔÊÐí£¨Permit£©¡±»ò¡°»Ø¾ø£¨Deny£©¡±Á½ÖÖ×÷Ϊ£¬ÒÔ¼°¹ýÂ˹涨µÄÒ»ÌõÓï¾ä¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ£¬¸ÃÐòºÅ¿ÉÓÉÉ豸×Ô¶¯·ÖÅä»òÕßÊÖ¶¯ÅäÖá£Ò»ÌõACLÖÐÔ̺¬Ò»¸ö»òÕß¶à¸öACE¡£ACLͨ¹ýACE¶ÔÊý¾Ý°ü½øÐбêʶ¹ýÂË¡£
ACLÖÐACEµÄ°¤´Î¾ö¶¨Á˸ÃACEÔÚ½Ó¼ûÁбíÖÐµÄÆ¥ÅäÓÅÏȼ¶¡£ÍøÂçÉ豸ÔÚ´¦Öñ¨ÎÄʱ£¬°´ACEµÄÐòºÅ´ÓÓ×µ½ÃͽøÐй涨ƥÅ䣬µ¹ØÒµ½Æ¥ÅäµÄACEºóÔòÖÕ³¡²é³ºóÐøµÄACE¡£
ÀýÈç´´½¨Ò»ÌõÐòºÅΪ10µÄACE£¬Ëü»Ø¾øËùÓеÄÊý¾ÝÁ÷ͨ¹ý¡£
10 deny ip any any
20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
ÓÉÓÚÐòºÅΪ10µÄACE»Ø¾øÁËËùÓеÄIP±¨ÎÄ£¬¼´±ã192.168.12.0/24ÍøÂçµÄÖ÷»úTelnet±¨ÎÄ£¬Äܹ»±»ÐòºÅΪ20µÄACEÆ¥Å䣬¸Ã±¨ÎÄÒ²½«±»»Ø¾ø¡£ÓÉÓÚÉ豸Ôڲ鳵½±¨ÎĺÍÐòºÅΪ10µÄACEÆ¥Åäºó£¬±ãÖÕ³¡²é³ºóÃæÐòºÅΪ20µÄACE¡£
ÓÖÀýÈç´´½¨Ò»Ìõ±àºÅΪ10µÄACE£¬ËüÔÊÐíËùÓеÄIPv6Êý¾ÝÁ÷ͨ¹ý¡£
10 permit ipv6 any any
20 deny ipv6 host 200::1 any
ÓÉÓÚÐòºÅΪ10µÄACEÔÊÐíËùÓеÄIPv6±¨ÎÄͨ¹ý£¬Ö÷»ú200::1·¢³öµÄIPv6±¨ÎÄ£¬¼´±ãÆ¥ÅäÐòºÅΪ20µÄACE£¬¸Ã±¨ÎÄÒ²½«±»ÔÊÐíͨ¹ý¡£ÓÉÓÚÉ豸Ôڲ鳵½±¨Îĺ͵ÚÒ»ÌõACEÆ¥Å䣬±ãÖÕ³¡²é³ºóÃæÐòºÅΪ20µÄACE¡£
l ²½³¤
µ±É豸ΪACE×Ô¶¯·ÖÅäÐòºÅʱ£¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ£¬³ÆÎª²½³¤¡£ÀýÈ磬ÈôÊǽ«²½³¤É趨Ϊ5£¬ÔòÉ豸ÒÀÕÕ5¡¢10¡¢15¡ÕâÑùµÄµÝÔö°¤´Î×Ô¶¯ÎªACE·ÖÅäÐòºÅ¡£ÈçÏÂËùʾ¡£
5 deny ip any any
10 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
µ±²½³¤Å¤×ªºó£¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤Öµ³ÁзÖÅä¡£ÀýÈ磬µ±°Ñ²½³¤¸ÄΪ10ºó£¬ÔÀ´ACEÐòºÅ´Ó5¡¢10¡¢15Ôì³É5¡¢15¡¢25¡£
ͨ¹ýŤת²½³¤Äܹ»ÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£ÀýÈç´´½¨ÁË4¸öACE£¬²¢Í¨¹ýÊÖ¶¯ÅäÖÃACEÐòºÅ±ðÀëΪ1¡¢2¡¢3ºÍ4¡£ÈôÊǵ«Ô¸ÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE£¬ÔòÄܹ»ÏȽ«²½³¤Åú¸ÄΪ2£¬´ËʱÔÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7£¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÅäÖõÄÐòºÅΪ2µÄACE¡£
l ¹ýÂËÓòÄ£°å
¹ýÂËÓòÖ¸µÄÊÇÌìÉúÒ»ÌõACEʱ£¬Æ¾¾Ý±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎĽøÐмø±ð¡¢·ÖÀà¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£ACEƾ¾ÝÒÔÌ«Íø±¨ÎĵÄijЩ×Ö¶ÎÀ´±êʶÒÔÌ«Íø±¨ÎÄ£¬ÕâЩ×Ö¶ÎÔ̺¬£º
¶þ²ã×ֶΣ¨Layer 2 Fields£©£º
¡ð 48λµÄÔ´MACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩
¡ð 48λµÄÖ÷ÕÅMACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩
¡ð 16λµÄ¶þ²ãÀàÐÍ×Ö¶Î
Èý²ã×ֶΣ¨Layer 3 Fields£©£º
¡ð Ô´IPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÔ´IPµØÖ·Öµ£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©
¡ð Ö÷ÕÅIPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÖ÷ÕÅIPµØÖ·Öµ£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©
¡ð ºÍ̸ÀàÐÍ×Ö¶Î
ËIJã×ֶΣ¨Layer 4 Fields£©£º
¡ð Äܹ»ÉêÃ÷Ò»¸öTCPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷£¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£
¡ð Äܹ»ÉêÃ÷Ò»¸öUDPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷£¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£
ÀýÈ磬ÔÚ´´½¨Ò»ÌõACEʱ±ØÒªÆ¾¾Ý±¨ÎĵÄÖ÷ÕÅIP×ֶΣ¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£¶øÔÚ´´½¨ÁíÒ»ÌõACEʱ£¬±ØÒªÆ¾¾Ý±¨ÎĵÄÔ´IPµØÖ·×ֶκÍUDPµÄÔ´¶Ë¿Ú×ֶΣ¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£ÕâÁ½ÌõACE¾ÍʹÓÃÁË·ÖÆçµÄ¹ýÂËÓòÄ£°å¡£
l ¹æ¶¨
¹æ¶¨£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£ÀýÈ磬һÌõACEµÄÄÚÈÝÈçÏ£º
10 permit tcp host 192.168.12.2 any eq telnet
ÔÚÕâÌõACEÖУ¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεļ¯ÖУºÔ´IPµØÖ·×ֶΡ¢Ö÷ÕÅIPµØÖ·×ֶΡ¢IPºÍ̸×ֶΡ¢TCPÖ÷ÕŶ˿Ú×ֶΡ£¶ÔÓ¦µÄÖµ£¨¼´¹æ¶¨£©±ðÀëΪ£ºÔ´IPµØÖ·ÎªHost 192.168.12.2¡¢Ö÷ÕÅIPµØÖ·ÎªAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPºÍ̸ΪTCP¡¢TCPÖ÷ÕŶ˿ÚΪTelnet¡£Èçͼ1-1Ëùʾ¡£
ͼ1-1 ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄ·ÖÎö
×¢Ã÷
¡ñ ¹ýÂËÓòÄ£°å¿ÉËùÒÔÈý²ã×ֶΣ¨Layer 3 Field£©ºÍËIJã×ֶΣ¨Layer 4 Field£©µÄ¼¯ÖУ¬Ò²¿ÉËùÒÔ¶à¸ö¶þ²ã×ֶΣ¨Layer 2 Field£©µÄ¼¯ÖС£µ«³ß¶ÈÓëÀ©´óACLµÄ¹ýÂËÓòÄ£°å²»ÄÜÊǶþ²ãºÍÈý²ã×ֶΡ¢¶þ²ãºÍËIJã×ֶΡ¢¶þ²ãºÍÈý²ã×ֶΡ¢ËIJã×ֶεļ¯ÖС£ÒªÊ¹Óöþ²ã¡¢Èý²ã¡¢ËIJã×ֶμ¯ÖУ¬Äܹ»ÀûÓÃר¼Ò¼¶À©´ó½Ó¼û½ÚÔìÁÐ±í¡£
¡ñ ³ö·½ÏòACL¹ØÁªSVI½Ó¿Ú£¨Switch Virtual Interface£¬»¥»»É豸Ðé¹¹½Ó¿Ú£©È·µ±¿àÖÔÏ֧³ÖIP³ß¶È¡¢IPÀ©´ó¡¢MACÀ©´óºÍר¼Ò¼¶ACLÀûÓá£
¡ñ ÈôÊÇÔÚMACÀ©´óºÍר¼Ò¼¶ACLÖÐÆ¥ÅäÖ÷ÕÅMAC£¬½«ÕâÑùµÄACLÀûÓõ½SVI½Ó¿ÚµÄ³ö·½Ïòʱ£¬±íÏî»á±»ÉèÖ㬵«ÎÞ·¨ÉúЧ¡£ÈôÊÇÏëÒªÔÚIPÀ©´ó£¬×¨¼Ò¼¶ACLÖÐÆ¥ÅäÖ÷ÕÅIP£¬¶øÖ÷ÕÅIP²»ÔÚËù¹ØÁªµÄSVI½Ó¿ÚµÄ×ÓÍøIPÁìÓòÄÚʱ£¬ÅäÖõÄACL½«ÎÞ·¨ÉúЧ¡£ÀýÈçVLAN 1µÄµØÖ·Îª192.168.64.1 255.255.255.0£¬´´½¨Ò»ÌõIPÀ©´óµÄACL£¬ACEΪdeny udp any 192.168.65.1 0.0.0.255 eq 255£¬½«¸ÃACLÀûÓõ½VLAN 1µÄ³ö¿Ú£¬½«ÎÞ·¨ÉúЧ¡£ÓÉÓÚÖ÷ÕÅIP²»ÔÚVLAN 1×ÓÍøIPÁìÓòÄÚ£¬ÈôÊÇACEΪdeny udp any 192.168.64.1 0.0.0.255 eq 255½«Äܹ»ÉúЧ£¬ÓÉÓÚÖ÷ÕÅIPÇкϻ®¶¨¡£
¡ñ ÓÉÓÚACL×ÊÔ´£¨TCAM/KEY/¶Ë¿Ú×é/RangeµÈ£©Êô¶¯Ì¬·ÖÅä×ÊÔ´£¬¼´ÒµÎñÏ·¢Ê±Õ½ÊõÕûºÏ»ïÔ´Ä£¿éƾ¾Ýµ±Ç°µÄACL×ÊÔ´Çé¿ö½øÐзÖÅ䣬Ïȵ½µÄÒµÎñÏÈ·ÖÅäACL×ÊÔ´£¬ºóµ½µÄÒµÎñÈôÊÇACL×ÊÔ´²»¹»¾Í»á´æÔÚACL×ÊÔ´·ÖÅäʧ°Ü£¬²¢ÌáÐÑÃýÎósyslog¡£É豸³ÁÆô¹ý³Ì»òÈȰβåµÈ´¥·¢Êý¾Ýͬ²½µÄ¹ý³Ì£¬¸÷ÒµÎñÎÞ·¨±£Õϰ´ÔÀ´µÄʱÐò½«ÒµÎñͬ²½£¬ÓпÉÄÜ´¥·¢ÓÉÓÚÒµÎñʱÐò²»Ò»Ñùµ¼ÖÂÕý±¾Äܹ»·ÖÅäµ½ACL×ÊÔ´µÄÒµÎñ·ÖÅä²»µ½ACL×ÊÔ´£¬ACL×ÊÔ´²»¼°»áÌáÐÑÃýÎósyslog¡£
²úÆ·/°æ±¾Ö§³ÖÇé¿ö
¡ñ ×÷ÓÃÔÚÎïÀí¿ÚºÍÈý²ã¾ÛºÏ½Ó¿ÚÉϵijö·½ÏòACL£¬½öÖ§³Ôì¥Åä³ÛÃû±¨ÎÄ£¨µ¥²¥¡¢×é²¥£©£¬²»Ö§³Ôì¥Åäδ³ÛÃûµ¥²¥£¬¼´¶ÔÓÚδ³ÛÃû±¨ÎÄ»òÕ߹㲥±¨ÎÄ£¬½Ó¿ÚÉÏÅäÖõijö·½ÏòACL²»ÉúЧ¡£
¡ñ Èë·½ÏòACLºÍ802.1x£¬È«¾ÖIPºÍMAC°ó¶¨£¬¶Ë¿Ú°²È«£¬IP Source Guard¹²ÓÃʱ£¬PermitºÍĬÈÏDenyµÄACE²»ÉúЧ£¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ¡£
¡ñ Èë·½ÏòACLºÍQoS¹²ÓÃʱ£¬Permit±íÏîµÄACE²»ÉúЧ£¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ£»Ä¬ÈÏDeny±íÏîµÄACEÔÚQoS±íÏîºóÉúЧ¡£
¡ñ ÓÉÓÚÓ²¼þÈÝÁ¿µÄÏÞ¶È£¬×÷ÓÃÔÚ¶à¸öSVI½Ó¿ÚµÄÈë·½ÏòACL£¬ÈôÊÇÔÙÔö³¤ACE£¬±£ÁôÅäÖóÁÆôºó¿ÉÄܵ¼Ö²¿ÃÅSVI½Ó¿ÚÉϵÄACLÎÞ·¨ÅäÖóɹ¦¡£
×¢Ã÷
¡ñ µ±ÅäÖÃר¼Ò¼¶µÄACL£¬²¢ÀûÓÃÔڽӿڵijö·½Ïòʱ£¬ÈôÊǸÃACLÖеÄijЩACEÔ̺¬Èý²ãÆ¥ÅäÐÅÏ¢£¨ÀýÈçIP£¬L4portµÈ£©£¬½«µ¼Ö´ÓÀûÓýӿڽøÈëµÄ·ÇIP±¨ÎÄÎÞ·¨ÊܸÃACLµÄPermitºÍDeny¹æ¶¨½ÚÔì¡£
¡ñ ÀûÓÃACLʱ£¬ÈôÊÇACL£¨Ô̺¬IP ACLºÍר¼Ò¼¶À©´óACL£©ÖеÄACEÆ¥ÅäÁ˷Ƕþ²ã×ֶΣ¬ÀýÈçÔ´IP£¬Ö÷ÕÅIPʱ£¬¶ÔÓÚ´ø±êÇ©µÄMPLS±¨ÎÄÆ¥ÅäÊÇÎÞЧµÄ¡£
IP ACLÖØÒªÓÃÓÚ¶Ô½ø³öÉ豸µÄIPv4±¨ÎĽøÐо«ÃÜ»¯½ÚÔ죬Óû§Äܹ»Æ¾¾ÝÏÖʵ±ØÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬´Ó¶øÊµÏÖ½ÚÔìIPÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£
ÔÚIP ACLÖнç˵һϵÁеĽӼû¹æ¶¨£¬²¢½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ£¬Ò²Äܹ»¶ÔIP ACL½øÐÐÈ«¾ÖÀûÓᣵ±IPv4±¨ÎĽø³öÉ豸ʱ£¬É豸ͨ¹ýÅжϱ¨ÎÄÊÇ·ñÓë¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£
ÒªÔÚÉ豸ÉÏÅäÖÃIP ACL£¬±ØÐëΪ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬ÒÔ±ãΨһ±êʼû¿¸ö½Ó¼ûÁÐ±í¡£
IP ACL·ÖΪIP³ß¶ÈACLºÍIPÀ©´óACL¡£±í1-1ÁгöÁËIP³ß¶ÈACLºÍIPÀ©´óACLÄܹ»Ê¹ÓõıàºÅÁìÓò¡£
±í1-1 IP³ß¶ÈACLºÍIPÀ©´óACL±àºÅÁìÓò
|
ÀàÐÍ |
±àºÅÁìÓò |
Æ¥ÅäÓò |
|
IP³ß¶ÈACL |
1~99£¬1300~1999 |
Ô´IPµØÖ· |
|
IPÀ©´óACL |
100~199£¬2000~2699 |
¡ñ Ô´IPµØÖ· ¡ñ Ö÷ÕÅIPµØÖ· ¡ñ IPºÍ̸ºÅ ¡ñ ËIJãÔ´¶Ë±êÓï»òICMP type ¡ñ ËIJãÖ÷ÕŶ˱êÓï»òICMP code |
IP³ß¶ÈACLÖØÒªÆ¾¾ÝÔ´IPµØÖ·½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£IPÀ©´óACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓòµÄ×éºÏ£¬½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£
¶ÔÓÚµ¥Ò»µÄ½Ó¼ûÁбíÀ´Ëµ£¬Äܹ»Ê¹ÓöàÌõ¶ÀÁ¢µÄ½Ó¼ûÁбíÓï¾äÀ´½ç˵¶àÖֹ涨£¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö½Ó¼ûÁÐ±í¡£
×¢Ã÷
ACL¹æ¶¨ÖеÄICMP codeÆ¥ÅäÓò¶ÔICMP typeΪ3µÄICMP±¨ÎÄÎÞЧ¡£ÈôÊÇACL¹æ¶¨ÖÐÅäÖÃÁËҪƥÅäICMP±¨ÎĵÄcode×ֶΣ¬µ±TypeΪ3µÄICMP±¨ÎĽøÈëÉ豸ִÐÐACLÆ¥Åäʱ£¬Æ¥ÅäÁ˾ֿÉÄÜÓëÔ¤ÆÚµÄ²»Ò»Ñù¡£
ÿ¸öIP ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨Óï¾ä¡£ÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Å䣬½«±»»Ø¾ø¡£ÈçÏÂÀý£º
access-list 1 permit host 192.168.4.12
´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ192.168.4.12µÄ±¨ÎÄͨ¹ý£¬ÆäËüÖ÷»ú¶¼½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º
access-list 1 deny any
ÓÖÀýÈ磺
access-list 1 deny host 192.168.4.12
ÈôÊÇÁбíÖ»Ô̺¬ÒÔÉÏÕâÒ»ÌõÓï¾ä£¬ÔòÈκÎÖ÷»ú±¨ÎÄͨ¹ý¸Ã½Ó¿Úʱ¶¼½«±»»Ø¾ø¡£
°ÑÎÈ
ÔÚ½ç˵½Ó¼ûÁбíµÄʱ³½£¬ÒªË¼¿¼µ½Â·Óɸüеı¨ÎÄ¡£ÓÉÓÚ½Ó¼ûÁбíĩβ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±£¬¿ÉÄܵ¼ÖÂËùÓеÄ·Óɸüб¨Îı»×è¶Ï¡£
MACÀ©´óACL»ùÓÚ±¨ÎĵĶþ²ãÐÅÏ¢À´¶Ô½ø³öÉ豸µÄ±¨ÎĽøÐо«ÃÜ»¯½ÚÔì¡£Óû§Äܹ»Æ¾¾ÝÏÖʵ±ØÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂ磬´Ó¶øÊµÏÖ½ÚÔì±£»¤ÍøÂç×ÊÔ´²»Êܹ¥»÷»òÕß½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£
ÔÚMACÀ©´óACLÖнç˵һϵÁеĽӼû¹æ¶¨£¬½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£µ±±¨ÎĽø³öÉ豸ʱ£¬É豸Åжϱ¨ÎÄÊÇ·ñÓë¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£
ÒªÔÚÉ豸ÉÏÅäÖÃMACÀ©´óACL£¬±ØÐëΪ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬ÒÔ±ãΨһ±êʼû¿¸ö½Ó¼ûÁÐ±í¡£±í1-2ÁгöMACÀ©´óACLµÄ±àºÅÁìÓò¡£
±í1-2 MACÀ©´óACL±àºÅÁìÓò
|
ºÍ̸ |
±àºÅÁìÓò |
Æ¥ÅäÓò |
|
MACÀ©´óACL |
700~799 |
¡ñ Ô´MACµØÖ· ¡ñ Ö÷ÕÅMACµØÖ· ¡ñ ÒÔÌ«ÍøºÍ̸ÀàÐÍ |
MACÀ©´óACLƾ¾ÝÔ´»òÖ÷ÕÅMACµØÖ·ÒÔ¼°±¨ÎĵÄÒÔÌ«ÍøÀàÐÍÀ´½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£
¶ÔÓÚµ¥Ò»µÄMACÀ©´óACLÀ´Ëµ£¬Äܹ»Ê¹ÓöàÌõ¶ÀÁ¢µÄ½Ó¼ûÁбíÓï¾äÀ´½ç˵¶àÖֹ涨£¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö½Ó¼ûÁÐ±í¡£
×¢Ã÷
ÈôÊÇMACÀ©´óACL¹æ¶¨ÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ£¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλò½ç˵µÄÒÔÌ«ÍøÀàÐÍ×Ö¶ÎÖµ²»ÊÇ0x86dd£¬ÄÇôMACÀ©´óACL²»Æ¥ÅäIPv6±¨ÎÄ¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ£¬ÇëʹÓÃIPv6 ACL¡£
ÿ¸öMACÀ©´óACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨Óï¾ä¡£ÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Å䣬½«±»»Ø¾ø¡£ÈçÏÂÀý£º
access-list 700 permit host 00d0.f800.0001 any
´ËÁбíÖ»ÔÊÐíÀ´×ÔMACµØÖ·Îª00d0.f800.0001µÄÖ÷»ú·¢³öµÄ±¨ÎÄͨ¹ý£¬À´×ÔÆäËüÖ÷»úµÄ±¨Îͼ½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º
access-list 700 deny any any
ר¼Ò¼¶À©´óACL»ùÓÚ±¨ÎĵĶþ²ãºÍÈý²ãÐÅÏ¢¶Ô½ø³öÉ豸µÄ±¨ÎĽøÐо«ÃÜ»¯½ÚÔì¡£Äܹ»½«×¨¼Ò¼¶À©´óACL¿´×÷ÊÇIP ACLºÍMACÀ©´óACLµÄÒ»ÖÖ½áºÏÓë¼ÓÇ¿¡£×¨¼Ò¼¶À©´óACLÖеĹ涨²»½öÄܹ»Ô̺¬IP ACL¹æ¶¨ºÍMACÀ©´óACL¹æ¶¨£¬»¹Äܹ»Ö¸¶¨»ùÓÚVLAN IDÀ´Æ¥Å䱨ÎÄ¡£
ÔÚר¼Ò¼¶À©´óACLÖнç˵һϵÁеĽӼû¹æ¶¨£¬²¢½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£±¨ÎĽø³öÉ豸ʱ£¬É豸¾Í»áͨ¹ýÅжϱ¨ÎÄÊÇ·ñÓë½Ó¼û¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£
ÒªÔÚÉ豸ÉÏÅäÖÃר¼Ò¼¶À©´óACL£¬±ØÐëΪºÍ̸µÄ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬ÒÔ±ãÔÚºÍ̸ÄÚ²¿¿ÉÄÜΨһ±êʼû¿¸ö½Ó¼ûÁÐ±í¡£±í1-3Áгöר¼Ò¼¶À©´óACLµÄ±àºÅÁìÓò¡£
±í1-3 ר¼Ò¼¶À©´óACLµÄ±àºÅÁìÓò
|
ºÍ̸ |
±àºÅÁìÓò |
Æ¥ÅäÓò |
|
ר¼Ò¼¶À©´óACL |
2700~2899 |
¡ñ Ô´IPµØÖ· ¡ñ Ö÷ÕÅIPµØÖ· ¡ñ IPºÍ̸ºÅ ¡ñ ËIJãÔ´¶Ë±êÓï»òICMP type ¡ñ ËIJãÖ÷ÕŶ˱êÓï»òICMP code ¡ñ Ô´MACµØÖ· ¡ñ Ö÷ÕÅMACµØÖ· ¡ñ ÒÔÌ«ÍøºÍ̸ÀàÐÍ ¡ñ VLAN ID |
ר¼Ò¼¶À©´óACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓò½øÐÐ×éºÏ£¬½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£
¶ÔÓÚµ¥Ò»µÄר¼Ò¼¶À©´óACLÀ´Ëµ£¬Äܹ»Ê¹ÓöàÌõ¶ÀÁ¢µÄ½Ó¼ûÁбíÓï¾äÀ´½ç˵¶àÖֹ涨£¬ÆäÖÐËùÓеÄÓï¾äÐèÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö½Ó¼ûÁÐ±í¡£
×¢Ã÷
ÈôÊÇר¼Ò¼¶À©´óACL¹æ¶¨ÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ£¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλòÒÔÌ«ÍøÀàÐÍ×ֶβ»ÊÇ0x86dd£¬ÄÇôר¼Ò¼¶À©´óACL²»Æ¥ÅäIPv6±¨ÎÄ¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ£¬ÇëʹÓÃIPv6 ACL¡£
²úÆ·/°æ±¾Ö§³ÖÇé¿ö
¡ñ
Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©´óACLÖУ¬VXLAN×Ö¶ÎÑ¡ÏîÖØÒªÊÇΪÁËÆ¥ÅäVXLANµÄÄڲ㱨ÎÄ£¬Òò¶øVXLANģʽÏÂÄܹ»ÀûÓÃר¼Ò¼¶ACLÆ¥ÅäVXLANµÄÄÚ²ãIP×ֶΡ£
¡ñ µ±É豸±ØÒªÆ¥ÅäVXLAN±¨ÎÄʱ£¬Äܹ»Ö¸¶¨VXLANºÍ̸Ö÷ÕŶ˱êÓïÓÃÓÚÈ·ÈÏVXLAN±¨ÎÄ£¬Í¬Ê±Äܹ»Ö¸¶¨Æ¥Åä¸ÃVXLAN±¨ÎÄÊÇ·ñЯ´øTag¡£
²úÆ·/°æ±¾Ö§³ÖÇé¿ö
Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©´óACLÖÐUDFÑ¡ÏîÊÇÓû§×Ô½ç˵×Ö¶ÎÆ¥ÅäÓò£¬ÓÉÓû§Ö¸¶¨±ØÒªÆ¥ÅäµÄºÍ̸²ã¡¢Æ«ÒÆÖµ¡¢Êý¾ÝºÍÑÚÂë¡£
ÿ¸öר¼Ò¼¶À©´óACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±¹æ¶¨Óï¾ä¡£ÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Å䣬½«±»»Ø¾ø¡£ÈçÏÂÀý£º
access-list 2700 permit 0x0806 any any any any any
´ËÁбíÖ»ÔÊÐíÒÔÌ«ÍøÀàÐÍΪ0x0806£¨¼´ARP£©µÄ±¨ÎÄͨ¹ý£¬ÆäËûÀàÐ͵ı¨Îͼ½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º
access-list 2700 deny any any any any
IPv6 ACLÖØÒªÓÃÓÚ¶Ô½ø³öÉ豸µÄIPv6±¨ÎĽøÐо«ÃÜ»¯½ÚÔì¡£Óû§Äܹ»Æ¾¾ÝÏÖʵ±ØÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂ磬´Ó¶øÊµÏÖ½ÚÔìIPv6Óû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£
ÔÚIPv6 ACLÖнç˵һϵÁеĽӼû¹æ¶¨£¬²¢½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£µ±IPv6±¨ÎĽø³öÉ豸ʱ£¬É豸Åжϱ¨ÎÄÊÇ·ñÓë¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£
ÒªÔÚÉ豸ÉÏÅäÖýӼûÁÐ±í£¬±ØÐëΪºÍ̸µÄ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ¡£
ÿ¸öIPv6 ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùÓÐIPv6Êý¾ÝÁ÷¡±¹æ¶¨Óï¾ä£¬Òò¶øÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Å䣬½«±»»Ø¾ø¡£ÈçÏÂÀý£º
ipv6 access-list ipv6_acl
?10 permit ipv6 host 200::1 any
´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ200::1µÄIPv6±¨ÎÄͨ¹ý£¬ÆäËüÖ÷»ú·¢³öµÄIPv6±¨Îͼ½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º
deny ipv6 any any
ר¼Ò¼¶¸ß¼¶ACL£¬¼´ACL80£¬Ò²³ÆÎª×Ô½ç˵ACL¡£ACL80Ö§³Ö¶Ô±¨ÎĵÄǰ80¸ö×Ö½ÚÖеÄÖ¸¶¨×Ö½Ú°´±ÈÌØÎ»½øÐÐÆ¥Åä¡£
ACL80Æ¥ÅäʱÓÐÈý¸öÉí·Ö£ºÆ¥ÅäÓòÄÚÈÝ¡¢Æ¥ÅäÓòÑÚÂëÒÔ¼°Æ¥ÅäµÄÕØÊ¼µØÎ»£¨¼´Æ«ÒÆÁ¿offset£©¡£Æ¥ÅäÓòÄÚÈÝºÍÆ¥ÅäÓòÑÚÂëÁ½ÕߵıÈÌØÎ»ÊÇÖðÒ»¶ÔÓ¦µÄ¡£Æ¥ÅäÓòÄÚÈÝÖ¸Ã÷±ØÒªÆ¥ÅäµÄ×Ö¶ÎÖµ£¬Æ¥ÅäÓòÑÚÂëÖ¸Ã÷¶ÔÓ¦±ÈÌØÎ»ÊÇ·ñ±ØÒªÆ¥Åä¡£µ±±ØÒªÆ¥Åäij¸ö±ÈÌØÎ»Ê±£¬±ØÐ뽫ƥÅäÓòÑÚÂëÖжÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ1¡£ÈôÊÇÆ¥ÅäÓòÑÚÂë¶ÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ0£¬ÎÞÂÛÆ¥ÅäÓòÄÚÈÝÖжÔÓ¦µÄ±ÈÌØÎ»ÊÇʲô£¬¶¼²»»áÆ¥Åä¡£ÀýÈ磺
10 permit 00d0f8123456 ffffffffffff 0
20 deny 00d0f8654321 ffffffffffff 6
ÔÚÐòºÅΪ10µÄACEÖУ¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8123456£¬Æ¥ÅäÓòÑÚÂëΪffffffffffff£¬Æ«ÒÆÁ¿Îª0¡£ÕâÌõÎÄÔò°µÊ¾ÈôÊDZ¨ÎĵÄÖ÷ÕÅMACΪ00d0f8123456£¬ÔòÔÊÐí±¨ÎÄת·¢¡£
ÔÚÐòºÅΪ20µÄACEÖУ¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8654321£¬Æ¥ÅäÓòÑÚÂëΪffffffffffff£¬Æ«ÒÆÁ¿Îª6¡£ÕâÌõÎÄÔò°µÊ¾ÈôÊDZ¨ÎĵÄÔ´MACΪ00d0f8654321£¬Ôò×è¶Ï¸Ã±¨ÎÄ¡£
ÕýȷʹÓÃ×Ô½ç˵½Ó¼û½ÚÔìÁÐ±í±ØÒª¶Ô¶þ²ãÊý¾ÝÖ¡½á¹¹ÓÐÉî¿ÌµÄÏàʶ¡£¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâÈçͼ1-2Ëùʾ¡£Í¼ÖÐÿ¸ö×Öĸ´ú±íÒ»¸öÊ®Áù½øÔìÊý£¬Ã¿Á½¸ö×Öĸ´ú±íÒ»¸ö×Ö½Ú¡£
ͼ1-2 ¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâͼ

¸÷¸ö×ÖĸµÄÔ¢Òâ¼°Æ«ÒÆÁ¿È¡ÖµÈç±í1-4Ëùʾ¡£
|
×Öĸ |
Ô¢Òâ |
Æ«ÒÆÁ¿ |
×Öĸ |
Ô¢Òâ |
Æ«ÒÆÁ¿ |
|
A |
Ö÷ÕÅMAC |
0 |
O |
TTL×Ö¶Î |
34 |
|
B |
Ô´MAC |
6 |
P |
ºÍ̸ºÅ |
35 |
|
C |
VLAN Tag×Ö¶Î |
12 |
Q |
IPУÑéºÍ |
36 |
|
D |
Êý¾ÝÖ¡³¤¶È×Ö¶Î |
16 |
R |
Ô´IPµØÖ· |
38 |
|
E |
DSAP(Ö÷ÕÅ·þÎñ½Ó¼ûµã)×Ö¶Î |
18 |
S |
Ö÷ÕÅIPµØÖ· |
42 |
|
F |
SSAP(Ô´·þÎñ½Ó¼ûµã)×Ö¶Î |
19 |
T |
TCPÔ´¶Ë¿Ú |
46 |
|
G |
Ctrl×Ö¶Î |
20 |
U |
TCPÖ÷ÕÅ¶Ë¿Ú |
48 |
|
H |
Org Code×Ö¶Î |
21 |
V |
ÐòÁкŠ|
50 |
|
I |
·â×°µÄÊý¾ÝÀàÐÍ |
24 |
W |
È·ÈÏ×Ö¶Î |
54 |
|
J |
IP°æ±¾ºÅ |
26 |
XY |
IPÍ·³¤¶ÈºÍ±£Áô±ÈÌØÎ» |
58 |
|
K |
TOS×Ö¶Î |
27 |
Z |
±£Áô±ÈÌØÎ»ºÍFlags±ÈÌØÎ» |
59 |
|
L |
IP°üµÄ³¤¶È |
28 |
a |
Windows Size×Ö¶Î |
60 |
|
M |
IDºÅ |
30 |
b |
ÆäËû |
62 |
|
N |
Flags×Ö¶Î |
32 |
|
|
|
±íÖи÷¸ö×Ö¶ÎµÄÆ«ÒÆÁ¿ÊÇËüÃÇÔÚSNAP£«TagµÄ802.3Êý¾ÝÖ¡ÖÐµÄÆ«ÒÆÁ¿¡£ÔÚ×Ô½ç˵½Ó¼û½ÚÔìÁбíÖУ¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿£¬´ÓÊý¾ÝÖ¡µÄǰ80¸ö×Ö½ÚÖÐÌáȡָ¶¨×Ö½Ú£¬ÔÙºÍÆ¥ÅäÓòÄÚÈݱÈÁ¦£¬´Ó¶ø¶Ô±¨ÎÄ×÷ÏàÓ¦µÄ´¦Öá£ÀýÈ磬Óû§ÔÊÐíËùÓеÄTCP±¨ÎÄת·¢£¬ÔòÄܹ»½«Æ¥ÅäÓòÄÚÈݽç˵Ϊ¡°06¡±£¬Æ¥ÅäÓòÑÚÂë½ç˵Ϊ¡°ff¡±£¬Æ«ÒÆÁ¿½ç˵Ϊ35¡£´´½¨ÐòºÅΪ10µÄACEÈçÏ¡£
10 permit 06 ff 35
½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£µ±±¨ÎĽø³öÉ豸ʱ£¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿£¬´ÓÊý¾ÝÖ¡Öн«TCPºÍ̸ºÅ×ֶεÄÄÚÈÝÌáÈ¡³öÀ´£¬ÔÙºÍÆ¥ÅäÓòÄÚÈݱÈÁ¦£¬Æ¥Åä³öËùÓеÄTCP±¨ÎIJ¢½øÐÐת·¢¡£
ACL³Á¶¨ÏòµÄ×÷ÓÃÊǽ«ÇкϹ涨µÄ±¨ÎijÁ¶¨ÏòÖÁÖ¸¶¨½Ó¿Úת·¢£¬»òÔÚÖ¸¶¨½Ó¿ÚÉÏץȡ±¨ÎļÓÒÔ·ÖÎö¡£
ACL³Á¶¨ÏòÔÚÖ¸¶¨½Ó¿ÚÉÏ°ó¶¨·ÖÆçµÄACLÕ½Êõ£¬²¢¸øÃ¿¸öÕ½ÊõÖ¸¶¨Ò»¸öÊä³ö½Ó¿Ú¡£µ±¸Ã½Ó¿ÚÊÕµ½±¨ÎÄʱ£¬½«ÖðÌõ²éÕÒ°ó¶¨ÔڸýӿÚÉϵÄACLÕ½Êõ¡£ÈôÊDZ¨ÎÄÇкÏijÌõÕ½ÊõÃèÊöµÄÌØµã£¬½«´Ó¸ÃÕ½ÊõËùÖ¸¶¨µÄÊä³ö½Ó¿Úת·¢¡£
ÓÉÓÚÍøÂçÖдæÔÚ¸÷Àಡ¶¾±¨ÎÄ£¬ÇÒ¸÷¶Ë¿ÚϵIJ¡¶¾±¨Îļø±ðÌØµãÒ»Ñù»òÀàËÆ¡£¶Ë¿Ú°²È«ACL³£±»ÅäÖÃ×÷Ϊ²¡¶¾±¨ÎĹýÂ˼°·À±¸Ê¹Óã¬ÓÃÓÚ¹ýÂËÇкÏÄ³Ð©ÌØµãµÄ±¨ÎÄ£¬ÀýÈ磺αÔìµÄTCP¹¥»÷±¨ÎÄ¡£Í¨¹ý´´½¨ACL²¢Ôö³¤Æ¥Åä¸÷Àಡ¶¾±¨ÎÄÌØµãµÄACEºó£¬½«ACLÀûÓõ½É豸¸÷¸ö¶Ë¿Ú£¬´ïµ½¹ýÂ˲¡¶¾±¨ÎĵÄ×÷Ó᣶˿ڰ²È«ACLÓÃÓÚ²¡¶¾¹ýÂ˵ȿ¹¹¥»÷³¡¾°Ê±£¬´æÔڽ϶಻±ã¡£
l ¶Ë¿Ú±ØÒªÖð¸öÅäÖᣴæÔÚ³Á¸´ÅäÖᢲÙ×÷»úÄܵÍϼ°ACL×ÊÔ´¹ý¶È¿÷ËðµÄÇé¿ö¡£
l °²È«ACLµÄ½Ó¼û½ÚÔì×÷Óñ»Èõ»¯¡£ÓÉÓÚ±»ÓÃÓÚ²¡¶¾¹ýÂË£¬°²È«ACLµÄÏÞ¶È·ÓɸüС¢ÏÞ¶ÈÍøÂç½Ó¼ûµÈ¸ù»ùÖ°ÄÜÎÞ·¨Õý³£Ê¹Óá£
È«¾Ö°²È«ACLÄܹ»ÔÚ²»Ó°Ïì¶Ë¿Ú°²È«ACLµÄÇé¿öÏ£¬½øÐÐÈ«¾Ö¿¹²¡¶¾²¿Êð¼°·ÀÓù¡£È«¾Ö°²È«ACLÖ»±ØÒªÒ»ÌõºÅÁî¼´ÔÚËùÓжþ²ã½Ó¿ÚÉÏÉúЧ¡£
µ±È«¾Ö°²È«ACLÓë¶Ë¿Ú°²È«ACLͬʱÅäÖÃʱ£¬Á½Õß¹²Í¬ÉúЧ¡£¶ÔÓÚÆ¥ÅäÈ«¾Ö°²È«ACL¹æ¶¨µÄ±¨ÎĽ«±»µ±×÷²¡¶¾±¨ÎÄÖ±½Ó¹ýÂË£¬¶ÔÓÚûÓÐÆ¥ÅäÈ«¾Ö°²È«ACL¹æ¶¨µÄ±¨ÎĽ«³ÖÐøÊܶ˿ڰ²È«ACL½ÚÔì¡£ÈôÊÇÏëÈÃijЩ¶Ë¿Ú²»ÊÜÈ«¾Ö°²È«ACLµÄ½ÚÔ죬Äܹ»ÔÚÕâЩ½Ó¿ÚÉ϶ÀÁ¢¹Ø¹ØÈ«¾Ö°²È«ACLÖ°ÄÜ¡£µ±È«¾Ö¡¢½Ó¿ÚºÍVLANµÄ°²È«ACLͬʱÀûÓÃʱ£¬ÓÅÏȼ¶½Ó¿Ú > VLAN > È«¾Ö¡£
ΪÁËÔ¤·ÀÈ«¾Ö°²È«ACL±»ÎóÅäÖã¬ÐÂÔöÈ«¾Ö°²È«ACLÎÞЧ¿ª¹Ø¡£ÅäÖÃÈ«¾Ö°²È«ACLÎÞЧºó£¬ÔÙÅäÖÃÈ«¾Ö°²È«ACL£¬»áÌáÐÑÅäÖÃʧ°Ü¡£ÈôÊÇÒѾÅäÖÃÁËÈ«¾Ö°²È«ACL£¬ÔÙÅäÖÃÈ«¾Ö°²È«ACLÎÞЧ£¬ÄÇô»á½«µ±Ç°ËùÓÐÈ«¾Ö°²È«ACLɾ³ý£¬²¢¸ø³öÈÕÖ¾ÌáÐÑ¡£
ÀûÓÃÔÚSVI½Ó¿ÚÉϵĽӼûÁÐ±í£¨¼´SVI ACL£©»áͬʱ¶ÔVLANÄÚ¶þ²ãת·¢µÄ±¨Îļ°VLAN¼äµÄ·Óɱ¨ÎÄÉúЧ£¬´Ó¶øµ¼ÖÂͳһVLANÄÚ·ÖÆçÓû§Ö®¼äÎÞ·¨Õý³£Í¨Ñ¶µÈÒì³£¾°Ïó¡£Ê¹ÓÃSVI Router ACLÖ°ÄÜÄܹ»Ê¹ÀûÓÃÔÚSVI½Ó¿ÚÉϵĽӼûÁбí½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£
ȱʡÇé¿öÏ£¬SVI Router ACLÖ°ÄÜĬÈϹعء£SVI ACLͬʱ¶ÔVLAN¼äµÄÈý²ãת·¢±¨Îļ°VLANÄÚµÄÇÅת·¢±¨ÎÄÉúЧ¡£SVI Router ACLÖ°ÄÜ¿ªÆôºó£¬SVI ACL½ö¶ÔVLAN¼äµÄÈý²ãת·¢±¨ÎÄÉúЧ¡£
±¨ÎÄÆ¥ÅäÈÕÖ¾ÓÃÓÚ¼à¿Ø½Ó¼ûÁÐ±í¹æ¶¨µÄÔËÐÐ״̬£¬ÎªÈÕ³£ÍøÂçÊØ»¤ÒÔ¼°ÍøÂçÓÅ»¯Ìṩ±ØÒªµÄÐÅÏ¢¡£
ΪÁËÈÃÓû§¸üºÃµÄ°ÑÎÕACLÔÚÉ豸ÖеÄÔËÐÐ״̬£¬ÔÚÔö³¤ACEʱÄܹ»Æ¾¾Ý±ØÒª¾ö¶¨ÊÇ·ñÖ¸¶¨±¨ÎÄÆ¥ÅäÈÕÖ¾Êä³öÑ¡Ïî¡£ÈôÊÇÖ¸¶¨Á˸ÃÑ¡ÏÔòµ±ACEÆ¥Åäµ½±¨ÎÄʱÊä³öÆ¥ÅäÈÕÖ¾ÐÅÏ¢¡£ACL»ùÓÚACE´òÓ¡ÈÕÖ¾ÐÅÏ¢£¬¼´É豸ÖÜÆÚÐԵĴòÓ¡Æ¥Å䱨ÎĵÄACEÐÅÏ¢£¬ÒÔ¼°Æ¥ÅäµÄ±¨ÎÄÊýÁ¿¡£ÈçÏ£º
*Sep¡¡9 16:23:06: %ACL-6-MATCH: ACL 100 ACE 10 permit icmp any any, match 78 packets.
ΪºÏÀí½ÚÔìÈÕÖ¾Êä³öµÄÊýÁ¿ºÍƵÂÊ£¬ACLÖ§³ÖÅäÖÃÈÕÖ¾Êä³ö¾àÀëµÄÅäÖá£
°ÑÎÈ
¡ñ ´øÈÕ־ѡÏîµÄ½Ó¼ûÁÐ±í¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐÈÕ־ѡÏÔò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£
¡ñ ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖýӼûÁÐ±í¹æ¶¨Ê±Ö¸¶¨ÁËÈÕ־ѡÏîºó£¬»¹±ØÒªÅäÖÃÊä³ö¾àÀ룬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£
¡ñ ¶ÔÓÚ´øÈÕ־ѡÏîµÄ¹æ¶¨£¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬Ôò¹¦·ò¾àÀëµ½ÆÚºó£¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý£¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£
²úÆ·/°æ±¾Ö§³ÖÇé¿ö
½öÖ§³ÖΪIP ACLºÍIPv6 ACL¹æ¶¨ÅäÖÃÈÕ־ѡÏî¡£
³öÓÚÍøÂçÖÎÀíµÄ±ØÒª£¬Óû§¿ÉÄÜÏë֪·ijÌõ½Ó¼ûÁÐ±í¹æ¶¨ÊÇ·ñÆ¥Åäµ½±¨ÎÄÒÔ¼°Æ¥ÅäÊýÁ¿¡£ACLÌṩÁË»ùÓڹ涨µÄ±¨ÎÄÆ¥Å伯ÊýÖ°ÄÜ¡£Óû§Äܹ»»ùÓÚACL¿ªÆôºÍ¹Ø¹Ø¸ÃACLϵÄËùÓй涨µÄ±¨ÎÄÆ¥Å伯ÊýÖ°ÄÜ¡£µ±Óб¨ÎÄÆ¥Åäµ½ÁËÕâÌõÎÄÔò£¬¶ÔÓ¦µÄÆ¥Å伯Êý¾ÍÏàÓ¦µØÔö³¤¡£Óû§¿Éͨ¹ýACLµÄͳ¼Æ¶Ï¸ùºÅÁ¸ÃACLÏÂËùÓй涨µÄ±¨ÎÄÆ¥Å伯ÊýÇåÁ㣬ÒÔ±ã³ÁÐÂͳ¼Æ¡£
°ÑÎÈ
¿ªÆôACLµÄ±¨ÎÄÆ¥Å伯ÊýÖ°ÄܱØÒª¸ü¶àµÄÓ²¼þ±íÏ¼«¶ËÇé¿öÏ»áʹÉ豸Äܹ»ÅäÖõÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£
²úÆ·/°æ±¾Ö§³ÖÇé¿ö
ÔÚIP ACL¡¢MACÀ©´óACL¡¢×¨¼Ò¼¶À©´óACLºÍIPv6 ACLÉÏ¿ªÆô±¨ÎÄÆ¥Å伯ÊýÖ°ÄÜ¡£
ÈôÊÇÓû§±ØÒªÔÚÖ¸¶¨µÄ¹¦·ò¶ÎÄÚ¶ÔijЩÁ÷Á¿½øÐнÚÔ죬ÀýÈ磬²»ÈÝÔÚ¹¤×÷¹¦·òʹÓÃ̸Ì칤¾ß¡£Äܹ»Í¨¹ýÅäÖÃACEµÄÉúЧ¹¦·ò¶Î£¬½ÚÔìÁ÷Á¿Í¨¹ýµÄ¹¦·ò¡£¹¦·ò¶Î·ÖΪ¾ø¶Ô¹¦·òºÍÖÜÆÚ¹¦·òÁ½ÖÖ¡£
¾ø¶Ô¹¦·ò°µÊ¾Ò»¸öÖ¸¶¨ÕØÊ¼¹¦·òÒÔ¼°ÊµÏÖ¹¦·òµÄ¹¦·òÇø¼ä¡£¸Ã¹¦·òÇø¼ä²»»áÑ»·³öÏÖ£¬Ò²Ã»ÓÐÖÜÆÚ¡£ÀýÈç¡°2000Äê1ÔÂ1ÈÕ12£º00£º00ÖÁ2001Äê1ÔÂ1ÈÕ12£º00£º00¡±¡£
ÖÜÆÚ¹¦·ò°µÊ¾Ò»¸öÖÜÆÚÐԵŦ·òÇø¼ä¡£ÀýÈ硰ÿÖÜÒ»8£º00µ½Ã¿ÖÜÎå17£º00¡±¡£
¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£
ʹÓ÷Ô쬱¨ÎÄÆ¥ÅäģʽÄܹ»Ê¹½Ó¼ûÁбí¶Ô·Ô쬱¨ÎĽøÐиü¾«ÃÜ»¯µÄ½ÚÔì¡£
¶ÔÓÚIP±¨ÎÄ£¬ÔÚÍøÂç´«ÊäʱÖпÉÄܻᱻ·Ô쬡£±¨ÎIJúÉú·Ôì¬Ê±£¬Ö»ÓÐÊׯ¬±¨ÎÄ´øÓÐËIJãÐÅÏ¢£¬ÀýÈçTCP»òUDP¶Ë±êÓï¡¢ICMPÀàÐͺÍICMP±àÂëµÈ£¬ÆäËûµÄ·Ô쬱¨Îͼ²»´øÓÐÕâЩËIJãÐÅÏ¢¡£ÔÚĬÈϵķÔ쬱¨ÎÄÆ¥ÅäģʽÏ£¬ÈôÊÇACL¹æ¶¨´øÓÐFagment±êʶ£¬ÔòÖ»»áÆ¥Åä·ÇÊׯ¬±¨ÎÄ£»ÈôÊÇACL¹æ¶¨²»´øÓÐFragment±êʶ£¬ÔòÆ¥ÅäËùÓб¨ÎÄ£¬Ô̺¬Êׯ¬±¨ÎĺͺóÐøµÄËùÓзÔ쬱¨ÎÄ¡£³ýÁËĬÈϵķÔ쬱¨ÎÄÆ¥Åäģʽ±í£¬»¹ÌṩÁíÒ»ÖÖеķÔ쬱¨ÎÄÆ¥Åä²½Ö裬Óû§Äܹ»Æ¾¾Ý±ØÒªÔÚÖ¸¶¨µÄACLÉϽøÐÐÇл»¡£ÔÚеķÔ쬱¨ÎÄÆ¥ÅäģʽÏ£¬µ±ACL¹æ¶¨²»´øÓÐFragment±êʶ£¬ÈôÊDZ¨Îı»·Ô쬣¬Êׯ¬±¨ÎÄ»áÆ¥Å乿¶¨ÖÐÓû§½ç˵µÄËùÓÐÆ¥ÅäÓò(Ô̺¬Èý²ãºÍËIJãÐÅÏ¢)£¬¶ø·ÇÊׯ¬±¨ÎÄÔòÖ»»áÆ¥Å乿¶¨ÖеķÇËIJãÐÅÏ¢¡£
²úÆ·/°æ±¾Ö§³ÖÇé¿ö
¡ñ ½öÔÚIPÀ©´óACLºÍר¼Ò¼¶À©´óACLÉÏÖ§³Ö·Ô쬱¨ÎÄÆ¥ÅäģʽµÄÇл»¡£
ÔÚijЩÀûÓó¡¾°ÖУ¬±ØÒª°ó¶¨ACLÏÞ¶ÈÔ´IP¶ÔTCPÎÕÊÖÊ×°ü½øÐд¦Ö㬶ø²»ÊdzÉÁ¢TCPÏνӺóÔÙ½øÐÐÏÞ¶È¡£Ê¹ÓÃÈ«¾Ö½ÚÔìÃæACLʵÏÖ½öÈí¼þ¹ýÂË£¬²»½öÄܹ»Ï÷¼õ¶ÔÓ²¼þ×ÊÔ´µÄ¿÷Ë𣬲¢ÇÒ¿ÉÄÜÂú×ã¶ÔTCPÊ×°ü½øÐд¦ÖõÄÐèÒª¡£½«°²È«ACLͨ¹ý½ÚÔìÃæÀûÓúÅÁîÀûÓõ½È«¾Ö£¬°µÊ¾¸ÃACL½öÈí¼þÉúЧ¡£
È«¾Ö½ÚÔìÃæACLÔÚËùÓжþ²ãÒÔÌ«Íø½Ó¿ÚÉÏÉúЧ£¬ACL±íÏî²»ÀûÓõ½Ó²¼þ£¬½ö¶ÔÈí¼þÉúЧ£¬´Ó¶øÏ÷¼õ¶ÔÓ²¼þ×ÊÔ´µÄËðºÄ£»µ±½øÐÐTCPÎÕÊÖʱ£¬Èí¼þACL¶ÔTCPÊ×°ü½øÐв鳣¬¶ÔÓÚÉäÖÐACLµÄTCP±¨ÎĽøÐйýÂË£¬ÊµÏÖ¶ÔÊ×°ü¹ýÂ˵ÄÖ÷ÕÅ¡£
×¢Ã÷
¡ñ È«¾Ö½ÚÔìÃæACL½ö¶ÔÈí¼þ¹ýÂËÉúЧ¡£
¡ñ È«¾Ö½ÚÔìÃæACL²»ÊÜÈ«¾ÖACLÀý±í¿ÚÅäÖÃÏÞ¶È£¬ÅäÖÃÀý±í¿ÚºóÈ«¾Ö½ÚÔìÃæACLÒÀÈ»ÉúЧ
¡ñ È«¾Ö½ÚÔìÃæACLÄܹ»ÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ£¬Ò²Äܹ»ÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¼´Äܹ»ÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£ÔÚSVI½Ó¿ÚºÍ¾ÛºÏ³ÉÔ±½Ó¿ÚÉϲ»ÉúЧ¡£
ACLÅäÖù¤×÷ÈçÏ£º
(1) ÅäÖÃACL¡£ÒÔÏÂÅäÖù¤×÷ÇëÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð
ÅäÖÃIPv6 ACL
(2)
£¨¿ÉÑ¡£©ÅäÖÃACL³Á¶¨Ïò
(3)
£¨¿ÉÑ¡£©ÅäÖÃÈ«¾Ö°²È«ACL
(4)
£¨¿ÉÑ¡£©ÅäÖ÷Ô쬱¨ÎÄÆ¥Åäģʽ
(5)
£¨¿ÉÑ¡£©ÅäÖÃSVI Router ACL
(6) £¨¿ÉÑ¡£©ÅäÖÃACL¹ÊÕϸ´Ô
´´½¨ºÍÀûÓÃIP³ß¶ÈACL£¬¶Ô½Ó¿ÚÉϽø³öµÄIPv4±¨ÎĽøÐнÚÔ죬²»ÈÝ»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬´Ó¶øÊµÏÖ½ÚÔìIPÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£
l ÈôÊÇÖ»Ïëͨ¹ý²é³±¨ÎĵÄÔ´IPµØÖ·À´½ÚÔìÓû§µÄÍøÂç×ÊÔ´½Ó¼ûȨÏÞ£¬ÄÇôÄܹ»ÅäÖÃIP³ß¶ÈACL¡£
l IP³ß¶ÈACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£IP³ß¶ÈACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
IP³ß¶ÈACLÅäÖù¤×÷ÈçÏ£º
(1)
´´½¨IP³ß¶ÈACL
(2)
ÀûÓÃIP³ß¶ÈACL
´´½¨IP³ß¶ÈACL²¢ÅäÖù涨¡£
l IP³ß¶ÈACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ£¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨£¬²»ÈÝËùÓÐIPv4±¨ÎĽøÈëÉ豸¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ£¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡£Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£
l ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê±£¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£
l ÅäÖôølogÑ¡ÏîµÄACL¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐlogÑ¡ÏÔò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£
l ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖÃACL¹æ¶¨Ê±Ö¸¶¨ÁËlogÑ¡Ïîºó£¬»¹±ØÒªÅäÖÃÊä³ö¾àÀ룬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£
l ¶ÔÓÚ´ølogÑ¡ÏîµÄ¹æ¶¨£¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬Ôò¹¦·ò¾àÀëµ½ÆÚºó£¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý£¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£
l ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖУ¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢£¬Äܹ»·½±ãÀí½âACLÓô¦¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ´´½¨IP³ß¶ÈACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ´´½¨Êý×ÖË÷ÒýµÄIP³ß¶ÈACLºÍ¹æ¶¨¡£
access-list acl-number { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]
ȱʡÇé¿öÏ£¬²»´æÔÚIP³ß¶ÈACLºÍ¹æ¶¨¡£
¡ð ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄIP³ß¶ÈACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃIP³ß¶ÈACLºÍ¹æ¶¨¡£
ip access-list standard { acl-name | acl-number }
ȱʡÇé¿öÏ£¬²»´æÔÚIP³ß¶ÈACL¡£
[ sequence-number ] { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]
ȱʡÇé¿öÏ£¬IP³ß¶ÈACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£
(4) £¨¿ÉÑ¡£©ÅäÖñ¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀë¡£
ip access-list
log-update interval time-value
ȱʡÇé¿öÏ£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£
(5) £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄIP³ß¶ÈACLÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄIP³ß¶ÈACLÅäÖÃ×¢½âÐÅÏ¢¡£
list-remark text
ȱʡÇé¿öÏ£¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(6) £¨¿ÉÑ¡£©ÅäÖÃIP³ß¶ÈACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄIP³ß¶ÈACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄIP³ß¶ÈACLÅäÖÃ×¢½âÐÅÏ¢¡£
remark text
ȱʡÇé¿öÏ£¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(7) £¨¿ÉÑ¡£©¿ªÆôIP³ß¶ÈACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£
ip access-list counter { acl-name | acl-number }
ȱʡÇé¿öÏ£¬IP³ß¶ÈACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£
(8) £¨¿ÉÑ¡£©ÅäÖÃIP³ß¶ÈACL¹æ¶¨²½³¤¡£
ip access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇé¿öÏ£¬IP³ß¶ÈACL¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10£¬¹æ¶¨ÐòºÅÔöÁ¿ÖµÎª10¡£
½«IP³ß¶ÈACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ£¬Ê¹IP³ß¶ÈACLÉúЧ¡£
l É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL£¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í£¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£
l ÅäÖôøin»òoutÑ¡Ï°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ£¬»¹ÊǶԴÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£
l ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ£¬Deny¹æ¶¨²»ÉúЧ¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ£¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL£¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£
l ÅäÖôøcontrol-planeÑ¡Ï°µÊ¾½öÈí¼þÉúЧACL£¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£
l ÅäÖôøforward-planeÑ¡Ï°µÊ¾½öÓ²¼þÉúЧACL¡£
l ÅäÖôøforward-control-planeÑ¡Ï°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) £¨¿ÉÑ¡£©È«¾ÖÀûÓÃIP³ß¶ÈACL¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬È«¾ÖδÀûÓÃIP³ß¶ÈACL¡£
(4) ½øÈë½Ó¿ÚÅäÖÃģʽ¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£
interface vlan interface-number
¡ð ½øÈëVXLANÅäÖÃģʽ¡£
vxlan vni-number
(5) ½Ó¿ÚÀûÓÃIP³ß¶ÈACL¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬½Ó¿ÚδÀûÓÃIP³ß¶ÈACL¡£
´´½¨ºÍÀûÓÃIPÀ©´óACL£¬¶Ô½Ó¿ÚÉϽø³öµÄIPv4±¨ÎĽøÐнÚÔ죬²»ÈÝ»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬´Ó¶øÊµÏÖ½ÚÔìIPÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£
l ÈôÊDZØÒªÍ¨¹ý²é³±¨ÎĵÄÔ´IPµØÖ·¡¢Ö÷ÕÅIPµØÖ·¡¢±¨ÎĵĺÍ̸ºÅ¡¢TCP/UDPÔ´»òÖ÷ÕŶ˱êÓÀ´½ÚÔìÓû§µÄÍøÂç×ÊÔ´½Ó¼ûȨÏÞ£¬¿ÉÅäÖÃIPÀ©´óACL¡£
l IPÀ©´óACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÅäÖá£IPÀ©´óACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
IPÀ©´óACLÅäÖù¤×÷ÈçÏ£º
(1)
´´½¨IPÀ©´óACL
(2)
ÀûÓÃIPÀ©´óACL
´´½¨IPÀ©´óACL²¢ÅäÖÃÆä¹æ¶¨¡£
l IPÀ©´óACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ£¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨£¬²»ÈÝËùÓÐIPv4±¨ÎĽøÈëÉ豸¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ£¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡£Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£
l ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê±£¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£
l ÅäÖôølogÑ¡ÏîµÄACL¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐlogÑ¡ÏÔò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£
l ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖÃACL¹æ¶¨Ê±Ö¸¶¨ÁËlogÑ¡Ïîºó£¬»¹±ØÒªÅäÖÃÊä³ö¾àÀ룬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£
l ¶ÔÓÚ´ølogÑ¡ÏîµÄ¹æ¶¨£¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬Ôò¹¦·ò¾àÀëµ½ÆÚºó£¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý£¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£
l ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖУ¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢£¬Äܹ»·½±ãÀí½âACLÓô¦¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ´´½¨IPÀ©´óACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ´´½¨Êý×ÖË÷ÒýµÄIPÀ©´óACLºÍ¹æ¶¨¡£
access-list acl-number { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]
ȱʡÇé¿öÏ£¬²»´æÔÚIPÀ©´óACLºÍ¹æ¶¨¡£
¡ð ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄIPÀ©´óACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃIPÀ©´óACLºÍ¹æ¶¨¡£
ip access-list extended { acl-name | acl-number }
ȱʡÇé¿öÏ£¬²»´æÔÚIPÀ©´óACL¡£
[ sequence-number ] { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]
ȱʡÇé¿öÏ£¬IPÀ©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£
(4) £¨¿ÉÑ¡£©ÅäÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£
ip
access-list log-update interval time-value
ȱʡÇé¿öÏ£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£
(5) £¨¿ÉÑ¡£©ÅäÖÃIPÀ©´óACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄIPÀ©´óACLÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄIPÀ©´óACLÅäÖÃ×¢½âÐÅÏ¢¡£
list-remark text
ȱʡÇé¿öÏ£¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(6) £¨¿ÉÑ¡£©ÅäÖÃIPÀ©´óACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄIPÀ©´óACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£
remark text
ȱʡÇé¿öÏ£¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(7) £¨¿ÉÑ¡£©¿ªÆôIPÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£
ip access-list counter { acl-name | acl-number }
ȱʡÇé¿öÏ£¬IPÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£
(8) £¨¿ÉÑ¡£©ÅäÖÃIPÀ©´óACL¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£
ip access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇé¿öÏ£¬IPÀ©´óACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10£¬²½³¤Îª10¡£
½«IPÀ©´óACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ£¬Ê¹IPÀ©´óACLÉúЧ¡£
l É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL£¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í£¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£
l ÅäÖôøin»òoutÑ¡Ï°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ£¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£
l ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ£¬Deny¹æ¶¨²»ÉúЧ¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ£¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL£¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£
l ÅäÖôøcontrol-planeÑ¡Ï°µÊ¾½öÈí¼þÉúЧACL£¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£
l ÅäÖôøforward-planeÑ¡Ï°µÊ¾½öÓ²¼þÉúЧACL¡£
l ÅäÖôøforward-control-planeÑ¡Ï°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) £¨¿ÉÑ¡£©È«¾ÖÀûÓÃIPÀ©´óACL¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬È«¾ÖδÀûÓÃIPÀ©´óACL¡£
(4) ½øÈë½Ó¿ÚÅäÖÃģʽ¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£
interface vlan interface-number
¡ð ½øÈëVXLANÅäÖÃģʽ¡£
vxlan vni-number
(5) ½Ó¿ÚÀûÓÃIPÀ©´óACL¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬½Ó¿ÚδÀûÓÃIPÀ©´óACL¡£
´´½¨ºÍÀûÓÃMACÀ©´óACL£¬¶Ô½Ó¿ÚÉϽø³öµÄ¶þ²ã±¨ÎĽøÐнÚÔ죬²»ÈÝ»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂ磬´Ó¶øÊµÏÖ»ùÓÚ¶þ²ã±¨ÎÄÍ·À´½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£
l ÈôÊDZØÒªÍ¨¹ý¶þ²ã±¨ÎÄÐÅÏ¢£¨ÀýÈçÓû§PCµÄMACµØÖ·£©£¬À´½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄȨÏÞ£¬Äܹ»ÅäÖÃMACÀ©´óACL¡£
l MACÀ©´óACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÅäÖá£MACÀ©´óACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
MACÀ©´óACLÅäÖù¤×÷ÈçÏ£º
(1)
´´½¨MACÀ©´óACL
(2)
ÀûÓÃMACÀ©´óACL
´´½¨MACÀ©´óACL²¢ÅäÖÃÆä¹æ¶¨¡£
l MACÀ©´óACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ£¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨£¬²»ÈÝËùÓÐÒÔÌ«Íø¶þ²ã±¨ÎĽøÈëÉ豸¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ£¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡£Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£
l ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê±£¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£
l ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖУ¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢£¬Äܹ»·½±ãÀí½âACLÓô¦¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ´´½¨MACÀ©´óACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ´´½¨Êý×ÖË÷ÒýµÄMACÀ©´óACLºÍ¹æ¶¨¡£
access-list acl-number { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]
ȱʡÇé¿öÏ£¬²»´æÔÚMACÀ©´óACLºÍ¹æ¶¨¡£
¡ð ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄMACÀ©´óACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃMACÀ©´óACLºÍ¹æ¶¨¡£
mac access-list extended { acl-name | acl-number }
ȱʡÇé¿öÏ£¬²»´æÔÚMACÀ©´óACL¡£
[ sequence-number ] { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]
ȱʡÇé¿öÏ£¬MACÀ©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£
(4) £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£
list-remark text
ȱʡÇé¿öÏ£¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(5) £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£
remark text
ȱʡÇé¿öÏ£¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(6) £¨¿ÉÑ¡£©¿ªÆôMACÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£
mac access-list counter { acl-name | acl-number }
ȱʡÇé¿öÏ£¬MACÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£
(7) £¨¿ÉÑ¡£©MACÀ©´óACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£
mac access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇé¿öÏ£¬MACÀ©´óACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10£¬²½³¤Îª10¡£
½«MACÀ©´óACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ£¬Ê¹MACÀ©´óACLÉúЧ¡£
l É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL£¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í£¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£
l ÅäÖôøin»òoutÑ¡Ï°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ£¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£
l ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ£¬Deny¹æ¶¨²»ÉúЧ¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ£¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL£¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£
l ÅäÖôøcontrol-planeÑ¡Ï°µÊ¾½öÈí¼þÉúЧACL£¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£
l ÅäÖôøforward-planeÑ¡Ï°µÊ¾½öÓ²¼þÉúЧACL¡£
l ÅäÖôøforward-control-planeÑ¡Ï°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) £¨¿ÉÑ¡£©È«¾ÖÀûÓÃMACÀ©´óACL¡£
mac access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬È«¾ÖδÀûÓÃMACÀ©´óACL¡£
(4) ½øÈë½Ó¿ÚÅäÖÃģʽ¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£
interface vlan interface-number
¡ð ½øÈëVXLANÅäÖÃģʽ¡£
vxlan vni-number
(5) ½Ó¿ÚÀûÓÃMACÀ©´óACL¡£
mac access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬½Ó¿ÚδÀûÓÃMACÀ©´óACL¡£
´´½¨ºÍÀûÓÃר¼Ò¼¶À©´óACL£¬¶Ô½Ó¿ÚÉϽø³öµÄ±¨ÎĽøÐнÚÔ죬²»ÈÝ»òÔÊÐíÌØ¶¨µÄ±¨ÎĽøÈëÍøÂç¡£
l ÈôÊDZØÒªÍ¨¹ý»ìºÏʹÓÃIP ACL¹æ¶¨¡¢MACÀ©´óACL¹æ¶¨ºÍVLAN£¬À´½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄȨÏÞ£¬ÔòÄܹ»ÅäÖÃר¼Ò¼¶À©´óACL¡£
l ר¼Ò¼¶À©´óACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£×¨¼Ò¼¶À©´óACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
ר¼Ò¼¶À©´óACLÅäÖù¤×÷ÈçÏ£º
´´½¨×¨¼Ò¼¶À©´óACL²¢ÅäÖÃÆä¹æ¶¨¡£
l ר¼Ò¼¶À©´óACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ£¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨£¬²»ÈÝËùÓб¨ÎĽøÈëÉ豸¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ£¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡£Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£
l ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê±£¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£
l ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖУ¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢£¬Äܹ»·½±ãÀí½âACLÓô¦¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ´´½¨×¨¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ´´½¨Êý×ÖË÷ÒýµÄר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£
access-list acl-number { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]
ȱʡÇé¿öÏ£¬²»´æÔÚר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£
¡ð ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£
expert access-list extended { acl-name | acl-number }
ȱʡÇé¿öÏ£¬²»´æÔÚר¼Ò¼¶À©´óACL¡£
[ sequence-number ] { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]
ȱʡÇé¿öÏ£¬×¨¼Ò¼¶À©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£
¡ð ´´½¨×¨¼Ò¼¶À©´óACL¼°VXLANÄÚ²ãÎåÔª×鹿¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃר¼Ò¼¶À©´óACL¼°VXLANÄÚ²ãÎåÔª×鹿¶¨¡£
expert access-list extended { acl-name | acl-number }
ȱʡÇé¿öÏ£¬²»´æÔÚר¼Ò¼¶À©´óACL¡£
[ sequence-number ] { deny | permit } { vxlan | vxlan-ignore-dport } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port ] [ tagged ] [ udp-dport dport ] [ match-all tcp-flag | established ] [ time-range time-range-name ]
ȱʡÇé¿öÏ£¬×¨¼Ò¼¶À©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£
(4) £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£
list-remark text
ȱʡÇé¿öÏ£¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(5) £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ΪÊý×ÖË÷ÒýµÄACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£
remark text
ȱʡÇé¿öÏ£¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(6) £¨¿ÉÑ¡£©¿ªÆôר¼Ò¼¶ACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£
expert access-list counter { acl-name | acl-number }
(7) £¨¿ÉÑ¡£©ÅäÖÃר¼Ò¼¶ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£
expert access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇé¿öÏ£¬×¨¼Ò¼¶ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10£¬²½³¤Îª10¡£
½«×¨¼Ò¼¶À©´óACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ£¬Ê¹×¨¼Ò¼¶À©´óACLÉúЧ¡£
l É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL£¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í£¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£
l ÅäÖôøin»òoutÑ¡Ï°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ£¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£
l ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ£¬Deny¹æ¶¨²»ÉúЧ¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-onlyºó£¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ£¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL£¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-onlyºÍͨ³£ACL¡£
l ÅäÖôøcontrol-planeÑ¡Ï°µÊ¾½öÈí¼þÉúЧACL£¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£
l ÅäÖôøforward-planeÑ¡Ï°µÊ¾½öÓ²¼þÉúЧACL¡£
l ÅäÖôøforward-control-planeÑ¡Ï°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) £¨¿ÉÑ¡£©È«¾ÖÀûÓÃר¼Ò¼¶ACL¡£
expert access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬È«¾ÖδÀûÓÃר¼Ò¼¶ACL¡£
(4) ½øÈë½Ó¿ÚÅäÖÃģʽ¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£
interface vlan interface-number
¡ð ½øÈëVXLANÅäÖÃģʽ¡£
vxlan vni-number
(5) ÀûÓÃר¼Ò¼¶À©´óACL¡£
expert access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬½Ó¿ÚδÀûÓÃר¼Ò¼¶À©´óACL¡£
´´½¨ºÍÀûÓÃIPv6 ACL£¬¶Ô½Ó¿ÚÉϽø³öµÄIPv6±¨ÎĽøÐнÚÔ죬²»ÈÝ»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂ磬´Ó¶øÊµÏÖ½ÚÔìIPv6Óû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£
l ÈôÊDZØÒª¶ÔIPv6Óû§½Ó¼ûÍøÂç×ÊÔ´µÄ½ÚÔ죬ÔòÄܹ»ÅäÖÃIPv6 ACL¡£
l IPv6 ACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£IPv6 ACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
IPv6 ACLÅäÖù¤×÷ÈçÏ£º
(1)
´´½¨IPv6 ACL
(2)
ÀûÓÃIPv6 ACL
´´½¨IPv6 ACL²¢ÅäÖÃÆä¹æ¶¨¡£
l ´´½¨IPv6 ACLʱֻÄÜÖ¸¶¨Ãû³Æ£¬²»ÄÜÖ¸¶¨±àºÅ¡£
l IPv6 ACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ£¬IPv6 ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨£¬²»ÈݳýND±¨ÎÄÒÔ±íµÄËùÓÐIPv6±¨ÎĽøÈëÉ豸¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ£¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡£Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£
l ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê±£¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£
l ÅäÖôølogÑ¡ÏîµÄACL¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐlogÑ¡ÏÔò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£
l ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖÃACL¹æ¶¨Ê±Ö¸¶¨ÁËlogÑ¡Ïîºó£¬»¹±ØÒªÅäÖÃÊä³ö¾àÀ룬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£
l ¶ÔÓÚ´ølogÑ¡ÏîµÄ¹æ¶¨£¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬Ôò¹¦·ò¾àÀëµ½ÆÚºó£¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý£¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£
l ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖУ¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢£¬Äܹ»·½±ãÀí½âACLÓô¦¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ´´½¨IPv6 ACL£¬²¢½øÈëIPv6 ACLÅäÖÃģʽ¡£
ipv6 access-list acl-name
ȱʡÇé¿öÏ£¬²»´æÔÚIPv6 ACL¡£
(4) ÅäÖÃIPv6 ACL¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ÅäÖÃIPv6 ACL¹æ¶¨¡£
[ sequence-number ] { deny | permit } [ protocol { source-ipv6-prefix / prefix-length | source-ipv6-address source-ipv6-mask | host source-ipv6-address | any } { destination-ipv6-prefix / prefix-length | destination-ipv6-address destination-ipv6-mask | host destination-ipv6-address | any } ] [ cos cos-value [ inner cos-value] ] [ { any | host source-mac-address | source-mac-address source-mac-wildcard } { any | host destination-mac-address | destination-mac-address destination-mac-wildcard } ] [ dscp dscp ] [ flow-label flow-label ] [ fragment ] [ VID [ vlan-id ] [ inner vlan-id ] ] [ udf udf-id header pos value mask ] [ time-range time-range-name ]¡¡[ log ]
ȱʡÇé¿öÏ£¬IPv6 ACL´æÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£
(5) £¨¿ÉÑ¡£©ÅäÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£
ipv6
access-list log-update interval time-value
ȱʡÇé¿öÏ£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£
(6) £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£
list-remark text
ȱʡÇé¿öÏ£¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(7) £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£
remark text
ȱʡÇé¿öÏ£¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(8) £¨¿ÉÑ¡£©¿ªÆôIPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£
ipv6 access-list counter acl-name
ȱʡÇé¿öÏ£¬IPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£
(9) £¨¿ÉÑ¡£©ÅäÖÃIPv6 ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£
ipv6 access-list resequence acl-name start-value step-value
ȱʡÇé¿öÏ£¬IPv6 ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10£¬²½³¤Îª10¡£
½«IPv6 ACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ£¬Ê¹IPv6 ACLÉúЧ¡£
l É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL£¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í£¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£
l ÅäÖôøin»òoutÑ¡Ï°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ£¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£
l ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ£¬DenyÀàÐ͹涨²»ÉúЧ¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ£¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL£¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£
l ÅäÖôøcontrol-planeÑ¡Ï°µÊ¾½öÈí¼þÉúЧACL£¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£
l ÅäÖôøforward-planeÑ¡Ï°µÊ¾½öÓ²¼þÉúЧACL¡£
l ÅäÖôøforward-control-planeÑ¡Ï°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) £¨¿ÉÑ¡£©È«¾ÖÀûÓÃIPv6 ACL¡£
ipv6 traffic-filter acl-name { in | out } { control-plane | forward-control-plane | forward-plane }
ȱʡÇé¿öÏ£¬È«¾ÖδÀûÓÃIPv6 ACL¡£
(4) ½øÈë½Ó¿ÚÅäÖÃģʽ¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£
interface vlan interface-number
¡ð ½øÈëVXLANÅäÖÃģʽ¡£
vxlan vni-number
(5) ½Ó¿ÚÀûÓÃIPv6 ACL¡£
ipv6 traffic-filter acl-name { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇé¿öÏ£¬½Ó¿ÚδÀûÓÃIPv6 ACL¡£
µ±¹Ì¶¨Æ¥ÅäÓòµÄIP³ß¶ÈACL¡¢IPÀ©´óACL¡¢MACÀ©´óACL¡¢×¨¼Ò¼¶À©´óACLÒÔ¼°IPv6 ACL¶¼ÎÞ·¨Âú×ãÒªÇóʱ£¬Äܹ»Í¨¹ýÅäÖÃר¼Ò¼¶¸ß¼¶ACL£¬¼´ACL80£¬ÓÉÓû§½ç˵±ØÒªÆ¥ÅäµÄ±¨ÎÄÓò£¬´Ó¶øÊµÏÖ×Ô½ç˵ƥÅäÓòµÄÖ÷ÕÅ¡£
l ר¼Ò¼¶¸ß¼¶ACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£×¨¼Ò¼¶¸ß¼¶ACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
ר¼Ò¼¶¸ß¼¶ACLÅäÖù¤×÷ÈçÏ£º
´´½¨ACL80²¢ÅäÖÃÆä¹æ¶¨¡£
l ACL80Äܹ»Ö§³Ôì¥ÅäEthernet IIÖ¡¡¢802.2 LLCÖ¡ºÍ802.2 SNAPÖ¡¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪAAAA03£¬Ôò°µÊ¾Æ¥Åä802.2 SNAPÖ¡¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪE0E003£¬Ôò°µÊ¾Æ¥Åä802.2 LLCÖ¡¡£ÈôÊÇÆ¥ÅäEthernet IIÖ¡²»ÄÜÉèÖÃDSAPµ½Cntl×ֶεÄÖµ¡£
l ÓÉÓÚÓ²¼þµÄÔÒò£¬µ±Ç°ACL80²¢²»ÄܶԱ¨ÎÄǰ80¸ö×Ö½ÚµÄËÁÒâ×Ö½ÚÆ¥Å䣬ֻ֧³Ö±¨ÎÄÖÐÖ÷ÕÅMAC¡¢Ô´MAC¡¢VLAN ID¡¢ETYPE¡¢IPºÍ̸ºÅ¡¢Ô´IPv4µØÖ·¡¢Ö÷ÕÅIPv4µØÖ·¡¢Ô´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڡ¢ICMP_TYPE¡¢ICMP_CODE¡¢PPPOE_IPTYPEÕâЩ×Ö¶ÎµØµãµØÎ»µÄÆ¥Åä¡£
l ACL80Æ¥ÅäIP¡¢ARPµÈÐÅϢʱ£¬±ØÒªÏÈÅäÖ÷â×°µÄÊý¾ÝÀàÐͺÍÊý¾ÝÀàÐÍÑÚÂ룬¼´±ØÒªÏÈÅäÖÃÆ«ÒÆÁ¿Îª24µÄ×ֶΣ¬²¢ÇÒÑÚÂëҪΪȫF¡£ÀýÈç·ÅÐÐÔ´IPΪ192.168.1.2µÄ±¨ÎÄ£¬¶ÔÓ¦µÄÅäÖúÅÁîΪpermit 0800 FFFF 24 C0A80102 FFFFFFFF 38¡£
l ר¼Ò¼¶¸ß¼¶ACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ£¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨£¬²»ÈÝËùÓб¨ÎĽøÈëÉ豸¡£
l ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖУ¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢£¬Äܹ»·½±ãÀí½âACLÓô¦¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ´´½¨×¨¼Ò¼¶¸ß¼¶ACL£¬²¢½øÈëר¼Ò¼¶¸ß¼¶ACLÅäÖÃģʽ¡£
expert access-list advanced
acl-name
ȱʡÇé¿öÏ£¬²»´æÔÚר¼Ò¼¶¸ß¼¶ACL¡£
(4) £¨¿ÉÑ¡£©ÅäÖÃר¼Ò¼¶¸ß¼¶ACL¹æ¶¨¡£
[ sequence-number ]
{ deny | permit } hex hex-mask offset
ȱʡÇé¿öÏ£¬Î´ÅäÖÃר¼Ò¼¶¸ß¼¶ACL¹æ¶¨¡£
(5) £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£
list-remark text
ȱʡÇé¿öÏ£¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
(6) £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£
remark text
ȱʡÇé¿öÏ£¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£
½«×¨¼Ò¼¶¸ß¼¶ACLÀûÓõ½½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ£¬Ê¹×¨¼Ò¼¶¸ß¼¶ACLÉúЧ¡£
l ÅäÖôøin»òoutÑ¡Ï°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ£¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ½øÈë½Ó¿ÚÅäÖÃģʽ¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£
interface vlan interface-number
¡ð ½øÈëVXLANÅäÖÃģʽ¡£
vxlan vni-number
(4) ½Ó¿ÚÀûÓÃר¼Ò¼¶¸ß¼¶ACL¡£
expert access-group { acl-name | acl-number } { in |
out }
ȱʡÇé¿öÏ£¬½Ó¿ÚδÀûÓÃר¼Ò¼¶¸ß¼¶ACL¡£
ÔÚÖ¸¶¨½Ó¿ÚÉÏÅäÖÃACL³Á¶¨ÏòÖ°ÄÜ£¬¶Ô½øÈë¸Ã½Ó¿ÚµÄÆ¥Å䱨ÎÄ£¬³Á¶¨Ïòµ½Ö¸¶¨½Ó¿Úת·¢³öÈ¥¡£
l ACL³Á¶¨ÏòÖ°ÄܽöÔÚ½Ó¿ÚÈë·½ÏòÉúЧ¡£
l ACLÖÐûÓÐÅäÖù涨ʱ£¬ACL³Á¶¨ÏòÖ°Äܲ»ÉúЧ¡£
l Ö»Ö§³ÖÔÚÒÔÌ«Íø½Ó¿Ú¡¢¾ÛºÏ½Ó¿ÚÉÏÅäÖÃACL³Á¶¨ÏòÖ°ÄÜ¡£
l ´ý³Á¶¨ÏòµÄ±¨ÎıØÐëÊǶþ²ãת·¢£¬Í¬Ê±³Á¶¨ÏòµÄÖ÷ÕŽӿڱØÐëºÍÔ´½Ó¿ÚÔÚͳһ¸öVLANÄÜÁ¦ÉúЧ¡£ÀýÈçÈç¹û±¨ÎÄÊÇ´ÓVLAN 2ת·¢µ½VLAN 3£¬Ôò²»ÄܽøÐгÁ¶¨Ïò¡£
l Äܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖÃACL³Á¶¨ÏòÖ°ÄÜ¡£ÅäÖýö¶Ô±¾É豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
ʵÏÖACL³Á¶¨ÏòÖ°ÄÜ£¬±ØÒªÏÈÅäÖÃACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ÅäÖÃACL³Á¶¨Ïò¡£
¡ð ÅäÖýӿÚACL³Á¶¨Ïò¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖýӿÚACL³Á¶¨Ïò¡£
interface interface-type interface-number
redirect destination interface interface-type interface-number acl { acl-name
| acl-number } in
ȱʡÇé¿öÏ£¬½Ó¿Ú²»´æÔÚACL³Á¶¨ÏòÅäÖá£
ÅäÖÃÈ«¾Ö°²È«ACLÖ°ÄÜ£¬Äܹ»×èÖ¹ÆóÒµÄÚ²¿½Ó¼û·¸·¨ÍøÕ¾£¬»òÕß×èÖ¹²¡¶¾½øÈëÆóÒµÄÚ²¿ÍøÂ硣ͨ¹ýÅäÖÃÈ«¾Ö°²È«ACLÀý±í¿Ú£¬ÔÊÐíÆóÒµÄÚ²¿ÌØÊⲿÃŽӼû±í²¿Ä³Ð©Õ¾µã¡£
l ACLÖÐûÓÐÅäÖù涨ʱ£¬È«¾Ö°²È«ACLÖ°Äܲ»´æÔÚ¡£
l ÓÉÓÚÈ«¾Ö°²È«ACLÖØÒªÓÃÓÚ²¡¶¾¹ýÂË£¬Òò¶ø±»¹ØÁªÓÚÈ«¾Ö°²È«ACLµÄACEÖУ¬Ö»ÓÐDenyÀàÐ͵ÄACE»áÉúЧ£¬PermitÀàÐ͵ÄACE²»»áÉúЧ¡£
l Óë¶Ë¿Ú°²È«ACL·ÖÆç£¬È«¾Ö°²È«ACLûÓÐĬÈϵÄDenyËùÓбíÏ¼´Ã»ÉäÖй涨µÄ±¨ÎͼÄܹ»Í¨¹ý¡£
l È«¾Ö°²È«ACLÖ»Ö§³Ö¹ØÁªIP³ß¶ÈACL¡¢IPÀ©´óACL¡¢MACÀ©´óACL¡¢×¨¼Ò¼¶À©´óACL¡£
l È«¾ÖACLÄܹ»ÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ£¬Ò²Äܹ»ÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¼´Äܹ»ÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢¶þ²ãÒÔÌ«Íø½Ó¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£ÔÚSVI½Ó¿ÚÉϲ»ÉúЧ¡£
l ÔÊÐíÔÚÎïÀí½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿ÚÉ϶ÀÁ¢¹Ø¹ØÈ«¾Ö°²È«ACLÖ°ÄÜ£¬²»Ö§³ÖÔھۺϳÉÔ±½Ó¿ÚÉϹعØÈ«¾Ö°²È«ACLÖ°ÄÜ¡£
l Äܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö£¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖÃÈ«¾Ö°²È«ACLÖ°ÄÜ¡£ÅäÖýö¶Ô±¾É豸ÓÐЧ£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£
l ͨ¹ýÅäÖÃÈ«¾Ö°²È«ACLÎÞЧְÄÜ£¬Äܹ»ÊµÏÖ²»ÈÝÅäÖÃÈ«¾Ö°²È«ACL¡£
l ½«½Ó¿ÚÅäÖÃΪÀý±í¿Ú£¬¿Éʹȫ¾Ö°²È«ACLÔÚ½Ó¿ÚÉϲ»ÉúЧ¡£
ʵÏÖÈ«¾Ö°²È«ACLÖ°ÄÜ£¬±ØÒªÏÈÅäÖÃACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) £¨¿ÉÑ¡£©ÅäÖÃÈ«¾Ö°²È«ACLÎÞЧ¡£
global access-group disable
ȱʡÇé¿öÏ£¬²»´æÔÚÈ«¾Ö°²È«ACLÎÞЧÅäÖá£
ÅäÖøÃÖ°ÄÜÄܹ»Ê¹ACL¶Ô·Ô쬱¨ÎĽøÐиü¾«ÃÜ»¯µÄ½ÚÔì¡£
l ÅäÖ÷Ô쬱¨ÎÄÆ¥ÅäģʽÇл»Ê±£¬»áµ¼ÖÂACLµÄ¶ÌʱʧЧ¡£
l ÔÚеķÔ쬱¨ÎÄÆ¥ÅäģʽÏ£¬ÈôÊÇACL¹æ¶¨²»´øFragment±êʶ£¬ÇÒÆ¥Åä×÷ΪÊÇPermit£¬ÕâÑùµÄACL¹æ¶¨±ØÒªÕ¼Óøü¶àµÄÓ²¼þ±íÏî×ÊÔ´£¬¼«¶ËÇé¿öÏ»áʹӲ¼þÕ½Êõ±íÏîÈÝÁ¿¼õ°ë¡£ÈôÊÇÕâÑùµÄACEÅäÖÃÁËTCP Flag¹ýÂ˽ÚÔìµÄEstablished£¬Ôò»¹»áÕ¼Óøü¶àµÄÓ²¼þÕ½Êõ±íÏî¡£
l ÔÚеķÔ쬱¨ÎÄÆ¥ÅäģʽÏ£¬ÈôÊÇACL¹æ¶¨²»´øFragment±êʶ²¢ÇÒ±ØÒªÆ¥Å䱨ÎĵÄËIJãÐÅϢʱ£¬µ±Æ¥Åä×÷ΪΪPermitʱ£¬ACL¹æ¶¨»á²é³Êׯ¬±¨ÎÄÈý²ãºÍËIJãÐÅÏ¢£¬¶ÔÓÚ·ÇÊׯ¬±¨ÎÄÖ»»á²é³±¨ÎĵÄÈý²ãÐÅÏ¢¡£µ±Æ¥Åä×÷ΪΪDenyʱ£¬ACL¹æ¶¨Ö»»á²é³Êׯ¬±¨ÎÄ£¬²»»á²é³·ÇÊׯ¬·Ô쬱¨ÎÄ¡£
l ÔÚеķÔ쬱¨ÎÄÐÂÆ¥ÅäģʽÏ£¬ÈôÊÇACL¹æ¶¨´øÓÐFragment±êʶ£¬²»ÂÛACL¹æ¶¨µÄÆ¥Åä×÷ΪÊÇPermit»¹ÊÇDeny£¬¶¼Ö»²é³·ÇÊׯ¬±¨ÎÄ£¬¶ø²»»á²é³Êׯ¬±¨ÎÄ¡£
ÅäÖ÷Ô쬱¨ÎÄÆ¥ÅäģʽÇл»Ê±£¬±ØÒªÏÈÅäÖÃACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ÅäÖÃеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ÅäÖÃIP ACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£
ip access-list new-fragment-mode { acl-name | acl-number }
ȱʡÇé¿öÏ£¬Î´ÅäÖÃIP ACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£
¡ð ÅäÖÃר¼Ò¼¶À©´óACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£
expert access-list new-fragment-mode { acl-name | acl-number }
ȱʡÇé¿öÏ£¬Î´ÅäÖÃר¼Ò¼¶À©´óACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£
ÅäÖøÃÖ°ÄÜ£¬Äܹ»Ê¹ÀûÓÃÔÚSVI½Ó¿ÚÉϵÄACL½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£
ʵÏÖ¸ÃÖ°ÄÜ£¬±ØÒªÏÈÅäÖÃACL¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ÅäÖÃSVI Router ACL¡£
svi router-acls enable
µ±É豸Èí¼þ±íÏîÈÝÁ¿´óÓÚÓ²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ê±£¬±íÏîÔö³¤½«Ê§°Ü¡£µ±É豸±íÏîÈÝÁ¿½µµÍµ½Ó²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ö®ÏÂʱ£¬ÔÏÈÔö³¤Ê§°ÜµÄ±íÏîÒ²²»»á³ÁÐÂÔö³¤¡£Í¨¹ý±¾ºÅÁî³ÁË¢ÅäÖ㬴¥°ä·¢ÏîµÄ³ÁÐÂÔö³¤£¬´Ó¶ø¸´ÔACL¹ÊÕÏ¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ÅäÖÃACL¹ÊÕϸ´Ô¡£
acl ref synchronize all
Äܹ»Í¨¹ýshowºÅÁîÐв鿴ְÄÜÅäÖúóµÄÔËÐÐÇé¿öÒÔÑéÖ¤ÅäÖóÉЧ¡£
Äܹ»Í¨¹ýÖ´ÐÐclearºÅÁîÀ´¶Ï¸ù¸÷ÀàÐÅÏ¢¡£
°ÑÎÈ
ÔÚÉ豸ÔËÐйý³ÌÖÐÖ´ÐÐclearºÅÁ¿ÉÄÜÓÉÓÚ³ÁÒªÐÅÏ¢ÃÔʧ¶øµ¼ÖÂÒµÎñÖжϡ£
Äܹ»Í¨¹ýdebugºÅÁîÐÐÁоÙÊä³öµÄ¸÷Ààµ÷ÊÔÐÅÏ¢¡£
°ÑÎÈ
Êä³öµ÷ÊÔÐÅÏ¢£¬»áÕ¼ÓÃϵͳ×ÊÔ´¡£Ê¹ÓýáÊøºó£¬Çëµ±¼´¹Ø¹Øµ÷ÊÔ¿ª¹Ø¡£
±í1-5 ACL¼à¶½ÓëÊØ»¤
|
×÷ÓÃ |
ºÅÁî |
|
²é¿´¸ù»ùACL |
show access-lists [ acl-name | acl-number ] [ summary ] |
|
²é¿´Ö¸¶¨½Ó¿ÚÉϰ󶨵ijÁ¶¨Ïò±íÏ²»ÊäÈë½Ó¿ÚÔò²é¿´ËùÓнӿÚÉϰ󶨵ijÁ¶¨Ïò±íÏî |
show redirect [ interface interface-type interface-number ] |
|
²é¿´½Ó¿ÚÉÏÀûÓõÄACLÅäÏàÐÅÏ¢ |
show access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
²é¿´½Ó¿ÚÉÏÀûÓõÄIP³ß¶ÈACLºÍÀ©´óACLÅäÏàÐÅÏ¢ |
show ip access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
²é¿´½Ó¿ÚÉÏÀûÓõÄMACÀ©´óACLÅäÏàÐÅÏ¢ |
show mac access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
²é¿´½Ó¿ÚÉÏÀûÓõÄר¼Ò¼¶À©´óACLÅäÏàÐÅÏ¢ |
show expert access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
²é¿´½Ó¿ÚÉÏÀûÓõÄIPv6 ACLÅäÏàÐÅÏ¢ |
show ipv6 traffic-filter [ interface interface-type interface-number | vlan vlan-id ] |
|
²é¿´ËùÓеÄTCAMÐÅÏ¢»òÖ¸¶¨µÄTCAMÐÅÏ¢ |
show acl res [ dev dev-number [ slot slot-number ] ] |
|
ÏÔʾµ±Ç°É豸µÄÄÜÁ¦ÖµÇé¿ö |
show acl capability |
|
²é¿´SVI½Ó¿ÚACLÀûÓõĶþÈý²ãÉúЧÇé¿ö |
show svi router-acls state |
|
²é¿´ËùÓеÄTCAM¾ßÌåʹÓÃÐÅÏ¢»òÖ¸¶¨µÄTCAM¾ßÌåʹÓÃÐÅÏ¢ |
show acl res detail [ dev dev-number [ slot slot-number ] ] |
|
¶Ï¸ùTCAM×ÊԴʹÓÃÁ¿µÄº¹Çà·åÖµÊý¾Ý |
clear acl res |
|
¶Ï¸ùACL±¨ÎÄÆ¥Å伯Êý |
clear counters access-list [ acl-name | acl-number ] |
|
¶Ï¸ùACL deny±¨ÎÄÆ¥Å伯Êý |
clear access-list counters [ acl-name | acl-number ] |
|
´ò¿ªACLÔËÐйý³Ìµ÷ÊÔ¿ª¹Ø |
debug acl acld event |
|
²é¿´ACL¿Í»§¶ËÐÅÏ¢ |
debug acl acld client-show |
|
²é¿´ËùÓÐACL¿Í»§¶Ë´´½¨µÄACL |
debug acl acld acl-show |
ͨ¹ýÅäÖÃIP³ß¶ÈACL£¬²»ÈݲÆÕþ²¿ÒÔ±íµÄ²¿ÃŽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£
ͼ1-3 IP³ß¶ÈACLÀûÓó¡¾°×éÍøÍ¼

l Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
l Device A½«IP³ß¶ÈACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£
(1) ÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# ip access-list standard 1
DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255
DeviceA(config-std-nacl)# deny 11.1.1.1 0.0.0.255
DeviceA(config-std-nacl)# exit
(2) ½«IP³ß¶ÈACLÀûÓõ½½Ó¿ÚÉÏ¡£
# Device A½«ACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/3
DeviceA(config-if-GigabitEthernet 0/3)# ip access-group 1 out
# ²é³Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£
DeviceA# show access-lists
ip access-list standard 1
10 permit 10.1.1.0 0.0.0.255
20 deny 11.1.1.0 0.0.0.255
DeviceA# show access-group
ip access-group 1 out
Applied
On interface GigabitEthernet 0/3
# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷£¬È·ÈÏping²»Í¨¡£
# ´Ó²ÆÕþ²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷£¬È·ÈÏÄÜpingͨ¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
ip access-list standard 1
?10 permit 10.1.1.0 0.0.0.255
?20 deny 11.1.1.0 0.0.0.255
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip access-group 1 out
?ip address 12.1.1.1 255.255.255.0
!
Device A£¨VLAN 1£©¡¢Device B£¨VLAN 2£©ºÍDevice C£¨VLAN 3£©Ö±Á¬Device D£¬Device DÊÇËùÓÐÖ÷»úµÄÍø¹Ø¡£ÐèÒª1£ºVLAN2ÓëVLAN3Ö®¼ä²»³ÉÒÔPingͨ£¬VLAN1ÓëVLAN2Äܹ»Pingͨ£¬VLAN1ÓëVLAN3Äܹ»Pingͨ¡£ÐèÒª2£ºVLAN1ÓëVLAN2µÄDHCP±¨ÎÄÏ໥²»³É´ï£¬ÆäËûÕý³£Í¨Ñ¶¡£ÐèÒª3£ºVLAN1²»ÄÜͨ¹ýTelnet»òÕßSSH½Ó¼ûVLAN3£¬ÆäËûÕý³£Í¨Ñ¶¡£
ͼ1-4 IPÀ©´óACLÀûÓó¡¾°×éÍøÍ¼

l Device DÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨£¬¹ýÂËUDP¶Ë±êÓï67»òÕß68Äܹ»ÊµÏÖÐèÒª2¡£Device CÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨£¬¹ýÂËTCP¶Ë¿Ú23ºÍ22Äܹ»ÊµÏÖÐèÒª3¡£
l Device D½«IPÀ©´óACL±ðÀëÀûÓÃÔÚVLAN1½Ó¿Ú¡¢VLAN2½Ó¿ÚºÍVLAN3½Ó¿ÚÉÏ¡£Device C½«IPÀ©´óACLÀûÓÃÔÚÓëDevice DÏàÏß·ÉÏ¡£
(1) ÅäÖÃËùÓÐÉ豸½Ó¿ÚµÄIPµØÖ·£¨ÂÔ£©¡£
(2) ÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device DÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceD> enable
DeviceD# configure terminal
DeviceD(config)# ip access-list extended inter_vlan_access1
DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc
DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps
DeviceD(config-ext-nacl)# remark »Ø¾øDHCP±¨ÎÄ
DeviceD(config-ext-nacl)# permit ip any any
DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ
DeviceD(config-ext-nacl)# exit
DeviceD(config)# ip access-list extended inter_vlan_access2
DeviceD(config-ext-nacl)# deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255
DeviceD(config-ext-nacl)# remark »Ø¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping
DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps
DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc
DeviceD(config-ext-nacl)# remark »Ø¾øDHCP±¨ÎÄ
DeviceD(config-ext-nacl)# permit ip any any
DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ
DeviceD(config-ext-nacl)# exit
DeviceD(config)# ip access-list extended inter_vlan_access3
DeviceD(config-ext-nacl)# deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
DeviceD(config-ext-nacl)# remark »Ø¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping
DeviceD(config-ext-nacl)# permit ip any any
DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ
DeviceD(config-ext-nacl)# exit
# Device CÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceC> enable
DeviceC# configure terminal
DeviceC(config)# ip access-list extended access_deny
DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet
DeviceC(config-ext-nacl)# remark »Ø¾øVLAN1ͨ¹ýTelnet½Ó¼ûVLAN 3
DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22
DeviceC(config-ext-nacl)# remark »Ø¾øVLAN1ͨ¹ýSSH½Ó¼ûVLAN 3
DeviceC(config-ext-nacl)# exit
(3) ÀûÓÃIPÀ©´óACL¡£
# Device D½«IPÀ©´óACLÀûÓõ½¶ÔÓ¦½Ó¿ÚÉÏ¡£
DeviceD(config)# interface vlan 1
DeviceD(config-if-VLAN 1)# ip access-group inter_vlan_access1 in
DeviceD(config-if-VLAN 1)# exit
DeviceD(config)# interface vlan 2
DeviceD(config-if-VLAN 2)# ip access-group inter_vlan_access2 in
DeviceD(config-if-VLAN 2)# exit
DeviceD(config)# interface vlan 3
DeviceD(config-if-VLAN 3)# ip access-group inter_vlan_access3 in
DeviceD(config-if-VLAN 3)# exit
# Device C½«IPÀ©´óACLÀûÓõ½ÓëDevice DÏàÁ¬Ïß·ÉÏ¡£
DeviceC(config)# line vty 0
DeviceC(config-line)# access-class access_deny in
DeviceC(config-line)# exit
(1) ÑéÖ¤Á¬Í¨ÐÔ¡£
# VLAN 1ÓëVLAN 2Ö®¼äÄܹ»Pingͨ£¬VLAN 1ÓëVLAN 3Ö®¼äÄܹ»Pingͨ¡£
DeviceA# ping 192.168.2.2
Sending 5, 100-byte ICMP Echoes to 192.168.2.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
DeviceA#
DeviceA# ping 192.168.3.2
Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
# VLAN 2ÓëVLAN 3Ö®¼ä²»³ÉÒÔPingͨ¡£
DeviceB# ping 192.168.3.2
Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
.....
Success rate is 0 percent (0/5)
(2) VLAN 1²»ÄÜͨ¹ýTelnet½Ó¼ûVLAN 3¡£
DeviceA# ping 192.168.3.2
Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
DeviceA#
DeviceA# telnet 192.168.3.2
Trying 192.168.3.2, 23...
% Destination unreachable; gateway or host down
l Device DµÄÅäÖÃÎļþ
hostname DeviceD
!
vlan 1
!
vlan 2
!
vlan 3
!
ip access-list extended inter_vlan_access1
?10 deny udp any eq bootps any eq bootpc
?20 deny udp any eq bootpc any eq bootps
?remark »Ø¾øDHCP±¨ÎÄ
?30 permit ip any any
?remarkÔÊÐíÆäËû±¨ÎÄͨѶ
!
ip access-list extended inter_vlan_access2
?10 deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255
?remark »Ø¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping
?20 deny udp any eq bootpc any eq bootps
?30 deny udp any eq bootps any eq bootpc
?remark »Ø¾øDHCP±¨ÎÄ
?40 permit ip any any
?remark ÔÊÐíÆäËû±¨ÎÄͨѶ
!
ip access-list extended inter_vlan_access3
?10 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
?remark »Ø¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping
?20 permit ip any any
?remark ÔÊÐíÆäËû±¨ÎÄͨѶ
!
interface GigabitEthernet 1/0
?switchport access vlan 1
?description link_to_DeviceA
!
interface GigabitEthernet 1/1
?switchport access vlan 2
?description link_to_DeviceB
!
interface GigabitEthernet 1/2
?switchport access vlan 3
?description link_to_DeviceC
!
interface VLAN 1
?ip access-group inter_vlan_access1 in
?ip address 192.168.1.1 255.255.255.0
!
interface VLAN 2
?ip access-group inter_vlan_access2 in
?ip address 192.168.2.1 255.255.255.0
!
interface VLAN 3
?ip access-group inter_vlan_access3 in
?ip address 192.168.3.1 255.255.255.0
!
l Device AµÄÅäÖÃÎļþ
hostname DeviceA
!
interface GigabitEthernet 0/1
?ip address 192.168.1.2 255.255.255.0
!
l Device BµÄÅäÖÃÎļþ
hostname DeviceB
!
interface GigabitEthernet 0/1
?ip address 192.168.2.2 255.255.255.0
!
l Device CµÄÅäÖÃÎļþ
hostname DeviceC
!
ip access-list extended access_deny
?10 deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet
?remark »Ø¾øVLAN1ͨ¹ýTelnet½Ó¼ûVLAN 3
?20 deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22
?remark »Ø¾øVLAN1ͨ¹ýSSH½Ó¼ûVLAN 3
!
interface GigabitEthernet 0/1
?ip address 192.168.3.2 255.255.255.0
!
line vty 0
?access-class access_deny in
?login
?password abcdef
!
ͨ¹ýMACÀ©´óACL£¬ÏÞ¶ÈÀ´·Ã¿Í»§¿É½Ó¼ûµÄ×ÊÔ´¡£
ͼ1-5 MACÀ©´óACLÀûÓó¡¾°×éÍøÍ¼

l Device AÅäÖÃMACÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£ÔÊÐí·Ã¿ÍÇøPC½Ó¼ûInternetÒÔ¼°¹«Ë¾ÄÚ²¿µÄ¹«¹²·þÎñÆ÷£¬µ«²»ÔÊÐí½Ó¼û¹«Ë¾µÄ²ÆÕþÊý¾Ý·þÎñÆ÷£¬¼´²»ÈݽӼûMACµØÖ·Îª00e0.f800.000dµÄ·þÎñÆ÷¡£
l Device A½«MACÀ©´óACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
(1) ÅäÖÃMACÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device AÅäÖÃMACÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# mac access-list extended 700
DeviceA(config-mac-nacl)# deny any host 00e0.f800.000d
DeviceA(config-mac-nacl)# permit any any
DeviceA(config-mac-nacl)# exit
(2) ½«MACÀ©´óACLÀûÓõ½½Ó¿ÚÉÏ¡£
# Device A½«ACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# mac access-group 700 in
# ²é³Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£
DeviceA# show access-lists
mac access-list extended 700
10 deny any host 00e0.f800.000d etype-any
20 permit any any etype-any
DeviceA# show access-group
mac access-group 700 in
Applied On interface GigabitEthernet 0/2
# ´Ó·Ã¿ÍPC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷£¬È·ÈÏping²»Í¨¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬È·ÈÏÄܹ»pingµÃͨ¡£
# ÔڷÿÍPC»úÉϽӼûInternet£¬ÀýÈç½Ó¼û°Ù¶È£¬È·ÈÏÄܹ»´ò¿ªÖ÷Ò³¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
mac access-list extended 700
?10 deny any host 00e0.f800.000d
?20 permit any any
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?mac access-group 700 in
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip address 12.1.1.1 255.255.255.0
!
ͨ¹ýÅäÖÃר¼Ò¼¶À©´óACL£¬ÏÞ¶ÈÀ´·Ã¿Í»§¿É½Ó¼ûµÄ×ÊÔ´¡£ÒªÇó·Ã¿Í²»ÄܽӼû¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÕþÊý¾Ý·þÎñÆ÷£¬µ«ÄܽӼû¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£
ͼ1-6 ר¼Ò¼¶À©´óACLÀûÓó¡¾°×éÍøÍ¼

l Device AÅäÖÃר¼Ò¼¶À©´óACL²¢Ôö³¤¹æ¶¨£¬Ô̺¬£º
¡ð ²»ÈݷÿÍÇøÄÚÖ÷»ú·¢³öÖ¸±êΪ¹«Ë¾ÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£
¡ð ²»ÈݷÿͽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£
¡ð ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£
l Device A½«ACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
(1) ÅäÖÃר¼Ò¼¶À©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device AÅäÖÃר¼Ò¼¶À©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# expert access-list extended 2700
DeviceA(config-exp-nacl)# deny ip any any 10.1.1.0 0.0.0.255 any
DeviceA(config-exp-nacl)# deny ip any any host 12.1.1.2 any
DeviceA(config-exp-nacl)# permit any any any any
DeviceA(config-exp-nacl)# exit
(2) ½«×¨¼Ò¼¶À©´óACLÀûÓõ½½Ó¿ÚÉÏ¡£
# Device A½«ACLÀûÓÃÔÚÓë·Ã¿ÍÇøÏàÏνӿڵÄÈë·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# expert access-group 2700 in
# ²é³Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£
DeviceA(config)# show access-lists
expert access-list extended 2700
?10 deny ip any any 192.168.1.0 0.0.0.255 any
20 deny ip any any host 10.1.1.1 any
30 permit ip any any any any
DeviceA(config)# show access-group
expert access-group 2700in
Applied On interface GigabitEthernet 0/2
# ´Ó·Ã¿ÍPC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷£¬È·ÈÏping²»Í¨¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬È·Èϲ»ÄÜpingͨ¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1£¬È·¶¨ping²»Í¨¡£
# ÔڷÿÍPC»úÉϽӼûInternet£¬ÀýÈç½Ó¼û°Ù¶È£¬È·ÈÏÄܹ»´ò¿ªÖ÷Ò³¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
expert access-list extended 2700
?10 deny ip any any 10.1.1.0 0.0.0.255 any
?20 deny ip any any host 12.1.1.2 any
?30 permit ip any any any any
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?expert access-group 2700 in
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip address 12.1.1.1 255.255.255.0
!
ͨ¹ýÅäÖÃIPv6 ACL£¬²»ÈÝ¿ª·¢²¿ÃŽӼûÊÓÆµ·þÎñÆ÷¡£
ͼ1-7 IPv6 ACLÀûÓó¡¾°×éÍøÍ¼

l Device AÅäÖÃIPv6 ACL²¢Ôö³¤¹æ¶¨£¬Ô̺¬£º
¡ð ²»ÈݽӼûÊÓÆµ·þÎñÆ÷IPv6µØÖ·¹æ¶¨¡£
¡ð ÔÚIPv6 ACLÖÐÔö³¤ÔÊÐíËùÓÐIPv6±¨ÎÄͨ¹ý¹æ¶¨¡£
l Device A½«IPv6 ACLÀûÓÃÔÚÏνӿª·¢²¿ÃŽӿڵÄÈë·½ÏòÉÏ¡£
(1) ÅäÖÃIPv6 ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device AÅäÖÃIPv6 ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# ipv6 access-list dev_deny_ipv6video
DeviceA(config-ipv6-nacl)# deny ipv6 any host 1002::2
DeviceA(config-ipv6-nacl)# permit ipv6 any any
DeviceA(config-ipv6-nacl)# exit
(2) ½«IPv6 ACLÀûÓõ½½Ó¿ÚÉÏ¡£
# Device A½«ACLÀûÓÃÔÚÏνӿª·¢²¿Ãŵصã½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# ipv6 traffic-filter dev_deny_ipv6video in
# ²é³Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£
DeviceA(config)# show access-lists
ipv6 access-list dev_deny_ipv6video
10 deny ipv6 any host 200::1
20 permit ipv6 any any
DeviceA(config)# show access-group
ipv6 traffic-filter dev_deny_ipv6video in
Applied On interface GigabitEthernet 0/2
# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏpingÊÓÆµ·þÎñÆ÷£¬È·ÈÏping²»Í¨¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
ipv6 access-list dev_deny_ipv6video
?10 deny ipv6 any host 1002::2
?20 permit ipv6 any any
!
interface GigabitEthernet 0/1
?no switchport
?ipv6 address 1000::1/96
!
interface GigabitEthernet 0/2
?no switchport
?ipv6 traffic-filter dev_deny_ipv6video in
?ipv6 address 1001::1/96
!
interface GigabitEthernet 0/3
?no switchport
?ipv6 address 1002::1/96
!
ͨ¹ýACL80¼´×¨¼Ò¼¶¸ß¼¶ACL£¬ÏÞ¶ÈÀ´·Ã¿Í»§¿É½Ó¼ûµÄ×ÊÔ´¡£ÒªÇó·Ã¿Í²»ÄܽӼû¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÕþÊý¾Ý·þÎñÆ÷£¬µ«ÄܽӼû¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£
ͼ1-8 ACL80ÀûÓó¡¾°×éÍøÍ¼

l Device AÅäÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ôö³¤¹æ¶¨£¬Ô̺¬£º
¡ð ²»ÈݷÿÍÇøÄÚÖ÷»ú·¢³öÖ¸±êΪÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£
¡ð ²»ÈݷÿͽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£
¡ð ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£
l Device A½«ACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
(1) ÅäÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device AÅäÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# expert access-list advanced acl80-guest
DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0A0101 FFFFFF 42
DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0C010102 FFFFFFFF 42
DeviceA(config-exp-dacl)# permit 0806 FFFF 24
DeviceA(config-exp-dacl)# permit 0800 FFFF 24
DeviceA(config-exp-dacl)# exit
(2) ½«×¨¼Ò¼¶¸ß¼¶ACLÀûÓõ½½Ó¿ÚÉÏ¡£
# Device A½«ACL80ÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# expert access-group acl80-guest in
# ²é³Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£
DeviceA(config)# show access-lists
expert access-list advanced sss
?10 deny 0800 FFFF 24 0A0101 FFFFFF 42
?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42
?30 permit 0806 FFFF 24
?40 permit 0800 FFFF 24
expert access-group acl80-guest in
Applied On interface GigabitEthernet 0/2
# ´Ó·Ã¿ÍPC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷£¬È·ÈÏping²»Í¨¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬È·ÈÏÄܹ»pingµÃͨ¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1£¬È·¶¨ping²»Í¨¡£
# ÔڷÿÍPC»úÉϽӼûInternet£¬ÀýÈç½Ó¼û°Ù¶È£¬È·ÈÏÄܹ»´ò¿ªÖ÷Ò³¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
expert access-list advanced acl80-guest
?10 deny 0800 FFFF 24 0A0101 FFFFFF 42
?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42
?30 permit 0806 FFFF 24
?40 permit 0800 FFFF 24
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?expert access-group 2700 in
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip address 12.1.1.1 255.255.255.0
!
ÅäÖûùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨£¬Ö»ÔÊÐíÑз¢²¿ÃÅÔÚÿÌìµÄ12:00µ½13:30½Ó¼ûInternet¡£
ͼ1-9 »ùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨ÀûÓó¡¾°×éÍøÍ¼

l Device AÅäÖù¦·ò¶Î£¬²¢Ôö³¤Ã¿Ìì12:00µ½13:30µÄ¹¦·ò¶Î±íÏî¡£
l Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤¹æ¶¨£¬Ô̺¬£º
¡ð Ôö³¤ÔÊÐíÔ´IPÍø¶ÎµØÖ·Îª10.1.1.0/24µÄ¹æ¶¨£¬¹ØÁªµÄ¹¦·ò¶ÎΪaccess-internet¡£
¡ð Ôö³¤²»ÈÝÔ´IPÍø¶ÎµØÖ·Îª10.1.1.0/24µÄ¹æ¶¨¡£Åú×¢¹¦·ò¶ÎÖ®±í¶¼²»ÔÊÐí½Ó¼ûInternet¡£
¡ð Ôö³¤ÔÊÐí³ýÑз¢Íø¶ÎµØÖ·±í£¬ÆäËûËùÓÐÍø¶ÎµØÖ·µÄ¹æ¶¨¡£
l Device A½«ACLÀûÓÃÔÚÏνÓÑз¢²¿½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
(1) ÅäÖù¦·òÇø¡£
# Device AÅäÖù¦·ò¶Î¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# time-range access-internet
DeviceA(config-time-range)# periodic daily 12:00 to 13:30
DeviceA(config-time-range)# exit
(2) ÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceA(config)# ip access-list standard ip_std_internet_acl
DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255 time-range access-internet
DeviceA(config-std-nacl)# deny 10.1.1.0 0.0.0.255
DeviceA(config-std-nacl)# permit any
DeviceA(config-std-nacl)# exit
(3) ½«IP³ß¶ÈACLÀûÓõ½½Ó¿ÚÉÏ¡£
# Device A½«ACLÀûÓÃÔÚÏνÓÑз¢²¿½Ó¿ÚµÄÈë·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/1
DeviceA(config-if-GigabitEthernet 0/1)# ip access-group ip_std_internet_acl in
# ²é³Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£
DeviceA# show time-range
time-range entry: access-internet (inactive)
¡¡periodic Daily 12:00 to 13:30
DeviceA# show access-lists
ip access-list standard ip_std_internet_acl
?10 permit 10.1.1.0 0.0.0.255 time-range access-internet (inactive)
?20 deny 10.1.1.0 0.0.0.255
?30 permit any
DeviceA# show access-group
ip access-group ip_std_internet_acl in
Applied On interface GigabitEthernet 0/1
# ÔÚ¹¦·ò¶ÎÉúЧÆÚÄÚ£¨12:00ÖÁ13:30£©£¬´ÓÑз¢²¿ÃÅÄÚµÄij̨PC»ú½Ó¼û°Ù¶ÈÖ÷Ò³£¬È·ÈÏÄܹ»½Ó¼û¡£
# ÔÚ¹¦·ò¶ÎʧЧÆÚ£¨12:00ÖÁ13:30ʱ¶Î±í£©£¬´ÓÑз¢²¿ÃÅÄÚµÄij̨PC»ú½Ó¼û°Ù¶ÈÖ÷Ò³£¬È·Èϲ»ÄܽӼû¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
ip access-list standard ip_std_internet_acl
?10 permit 10.1.1.0 0.0.0.255 time-range access-internet
?20 deny 10.1.1.0 0.0.0.255
?30 permit any
!
time-range access-internet
?periodic daily 12:00 to 13:30
!
interface GigabitEthernet 0/1
?no switchport
?ip access-group ip_std_internet_acl in
?ip address 10.1.1.1 255.255.255.0
!
ÅäÖÃVRRP+VLANÀûÓó¡¾°£¬Ö»ÔÊÐíÖ÷»úÓëÖ÷»úÖ®¼äµÄÈý²ãͨѶ¡£ÅäÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä½Ó¼ûµÄACL£¬»Ø¾øÆäËûËùÓÐÍø¶ÎµÄACL¡£
ͼ1-10 VRRP+VLANÀûÓó¡¾°×éÍøÍ¼

l DeviceAºÍDeviceB×é³ÉVRRP³¡¾°¡£Ö÷»úPC1ºÍPC2È«Êý½ÓÈëµ½DeviceC¡£
l ÅäÖÃÌìÉúÊ÷ºÍ̸£¬½â³ýDeviceA¡¢DeviceBºÍDeviceCÖ®¼äµÄ»·Â·¡£
l Ö÷»úPC1ºÍPC2µÄÍø¹ØÑ¡È¡SVI½Ó¿ÚµÄµØÖ·¡£
l ÅäÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä½Ó¼ûµÄACL£¬»Ø¾øÆäËûËùÓÐÍø¶ÎµÄACL£¬²¢½«ACLÀûÓÃÔÚSVI½Ó¿ÚÉÏ¡£´Ëʱ»áµ¼ÖÂVRRP×éÄÚDeviceAºÍDeviceBÐγÉË«Ö÷¡£
l ÅäÖÃsvi router-acls enableºÅÁîºó£¬VRRP×éÄÚDeviceAºÍDeviceBÐγÉÒ»Ö÷Ò»±¸£¬VRRPºÍ̸¸´ÔÕý³£¡£
(1) ÅäÖÃVLAN¡£
# DeviceAÅäÖÃVLAN¡£DeviceA¡¢DeviceBºÍDeviceCÅäÖÃÆëȫһÑù£¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# vlan 10
DeviceA(config-vlan)# exit
DeviceA(config)# vlan 20
DeviceA(config-vlan)# exit
(2) ÅäÖÃVRRP×é¡£
# DeviceAÅäÖÃVRRP¡£
DeviceA(config)# interface VLAN 10
DeviceA(config-if-VLAN 10)# ip address 172.16.1.3 255.255.255.0
DeviceA(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1
DeviceA(config-if-VLAN 10)# vrrp 10 priority 120
DeviceA(config-if-VLAN 10)# exit
DeviceA(config)# interface VLAN 20
DeviceA(config-if-VLAN 20)# ip address 172.31.1.4 255.255.255.0
DeviceA(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1
# DeviceBÅäÖÃVRRP¡£
DeviceB(config)# interface VLAN 10
DeviceB(config-if-VLAN 10)# ip address 172.16.1.4 255.255.255.0
DeviceB(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1
DeviceB(config-if-VLAN 10)# exit
DeviceB(config)# interface VLAN 20
DeviceB(config-if-VLAN 20)# ip address 172.31.1.3 255.255.255.0
DeviceB(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1
DeviceB(config-if-VLAN 20)# vrrp 20 priority 120
DeviceB(config-if-VLAN 20)# exit
(3) ÅäÖÃÌìÉúÊ÷ºÍ̸£¬½â³ý»·Â·¡£
# DeviceAÅäÖÃÌìÉúÊ÷ºÍ̸¡£DeviceA¡¢DeviceBºÍDeviceCÅäÖÃÆëȫһÑù£¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£
DeviceA(config)# spanning-tree
(4) ÅäÖÃACL¡£
# DeviceAÅäÖÃACL¡£DeviceAºÍDeviceBÅäÖÃÆëȫһÑù£¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£
DeviceA(config)# ip access-list standard 10
DeviceA(config-std-nacl)# permit host 3.3.3.3
DeviceA(config-std-nacl)# deny any
DeviceA(config-std-nacl)# exit
(5) ½«ACLÀûÓõ½SVI½Ó¿Ú¡£
# DeviceAÀûÓÃACL¡£DeviceAºÍDeviceBÅäÖÃÆëȫһÑù£¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£
DeviceA(config)# int vlan 20
DeviceA(config-if-VLAN 20)# ip access-group 10 in
(6)
ÅäÖúÅÁîsvi router-acls enable¡£
# DeviceAÅäÖúÅÁîsvi router-acls enable¡£DeviceAºÍDeviceBÅäÖÃÆëȫһÑù£¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£
DeviceA(config)# svi router-acls enable
# ²é³DeviceAÉ豸VRRPºÍ̸״̬¡£
DeviceA# show vrrp
Interface¡¡¡¡Grp¡¡Pri¡¡ timer¡¡ Own¡¡Pre¡¡ State¡¡ Master addr¡¡¡¡ Group addr¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡
VLAN 10¡¡¡¡¡¡10¡¡ 120¡¡ 3.53¡¡¡¡-¡¡¡¡P¡¡¡¡ Master¡¡172.16.1.3¡¡¡¡¡¡172.16.1.1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡
VLAN 20¡¡¡¡¡¡20¡¡ 100¡¡ 3.60¡¡¡¡-¡¡¡¡P¡¡¡¡ Backup¡¡172.31.1.3¡¡¡¡¡¡172.31.1.1
l DeviceAµÄÅäÖÃÎļþ¡£
hostname DeviceA
!
vlan 1
!
vlan 10
!
vlan 20
!
spanning-tree
!
ip access-list standard 10
?10 permit host 3.3.3.3
?20 deny any
!
svi router-acls enable
!
interface GigabitEthernet 0/1
?switchport mode trunk
!
interface GigabitEthernet 0/3
?switchport mode trunk
!
interface VLAN 1
?ip address 192.168.1.2 255.255.255.0
!
interface VLAN 10
?ip address 172.16.1.3 255.255.255.0
?vrrp 10 priority 120
?vrrp 10 ip 172.16.1.1
!
interface VLAN 20
?ip access-group 10 in
?ip address 172.31.1.4 255.255.255.0
?vrrp 20 ip 172.31.1.1
!
ip route 3.3.3.0 255.255.255.0 192.168.1.1
!
l DeviceBµÄÅäÖÃÎļþ¡£
hostname DeviceB
!
vlan 1
!
vlan 10
!
vlan 20
!
spanning-tree
!
ip access-list standard 10
?10 permit host 3.3.3.3
?20 deny any
!
svi router-acls enable
!
interface GigabitEthernet 0/1
?switchport mode trunk
!
interface GigabitEthernet 0/3
?switchport mode trunk
!
interface VLAN 1
?ip address 192.168.2.2 255.255.255.0
!
interface VLAN 10
?ip access-group 10 in
?ip address 172.16.1.4 255.255.255.0
?vrrp 10 ip 172.16.1.1
!
interface VLAN 20
?ip address 172.31.1.3 255.255.255.0
?vrrp 20 priority 120
?vrrp 20 ip 172.31.1.1
!
ip route 3.3.3.0 255.255.255.0 192.168.2.1
!
l DeviceCµÄÅäÖÃÎļþ¡£
hostname DeviceC
!
vlan 1
!
vlan 10
!
vlan 20
!
interface GigabitEthernet 0/1
?switchport access vlan 10
!
interface GigabitEthernet 0/2
?switchport access vlan 20
!
interface GigabitEthernet 0/3
?switchport mode trunk
!
interface GigabitEthernet 0/4
?switchport mode trunk
!
l ServerAµÄÅäÖÃÎļþ¡£
hostname ServerA
!
interface GigabitEthernet 0/1
?ip address 192.168.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?ip address 192.168.2.1 255.255.255.0
!
interface Loopback 0
?ip address 3.3.3.3 255.255.255.0
!
ip route 172.16.1.0 255.255.255.0 192.168.1.2
ip route 172.31.1.0 255.255.255.0 192.168.2.2
!
ÀûÓÃACLʱÈôÊÇÅäÖôøcounter-onlyÑ¡ÏÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£ÒÔPC pingÍø¹ØÅׯúICMP±¨ÎÄΪÀý½øÐмÆÊýͳ¼Æ£¬²¢¶¨Î»¶ª°üµØÎ»¡£

l DeviceÉÏG0/1ºÍG0/2µÄÈë·½ÏòºÍ³ö·½Ïò¶¼ÒªÀûÓÃACL£¬ËùÒÔDevice±ØÒªÅäÖÃ4ÌõACL£¬±ðÀëÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£
l GatewayÉ豸G0/1µÄÈë·½ÏòºÍ³ö·½Ïò¶¼ÒªÀûÓÃACL£¬ËùÒÔGatewayÅäÖÃ2ÌõACL£¬±ðÀëÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£
l ÀûÓÃACLʱÅäÖñØÒªcounter-onlyÑ¡Ïî¡£
l ¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACLÖеÄPermit¹æ¶¨ÉúЧ£¬Deny¹æ¶¨²»ÉúЧ¡£
(1) ÅäÖÃACL¡£
# DeviceÉ豸ÅäÖÃ4ÌõACL£¬±ðÀëÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£
Device> enable
Device# configure terminal
Device(config)# ip access-list extend 100
Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254
Device(config-ext-nacl)# exit
Device(config)# ip access-list extend 101
Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1
Device(config-ext-nacl)# exit
Device(config)# ip access-list extend 102
Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254
Device(config-ext-nacl)# exit
Device(config)# ip access-list extend 103
Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1
Device(config-ext-nacl)# exit
# GatewayÉ豸ÅäÖÃ2ÌõACL£¬±ðÀëÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£
Gateway> enable
Gateway #configure terminal
Gateway(config)# ip access-list extend 100
Gateway(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254
Gateway(config-ext-nacl)# exit
Gateway(config)# ip access-list extend 101
Gateway(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1
Gateway(config-ext-nacl)# exit
(2) ÀûÓÃACL¡£
# ÔÚGatewayÉ豸ºÍDeviceÉ豸»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòºÍ³ö·½ÏòÀûÓÃACL¡£
Gateway(config)# interface gigabitEthernet 0/1
Gateway(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only
Gateway(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only
Gateway(config-if-GigabitEthernet 0/1)# exit
# ÔÚDeviceÉ豸ºÍGatewayÉ豸»¥Áª½Ó¿ÚG0/2µÄÈë·½ÏòºÍ³ö·½ÏòÀûÓÃACL¡£
Device# configure terminal
Device(config)# interface gigabitEthernet 0/2
Device(config-if-GigabitEthernet 0/2)# ip access-group 103 in counter-only
Device(config-if-GigabitEthernet 0/2)# ip access-group 102 out counter-only
Device(config-if-GigabitEthernet 0/2)# exit
# ÔÚDeviceÉ豸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòºÍ³ö·½ÏòÀûÓÃACL¡£
Device# configure terminal
Device(config)# interface gigabitEthernet 0/1
Device(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only
Device(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only
Device(config-if-GigabitEthernet 0/1)# exit
# ÔÚPCÉÏpingÍø¹ØµØÖ·10.10.10.254£¬3´Î¹²·¢³ö15¸öICMP±¨ÎÄ¡£±ðÀë²é¿´DeviceÉ豸ºÍGatewayÉ豸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£²é¿´DeviceÉ豸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£
Device# show access-list
ip access-list extended 100
¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)
ip access-list extended 101
¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)
ip access-list extended 102¡¡
¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)
ip access-list extended 103¡¡
¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)
# ²é¿´GatewayÉ豸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£
Gateway# show access-list
ip access-list extended 100
¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)
ip access-list extended 101
¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (15 matches)
# ·ÖÎö±¨ÎÄͳ¼Æ¼ÆÊý£¬¶¨Î»±¨ÎÄÅׯúµØÎ»¡£
DeviceÉ豸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòÊÕµ½15¸ö±¨ÎÄ£¨DeviceÉ豸ACL 100£©¡£
DeviceÉ豸ºÍGatewayÉ豸»¥Áª½Ó¿ÚG0/2µÄ³ö·½Ïò·¢³ö15¸ö±¨ÎÄ£¨DeviceÉ豸ACL 102£©¡£
GatewayÉ豸ºÍDeviceÉ豸»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòÊÕµ½15¸ö±¨ÎÄ£¨GatewayÉ豸ACL 100£©¡£
GatewayÉ豸ºÍDeviceÉ豸»¥Áª½Ó¿ÚG0/1µÄ³ö·½Ïò·¢³ö15¸ö±¨ÎÄ£¨GatewayÉ豸ACL 101£©¡£
DeviceÉ豸ºÍGatewayÉ豸»¥Áª½Ó¿ÚG0/2µÄÈë·½ÏòÊÕµ½10¸ö±¨ÎÄ£¨DeviceÉ豸ACL 103£©¡£
×¢Ã÷±¨ÎÄÅׯúÔÚDeviceÉ豸ºÍGatewayÉ豸֮¼äµÄÁ´Â·ÉÏ¡£
l DeviceµÄÅäÖÃÎļþ¡£
hostname Device
!
ip access-list extended 100
?10 permit icmp host 10.10.10.1 host 10.10.10.254
!
ip access-list extended 101
?10 permit icmp host 10.10.10.254 host 10.10.10.1
!
ip access-list extended 102
?10 permit icmp host 10.10.10.1 host 10.10.10.254
!
ip access-list extended 103
?10 permit icmp host 10.10.10.254 host 10.10.10.1
!
interface GigabitEthernet 0/1
?ip access-group 100 in counter-only
?ip access-group 101 out counter-only
!
interface GigabitEthernet 0/2
?ip access-group 103 in counter-only
?ip access-group 104 out counter-only
!
l GatewayµÄÅäÖÃÎļþ¡£
hostname Gateway
!
ip access-list extended 100
?10 permit icmp host 10.10.10.1 host 10.10.10.254
!
ip access-list extended 101
?10 permit icmp host 10.10.10.254 host 10.10.10.1
!
interface GigabitEthernet 0/1
?ip access-group 100 in counter-only
?ip access-group 101 out counter-only
?ip address 10.10.10.254 255.255.255.0
!