ACL£¨Access Control List£¬½Ó¼û½ÚÔìÁÐ±í£©Ò²³ÆÎª½Ó¼ûÁÐ±í£¬ÓеÄÎĵµÖл¹³ÆÖ®Îª°ü¹ýÂË¡£ACLͨ¹ý½ç˵һϵÁÐÔ̺¬“ÔÊÐí”»ò“»Ø¾ø”µÄ¹æ¶¨Óï¾ä£¬²¢½«ÕâЩ¹æ¶¨ÀûÓõ½É豸½Ó¿ÚÉÏ£¬¶Ô½ø³ö½Ó¿ÚµÄÊý¾Ý°ü½øÐнÚÔ죬´Ó¶øÌáÉýÍøÂçÉ豸µÄ°²È«ÐÔ¡£
ÅäÖÃACL¿ÉÄܱ£ÏÕÍøÂ簲ȫ¡¢¿¿µÃסºÍ²»±ä£¬ÀýÈ磺
l Ô¤·À±¨ÎĹ¥»÷£ºÕë¶ÔIP¡¢TCP»òÕßICMP±¨ÎĵĹ¥»÷£¬¶ÔÕâЩ¹¥»÷±¨ÎÄ×ö“»Ø¾ø”´¦Öá£
l ÍøÂç½Ó¼û½ÚÔ죺ÏÞ¶Å×û§½Ó¼û·þÎñ£¬ÀýÈçÖ»ÔÊÐí½Ó¼ûWWWºÍµç×ÓÓʼþ·þÎñ£¬ÆäËû·þÎñÈçTelnetÔò²»ÈÝ¡£»òÕßÖ»ÔÊÐíÔÚ¸ø¶¨µÄ¹¦·ò¶ÎÄÚ½Ó¼û£¬»òÕßÖ»ÔÊÐíÌØ¶¨Ö÷»ú½Ó¼ûÍøÂçµÈ¡£
l ÍøÂçÁ÷Á¿½ÚÔ죺½áºÏQoS¿ÉÒÔΪ³ÁÒªµÄÊý¾ÝÁ÷½øÐÐÓÅÏÈ·þÎñ±£ÕÏ¡£¹ØÓÚQoSµÄÅäÖÃÇë°Ý¼û“QoS”¡£
l ½Ó¼ûÁбí
½Ó¼ûÁбíÓУº¸ù»ù½Ó¼ûÁбíºÍ¶¯Ì¬½Ó¼ûÁÐ±í¡£
Óû§Äܹ»Æ¾¾Ý±ØÒªÑ¡Ôñ¸ù»ù½Ó¼ûÁбí»ò¶¯Ì¬½Ó¼ûÁÐ±í¡£Í¨³£Çé¿öÏ£¬Ê¹Óøù»ù½Ó¼ûÁбíÒѾ¿ÉÄÜÂú×㰲ȫ±ØÒª¡£µ«¹¥»÷Õß¿ÉÄÜͨ¹ýÈí¼þ¼ÙðԴµØÖ·ºýŪÉ豸£¬´Ó¶ø½Ó¼ûÍøÂç¡£¶ø¶¯Ì¬½Ó¼ûÁбíÔÚÓû§½Ó¼ûÍøÂçÒÔǰ£¬ÒªÇóͨ¹ýÉí·ÝÈÏÖ¤£¬Ê¹¹¥»÷ÕßÄÑÒÔ½Ó¼ûÍøÂç¡£ÔÚÃô¸ÐÇøÓòÄܹ»Ê¹Óö¯Ì¬½Ó¼ûÁÐ±í±£ÕÏÍøÂ簲ȫ¡£
×¢Ã÷
ͨ¹ý¼ÙðԴµØÖ·ºýŪÉ豸¼´µç×ÓºýŪÊÇËùÓнӼûÁбí¹ÌÓеÄÎÊÌ⣬ʹÓö¯Ì¬ÁбíÒ²»áÔâ·êµç×ÓºýŪÎÊÌ⣺¹¥»÷Õß¿ÉÄÜÔÚÓû§Í¨¹ýÉí·ÝÈÏÖ¤µÄÓÐЧ½Ó¼ûÆÚ¼ä£¬¼ÙðÓû§µÄµØÖ·½Ó¼ûÍøÂç¡£½â¾ö¸ÃÎÊÌâµÄ²½ÖèÓÐÁ½ÖÖ£¬Ò»ÖÖÊǾ¡Á¿ÉèÖøü¶ÌµÄÓû§½Ó¼û¿ÕÏй¦·ò£»ÁíÒ»ÖÖÊÇʹÓÃIPsec¼ÓÃܺÍ̸¶ÔÍøÂçÊý¾Ý½øÐмÓÃÜ£¬È·±£½øÈëÉ豸ʱ£¬ËùÓеÄÊý¾Ý¶¼ÊǼÓÃܵġ£
½Ó¼ûÁбíͨ³£ÅäÖÃÔÚÒÔϵØÎ»µÄÍøÂçÉ豸ÉÏ£º
¡ð ÄÚ²¿ÍøºÍ±í²¿Íø£¨ÈçInternet£©Ö®¼äµÄÉ豸
¡ð Á½¸öÍøÂç½ÓÈÀ²¿ÃŵÄÉ豸
¡ð ½ÓÈë½ÚÔì¶Ë¿ÚµÄÉ豸
ACE£¨Access Control Entry£¬½Ó¼û½ÚÔìÌõ¿î£©ÊÇÔ̺¬“ÔÊÐí£¨Permit£©”»ò“»Ø¾ø£¨Deny£©”Á½ÖÖ×÷Ϊ£¬ÒÔ¼°¹ýÂ˹涨µÄÒ»ÌõÓï¾ä¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ£¬¸ÃÐòºÅ¿ÉÓÉÉ豸×Ô¶¯·ÖÅä»òÕßÊÖ¶¯ÅäÖá£Ò»ÌõACLÖÐÔ̺¬Ò»¸ö»òÕß¶à¸öACE¡£ACLͨ¹ýACE¶ÔÊý¾Ý°ü½øÐбêʶ¹ýÂË¡£
ACLÖÐACEµÄ°¤´Î¾ö¶¨Á˸ÃACEÔÚ½Ó¼ûÁбíÖÐµÄÆ¥ÅäÓÅÏȼ¶¡£ÍøÂçÉ豸ÔÚ´¦Öñ¨ÎÄʱ£¬°´ACEµÄÐòºÅ´ÓÓ×µ½ÃͽøÐй涨ƥÅ䣬µ¹ØÒµ½Æ¥ÅäµÄACEºóÔòÖÕ³¡²é³ºóÐøµÄACE¡£
ÀýÈç´´½¨Ò»ÌõÐòºÅΪ10µÄACE£¬Ëü»Ø¾øËùÓеÄÊý¾ÝÁ÷ͨ¹ý¡£
10 deny ip any any
20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
ÓÉÓÚÐòºÅΪ10µÄACE»Ø¾øÁËËùÓеÄIP±¨ÎÄ£¬¼´±ã192.168.12.0/24ÍøÂçµÄÖ÷»úTelnet±¨ÎÄ£¬Äܹ»±»ÐòºÅΪ20µÄACEÆ¥Å䣬¸Ã±¨ÎÄÒ²½«±»»Ø¾ø¡£ÓÉÓÚÉ豸Ôڲ鳵½±¨ÎĺÍÐòºÅΪ10µÄACEÆ¥Åäºó£¬±ãÖÕ³¡²é³ºóÃæÐòºÅΪ20µÄACE¡£
ÓÖÀýÈç´´½¨Ò»Ìõ±àºÅΪ10µÄACE£¬ËüÔÊÐíËùÓеÄIPv6Êý¾ÝÁ÷ͨ¹ý¡£
10 permit ipv6 any any
20 deny ipv6 host 200::1 any
ÓÉÓÚÐòºÅΪ10µÄACEÔÊÐíËùÓеÄIPv6±¨ÎÄͨ¹ý£¬Ö÷»ú200::1·¢³öµÄIPv6±¨ÎÄ£¬¼´±ãÆ¥ÅäÐòºÅΪ20µÄACE£¬¸Ã±¨ÎÄÒ²½«±»ÔÊÐíͨ¹ý¡£ÓÉÓÚÉ豸Ôڲ鳵½±¨Îĺ͵ÚÒ»ÌõACEÆ¥Å䣬±ãÖÕ³¡²é³ºóÃæÐòºÅΪ20µÄACE¡£
l ²½³¤
µ±É豸ΪACE×Ô¶¯·ÖÅäÐòºÅʱ£¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ£¬³ÆÎª²½³¤¡£ÀýÈ磬ÈôÊǽ«²½³¤É趨Ϊ5£¬ÔòÉ豸ÒÀÕÕ5¡¢10¡¢15…ÕâÑùµÄµÝÔö°¤´Î×Ô¶¯ÎªACE·ÖÅäÐòºÅ¡£ÈçÏÂËùʾ¡£
5 deny ip any any
10 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
µ±²½³¤Å¤×ªºó£¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤Öµ³ÁзÖÅä¡£ÀýÈ磬µ±°Ñ²½³¤¸ÄΪ10ºó£¬ÔÀ´ACEÐòºÅ´Ó5¡¢10¡¢15Ôì³É5¡¢15¡¢25¡£
ͨ¹ýŤת²½³¤Äܹ»ÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£ÀýÈç´´½¨ÁË4¸öACE£¬²¢Í¨¹ýÊÖ¶¯ÅäÖÃACEÐòºÅ±ðÀëΪ1¡¢2¡¢3ºÍ4¡£ÈôÊǵ«Ô¸ÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE£¬ÔòÄܹ»ÏȽ«²½³¤Åú¸ÄΪ2£¬´ËʱÔÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7£¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÅäÖõÄÐòºÅΪ2µÄACE¡£
l ¹ýÂËÓòÄ£°å
¹ýÂËÓòÖ¸µÄÊÇÌìÉúÒ»ÌõACEʱ£¬Æ¾¾Ý±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎĽøÐмø±ð¡¢·ÖÀà¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£ACEƾ¾ÝÒÔÌ«Íø±¨ÎĵÄijЩ×Ö¶ÎÀ´±êʶÒÔÌ«Íø±¨ÎÄ£¬ÕâЩ×Ö¶ÎÔ̺¬£º
¶þ²ã×ֶΣ¨Layer 2 Fields£©£º
¡ð 48λµÄÔ´MACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩
¡ð 48λµÄÖ÷ÕÅMACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩
¡ð 16λµÄ¶þ²ãÀàÐÍ×Ö¶Î
Èý²ã×ֶΣ¨Layer 3 Fields£©£º
¡ð Ô´IPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÔ´IPµØÖ·Öµ£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©
¡ð Ö÷ÕÅIPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÖ÷ÕÅIPµØÖ·Öµ£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©
¡ð ºÍ̸ÀàÐÍ×Ö¶Î
ËIJã×ֶΣ¨Layer 4 Fields£©£º
¡ð Äܹ»ÉêÃ÷Ò»¸öTCPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷£¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£
¡ð Äܹ»ÉêÃ÷Ò»¸öUDPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷£¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£
ÀýÈ磬ÔÚ´´½¨Ò»ÌõACEʱ±ØÒªÆ¾¾Ý±¨ÎĵÄÖ÷ÕÅIP×ֶΣ¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£¶øÔÚ´´½¨ÁíÒ»ÌõACEʱ£¬±ØÒªÆ¾¾Ý±¨ÎĵÄÔ´IPµØÖ·×ֶκÍUDPµÄÔ´¶Ë¿Ú×ֶΣ¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£ÕâÁ½ÌõACE¾ÍʹÓÃÁË·ÖÆçµÄ¹ýÂËÓòÄ£°å¡£
l ¹æ¶¨
¹æ¶¨£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£ÀýÈ磬һÌõACEµÄÄÚÈÝÈçÏ£º
10 permit tcp host 192.168.12.2 any eq telnet
ÔÚÕâÌõACEÖУ¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεļ¯ÖУºÔ´IPµØÖ·×ֶΡ¢Ö÷ÕÅIPµØÖ·×ֶΡ¢IPºÍ̸×ֶΡ¢TCPÖ÷ÕŶ˿Ú×ֶΡ£¶ÔÓ¦µÄÖµ£¨¼´¹æ¶¨£©±ðÀëΪ£ºÔ´IPµØÖ·ÎªHost 192.168.12.2¡¢Ö÷ÕÅIPµØÖ·ÎªAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPºÍ̸ΪTCP¡¢TCPÖ÷ÕŶ˿ÚΪTelnet¡£Èçͼ1-1Ëùʾ¡£
ͼ1-1 ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄ·ÖÎö
ͨ¹ýÅäÖÃIP³ß¶ÈACL£¬²»ÈݲÆÕþ²¿ÒÔ±íµÄ²¿ÃŽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£
ͼ1-3 IP³ß¶ÈACLÀûÓó¡¾°×éÍøÍ¼

l Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
l Device A½«IP³ß¶ÈACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£
(1) ÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
# Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# ip access-list standard 1
DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255
DeviceA(config-std-nacl)# deny 11.1.1.1 0.0.0.255
DeviceA(config-std-nacl)# exit
(2) ½«IP³ß¶ÈACLÀûÓõ½½Ó¿ÚÉÏ¡£
# Device A½«ACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/3
DeviceA(config-if-GigabitEthernet 0/3)# ip access-group 1 out
# ²é³Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£
DeviceA# show access-lists
ip access-list standard 1
10 permit 10.1.1.0 0.0.0.255
20 deny 11.1.1.0 0.0.0.255
DeviceA# show access-group
ip access-group 1 out
Applied On interface GigabitEthernet 0/3
# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷£¬È·ÈÏping²»Í¨¡£
# ´Ó²ÆÕþ²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷£¬È·ÈÏÄÜpingͨ¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
ip access-list standard 1
10 permit 10.1.1.0 0.0.0.255
20 deny 11.1.1.0 0.0.0.255
!
interface GigabitEthernet 0/1
no switchport
ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
no switchport
ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
no switchport
ip access-group 1 out
ip address 12.1.1.1 255.255.255.0
!