GA»Æ½ð¼×

¡°¼«¼ò¡±»ÀР¡¤ È«ÓòÖÇÁª Ø­ GA»Æ½ð¼×м«¼òÁ캽ÏÂÒ»´úÐ£Ô°Íø½¨Éè×êÑлá
date
Ô¤Ô¼Ö±²¥
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨°ä²¼
date
Ô¤Ô¼Ö±²¥
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¹æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¹æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷ͬ°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/˵»°
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ACL¸ù»ù¸ÅÏë¼°µÀÀí½éÉÜ

ACLͨ¹ý½ç˵һϵÁеÄACL¹æ¶¨  £¬²¢ÀûÓÃÔÚÉ豸ÖÐ  £¬ÒÔʵÏÖÍøÂç´«ÊäÖеÄÉ豸µÄÊý¾Ý±¨ÎĹýÂ˺ÍÊý¾Ý±¨ÎÄ·ÖÀàµÄÖ°ÄÜ  £¬¿ÉÄÜÔ¤·ÀÍøÂçÖеı¨ÎĹ¥»÷ºÍ½ÚÔìÍøÂç½Ó¼û  £¬ÊµÏÖÁËÍøÂç¶Ô°²È«¡¢¿¿µÃסºÍ²»±äµÄ±£¾þÇÍÇó¡£

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    °ä²¼¹¦·ò£º2022-11-24

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    µã»÷Á¿£º

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    µãÔÞ£º

·ÖÏíÖÁ

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ÎÒÏëÆÀÂÛ

1 ACL¸ÅÊö
1.1   ACLÊÇʲô
ÔÚ½éÉÜACL×÷ÓÃ֮ǰ  £¬ÏÈÀ´¿´¿´Ê²Ã´ÊÇACL¡£ACL£¨Access Control List  £¬½Ó¼û½ÚÔìÁÐ±í£©Ò²³ÆÎª½Ó¼ûÁбí  £¬»òÕß°ü¹ýÂË¡£ACLÔ̺¬ÁËһϵÁÐǰÌáÓï¾ä  £¬ÏÖʵÉÏÊÇһϵÁÐÔ̺¬“ÔÊÐí”»òÕß“»Ø¾ø”µÄ¹æ¶¨¡£»»¾ä»°Ëµ  £¬ACLÊDZ¨´ð½ç˵µÄһϵÁй涨  £¬ÒÔ±ãÉ豸ÅжÏÊÇ·ñÖ´ÐÐÓû§»®¶¨×÷Ϊ¡£
1.2   ACL×÷ÓÃ
ACL³öÏֵijõʼÖ÷ÕÅÊÇÓÃÓÚÊý¾Ý±¨ÎĹýÂ˺ÍÊý¾Ý±¨ÎÄ·ÖÀà¡£ÏÂÃæ¶ÔACL×÷ÓÃ×ö¼òÒª½éÉÜ¡£
¡ñÊý¾Ý±¨ÎĹýÂË
ÓÉÓÚACLÔ̺¬ÁË“ÔÊÐí”»ò“»Ø¾ø”µÄACL¹æ¶¨  £¬Í¨¹ýACL¹æ¶¨  £¬¿ÉÄܽÚÔìÉ豸ÊÇ·ñת·¢Êý¾Ý±¨ÎÄ  £¬»òÕßÏÞ¶Å×û§½Ó¼û·þÎñ¡£
¡ñÊý¾Ý±¨ÎÄ·ÖÀà
ͨ¹ýACL¹æ¶¨¶ÔÊý¾Ý±¨ÎĽøÐзÖÀà  £¬ÆäËûÀûÓ㨺ñÈQoS¡¢Õ½Êõ·Óɵȣ©Í¨¹ýŲÓÃACL  £¬¿ÉÄÜ¶Ô·ÖÆçÀà´ËÍâÊý¾Ý±¨ÎĽøÐÐÇø±ð´¦Öá£
                                                                              
2 ACL¹¤×÷µÀÀí
2.1   ACLµÄ¸ù»ù¸ÅÏë½éÉÜ
¡ñACE
ACE£¨Access Control Entry  £¬½Ó¼û½ÚÔìÌõ¿î£©ÊÇÔ̺¬“ÔÊÐí£¨Permit£©”»ò“»Ø¾ø£¨Deny£©”Á½ÖÖ×÷Ϊ  £¬ÒÔ¼°¹ýÂ˹涨µÄÒ»ÌõÓï¾ä¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ  £¬¸ÃÐòºÅ¿ÉÓÉÉ豸×Ô¶¯·ÖÅä»òÕßÊÖ¶¯ÅäÖá£Ò»ÌõACLÖÐÔ̺¬Ò»¸ö»òÕß¶à¸öACE¡£ACLͨ¹ýACE¶ÔÊý¾Ý±¨ÎĽøÐйýÂ˺ͷÖÀà¡£
¡ñ²½³¤
µ±É豸ΪACE×Ô¶¯·ÖÅäÐòºÅʱ  £¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ  £¬³ÆÎª²½³¤¡£ÀýÈç  £¬ÈôÊǽ«ACEµÄ²½³¤É趨Ϊ20  £¬ÔòÉ豸ÒÀÕÕ0¡¢20¡¢40¡¢60…ÕâÑùµÄµÝÔö°¤´Î×Ô¶¯ÎªACE·ÖÅäÐòºÅ¡£ÈçÏÂËùʾ¡£
0 deny ip any any
20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
µ±²½³¤Å¤×ªºó  £¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤Öµ³ÁзÖÅä¡£ÀýÈç  £¬µ±°Ñ²½³¤¸ÄΪ10ºó  £¬Ô­À´ACEÐòºÅ´Ó0¡¢20¡¢40Ôì³É0¡¢20¡¢30¡£
ͨ¹ýŤת²½³¤Äܹ»ÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£ÀýÈç´´½¨ÁË4¸öACE  £¬²¢Í¨¹ýÊÖ¶¯ÅäÖÃACEÐòºÅ±ðÀëΪ1¡¢2¡¢3ºÍ4¡£ÈôÊǵ«Ô¸ÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE  £¬ÔòÄܹ»ÏȽ«²½³¤Åú¸ÄΪ2  £¬´ËʱԭÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7  £¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÅäÖõÄÐòºÅΪ2µÄACE¡£
¡ñ¹ýÂËÓòºÍ¹ýÂËÓòÄ£°å
¹ýÂËÓòÖ¸µÄÊÇÌìÉúÒ»ÌõACEʱ  £¬Æ¾¾Ý±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎĽøÐмø±ð¡¢·ÖÀà¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£
¡ñACL¹æ¶¨
ACL¹æ¶¨£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£ÀýÈç  £¬Ò»ÌõACEµÄÄÚÈÝÈçÏ£º
10 permit tcp host 192.168.12.2 any eq telnet
ÔÚÕâÌõACEÖÐ  £¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεļ¯ÖУºÔ´IPµØÖ·×ֶΡ¢Ö÷ÕÅIPµØÖ·×ֶΡ¢IPºÍ̸×ֶΡ¢TCPÖ÷ÕŶ˿Ú×ֶΡ£¶ÔÓ¦µÄÖµ£¨¼´¹æ¶¨£©±ðÀëΪ£ºÔ´IPµØÖ·ÎªHost 192.168.12.2¡¢Ö÷ÕÅIPµØÖ·ÎªAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPºÍ̸ΪTCP¡¢TCPÖ÷ÕŶ˿ÚΪTelnet¡£Èçͼ2-1Ëùʾ¡£
¡ñÐÐΪ
ÐÐΪ£¨Action£©Ö¸µÄÊÇACEÖÐÖ¸¶¨µÄ×÷Ϊ  £¬Ô̺¬“ÔÊÐí£¨Permit£©”»ò“»Ø¾ø£¨Deny£©”Á½ÖÖ¡£PermitΪÔÊÐí¹æ¶¨ÖÐÖ¸¶¨µÄÁ÷Á¿  £¬DenyΪ»Ø¾ø¹æ¶¨ÖÐÖ¸¶¨µÄÁ÷Á¿¡£
ͼ2-1 ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄ·ÖÎö
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
                                                                                
2.2   ACL¹¤×÷µÀÀí½éÉÜ
ACLÓÉһϵÁеÄACE×é³É¡£Ã¿¸öACE¶¼½ç˵ÁËACL¹æ¶¨¼°ÐÐΪ¡£ÔÚËùÓеÄACEÖ®ºó  £¬´æÔÚÒ»ÌõĬÈϻؾøËùÓб¨ÎĵÄACE£ºdeny any any£¨²»ÏÔʾ£©¡£
ACEÄܹ»Õë¶ÔÊý¾Ý±¨ÎĵÄÔ´µØÖ·¡¢Ö÷ÕŵØÖ·¡¢ÉϲãºÍ̸  £¬¹¦·òÇøÓòµÈÐÅÏ¢½øÐйýÂË¡£
ACEÔÚACLÖеݤ´Î¾ö¶¨Á˸ÃACEÔÚACLÖеı¨ÎÄÆ¥ÅäÓÅÏȼ¶¡£µ±Êý¾Ý±¨ÎĽøÈëÉ豸»òÕßÒª´ÓÉ豸ÖÐת·¢Ê±  £¬°´ACEµÄÐòºÅ´ÓÓ×µ½ÃͽøÐй涨ƥÅä  £¬µ¹ØÒµ½Æ¥ÅäµÄACEºóÖÕ³¡²é³­ºóÐøµÄACE¡£ÈôÊÇÅäÖõÄACE¶¼Î´Æ¥Åäµ½  £¬ÔòÆ¥Åä×îºóÒ»ÌõĬÈϻؾøËùÓб¨ÎĵÄACE¡£Èçͼ2-2Ëùʾ¡£
´´½¨ACL²¢½«ACLÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»òÕß³ö·½Ïòºó  £¬ACLÖ°ÄܲÅÉúЧ¡£µ±±¨ÎĽø³öÉ豸ʱ  £¬É豸ͨ¹ýÅжϱ¨ÎÄÊÇ·ñÆ¥ÅäACL¹æ¶¨  £¬¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£ACL²Å¿ÉÄܲûÑï½ÚÔì½Ó¼ûµÄ×÷Óá£
ͼ2-2 ACL¹¤×÷µÀÀíͼ
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
                                                                                    
3 ʵÏÖÓï
Ëæ×ÅÍøÂçÀûÓõÄÍÆ¹ãºÍÍøÂç¼¼ÊõµÄ·¢Õ¹  £¬ÍøÂçµÄ±£¾þÇÍÔ½À´Ô½¸ß¡£ACLµÄÊý¾Ý±¨ÎĹýÂ˺ÍÊý¾Ý±¨ÎÄ·ÖÀàµÄÖ°ÄÜ  £¬¿ÉÄÜÔ¤·ÀÍøÂçÖеı¨ÎĹ¥»÷ºÍ½ÚÔìÍøÂç½Ó¼û  £¬ÊµÏÖÁËÍøÂç¶Ô°²È«¡¢¿¿µÃסºÍ²»±äµÄ±£¾þÇÍÇó¡£ÄÇô  £¬ACL·ÖÀàÓÐÄÄЩ£¿¸ß¼¶ACLºÍ¸ù»ùACLµÄÇø±ð¡¢³ß¶ÈACLºÍÀ©´óACLµÄÇø±ð±ðÀëÊÇʲô£¿ACLÅäÖÃÈôºÎʵÏÖÄØ£¿¾´ÇëµÈ´ýºóÐø½éÉÜ¡£
                                                                          

ÓйرêÇ©£º

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

µãÔÞ

¸ü¶à¼¼Êõ²©ÎÄ

ÈκαØÒª  £¬ÇëÁªÏµGA»Æ½ð¼×

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµAI¸±ÊÖ
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµÆÀ¼Û
ev-close
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
ev-close
Äú¶Ôµ±Ç°Ò³ÃæµÄÖÐÒâ¶ÈÈôºÎ£¿
²»Õ¦µÎ
¼«¶ÈºÃ
dark-star dark-star dark-star dark-star dark-star
ev-close
ÄúÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
Äú²»ÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
ÄúÊÇ·ñ»¹ÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁ˼±¾ç½â¾ö²¢»Ø¸´ÄúµÄÎÊÌâ  £¬ÄúÄܹ»ÁôÏÂÁªÏµ·½Ê½
ÓÊÏä
ÊÖ»úºÅ
ev-bg
¸Ð¼¤ÄúµÄ·´À¡£¡
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø¹ØÕ÷ѯҳ
ÊÛǰÕ÷ѯ ÊÛǰÕ÷ѯ
ÊÛǰÕ÷ѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
¶¨¼û·´À¡ ¶¨¼û·´À¡
¶¨¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿