Video 28-29 µÚÊ®ËÄÕ IP·ÃÎÊ¿ØÖÆÁбí IP Access Control List(ACL)
2007-07-15 11:43:45
Video 28 µÚÊ®ËÄÕ IP·ÃÎÊ¿ØÖÆÁбí IP Access Control List(ACL)
±ê×¼
¼ì²éÔ´µØÖ·
ͨ³£ÔÊÐí¡¢¾Ü¾øµÄÊÇÍêÕûµÄÐÒé
À©Õ¹
¼ì²éÔ´µØÖ·ºÍÄ¿µÄµØÖ·
ͨ³£ÔÊÐí¡¢¾Ü¾øµÄÊÇij¸öÌØ¶¨µÄÐÒé
½ø·½ÏòºÍ³ö·½Ïò
·ÃÎÊÁбíµÄ±àºÅÖ¸Ã÷ÁËʹÓúÉÖØÐÒéµÄ·ÃÎÊÁбí
ÿ¸ö¶Ë¿Ú¡¢Ã¿¸ö·½Ïò¡¢Ã¿ÌõÐÒéÖ»ÄܶÔÓ¦ÓÚÒ»Ìõ·ÃÎÊÁбí
·ÃÎÊÁбíµÄÄÚÈݾö¶¨ÁËÊý¾ÝµÄ¿ØÖÆË³Ðò
¾ßÓÐÑϸñÏÞÖÆÌõ¼þµÄÓï¾äÓ¦·ÅÔÚ·ÃÎÊÁбíËùÓÐÓï¾äµÄ×îÉÏÃæ
ÔÚ·ÃÎÊÁбíµÄ×îºóÓÐÒ»ÌõÒþº¬ÉùÃ÷£ºdeny anyÿһÌõÕýÈ·µÄ·ÃÎÊÁÐ±í¶¼ÖÁÉÙÓ¦¸ÃÓÐÒ»ÌõÔÊÐíÓï¾ä
ÏÈ´´½¨·ÃÎÊÁÐ±í£¬È»ºóÓ¦Óõ½¶Ë¿ÚÉÏ
·ÃÎÊÁÐ±í²»ÄܹýÂËÓÉÂËÓÍÆ÷×Ô¼º²úÉúµÄÊý¾Ý
·ÃÎÊ¿ØÖÆÁбíÉèÖÃÃüÁî
Step1:ÉèÖ÷ÃÎÊÁбí²âÊÔÓï¾äµÄ²ÎÊý
Router(config)# access-list access-list-number{permit|deny}{set conditions}
Step2:ÔÚ¶Ë¿ÚÉÏÓ¦Ó÷ÃÎÊÁбí
Router(config-if)#
{protocol}access-group access-list-number{in|out}
IP·ÃÎÊÁбíµÄ±êºÅΪ1-99£¨±ê×¼£©ºÍ100-199£¨À©Õ¹£©
Video 29 ÅäÖñê×¼µÄIP·ÃÎÊÁбí
Router(config)# access-list access-list-nuimber {permit|deny}source[mask]
Ϊ·ÃÎÊÁбíÉèÖòÎÊý
IP±ê×¼·ÃÎÊÁбí±àºÅ1µ½99
ȱʡµÄͨÅä·ûÑÚÂë = 0.0.0.0
no access-list access-list-number ÃüÁîɾ³ý·ÃÎÊÁбí
·´ÑÚÂëwildcard mask: 0±íʾ¾«È·Æ¥Å䣬1´ú±íÈÎÒâÆ¥Åä
ͨÅä·ûÑÚÂëÖ¸Ã÷ËùÓÐÖ÷»ú
ËùÓÐÖ÷»ú£º0.0.0.0 ·´ÑÚÂë255.255.255.255
¿ÉÒÔÓÃANY¼òд
¿ÉÒÔ¼òдΪ host (host 172.30.16.29)
172.30.16.29 0.0.0.0 = host 172.30.16.29
ÅäÖÃ
Router(config-if)#
|


tommy5
²©¿Íͳ¼ÆÐÅÏ¢
ÈÈÃÅÎÄÕÂ
×îÐÂÆÀÂÛ
ÓÑÇéÁ´½Ó
