Ä¿¡¡Â¼

1 ACL. 1

1.1 Ö°ÄܽéÉÜ... 1

1.1.1 ACL¸ÅÊö... 1

1.1.2 ¹¤×÷µÀÀí... 1

1.2 ÅäÖù¤×÷¸ÅÀÀ... 10

1.3 ÅäÖÃIP³ß¶ÈACL. 11

1.3.1 Ö°Äܼò½é... 11

1.3.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 11

1.3.3 ÅäÖù¤×÷¼ò½é... 11

1.3.4 ´´½¨IP³ß¶ÈACL. 11

1.3.5 ÀûÓÃIP³ß¶ÈACL. 13

1.4 ÅäÖÃIPÀ©´óACL. 14

1.4.1 Ö°Äܼò½é... 14

1.4.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 14

1.4.3 ÅäÖù¤×÷¼ò½é... 14

1.4.4 ´´½¨IPÀ©´óACL. 14

1.4.5 ÀûÓÃIPÀ©´óACL. 16

1.5 ÅäÖÃMACÀ©´óACL. 17

1.5.1 Ö°Äܼò½é... 17

1.5.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 17

1.5.3 ÅäÖù¤×÷¼ò½é... 17

1.5.4 ´´½¨MACÀ©´óACL. 17

1.5.5 ÀûÓÃMACÀ©´óACL. 18

1.6 ÅäÖÃר¼Ò¼¶À©´óACL. 19

1.6.1 Ö°Äܼò½é... 19

1.6.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 19

1.6.3 ÅäÖù¤×÷¼ò½é... 19

1.6.4 ´´½¨×¨¼Ò¼¶À©´óACL. 19

1.6.5 ÀûÓÃר¼Ò¼¶À©´óACL. 21

1.7 ÅäÖÃIPv6 ACL. 22

1.7.1 Ö°Äܼò½é... 22

1.7.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 22

1.7.3 ÅäÖù¤×÷¼ò½é... 22

1.7.4 ´´½¨IPv6 ACL. 22

1.7.5 ÀûÓÃIPv6 ACL. 24

1.8 ÅäÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©... 24

1.8.1 Ö°Äܼò½é... 24

1.8.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 25

1.8.3 ÅäÖù¤×÷¼ò½é... 25

1.8.4 ´´½¨×¨¼Ò¼¶¸ß¼¶ACL. 25

1.8.5 ÀûÓÃר¼Ò¼¶¸ß¼¶ACL. 26

1.9 ÅäÖÃACL³Á¶¨Ïò... 26

1.9.1 Ö°Äܼò½é... 26

1.9.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 26

1.9.3 ÅäÖóﱸ... 27

1.9.4 ÅäÖò½Öè... 27

1.10 ÅäÖÃÈ«¾Ö°²È«ACL. 27

1.10.1 Ö°Äܼò½é... 27

1.10.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 27

1.10.3 ÅäÖóﱸ... 27

1.10.4 ÅäÖò½Öè... 27

1.11 ÅäÖ÷Ô쬱¨ÎÄÆ¥Åäģʽ... 28

1.11.1 Ö°Äܼò½é... 28

1.11.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 28

1.11.3 ÅäÖóﱸ... 28

1.11.4 ÅäÖò½Öè... 28

1.12 ÅäÖÃSVI Router ACL. 29

1.12.1 Ö°Äܼò½é... 29

1.12.2 ÅäÖóﱸ... 29

1.12.3 ÅäÖò½Öè... 29

1.13 ÅäÖÃACL¹ÊÕϸ´Ô­... 29

1.13.1 Ö°Äܼò½é... 29

1.13.2 ÅäÖò½Öè... 29

1.14 ¼à¶½ÓëÊØ»¤... 29

1.15 µäÐÍÅäÖþÙÀý... 30

1.15.1 IP³ß¶ÈACLÅäÖþÙÀý... 30

1.15.2 IPÀ©´óACLÅäÖþÙÀý... 32

1.15.3 MACÀ©´óACLÅäÖþÙÀý... 37

1.15.4 ר¼Ò¼¶À©´óACLÅäÖþÙÀý... 39

1.15.5 IPv6 ACLÅäÖþÙÀý... 41

1.15.6 ACL80ÅäÖþÙÀý... 43

1.15.7 »ùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨ÅäÖþÙÀý... 45

1.15.8 SVI Router ACLÅäÖþÙÀý... 47

1.15.9 ACL±¨ÎļÆÊýͳ¼ÆÅäÖþÙÀý... 51

 


1 ACL

1.1?? Ö°ÄܽéÉÜ

1.1.1? ACL¸ÅÊö

ACL£¨Access Control List £¬½Ó¼û½ÚÔìÁÐ±í£©Ò²³ÆÎª½Ó¼ûÁбí £¬ÓеÄÎĵµÖл¹³ÆÖ®Îª°ü¹ýÂË¡£ACLͨ¹ý½ç˵һϵÁÐÔ̺¬¡°ÔÊÐí¡±»ò¡°»Ø¾ø¡±µÄ¹æ¶¨Óï¾ä £¬²¢½«ÕâЩ¹æ¶¨ÀûÓõ½É豸½Ó¿ÚÉÏ £¬¶Ô½ø³ö½Ó¿ÚµÄÊý¾Ý°ü½øÐнÚÔì £¬´Ó¶øÌáÉýÍøÂçÉ豸µÄ°²È«ÐÔ¡£

ÅäÖÃACL¿ÉÄܱ£ÏÕÍøÂ簲ȫ¡¢¿¿µÃסºÍ²»±ä £¬ÀýÈ磺

l  Ô¤·À±¨ÎĹ¥»÷£ºÕë¶ÔIP¡¢TCP»òÕßICMP±¨ÎĵĹ¥»÷ £¬¶ÔÕâЩ¹¥»÷±¨ÎÄ×ö¡°»Ø¾ø¡±´¦Öá£

l  ÍøÂç½Ó¼û½ÚÔ죺ÏÞ¶Å×û§½Ó¼û·þÎñ £¬ÀýÈçÖ»ÔÊÐí½Ó¼ûWWWºÍµç×ÓÓʼþ·þÎñ £¬ÆäËû·þÎñÈçTelnetÔò²»ÈÝ¡£»òÕßÖ»ÔÊÐíÔÚ¸ø¶¨µÄ¹¦·ò¶ÎÄÚ½Ó¼û £¬»òÕßÖ»ÔÊÐíÌØ¶¨Ö÷»ú½Ó¼ûÍøÂçµÈ¡£

l  ÍøÂçÁ÷Á¿½ÚÔ죺½áºÏQoS¿ÉÒÔΪ³ÁÒªµÄÊý¾ÝÁ÷½øÐÐÓÅÏÈ·þÎñ±£ÕÏ¡£¹ØÓÚQoSµÄÅäÖÃÇë°Ý¼û¡°QoS¡±¡£

1.1.2? ¹¤×÷µÀÀí

1.    ¸ù»ù¸ÅÏë

l  ½Ó¼ûÁбí

½Ó¼ûÁбíÓУº¸ù»ù½Ó¼ûÁбíºÍ¶¯Ì¬½Ó¼ûÁбí¡£

Óû§Äܹ»Æ¾¾Ý±ØÒªÑ¡Ôñ¸ù»ù½Ó¼ûÁбí»ò¶¯Ì¬½Ó¼ûÁбí¡£Í¨³£Çé¿öÏ £¬Ê¹Óøù»ù½Ó¼ûÁбíÒѾ­¿ÉÄÜÂú×㰲ȫ±ØÒª¡£µ«¹¥»÷Õß¿ÉÄÜͨ¹ýÈí¼þ¼ÙðԴµØÖ·ºýŪÉ豸 £¬´Ó¶ø½Ó¼ûÍøÂç¡£¶ø¶¯Ì¬½Ó¼ûÁбíÔÚÓû§½Ó¼ûÍøÂçÒÔǰ £¬ÒªÇóͨ¹ýÉí·ÝÈÏÖ¤ £¬Ê¹¹¥»÷ÕßÄÑÒÔ½Ó¼ûÍøÂç¡£ÔÚÃô¸ÐÇøÓòÄܹ»Ê¹Óö¯Ì¬½Ó¼ûÁÐ±í±£ÕÏÍøÂ簲ȫ¡£

*     ×¢Ã÷

ͨ¹ý¼ÙðԴµØÖ·ºýŪÉ豸¼´µç×ÓºýŪÊÇËùÓнӼûÁбí¹ÌÓеÄÎÊÌâ £¬Ê¹Óö¯Ì¬ÁбíÒ²»áÔâ·êµç×ÓºýŪÎÊÌ⣺¹¥»÷Õß¿ÉÄÜÔÚÓû§Í¨¹ýÉí·ÝÈÏÖ¤µÄÓÐЧ½Ó¼ûÆÚ¼ä £¬¼ÙðÓû§µÄµØÖ·½Ó¼ûÍøÂç¡£½â¾ö¸ÃÎÊÌâµÄ²½ÖèÓÐÁ½ÖÖ £¬Ò»ÖÖÊǾ¡Á¿ÉèÖøü¶ÌµÄÓû§½Ó¼û¿ÕÏй¦·ò£»ÁíÒ»ÖÖÊÇʹÓÃIPsec¼ÓÃܺÍ̸¶ÔÍøÂçÊý¾Ý½øÐмÓÃÜ £¬È·±£½øÈëÉ豸ʱ £¬ËùÓеÄÊý¾Ý¶¼ÊǼÓÃܵÄ¡£

 

½Ó¼ûÁбíͨ³£ÅäÖÃÔÚÒÔϵØÎ»µÄÍøÂçÉ豸ÉÏ£º

¡ð         ÄÚ²¿ÍøºÍ±í²¿Íø£¨ÈçInternet£©Ö®¼äµÄÉ豸

¡ð         Á½¸öÍøÂç½ÓÈÀ²¿ÃŵÄÉ豸

¡ð         ½ÓÈë½ÚÔì¶Ë¿ÚµÄÉ豸

l  ACE

ACE£¨Access Control Entry £¬½Ó¼û½ÚÔìÌõ¿î£©ÊÇÔ̺¬¡°ÔÊÐí£¨Permit£©¡±»ò¡°»Ø¾ø£¨Deny£©¡±Á½ÖÖ×÷Ϊ £¬ÒÔ¼°¹ýÂ˹涨µÄÒ»ÌõÓï¾ä¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ £¬¸ÃÐòºÅ¿ÉÓÉÉ豸×Ô¶¯·ÖÅä»òÕßÊÖ¶¯ÅäÖá£Ò»ÌõACLÖÐÔ̺¬Ò»¸ö»òÕß¶à¸öACE¡£ACLͨ¹ýACE¶ÔÊý¾Ý°ü½øÐбêʶ¹ýÂË¡£

ACLÖÐACEµÄ°¤´Î¾ö¶¨Á˸ÃACEÔÚ½Ó¼ûÁбíÖÐµÄÆ¥ÅäÓÅÏȼ¶¡£ÍøÂçÉ豸ÔÚ´¦Öñ¨ÎÄʱ £¬°´ACEµÄÐòºÅ´ÓÓ×µ½ÃͽøÐй涨ƥÅä £¬µ¹ØÒµ½Æ¥ÅäµÄACEºóÔòÖÕ³¡²é³­ºóÐøµÄACE¡£

ÀýÈç´´½¨Ò»ÌõÐòºÅΪ10µÄACE £¬Ëü»Ø¾øËùÓеÄÊý¾ÝÁ÷ͨ¹ý¡£

10 deny ip any any

20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any

ÓÉÓÚÐòºÅΪ10µÄACE»Ø¾øÁËËùÓеÄIP±¨ÎÄ £¬¼´±ã192.168.12.0/24ÍøÂçµÄÖ÷»úTelnet±¨ÎÄ £¬Äܹ»±»ÐòºÅΪ20µÄACEÆ¥Åä £¬¸Ã±¨ÎÄÒ²½«±»»Ø¾ø¡£ÓÉÓÚÉ豸Ôڲ鳭µ½±¨ÎĺÍÐòºÅΪ10µÄACEÆ¥Åäºó £¬±ãÖÕ³¡²é³­ºóÃæÐòºÅΪ20µÄACE¡£

ÓÖÀýÈç´´½¨Ò»Ìõ±àºÅΪ10µÄACE £¬ËüÔÊÐíËùÓеÄIPv6Êý¾ÝÁ÷ͨ¹ý¡£

10 permit ipv6 any any

20 deny ipv6 host 200::1 any

ÓÉÓÚÐòºÅΪ10µÄACEÔÊÐíËùÓеÄIPv6±¨ÎÄͨ¹ý £¬Ö÷»ú200::1·¢³öµÄIPv6±¨ÎÄ £¬¼´±ãÆ¥ÅäÐòºÅΪ20µÄACE £¬¸Ã±¨ÎÄÒ²½«±»ÔÊÐíͨ¹ý¡£ÓÉÓÚÉ豸Ôڲ鳭µ½±¨Îĺ͵ÚÒ»ÌõACEÆ¥Åä £¬±ãÖÕ³¡²é³­ºóÃæÐòºÅΪ20µÄACE¡£

l  ²½³¤

µ±É豸ΪACE×Ô¶¯·ÖÅäÐòºÅʱ £¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ £¬³ÆÎª²½³¤¡£ÀýÈç £¬ÈôÊǽ«²½³¤É趨Ϊ5 £¬ÔòÉ豸ÒÀÕÕ5¡¢10¡¢15¡­ÕâÑùµÄµÝÔö°¤´Î×Ô¶¯ÎªACE·ÖÅäÐòºÅ¡£ÈçÏÂËùʾ¡£

5 deny ip any any

10 permit tcp 192.168.12.0 0.0.0.255 eq telnet any

µ±²½³¤Å¤×ªºó £¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤Öµ³ÁзÖÅä¡£ÀýÈç £¬µ±°Ñ²½³¤¸ÄΪ10ºó £¬Ô­À´ACEÐòºÅ´Ó5¡¢10¡¢15Ôì³É5¡¢15¡¢25¡£

ͨ¹ýŤת²½³¤Äܹ»ÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£ÀýÈç´´½¨ÁË4¸öACE £¬²¢Í¨¹ýÊÖ¶¯ÅäÖÃACEÐòºÅ±ðÀëΪ1¡¢2¡¢3ºÍ4¡£ÈôÊǵ«Ô¸ÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE £¬ÔòÄܹ»ÏȽ«²½³¤Åú¸ÄΪ2 £¬´ËʱԭÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7 £¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÅäÖõÄÐòºÅΪ2µÄACE¡£

l  ¹ýÂËÓòÄ£°å

¹ýÂËÓòÖ¸µÄÊÇÌìÉúÒ»ÌõACEʱ £¬Æ¾¾Ý±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎĽøÐмø±ð¡¢·ÖÀà¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£ACEƾ¾ÝÒÔÌ«Íø±¨ÎĵÄijЩ×Ö¶ÎÀ´±êʶÒÔÌ«Íø±¨ÎÄ £¬ÕâЩ×Ö¶ÎÔ̺¬£º

¶þ²ã×ֶΣ¨Layer 2 Fields£©£º

¡ð         48λµÄÔ´MACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩

¡ð         48λµÄÖ÷ÕÅMACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩

¡ð         16λµÄ¶þ²ãÀàÐÍ×Ö¶Î

Èý²ã×ֶΣ¨Layer 3 Fields£©£º

¡ð         Ô´IPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÔ´IPµØÖ·Öµ £¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©

¡ð         Ö÷ÕÅIPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÖ÷ÕÅIPµØÖ·Öµ £¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©

¡ð         ºÍ̸ÀàÐÍ×Ö¶Î

ËIJã×ֶΣ¨Layer 4 Fields£©£º

¡ð         Äܹ»ÉêÃ÷Ò»¸öTCPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷ £¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£

¡ð         Äܹ»ÉêÃ÷Ò»¸öUDPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷ £¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£

ÀýÈç £¬ÔÚ´´½¨Ò»ÌõACEʱ±ØÒªÆ¾¾Ý±¨ÎĵÄÖ÷ÕÅIP×Ö¶Î £¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£¶øÔÚ´´½¨ÁíÒ»ÌõACEʱ £¬±ØÒªÆ¾¾Ý±¨ÎĵÄÔ´IPµØÖ·×ֶκÍUDPµÄÔ´¶Ë¿Ú×Ö¶Î £¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£ÕâÁ½ÌõACE¾ÍʹÓÃÁË·ÖÆçµÄ¹ýÂËÓòÄ£°å¡£

l  ¹æ¶¨

¹æ¶¨£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£ÀýÈç £¬Ò»ÌõACEµÄÄÚÈÝÈçÏ£º

10 permit tcp host 192.168.12.2 any eq telnet

ÔÚÕâÌõACEÖÐ £¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεļ¯ÖУºÔ´IPµØÖ·×ֶΡ¢Ö÷ÕÅIPµØÖ·×ֶΡ¢IPºÍ̸×ֶΡ¢TCPÖ÷ÕŶ˿Ú×ֶΡ£¶ÔÓ¦µÄÖµ£¨¼´¹æ¶¨£©±ðÀëΪ£ºÔ´IPµØÖ·ÎªHost 192.168.12.2¡¢Ö÷ÕÅIPµØÖ·ÎªAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPºÍ̸ΪTCP¡¢TCPÖ÷ÕŶ˿ÚΪTelnet¡£Èçͼ1-1Ëùʾ¡£

ͼ1-1     ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄ·ÖÎö

image011

 

*     ×¢Ã÷

¡ñ     ¹ýÂËÓòÄ£°å¿ÉËùÒÔÈý²ã×ֶΣ¨Layer 3 Field£©ºÍËIJã×ֶΣ¨Layer 4 Field£©µÄ¼¯ÖÐ £¬Ò²¿ÉËùÒÔ¶à¸ö¶þ²ã×ֶΣ¨Layer 2 Field£©µÄ¼¯ÖС£µ«³ß¶ÈÓëÀ©´óACLµÄ¹ýÂËÓòÄ£°å²»ÄÜÊǶþ²ãºÍÈý²ã×ֶΡ¢¶þ²ãºÍËIJã×ֶΡ¢¶þ²ãºÍÈý²ã×ֶΡ¢ËIJã×ֶεļ¯ÖС£ÒªÊ¹Óöþ²ã¡¢Èý²ã¡¢ËIJã×ֶμ¯ÖÐ £¬Äܹ»ÀûÓÃר¼Ò¼¶À©´ó½Ó¼û½ÚÔìÁбí¡£

¡ñ     ³ö·½ÏòACL¹ØÁªSVI½Ó¿Ú£¨Switch Virtual Interface £¬»¥»»É豸Ðé¹¹½Ó¿Ú£©È·µ±¿àÖÔÏ֧³ÖIP³ß¶È¡¢IPÀ©´ó¡¢MACÀ©´óºÍר¼Ò¼¶ACLÀûÓá£

¡ñ     ÈôÊÇÔÚMACÀ©´óºÍר¼Ò¼¶ACLÖÐÆ¥ÅäÖ÷ÕÅMAC £¬½«ÕâÑùµÄACLÀûÓõ½SVI½Ó¿ÚµÄ³ö·½Ïòʱ £¬±íÏî»á±»ÉèÖà £¬µ«ÎÞ·¨ÉúЧ¡£ÈôÊÇÏëÒªÔÚIPÀ©´ó £¬×¨¼Ò¼¶ACLÖÐÆ¥ÅäÖ÷ÕÅIP £¬¶øÖ÷ÕÅIP²»ÔÚËù¹ØÁªµÄSVI½Ó¿ÚµÄ×ÓÍøIPÁìÓòÄÚʱ £¬ÅäÖõÄACL½«ÎÞ·¨ÉúЧ¡£ÀýÈçVLAN 1µÄµØÖ·Îª192.168.64.1 255.255.255.0 £¬´´½¨Ò»ÌõIPÀ©´óµÄACL £¬ACEΪdeny udp any 192.168.65.1 0.0.0.255 eq 255 £¬½«¸ÃACLÀûÓõ½VLAN 1µÄ³ö¿Ú £¬½«ÎÞ·¨ÉúЧ¡£ÓÉÓÚÖ÷ÕÅIP²»ÔÚVLAN 1×ÓÍøIPÁìÓòÄÚ £¬ÈôÊÇACEΪdeny udp any 192.168.64.1 0.0.0.255 eq 255½«Äܹ»ÉúЧ £¬ÓÉÓÚÖ÷ÕÅIPÇкϻ®¶¨¡£

¡ñ     ÓÉÓÚACL×ÊÔ´£¨TCAM/KEY/¶Ë¿Ú×é/RangeµÈ£©Êô¶¯Ì¬·ÖÅä×ÊÔ´ £¬¼´ÒµÎñÏ·¢Ê±Õ½ÊõÕûºÏ»ïÔ´Ä £¿éƾ¾Ýµ±Ç°µÄACL×ÊÔ´Çé¿ö½øÐзÖÅä £¬Ïȵ½µÄÒµÎñÏÈ·ÖÅäACL×ÊÔ´ £¬ºóµ½µÄÒµÎñÈôÊÇACL×ÊÔ´²»¹»¾Í»á´æÔÚACL×ÊÔ´·ÖÅäʧ°Ü £¬²¢ÌáÐÑÃýÎósyslog¡£É豸³ÁÆô¹ý³Ì»òÈȰβåµÈ´¥·¢Êý¾Ýͬ²½µÄ¹ý³Ì £¬¸÷ÒµÎñÎÞ·¨±£Õϰ´Ô­À´µÄʱÐò½«ÒµÎñͬ²½ £¬ÓпÉÄÜ´¥·¢ÓÉÓÚÒµÎñʱÐò²»Ò»Ñùµ¼ÖÂÕý±¾Äܹ»·ÖÅäµ½ACL×ÊÔ´µÄÒµÎñ·ÖÅä²»µ½ACL×ÊÔ´ £¬ACL×ÊÔ´²»¼°»áÌáÐÑÃýÎósyslog¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇé¿ö

¡ñ     ×÷ÓÃÔÚÎïÀí¿ÚºÍÈý²ã¾ÛºÏ½Ó¿ÚÉϵijö·½ÏòACL £¬½öÖ§³Ôì¥Åä³ÛÃû±¨ÎÄ£¨µ¥²¥¡¢×é²¥£© £¬²»Ö§³Ôì¥Åäδ³ÛÃûµ¥²¥ £¬¼´¶ÔÓÚδ³ÛÃû±¨ÎÄ»òÕ߹㲥±¨ÎÄ £¬½Ó¿ÚÉÏÅäÖõijö·½ÏòACL²»ÉúЧ¡£

¡ñ     Èë·½ÏòACLºÍ802.1x £¬È«¾ÖIPºÍMAC°ó¶¨ £¬¶Ë¿Ú°²È« £¬IP Source Guard¹²ÓÃʱ £¬PermitºÍĬÈÏDenyµÄACE²»ÉúЧ £¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ¡£

¡ñ     Èë·½ÏòACLºÍQoS¹²ÓÃʱ £¬Permit±íÏîµÄACE²»ÉúЧ £¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ£»Ä¬ÈÏDeny±íÏîµÄACEÔÚQoS±íÏîºóÉúЧ¡£

¡ñ     ÓÉÓÚÓ²¼þÈÝÁ¿µÄÏÞ¶È £¬×÷ÓÃÔÚ¶à¸öSVI½Ó¿ÚµÄÈë·½ÏòACL £¬ÈôÊÇÔÙÔö³¤ACE £¬±£ÁôÅäÖóÁÆôºó¿ÉÄܵ¼Ö²¿ÃÅSVI½Ó¿ÚÉϵÄACLÎÞ·¨ÅäÖóɹ¦¡£

 

*     ×¢Ã÷

¡ñ     µ±ÅäÖÃר¼Ò¼¶µÄACL £¬²¢ÀûÓÃÔڽӿڵijö·½Ïòʱ £¬ÈôÊǸÃACLÖеÄijЩACEÔ̺¬Èý²ãÆ¥ÅäÐÅÏ¢£¨ÀýÈçIP £¬L4portµÈ£© £¬½«µ¼Ö´ÓÀûÓýӿڽøÈëµÄ·ÇIP±¨ÎÄÎÞ·¨ÊܸÃACLµÄPermitºÍDeny¹æ¶¨½ÚÔì¡£

¡ñ     ÀûÓÃACLʱ £¬ÈôÊÇACL£¨Ô̺¬IP ACLºÍר¼Ò¼¶À©´óACL£©ÖеÄACEÆ¥ÅäÁ˷Ƕþ²ã×Ö¶Î £¬ÀýÈçÔ´IP £¬Ö÷ÕÅIPʱ £¬¶ÔÓÚ´ø±êÇ©µÄMPLS±¨ÎÄÆ¥ÅäÊÇÎÞЧµÄ¡£

 

2.    IP ACL

IP ACLÖØÒªÓÃÓÚ¶Ô½ø³öÉ豸µÄIPv4±¨ÎĽøÐо«ÃÜ»¯½ÚÔì £¬Óû§Äܹ»Æ¾¾ÝÏÖʵ±ØÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂç £¬´Ó¶øÊµÏÖ½ÚÔìIPÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£

ÔÚIP ACLÖнç˵һϵÁеĽӼû¹æ¶¨ £¬²¢½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ £¬Ò²Äܹ»¶ÔIP ACL½øÐÐÈ«¾ÖÀûÓᣵ±IPv4±¨ÎĽø³öÉ豸ʱ £¬É豸ͨ¹ýÅжϱ¨ÎÄÊÇ·ñÓë¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£

ÒªÔÚÉ豸ÉÏÅäÖÃIP ACL £¬±ØÐëΪ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ £¬ÒÔ±ãΨһ±êʼû¿¸ö½Ó¼ûÁбí¡£

IP ACL·ÖΪIP³ß¶ÈACLºÍIPÀ©´óACL¡£±í1-1ÁгöÁËIP³ß¶ÈACLºÍIPÀ©´óACLÄܹ»Ê¹ÓõıàºÅÁìÓò¡£

±í1-1     IP³ß¶ÈACLºÍIPÀ©´óACL±àºÅÁìÓò

ÀàÐÍ

±àºÅÁìÓò

Æ¥ÅäÓò

IP³ß¶ÈACL

1~99 £¬1300~1999

Ô´IPµØÖ·

IPÀ©´óACL

100~199 £¬2000~2699

¡ñ    Ô´IPµØÖ·

¡ñ    Ö÷ÕÅIPµØÖ·

¡ñ    IPºÍ̸ºÅ

¡ñ    ËIJãÔ´¶Ë±êÓï»òICMP type

¡ñ    ËIJãÖ÷ÕŶ˱êÓï»òICMP code

 

IP³ß¶ÈACLÖØÒªÆ¾¾ÝÔ´IPµØÖ·½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£IPÀ©´óACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓòµÄ×éºÏ £¬½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£

¶ÔÓÚµ¥Ò»µÄ½Ó¼ûÁбíÀ´Ëµ £¬Äܹ»Ê¹ÓöàÌõ¶ÀÁ¢µÄ½Ó¼ûÁбíÓï¾äÀ´½ç˵¶àÖֹ涨 £¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö £¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö½Ó¼ûÁбí¡£

*     ×¢Ã÷

ACL¹æ¶¨ÖеÄICMP codeÆ¥ÅäÓò¶ÔICMP typeΪ3µÄICMP±¨ÎÄÎÞЧ¡£ÈôÊÇACL¹æ¶¨ÖÐÅäÖÃÁËҪƥÅäICMP±¨ÎĵÄcode×Ö¶Î £¬µ±TypeΪ3µÄICMP±¨ÎĽøÈëÉ豸ִÐÐACLÆ¥Åäʱ £¬Æ¥ÅäÁ˾ֿÉÄÜÓëÔ¤ÆÚµÄ²»Ò»Ñù¡£

 

ÿ¸öIP ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨Óï¾ä¡£ÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Åä £¬½«±»»Ø¾ø¡£ÈçÏÂÀý£º

access-list 1 permit host 192.168.4.12

´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ192.168.4.12µÄ±¨ÎÄͨ¹ý £¬ÆäËüÖ÷»ú¶¼½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º

access-list 1 deny any

ÓÖÀýÈ磺

access-list 1 deny host 192.168.4.12

ÈôÊÇÁбíÖ»Ô̺¬ÒÔÉÏÕâÒ»ÌõÓï¾ä £¬ÔòÈκÎÖ÷»ú±¨ÎÄͨ¹ý¸Ã½Ó¿Úʱ¶¼½«±»»Ø¾ø¡£

*    °ÑÎÈ

ÔÚ½ç˵½Ó¼ûÁбíµÄʱ³½ £¬ÒªË¼¿¼µ½Â·Óɸüеı¨ÎÄ¡£ÓÉÓÚ½Ó¼ûÁбíĩβ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡± £¬¿ÉÄܵ¼ÖÂËùÓеÄ·Óɸüб¨Îı»×è¶Ï¡£

 

3.    MACÀ©´óACL

MACÀ©´óACL»ùÓÚ±¨ÎĵĶþ²ãÐÅÏ¢À´¶Ô½ø³öÉ豸µÄ±¨ÎĽøÐо«ÃÜ»¯½ÚÔì¡£Óû§Äܹ»Æ¾¾ÝÏÖʵ±ØÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂç £¬´Ó¶øÊµÏÖ½ÚÔì±£»¤ÍøÂç×ÊÔ´²»Êܹ¥»÷»òÕß½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£

ÔÚMACÀ©´óACLÖнç˵һϵÁеĽӼû¹æ¶¨ £¬½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£µ±±¨ÎĽø³öÉ豸ʱ £¬É豸Åжϱ¨ÎÄÊÇ·ñÓë¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£

ÒªÔÚÉ豸ÉÏÅäÖÃMACÀ©´óACL £¬±ØÐëΪ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ £¬ÒÔ±ãΨһ±êʼû¿¸ö½Ó¼ûÁбí¡£±í1-2ÁгöMACÀ©´óACLµÄ±àºÅÁìÓò¡£

±í1-2     MACÀ©´óACL±àºÅÁìÓò

ºÍ̸

±àºÅÁìÓò

Æ¥ÅäÓò

MACÀ©´óACL

700~799

¡ñ    Ô´MACµØÖ·

¡ñ    Ö÷ÕÅMACµØÖ·

¡ñ    ÒÔÌ«ÍøºÍ̸ÀàÐÍ

 

MACÀ©´óACLƾ¾ÝÔ´»òÖ÷ÕÅMACµØÖ·ÒÔ¼°±¨ÎĵÄÒÔÌ«ÍøÀàÐÍÀ´½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£

¶ÔÓÚµ¥Ò»µÄMACÀ©´óACLÀ´Ëµ £¬Äܹ»Ê¹ÓöàÌõ¶ÀÁ¢µÄ½Ó¼ûÁбíÓï¾äÀ´½ç˵¶àÖֹ涨 £¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö £¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö½Ó¼ûÁбí¡£

*     ×¢Ã÷

ÈôÊÇMACÀ©´óACL¹æ¶¨ÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ £¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλò½ç˵µÄÒÔÌ«ÍøÀàÐÍ×Ö¶ÎÖµ²»ÊÇ0x86dd £¬ÄÇôMACÀ©´óACL²»Æ¥ÅäIPv6±¨ÎÄ¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ £¬ÇëʹÓÃIPv6 ACL¡£

 

ÿ¸öMACÀ©´óACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨Óï¾ä¡£ÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Åä £¬½«±»»Ø¾ø¡£ÈçÏÂÀý£º

access-list 700 permit host 00d0.f800.0001 any

´ËÁбíÖ»ÔÊÐíÀ´×ÔMACµØÖ·Îª00d0.f800.0001µÄÖ÷»ú·¢³öµÄ±¨ÎÄͨ¹ý £¬À´×ÔÆäËüÖ÷»úµÄ±¨Îͼ½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º

access-list 700 deny any any

4.    ר¼Ò¼¶À©´óACL

ר¼Ò¼¶À©´óACL»ùÓÚ±¨ÎĵĶþ²ãºÍÈý²ãÐÅÏ¢¶Ô½ø³öÉ豸µÄ±¨ÎĽøÐо«ÃÜ»¯½ÚÔì¡ £Äܹ»½«×¨¼Ò¼¶À©´óACL¿´×÷ÊÇIP ACLºÍMACÀ©´óACLµÄÒ»ÖÖ½áºÏÓë¼ÓÇ¿¡£×¨¼Ò¼¶À©´óACLÖеĹ涨²»½öÄܹ»Ô̺¬IP ACL¹æ¶¨ºÍMACÀ©´óACL¹æ¶¨ £¬»¹Äܹ»Ö¸¶¨»ùÓÚVLAN IDÀ´Æ¥Å䱨ÎÄ¡£

ÔÚר¼Ò¼¶À©´óACLÖнç˵һϵÁеĽӼû¹æ¶¨ £¬²¢½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£±¨ÎĽø³öÉ豸ʱ £¬É豸¾Í»áͨ¹ýÅжϱ¨ÎÄÊÇ·ñÓë½Ó¼û¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£

ÒªÔÚÉ豸ÉÏÅäÖÃר¼Ò¼¶À©´óACL £¬±ØÐëΪºÍ̸µÄ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ £¬ÒÔ±ãÔÚºÍ̸ÄÚ²¿¿ÉÄÜΨһ±êʼû¿¸ö½Ó¼ûÁбí¡£±í1-3Áгöר¼Ò¼¶À©´óACLµÄ±àºÅÁìÓò¡£

±í1-3     ר¼Ò¼¶À©´óACLµÄ±àºÅÁìÓò

ºÍ̸

±àºÅÁìÓò

Æ¥ÅäÓò

ר¼Ò¼¶À©´óACL

2700~2899

¡ñ    Ô´IPµØÖ·

¡ñ    Ö÷ÕÅIPµØÖ·

¡ñ    IPºÍ̸ºÅ

¡ñ    ËIJãÔ´¶Ë±êÓï»òICMP type

¡ñ    ËIJãÖ÷ÕŶ˱êÓï»òICMP code

¡ñ    Ô´MACµØÖ·

¡ñ    Ö÷ÕÅMACµØÖ·

¡ñ    ÒÔÌ«ÍøºÍ̸ÀàÐÍ

¡ñ    VLAN ID

 

ר¼Ò¼¶À©´óACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓò½øÐÐ×éºÏ £¬½ÚÔ챨ÎĵÄת·¢»ò×è¶Ï¡£

¶ÔÓÚµ¥Ò»µÄר¼Ò¼¶À©´óACLÀ´Ëµ £¬Äܹ»Ê¹ÓöàÌõ¶ÀÁ¢µÄ½Ó¼ûÁбíÓï¾äÀ´½ç˵¶àÖֹ涨 £¬ÆäÖÐËùÓеÄÓï¾äÐèÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö £¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö½Ó¼ûÁбí¡£

*     ×¢Ã÷

ÈôÊÇר¼Ò¼¶À©´óACL¹æ¶¨ÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ £¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλòÒÔÌ«ÍøÀàÐÍ×ֶβ»ÊÇ0x86dd £¬ÄÇôר¼Ò¼¶À©´óACL²»Æ¥ÅäIPv6±¨ÎÄ¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ £¬ÇëʹÓÃIPv6 ACL¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇé¿ö

¡ñ     Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©´óACLÖÐ £¬VXLAN×Ö¶ÎÑ¡ÏîÖØÒªÊÇΪÁËÆ¥ÅäVXLANµÄÄڲ㱨ÎÄ £¬Òò¶øVXLANģʽÏÂÄܹ»ÀûÓÃר¼Ò¼¶ACLÆ¥ÅäVXLANµÄÄÚ²ãIP×ֶΡ£

¡ñ     µ±É豸±ØÒªÆ¥ÅäVXLAN±¨ÎÄʱ £¬Äܹ»Ö¸¶¨VXLANºÍ̸Ö÷ÕŶ˱êÓïÓÃÓÚÈ·ÈÏVXLAN±¨ÎÄ £¬Í¬Ê±Äܹ»Ö¸¶¨Æ¥Åä¸ÃVXLAN±¨ÎÄÊÇ·ñЯ´øTag¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇé¿ö

Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©´óACLÖÐUDFÑ¡ÏîÊÇÓû§×Ô½ç˵×Ö¶ÎÆ¥ÅäÓò £¬ÓÉÓû§Ö¸¶¨±ØÒªÆ¥ÅäµÄºÍ̸²ã¡¢Æ«ÒÆÖµ¡¢Êý¾ÝºÍÑÚÂë¡£

 

ÿ¸öר¼Ò¼¶À©´óACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±¹æ¶¨Óï¾ä¡£ÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Åä £¬½«±»»Ø¾ø¡£ÈçÏÂÀý£º

access-list 2700 permit 0x0806 any any any any any

´ËÁбíÖ»ÔÊÐíÒÔÌ«ÍøÀàÐÍΪ0x0806£¨¼´ARP£©µÄ±¨ÎÄͨ¹ý £¬ÆäËûÀàÐ͵ı¨Îͼ½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º

access-list 2700 deny any any any any

5.    IPv6 ACL

IPv6 ACLÖØÒªÓÃÓÚ¶Ô½ø³öÉ豸µÄIPv6±¨ÎĽøÐо«ÃÜ»¯½ÚÔì¡£Óû§Äܹ»Æ¾¾ÝÏÖʵ±ØÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂç £¬´Ó¶øÊµÏÖ½ÚÔìIPv6Óû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£

ÔÚIPv6 ACLÖнç˵һϵÁеĽӼû¹æ¶¨ £¬²¢½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£µ±IPv6±¨ÎĽø³öÉ豸ʱ £¬É豸Åжϱ¨ÎÄÊÇ·ñÓë¹æ¶¨Æ¥ÅäÀ´¾ö¶¨ÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£

ÒªÔÚÉ豸ÉÏÅäÖýӼûÁбí £¬±ØÐëΪºÍ̸µÄ½Ó¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ¡£

ÿ¸öIPv6 ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°»Ø¾øËùÓÐIPv6Êý¾ÝÁ÷¡±¹æ¶¨Óï¾ä £¬Òò¶øÈôÊDZ¨ÎÄÓëÈκι涨¶¼²»Æ¥Åä £¬½«±»»Ø¾ø¡£ÈçÏÂÀý£º

ipv6 access-list ipv6_acl

?10 permit ipv6 host 200::1 any

´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ200::1µÄIPv6±¨ÎÄͨ¹ý £¬ÆäËüÖ÷»ú·¢³öµÄIPv6±¨Îͼ½«±»»Ø¾ø¡£ÓÉÓÚÕâÌõ½Ó¼ûÁбí×îºóÔ̺¬ÁËÒ»ÌõÎÄÔòÓï¾ä£º

deny ipv6 any any

6.    ר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©

ר¼Ò¼¶¸ß¼¶ACL £¬¼´ACL80 £¬Ò²³ÆÎª×Ô½ç˵ACL¡£ACL80Ö§³Ö¶Ô±¨ÎĵÄǰ80¸ö×Ö½ÚÖеÄÖ¸¶¨×Ö½Ú°´±ÈÌØÎ»½øÐÐÆ¥Åä¡£

ACL80Æ¥ÅäʱÓÐÈý¸öÉí·Ö£ºÆ¥ÅäÓòÄÚÈÝ¡¢Æ¥ÅäÓòÑÚÂëÒÔ¼°Æ¥ÅäµÄÕØÊ¼µØÎ»£¨¼´Æ«ÒÆÁ¿offset£©¡£Æ¥ÅäÓòÄÚÈÝºÍÆ¥ÅäÓòÑÚÂëÁ½ÕߵıÈÌØÎ»ÊÇÖðÒ»¶ÔÓ¦µÄ¡£Æ¥ÅäÓòÄÚÈÝÖ¸Ã÷±ØÒªÆ¥ÅäµÄ×Ö¶ÎÖµ £¬Æ¥ÅäÓòÑÚÂëÖ¸Ã÷¶ÔÓ¦±ÈÌØÎ»ÊÇ·ñ±ØÒªÆ¥Åä¡£µ±±ØÒªÆ¥Åäij¸ö±ÈÌØÎ»Ê± £¬±ØÐ뽫ƥÅäÓòÑÚÂëÖжÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ1¡£ÈôÊÇÆ¥ÅäÓòÑÚÂë¶ÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ0 £¬ÎÞÂÛÆ¥ÅäÓòÄÚÈÝÖжÔÓ¦µÄ±ÈÌØÎ»ÊÇʲô £¬¶¼²»»áÆ¥Åä¡£ÀýÈ磺

10 permit 00d0f8123456 ffffffffffff 0

20 deny 00d0f8654321 ffffffffffff 6

ÔÚÐòºÅΪ10µÄACEÖÐ £¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8123456 £¬Æ¥ÅäÓòÑÚÂëΪffffffffffff £¬Æ«ÒÆÁ¿Îª0¡£ÕâÌõÎÄÔò°µÊ¾ÈôÊDZ¨ÎĵÄÖ÷ÕÅMACΪ00d0f8123456 £¬ÔòÔÊÐí±¨ÎÄת·¢¡£

ÔÚÐòºÅΪ20µÄACEÖÐ £¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8654321 £¬Æ¥ÅäÓòÑÚÂëΪffffffffffff £¬Æ«ÒÆÁ¿Îª6¡£ÕâÌõÎÄÔò°µÊ¾ÈôÊDZ¨ÎĵÄÔ´MACΪ00d0f8654321 £¬Ôò×è¶Ï¸Ã±¨ÎÄ¡£

ÕýȷʹÓÃ×Ô½ç˵½Ó¼û½ÚÔìÁÐ±í±ØÒª¶Ô¶þ²ãÊý¾ÝÖ¡½á¹¹ÓÐÉî¿ÌµÄÏàʶ¡£¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâÈçͼ1-2Ëùʾ¡£Í¼ÖÐÿ¸ö×Öĸ´ú±íÒ»¸öÊ®Áù½øÔìÊý £¬Ã¿Á½¸ö×Öĸ´ú±íÒ»¸ö×Ö½Ú¡£

ͼ1-2     ¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâͼ

image013

 

¸÷¸ö×ÖĸµÄÔ¢Òâ¼°Æ«ÒÆÁ¿È¡ÖµÈç±í1-4Ëùʾ¡£

±í1-4     ×ÖĸµÄÔ¢Òâ¼°Æ«ÒÆÁ¿È¡Öµ

×Öĸ

Ô¢Òâ

Æ«ÒÆÁ¿

×Öĸ

Ô¢Òâ

Æ«ÒÆÁ¿

A

Ö÷ÕÅMAC

0

O

TTL×Ö¶Î

34

B

Ô´MAC

6

P

ºÍ̸ºÅ

35

C

VLAN Tag×Ö¶Î

12

Q

IPУÑéºÍ

36

D

Êý¾ÝÖ¡³¤¶È×Ö¶Î

16

R

Ô´IPµØÖ·

38

E

DSAP(Ö÷ÕÅ·þÎñ½Ó¼ûµã)×Ö¶Î

18

S

Ö÷ÕÅIPµØÖ·

42

F

SSAP(Ô´·þÎñ½Ó¼ûµã)×Ö¶Î

19

T

TCPÔ´¶Ë¿Ú

46

G

Ctrl×Ö¶Î

20

U

TCPÖ÷ÕŶ˿Ú

48

H

Org Code×Ö¶Î

21

V

ÐòÁкÅ

50

I

·â×°µÄÊý¾ÝÀàÐÍ

24

W

È·ÈÏ×Ö¶Î

54

J

IP°æ±¾ºÅ

26

XY

IPÍ·³¤¶ÈºÍ±£Áô±ÈÌØÎ»

58

K

TOS×Ö¶Î

27

Z

±£Áô±ÈÌØÎ»ºÍFlags±ÈÌØÎ»

59

L

IP°üµÄ³¤¶È

28

a

Windows Size×Ö¶Î

60

M

IDºÅ

30

b

ÆäËû

62

N

Flags×Ö¶Î

32

 

 

 

 

±íÖи÷¸ö×Ö¶ÎµÄÆ«ÒÆÁ¿ÊÇËüÃÇÔÚSNAP£«TagµÄ802.3Êý¾ÝÖ¡ÖÐµÄÆ«ÒÆÁ¿¡£ÔÚ×Ô½ç˵½Ó¼û½ÚÔìÁбíÖÐ £¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿ £¬´ÓÊý¾ÝÖ¡µÄǰ80¸ö×Ö½ÚÖÐÌáȡָ¶¨×Ö½Ú £¬ÔÙºÍÆ¥ÅäÓòÄÚÈݱÈÁ¦ £¬´Ó¶ø¶Ô±¨ÎÄ×÷ÏàÓ¦µÄ´¦Öá£ÀýÈç £¬Óû§ÔÊÐíËùÓеÄTCP±¨ÎÄת·¢ £¬ÔòÄܹ»½«Æ¥ÅäÓòÄÚÈݽç˵Ϊ¡°06¡± £¬Æ¥ÅäÓòÑÚÂë½ç˵Ϊ¡°ff¡± £¬Æ«ÒÆÁ¿½ç˵Ϊ35¡£´´½¨ÐòºÅΪ10µÄACEÈçÏ¡£

10 permit 06 ff 35

½«½Ó¼ûÁбíÀûÓÃÔÚ½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏ¡£µ±±¨ÎĽø³öÉ豸ʱ £¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿ £¬´ÓÊý¾ÝÖ¡Öн«TCPºÍ̸ºÅ×ֶεÄÄÚÈÝÌáÈ¡³öÀ´ £¬ÔÙºÍÆ¥ÅäÓòÄÚÈݱÈÁ¦ £¬Æ¥Åä³öËùÓеÄTCP±¨ÎIJ¢½øÐÐת·¢¡£

7.    ACL³Á¶¨Ïò

ACL³Á¶¨ÏòµÄ×÷ÓÃÊǽ«ÇкϹ涨µÄ±¨ÎijÁ¶¨ÏòÖÁÖ¸¶¨½Ó¿Úת·¢ £¬»òÔÚÖ¸¶¨½Ó¿ÚÉÏץȡ±¨ÎļÓÒÔ·ÖÎö¡£

ACL³Á¶¨ÏòÔÚÖ¸¶¨½Ó¿ÚÉÏ°ó¶¨·ÖÆçµÄACLÕ½Êõ £¬²¢¸øÃ¿¸öÕ½ÊõÖ¸¶¨Ò»¸öÊä³ö½Ó¿Ú¡£µ±¸Ã½Ó¿ÚÊÕµ½±¨ÎÄʱ £¬½«ÖðÌõ²éÕÒ°ó¶¨ÔڸýӿÚÉϵÄACLÕ½Êõ¡£ÈôÊDZ¨ÎÄÇкÏijÌõÕ½ÊõÃèÊöµÄÌØµã £¬½«´Ó¸ÃÕ½ÊõËùÖ¸¶¨µÄÊä³ö½Ó¿Úת·¢¡£

8.    È«¾Ö°²È«ACL

ÓÉÓÚÍøÂçÖдæÔÚ¸÷Àಡ¶¾±¨ÎÄ £¬ÇÒ¸÷¶Ë¿ÚϵIJ¡¶¾±¨Îļø±ðÌØµãÒ»Ñù»òÀàËÆ¡£¶Ë¿Ú°²È«ACL³£±»ÅäÖÃ×÷Ϊ²¡¶¾±¨ÎĹýÂ˼°·À±¸Ê¹Óà £¬ÓÃÓÚ¹ýÂËÇкÏÄ³Ð©ÌØµãµÄ±¨ÎÄ £¬ÀýÈ磺αÔìµÄTCP¹¥»÷±¨ÎÄ¡£Í¨¹ý´´½¨ACL²¢Ôö³¤Æ¥Åä¸÷Àಡ¶¾±¨ÎÄÌØµãµÄACEºó £¬½«ACLÀûÓõ½É豸¸÷¸ö¶Ë¿Ú £¬´ïµ½¹ýÂ˲¡¶¾±¨ÎĵÄ×÷Ó᣶˿ڰ²È«ACLÓÃÓÚ²¡¶¾¹ýÂ˵ȿ¹¹¥»÷³¡¾°Ê± £¬´æÔڽ϶಻±ã¡£

l  ¶Ë¿Ú±ØÒªÖð¸öÅäÖᣴæÔÚ³Á¸´ÅäÖᢲÙ×÷»úÄܵÍϼ°ACL×ÊÔ´¹ý¶È¿÷ËðµÄÇé¿ö¡£

l  °²È«ACLµÄ½Ó¼û½ÚÔì×÷Óñ»Èõ»¯¡£ÓÉÓÚ±»ÓÃÓÚ²¡¶¾¹ýÂË £¬°²È«ACLµÄÏÞ¶È·ÓɸüС¢ÏÞ¶ÈÍøÂç½Ó¼ûµÈ¸ù»ùÖ°ÄÜÎÞ·¨Õý³£Ê¹Óá£

È«¾Ö°²È«ACLÄܹ»ÔÚ²»Ó°Ïì¶Ë¿Ú°²È«ACLµÄÇé¿öÏ £¬½øÐÐÈ«¾Ö¿¹²¡¶¾²¿Êð¼°·ÀÓù¡£È«¾Ö°²È«ACLÖ»±ØÒªÒ»ÌõºÅÁî¼´ÔÚËùÓжþ²ã½Ó¿ÚÉÏÉúЧ¡£

µ±È«¾Ö°²È«ACLÓë¶Ë¿Ú°²È«ACLͬʱÅäÖÃʱ £¬Á½Õß¹²Í¬ÉúЧ¡£¶ÔÓÚÆ¥ÅäÈ«¾Ö°²È«ACL¹æ¶¨µÄ±¨ÎĽ«±»µ±×÷²¡¶¾±¨ÎÄÖ±½Ó¹ýÂË £¬¶ÔÓÚûÓÐÆ¥ÅäÈ«¾Ö°²È«ACL¹æ¶¨µÄ±¨ÎĽ«³ÖÐøÊܶ˿ڰ²È«ACL½ÚÔì¡£ÈôÊÇÏëÈÃijЩ¶Ë¿Ú²»ÊÜÈ«¾Ö°²È«ACLµÄ½ÚÔì £¬Äܹ»ÔÚÕâЩ½Ó¿ÚÉ϶ÀÁ¢¹Ø¹ØÈ«¾Ö°²È«ACLÖ°ÄÜ¡£µ±È«¾Ö¡¢½Ó¿ÚºÍVLANµÄ°²È«ACLͬʱÀûÓÃʱ £¬ÓÅÏȼ¶½Ó¿Ú > VLAN > È«¾Ö¡£

ΪÁËÔ¤·ÀÈ«¾Ö°²È«ACL±»ÎóÅäÖà £¬ÐÂÔöÈ«¾Ö°²È«ACLÎÞЧ¿ª¹Ø¡£ÅäÖÃÈ«¾Ö°²È«ACLÎÞЧºó £¬ÔÙÅäÖÃÈ«¾Ö°²È«ACL £¬»áÌáÐÑÅäÖÃʧ°Ü¡£ÈôÊÇÒѾ­ÅäÖÃÁËÈ«¾Ö°²È«ACL £¬ÔÙÅäÖÃÈ«¾Ö°²È«ACLÎÞЧ £¬ÄÇô»á½«µ±Ç°ËùÓÐÈ«¾Ö°²È«ACLɾ³ý £¬²¢¸ø³öÈÕÖ¾ÌáÐÑ¡£

9.    SVI Router ACL

ÀûÓÃÔÚSVI½Ó¿ÚÉϵĽӼûÁÐ±í£¨¼´SVI ACL£©»áͬʱ¶ÔVLANÄÚ¶þ²ãת·¢µÄ±¨Îļ°VLAN¼äµÄ·Óɱ¨ÎÄÉúЧ £¬´Ó¶øµ¼ÖÂͳһVLANÄÚ·ÖÆçÓû§Ö®¼äÎÞ·¨Õý³£Í¨Ñ¶µÈÒì³£¾°Ïó¡£Ê¹ÓÃSVI Router ACLÖ°ÄÜÄܹ»Ê¹ÀûÓÃÔÚSVI½Ó¿ÚÉϵĽӼûÁбí½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£

ȱʡÇé¿öÏ £¬SVI Router ACLÖ°ÄÜĬÈϹعØ¡£SVI ACLͬʱ¶ÔVLAN¼äµÄÈý²ãת·¢±¨Îļ°VLANÄÚµÄÇÅת·¢±¨ÎÄÉúЧ¡£SVI Router ACLÖ°ÄÜ¿ªÆôºó £¬SVI ACL½ö¶ÔVLAN¼äµÄÈý²ãת·¢±¨ÎÄÉúЧ¡£

10. ?±¨ÎÄÆ¥ÅäÈÕÖ¾

±¨ÎÄÆ¥ÅäÈÕÖ¾ÓÃÓÚ¼à¿Ø½Ó¼ûÁÐ±í¹æ¶¨µÄÔËÐÐ״̬ £¬ÎªÈÕ³£ÍøÂçÊØ»¤ÒÔ¼°ÍøÂçÓÅ»¯Ìṩ±ØÒªµÄÐÅÏ¢¡£

ΪÁËÈÃÓû§¸üºÃµÄ°ÑÎÕACLÔÚÉ豸ÖеÄÔËÐÐ״̬ £¬ÔÚÔö³¤ACEʱÄܹ»Æ¾¾Ý±ØÒª¾ö¶¨ÊÇ·ñÖ¸¶¨±¨ÎÄÆ¥ÅäÈÕÖ¾Êä³öÑ¡Ïî¡£ÈôÊÇÖ¸¶¨Á˸ÃÑ¡Ïî £¬Ôòµ±ACEÆ¥Åäµ½±¨ÎÄʱÊä³öÆ¥ÅäÈÕÖ¾ÐÅÏ¢¡£ACL»ùÓÚACE´òÓ¡ÈÕÖ¾ÐÅÏ¢ £¬¼´É豸ÖÜÆÚÐԵĴòÓ¡Æ¥Å䱨ÎĵÄACEÐÅÏ¢ £¬ÒÔ¼°Æ¥ÅäµÄ±¨ÎÄÊýÁ¿¡£ÈçÏ£º

*Sep¡¡9 16:23:06: %ACL-6-MATCH: ACL 100 ACE 10 permit icmp any any, match 78 packets.

ΪºÏÀí½ÚÔìÈÕÖ¾Êä³öµÄÊýÁ¿ºÍƵÂÊ £¬ACLÖ§³ÖÅäÖÃÈÕÖ¾Êä³ö¾àÀëµÄÅäÖá£

*    °ÑÎÈ

¡ñ     ´øÈÕ־ѡÏîµÄ½Ó¼ûÁÐ±í¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´ £¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐÈÕ־ѡÏî £¬Ôò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£

¡ñ     ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ £¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖýӼûÁÐ±í¹æ¶¨Ê±Ö¸¶¨ÁËÈÕ־ѡÏîºó £¬»¹±ØÒªÅäÖÃÊä³ö¾àÀë £¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£

¡ñ     ¶ÔÓÚ´øÈÕ־ѡÏîµÄ¹æ¶¨ £¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ £¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ £¬Ôò¹¦·ò¾àÀëµ½ÆÚºó £¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý £¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇé¿ö

½öÖ§³ÖΪIP ACLºÍIPv6 ACL¹æ¶¨ÅäÖÃÈÕ־ѡÏî¡£

 

11. ?±¨ÎÄÆ¥Å伯Êý

³öÓÚÍøÂçÖÎÀíµÄ±ØÒª £¬Óû§¿ÉÄÜÏë֪·ijÌõ½Ó¼ûÁÐ±í¹æ¶¨ÊÇ·ñÆ¥Åäµ½±¨ÎÄÒÔ¼°Æ¥ÅäÊýÁ¿¡£ACLÌṩÁË»ùÓڹ涨µÄ±¨ÎÄÆ¥Å伯ÊýÖ°ÄÜ¡£Óû§Äܹ»»ùÓÚACL¿ªÆôºÍ¹Ø¹Ø¸ÃACLϵÄËùÓй涨µÄ±¨ÎÄÆ¥Å伯ÊýÖ°ÄÜ¡£µ±Óб¨ÎÄÆ¥Åäµ½ÁËÕâÌõÎÄÔò £¬¶ÔÓ¦µÄÆ¥Å伯Êý¾ÍÏàÓ¦µØÔö³¤¡£Óû§¿Éͨ¹ýACLµÄͳ¼Æ¶Ï¸ùºÅÁ¸ÃACLÏÂËùÓй涨µÄ±¨ÎÄÆ¥Å伯ÊýÇåÁã £¬ÒÔ±ã³ÁÐÂͳ¼Æ¡£

*    °ÑÎÈ

¿ªÆôACLµÄ±¨ÎÄÆ¥Å伯ÊýÖ°ÄܱØÒª¸ü¶àµÄÓ²¼þ±íÏî £¬¼«¶ËÇé¿öÏ»áʹÉ豸Äܹ»ÅäÖõÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇé¿ö

ÔÚIP ACL¡¢MACÀ©´óACL¡¢×¨¼Ò¼¶À©´óACLºÍIPv6 ACLÉÏ¿ªÆô±¨ÎÄÆ¥Å伯ÊýÖ°ÄÜ¡£

 

12. ?ACLÉúЧ¹¦·ò¶Î

ÈôÊÇÓû§±ØÒªÔÚÖ¸¶¨µÄ¹¦·ò¶ÎÄÚ¶ÔijЩÁ÷Á¿½øÐнÚÔì £¬ÀýÈç £¬²»ÈÝÔÚ¹¤×÷¹¦·òʹÓÃ̸Ì칤¾ß¡ £Äܹ»Í¨¹ýÅäÖÃACEµÄÉúЧ¹¦·ò¶Î £¬½ÚÔìÁ÷Á¿Í¨¹ýµÄ¹¦·ò¡£¹¦·ò¶Î·ÖΪ¾ø¶Ô¹¦·òºÍÖÜÆÚ¹¦·òÁ½ÖÖ¡£

¾ø¶Ô¹¦·ò°µÊ¾Ò»¸öÖ¸¶¨ÕØÊ¼¹¦·òÒÔ¼°ÊµÏÖ¹¦·òµÄ¹¦·òÇø¼ä¡£¸Ã¹¦·òÇø¼ä²»»áÑ­»·³öÏÖ £¬Ò²Ã»ÓÐÖÜÆÚ¡£ÀýÈç¡°2000Äê1ÔÂ1ÈÕ12£º00£º00ÖÁ2001Äê1ÔÂ1ÈÕ12£º00£º00¡±¡£

ÖÜÆÚ¹¦·ò°µÊ¾Ò»¸öÖÜÆÚÐԵŦ·òÇø¼ä¡£ÀýÈ硰ÿÖÜÒ»8£º00µ½Ã¿ÖÜÎå17£º00¡±¡£

¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£

13. ?·Ô쬱¨ÎÄÆ¥Åäģʽ

ʹÓ÷Ô쬱¨ÎÄÆ¥ÅäģʽÄܹ»Ê¹½Ó¼ûÁбí¶Ô·Ô쬱¨ÎĽøÐиü¾«ÃÜ»¯µÄ½ÚÔì¡£

¶ÔÓÚIP±¨ÎÄ £¬ÔÚÍøÂç´«ÊäʱÖпÉÄܻᱻ·Ô쬡£±¨ÎIJúÉú·Ôì¬Ê± £¬Ö»ÓÐÊׯ¬±¨ÎÄ´øÓÐËIJãÐÅÏ¢ £¬ÀýÈçTCP»òUDP¶Ë±êÓï¡¢ICMPÀàÐͺÍICMP±àÂëµÈ £¬ÆäËûµÄ·Ô쬱¨Îͼ²»´øÓÐÕâЩËIJãÐÅÏ¢¡£ÔÚĬÈϵķÔ쬱¨ÎÄÆ¥ÅäģʽÏ £¬ÈôÊÇACL¹æ¶¨´øÓÐFagment±êʶ £¬ÔòÖ»»áÆ¥Åä·ÇÊׯ¬±¨ÎÄ£»ÈôÊÇACL¹æ¶¨²»´øÓÐFragment±êʶ £¬ÔòÆ¥ÅäËùÓб¨ÎÄ £¬Ô̺¬Êׯ¬±¨ÎĺͺóÐøµÄËùÓзÔ쬱¨ÎÄ¡£³ýÁËĬÈϵķÔ쬱¨ÎÄÆ¥Åäģʽ±í £¬»¹ÌṩÁíÒ»ÖÖеķÔ쬱¨ÎÄÆ¥Åä²½Öè £¬Óû§Äܹ»Æ¾¾Ý±ØÒªÔÚÖ¸¶¨µÄACLÉϽøÐÐÇл»¡£ÔÚеķÔ쬱¨ÎÄÆ¥ÅäģʽÏ £¬µ±ACL¹æ¶¨²»´øÓÐFragment±êʶ £¬ÈôÊDZ¨Îı»·Ôì¬ £¬Êׯ¬±¨ÎÄ»áÆ¥Å乿¶¨ÖÐÓû§½ç˵µÄËùÓÐÆ¥ÅäÓò(Ô̺¬Èý²ãºÍËIJãÐÅÏ¢) £¬¶ø·ÇÊׯ¬±¨ÎÄÔòÖ»»áÆ¥Å乿¶¨ÖеķÇËIJãÐÅÏ¢¡£

*     ²úÆ·/°æ±¾Ö§³ÖÇé¿ö

¡ñ     ½öÔÚIPÀ©´óACLºÍר¼Ò¼¶À©´óACLÉÏÖ§³Ö·Ô쬱¨ÎÄÆ¥ÅäģʽµÄÇл»¡£

 

14. ?È«¾Ö½ÚÔìÃæ°²È«ACL

ÔÚijЩÀûÓó¡¾°ÖÐ £¬±ØÒª°ó¶¨ACLÏÞ¶ÈÔ´IP¶ÔTCPÎÕÊÖÊ×°ü½øÐд¦Öà £¬¶ø²»ÊdzÉÁ¢TCPÏνӺóÔÙ½øÐÐÏÞ¶È¡£Ê¹ÓÃÈ«¾Ö½ÚÔìÃæACLʵÏÖ½öÈí¼þ¹ýÂË £¬²»½öÄܹ»Ï÷¼õ¶ÔÓ²¼þ×ÊÔ´µÄ¿÷Ë𠣬²¢ÇÒ¿ÉÄÜÂú×ã¶ÔTCPÊ×°ü½øÐд¦ÖõÄÐèÒª¡£½«°²È«ACLͨ¹ý½ÚÔìÃæÀûÓúÅÁîÀûÓõ½È«¾Ö £¬°µÊ¾¸ÃACL½öÈí¼þÉúЧ¡£

È«¾Ö½ÚÔìÃæACLÔÚËùÓжþ²ãÒÔÌ«Íø½Ó¿ÚÉÏÉúЧ £¬ACL±íÏî²»ÀûÓõ½Ó²¼þ £¬½ö¶ÔÈí¼þÉúЧ £¬´Ó¶øÏ÷¼õ¶ÔÓ²¼þ×ÊÔ´µÄËðºÄ£»µ±½øÐÐTCPÎÕÊÖʱ £¬Èí¼þACL¶ÔTCPÊ×°ü½øÐв鳭 £¬¶ÔÓÚÉäÖÐACLµÄTCP±¨ÎĽøÐйýÂË £¬ÊµÏÖ¶ÔÊ×°ü¹ýÂ˵ÄÖ÷ÕÅ¡£

*     ×¢Ã÷

¡ñ     È«¾Ö½ÚÔìÃæACL½ö¶ÔÈí¼þ¹ýÂËÉúЧ¡£

¡ñ     È«¾Ö½ÚÔìÃæACL²»ÊÜÈ«¾ÖACLÀý±í¿ÚÅäÖÃÏÞ¶È £¬ÅäÖÃÀý±í¿ÚºóÈ«¾Ö½ÚÔìÃæACLÒÀÈ»ÉúЧ

¡ñ     È«¾Ö½ÚÔìÃæACLÄܹ»ÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ £¬Ò²Äܹ»ÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¼´Äܹ»ÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£ÔÚSVI½Ó¿ÚºÍ¾ÛºÏ³ÉÔ±½Ó¿ÚÉϲ»ÉúЧ¡£

 

1.2?? ÅäÖù¤×÷¸ÅÀÀ

ACLÅäÖù¤×÷ÈçÏ£º

(1)   ÅäÖÃACL¡£ÒÔÏÂÅäÖù¤×÷ÇëÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ÅäÖÃIP³ß¶ÈACL

¡ð         ÅäÖÃIPÀ©´óACL

¡ð         ÅäÖÃMACÀ©´óACL

¡ð         ÅäÖÃר¼Ò¼¶À©´óACL

¡ð         ÅäÖÃIPv6 ACL

¡ð         ÅäÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©

(2)   £¨¿ÉÑ¡£©ÅäÖÃACL³Á¶¨Ïò

(3)   £¨¿ÉÑ¡£©ÅäÖÃÈ«¾Ö°²È«ACL

(4)   £¨¿ÉÑ¡£©ÅäÖ÷Ô쬱¨ÎÄÆ¥Åäģʽ

(5)   £¨¿ÉÑ¡£©ÅäÖÃSVI Router ACL

(6)   £¨¿ÉÑ¡£©ÅäÖÃACL¹ÊÕϸ´Ô­

1.3?? ÅäÖÃIP³ß¶ÈACL

1.3.1? Ö°Äܼò½é

´´½¨ºÍÀûÓÃIP³ß¶ÈACL £¬¶Ô½Ó¿ÚÉϽø³öµÄIPv4±¨ÎĽøÐнÚÔì £¬²»ÈÝ»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂç £¬´Ó¶øÊµÏÖ½ÚÔìIPÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£

1.3.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÈôÊÇÖ»Ïëͨ¹ý²é³­±¨ÎĵÄÔ´IPµØÖ·À´½ÚÔìÓû§µÄÍøÂç×ÊÔ´½Ó¼ûȨÏÞ £¬ÄÇôÄܹ»ÅäÖÃIP³ß¶ÈACL¡£

l  IP³ß¶ÈACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£IP³ß¶ÈACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

1.3.3? ÅäÖù¤×÷¼ò½é

IP³ß¶ÈACLÅäÖù¤×÷ÈçÏ£º

(1)   ´´½¨IP³ß¶ÈACL

(2)   ÀûÓÃIP³ß¶ÈACL

1.3.4? ´´½¨IP³ß¶ÈACL

1.    Ö°Äܼò½é

´´½¨IP³ß¶ÈACL²¢ÅäÖù涨¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  IP³ß¶ÈACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ £¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨ £¬²»ÈÝËùÓÐIPv4±¨ÎĽøÈëÉ豸¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ £¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ £¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡ £Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£

l  ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê± £¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£

l  ÅäÖôølogÑ¡ÏîµÄACL¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´ £¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐlogÑ¡Ïî £¬Ôò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£

l  ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ £¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖÃACL¹æ¶¨Ê±Ö¸¶¨ÁËlogÑ¡Ïîºó £¬»¹±ØÒªÅäÖÃÊä³ö¾àÀë £¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£

l  ¶ÔÓÚ´ølogÑ¡ÏîµÄ¹æ¶¨ £¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ £¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ £¬Ôò¹¦·ò¾àÀëµ½ÆÚºó £¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý £¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£

l  ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨ £¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖÐ £¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢ £¬Äܹ»·½±ãÀí½âACLÓô¦¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ´´½¨IP³ß¶ÈACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ´´½¨Êý×ÖË÷ÒýµÄIP³ß¶ÈACLºÍ¹æ¶¨¡£

access-list acl-number { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]

ȱʡÇé¿öÏ £¬²»´æÔÚIP³ß¶ÈACLºÍ¹æ¶¨¡£

¡ð         ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄIP³ß¶ÈACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃIP³ß¶ÈACLºÍ¹æ¶¨¡£

ip access-list standard { acl-name | acl-number }

ȱʡÇé¿öÏ £¬²»´æÔÚIP³ß¶ÈACL¡£

[ sequence-number ] { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]

ȱʡÇé¿öÏ £¬IP³ß¶ÈACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£

(4)   £¨¿ÉÑ¡£©ÅäÖñ¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀë¡£

ip access-list log-update interval time-value

ȱʡÇé¿öÏ £¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ £¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£

(5)   £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄIP³ß¶ÈACLÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄIP³ß¶ÈACLÅäÖÃ×¢½âÐÅÏ¢¡£

list-remark text

ȱʡÇé¿öÏ £¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(6)   £¨¿ÉÑ¡£©ÅäÖÃIP³ß¶ÈACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄIP³ß¶ÈACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄIP³ß¶ÈACLÅäÖÃ×¢½âÐÅÏ¢¡£

remark text

ȱʡÇé¿öÏ £¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(7)   £¨¿ÉÑ¡£©¿ªÆôIP³ß¶ÈACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£

ip access-list counter { acl-name | acl-number }

ȱʡÇé¿öÏ £¬IP³ß¶ÈACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£

(8)   £¨¿ÉÑ¡£©ÅäÖÃIP³ß¶ÈACL¹æ¶¨²½³¤¡£

ip access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇé¿öÏ £¬IP³ß¶ÈACL¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10 £¬¹æ¶¨ÐòºÅÔöÁ¿ÖµÎª10¡£

1.3.5? ÀûÓÃIP³ß¶ÈACL

1.    Ö°Äܼò½é

½«IP³ß¶ÈACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ £¬Ê¹IP³ß¶ÈACLÉúЧ¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL £¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í £¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£

l  ÅäÖôøin»òoutÑ¡Ïî £¬°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ £¬»¹ÊǶԴÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£

l  ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ £¬Deny¹æ¶¨²»ÉúЧ¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó £¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ £¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL £¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£

l  ÅäÖôøcontrol-planeÑ¡Ïî £¬°µÊ¾½öÈí¼þÉúЧACL £¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£

l  ÅäÖôøforward-planeÑ¡Ïî £¬°µÊ¾½öÓ²¼þÉúЧACL¡£

l  ÅäÖôøforward-control-planeÑ¡Ïî £¬°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   £¨¿ÉÑ¡£©È«¾ÖÀûÓÃIP³ß¶ÈACL¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬È«¾ÖδÀûÓÃIP³ß¶ÈACL¡£

(4)   ½øÈë½Ó¿ÚÅäÖÃģʽ¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÅäÖÃģʽ¡£

vxlan vni-number

(5)   ½Ó¿ÚÀûÓÃIP³ß¶ÈACL¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬½Ó¿ÚδÀûÓÃIP³ß¶ÈACL¡£

1.4?? ÅäÖÃIPÀ©´óACL

1.4.1? Ö°Äܼò½é

´´½¨ºÍÀûÓÃIPÀ©´óACL £¬¶Ô½Ó¿ÚÉϽø³öµÄIPv4±¨ÎĽøÐнÚÔì £¬²»ÈÝ»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂç £¬´Ó¶øÊµÏÖ½ÚÔìIPÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£

1.4.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÈôÊDZØÒªÍ¨¹ý²é³­±¨ÎĵÄÔ´IPµØÖ·¡¢Ö÷ÕÅIPµØÖ·¡¢±¨ÎĵĺÍ̸ºÅ¡¢TCP/UDPÔ´»òÖ÷ÕŶ˱êÓï £¬À´½ÚÔìÓû§µÄÍøÂç×ÊÔ´½Ó¼ûȨÏÞ £¬¿ÉÅäÖÃIPÀ©´óACL¡£

l  IPÀ©´óACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÅäÖá£IPÀ©´óACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

1.4.3? ÅäÖù¤×÷¼ò½é

IPÀ©´óACLÅäÖù¤×÷ÈçÏ£º

(1)   ´´½¨IPÀ©´óACL

(2)   ÀûÓÃIPÀ©´óACL

1.4.4? ´´½¨IPÀ©´óACL

1.    Ö°Äܼò½é

´´½¨IPÀ©´óACL²¢ÅäÖÃÆä¹æ¶¨¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  IPÀ©´óACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ £¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨ £¬²»ÈÝËùÓÐIPv4±¨ÎĽøÈëÉ豸¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ £¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ £¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡ £Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£

l  ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê± £¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£

l  ÅäÖôølogÑ¡ÏîµÄACL¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´ £¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐlogÑ¡Ïî £¬Ôò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£

l  ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ £¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖÃACL¹æ¶¨Ê±Ö¸¶¨ÁËlogÑ¡Ïîºó £¬»¹±ØÒªÅäÖÃÊä³ö¾àÀë £¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£

l  ¶ÔÓÚ´ølogÑ¡ÏîµÄ¹æ¶¨ £¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ £¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ £¬Ôò¹¦·ò¾àÀëµ½ÆÚºó £¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý £¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£

l  ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨ £¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖÐ £¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢ £¬Äܹ»·½±ãÀí½âACLÓô¦¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ´´½¨IPÀ©´óACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ´´½¨Êý×ÖË÷ÒýµÄIPÀ©´óACLºÍ¹æ¶¨¡£

access-list acl-number { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]

ȱʡÇé¿öÏ £¬²»´æÔÚIPÀ©´óACLºÍ¹æ¶¨¡£

¡ð         ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄIPÀ©´óACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃIPÀ©´óACLºÍ¹æ¶¨¡£

ip access-list extended { acl-name | acl-number }

ȱʡÇé¿öÏ £¬²»´æÔÚIPÀ©´óACL¡£

[ sequence-number ] { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]

ȱʡÇé¿öÏ £¬IPÀ©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£

(4)   £¨¿ÉÑ¡£©ÅäÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£

ip access-list log-update interval time-value

ȱʡÇé¿öÏ £¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ £¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£

(5)   £¨¿ÉÑ¡£©ÅäÖÃIPÀ©´óACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄIPÀ©´óACLÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄIPÀ©´óACLÅäÖÃ×¢½âÐÅÏ¢¡£

list-remark text

ȱʡÇé¿öÏ £¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(6)   £¨¿ÉÑ¡£©ÅäÖÃIPÀ©´óACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄIPÀ©´óACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£

remark text

ȱʡÇé¿öÏ £¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(7)   £¨¿ÉÑ¡£©¿ªÆôIPÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£

ip access-list counter { acl-name | acl-number }

ȱʡÇé¿öÏ £¬IPÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£

(8)   £¨¿ÉÑ¡£©ÅäÖÃIPÀ©´óACL¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£

ip access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇé¿öÏ £¬IPÀ©´óACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10 £¬²½³¤Îª10¡£

1.4.5? ÀûÓÃIPÀ©´óACL

1.    Ö°Äܼò½é

½«IPÀ©´óACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ £¬Ê¹IPÀ©´óACLÉúЧ¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL £¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í £¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£

l  ÅäÖôøin»òoutÑ¡Ïî £¬°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ £¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£

l  ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ £¬Deny¹æ¶¨²»ÉúЧ¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó £¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ £¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL £¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£

l  ÅäÖôøcontrol-planeÑ¡Ïî £¬°µÊ¾½öÈí¼þÉúЧACL £¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£

l  ÅäÖôøforward-planeÑ¡Ïî £¬°µÊ¾½öÓ²¼þÉúЧACL¡£

l  ÅäÖôøforward-control-planeÑ¡Ïî £¬°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   £¨¿ÉÑ¡£©È«¾ÖÀûÓÃIPÀ©´óACL¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬È«¾ÖδÀûÓÃIPÀ©´óACL¡£

(4)   ½øÈë½Ó¿ÚÅäÖÃģʽ¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÅäÖÃģʽ¡£

vxlan vni-number

(5)   ½Ó¿ÚÀûÓÃIPÀ©´óACL¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬½Ó¿ÚδÀûÓÃIPÀ©´óACL¡£

1.5?? ÅäÖÃMACÀ©´óACL

1.5.1? Ö°Äܼò½é

´´½¨ºÍÀûÓÃMACÀ©´óACL £¬¶Ô½Ó¿ÚÉϽø³öµÄ¶þ²ã±¨ÎĽøÐнÚÔì £¬²»ÈÝ»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂç £¬´Ó¶øÊµÏÖ»ùÓÚ¶þ²ã±¨ÎÄÍ·À´½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£

1.5.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÈôÊDZØÒªÍ¨¹ý¶þ²ã±¨ÎÄÐÅÏ¢£¨ÀýÈçÓû§PCµÄMACµØÖ·£© £¬À´½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄȨÏÞ £¬Äܹ»ÅäÖÃMACÀ©´óACL¡£

l  MACÀ©´óACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÅäÖá£MACÀ©´óACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

1.5.3? ÅäÖù¤×÷¼ò½é

MACÀ©´óACLÅäÖù¤×÷ÈçÏ£º

(1)   ´´½¨MACÀ©´óACL

(2)   ÀûÓÃMACÀ©´óACL

1.5.4? ´´½¨MACÀ©´óACL

1.    Ö°Äܼò½é

´´½¨MACÀ©´óACL²¢ÅäÖÃÆä¹æ¶¨¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  MACÀ©´óACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ £¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨ £¬²»ÈÝËùÓÐÒÔÌ«Íø¶þ²ã±¨ÎĽøÈëÉ豸¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ £¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ £¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡ £Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£

l  ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê± £¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£

l  ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨ £¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖÐ £¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢ £¬Äܹ»·½±ãÀí½âACLÓô¦¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ´´½¨MACÀ©´óACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ´´½¨Êý×ÖË÷ÒýµÄMACÀ©´óACLºÍ¹æ¶¨¡£

access-list acl-number { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]

ȱʡÇé¿öÏ £¬²»´æÔÚMACÀ©´óACLºÍ¹æ¶¨¡£

¡ð         ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄMACÀ©´óACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃMACÀ©´óACLºÍ¹æ¶¨¡£

mac access-list extended { acl-name | acl-number }

ȱʡÇé¿öÏ £¬²»´æÔÚMACÀ©´óACL¡£

[ sequence-number ] { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]

ȱʡÇé¿öÏ £¬MACÀ©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£

(4)   £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£

list-remark text

ȱʡÇé¿öÏ £¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(5)   £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£

remark text

ȱʡÇé¿öÏ £¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(6)   £¨¿ÉÑ¡£©¿ªÆôMACÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£

mac access-list counter { acl-name | acl-number }

ȱʡÇé¿öÏ £¬MACÀ©´óACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£

(7)   £¨¿ÉÑ¡£©MACÀ©´óACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£

mac access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇé¿öÏ £¬MACÀ©´óACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10 £¬²½³¤Îª10¡£

1.5.5? ÀûÓÃMACÀ©´óACL

1.    Ö°Äܼò½é

½«MACÀ©´óACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ £¬Ê¹MACÀ©´óACLÉúЧ¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL £¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í £¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£

l  ÅäÖôøin»òoutÑ¡Ïî £¬°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ £¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£

l  ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ £¬Deny¹æ¶¨²»ÉúЧ¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó £¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ £¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL £¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£

l  ÅäÖôøcontrol-planeÑ¡Ïî £¬°µÊ¾½öÈí¼þÉúЧACL £¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£

l  ÅäÖôøforward-planeÑ¡Ïî £¬°µÊ¾½öÓ²¼þÉúЧACL¡£

l  ÅäÖôøforward-control-planeÑ¡Ïî £¬°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   £¨¿ÉÑ¡£©È«¾ÖÀûÓÃMACÀ©´óACL¡£

mac access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬È«¾ÖδÀûÓÃMACÀ©´óACL¡£

(4)   ½øÈë½Ó¿ÚÅäÖÃģʽ¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÅäÖÃģʽ¡£

vxlan vni-number

(5)   ½Ó¿ÚÀûÓÃMACÀ©´óACL¡£

mac access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬½Ó¿ÚδÀûÓÃMACÀ©´óACL¡£

1.6?? ÅäÖÃר¼Ò¼¶À©´óACL

1.6.1? Ö°Äܼò½é

´´½¨ºÍÀûÓÃר¼Ò¼¶À©´óACL £¬¶Ô½Ó¿ÚÉϽø³öµÄ±¨ÎĽøÐнÚÔì £¬²»ÈÝ»òÔÊÐíÌØ¶¨µÄ±¨ÎĽøÈëÍøÂç¡£

1.6.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÈôÊDZØÒªÍ¨¹ý»ìºÏʹÓÃIP ACL¹æ¶¨¡¢MACÀ©´óACL¹æ¶¨ºÍVLAN £¬À´½ÚÔìÓû§½Ó¼ûÍøÂç×ÊÔ´µÄȨÏÞ £¬ÔòÄܹ»ÅäÖÃר¼Ò¼¶À©´óACL¡£

l  ר¼Ò¼¶À©´óACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£×¨¼Ò¼¶À©´óACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

1.6.3? ÅäÖù¤×÷¼ò½é

ר¼Ò¼¶À©´óACLÅäÖù¤×÷ÈçÏ£º

(1)   ´´½¨×¨¼Ò¼¶À©´óACL

(2)   ÀûÓÃר¼Ò¼¶À©´óACL

1.6.4? ´´½¨×¨¼Ò¼¶À©´óACL

1.    Ö°Äܼò½é

´´½¨×¨¼Ò¼¶À©´óACL²¢ÅäÖÃÆä¹æ¶¨¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ר¼Ò¼¶À©´óACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ £¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨ £¬²»ÈÝËùÓб¨ÎĽøÈëÉ豸¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ £¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ £¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡ £Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£

l  ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê± £¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£

l  ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨ £¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖÐ £¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢ £¬Äܹ»·½±ãÀí½âACLÓô¦¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ´´½¨×¨¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ´´½¨Êý×ÖË÷ÒýµÄר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£

access-list acl-number { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]

ȱʡÇé¿öÏ £¬²»´æÔÚר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£

¡ð         ´´½¨Êý×ÖË÷Òý»òÕß¶¨ÃûµÄר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃר¼Ò¼¶À©´óACLºÍ¹æ¶¨¡£

expert access-list extended { acl-name | acl-number }

ȱʡÇé¿öÏ £¬²»´æÔÚר¼Ò¼¶À©´óACL¡£

[ sequence-number ] { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]

ȱʡÇé¿öÏ £¬×¨¼Ò¼¶À©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£

¡ð         ´´½¨×¨¼Ò¼¶À©´óACL¼°VXLANÄÚ²ãÎåÔª×鹿¶¨¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖÃר¼Ò¼¶À©´óACL¼°VXLANÄÚ²ãÎåÔª×鹿¶¨¡£

expert access-list extended { acl-name | acl-number }

ȱʡÇé¿öÏ £¬²»´æÔÚר¼Ò¼¶À©´óACL¡£

[ sequence-number ] { deny | permit } { vxlan | vxlan-ignore-dport } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port ] [ tagged ] [ udp-dport dport ] [ match-all tcp-flag | established ] [ time-range time-range-name ]

ȱʡÇé¿öÏ £¬×¨¼Ò¼¶À©´óACLÖдæÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£

(4)   £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£

list-remark text

ȱʡÇé¿öÏ £¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(5)   £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ΪÊý×ÖË÷ÒýµÄACL¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕß¶¨ÃûµÄACLÅäÖÃ×¢½âÐÅÏ¢¡£

remark text

ȱʡÇé¿öÏ £¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(6)   £¨¿ÉÑ¡£©¿ªÆôר¼Ò¼¶ACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£

expert access-list counter { acl-name | acl-number }

(7)   £¨¿ÉÑ¡£©ÅäÖÃר¼Ò¼¶ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£

expert access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇé¿öÏ £¬×¨¼Ò¼¶ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10 £¬²½³¤Îª10¡£

1.6.5? ÀûÓÃר¼Ò¼¶À©´óACL

1.    Ö°Äܼò½é

½«×¨¼Ò¼¶À©´óACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ £¬Ê¹×¨¼Ò¼¶À©´óACLÉúЧ¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL £¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í £¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£

l  ÅäÖôøin»òoutÑ¡Ïî £¬°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ £¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£

l  ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ £¬Deny¹æ¶¨²»ÉúЧ¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-onlyºó £¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ £¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL £¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-onlyºÍͨ³£ACL¡£

l  ÅäÖôøcontrol-planeÑ¡Ïî £¬°µÊ¾½öÈí¼þÉúЧACL £¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£

l  ÅäÖôøforward-planeÑ¡Ïî £¬°µÊ¾½öÓ²¼þÉúЧACL¡£

l  ÅäÖôøforward-control-planeÑ¡Ïî £¬°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   £¨¿ÉÑ¡£©È«¾ÖÀûÓÃר¼Ò¼¶ACL¡£

expert access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬È«¾ÖδÀûÓÃר¼Ò¼¶ACL¡£

(4)   ½øÈë½Ó¿ÚÅäÖÃģʽ¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÅäÖÃģʽ¡£

vxlan vni-number

(5)   ÀûÓÃר¼Ò¼¶À©´óACL¡£

expert access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬½Ó¿ÚδÀûÓÃר¼Ò¼¶À©´óACL¡£

1.7?? ÅäÖÃIPv6 ACL

1.7.1? Ö°Äܼò½é

´´½¨ºÍÀûÓÃIPv6 ACL £¬¶Ô½Ó¿ÚÉϽø³öµÄIPv6±¨ÎĽøÐнÚÔì £¬²»ÈÝ»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂç £¬´Ó¶øÊµÏÖ½ÚÔìIPv6Óû§½Ó¼ûÍøÂç×ÊÔ´µÄÖ÷ÕÅ¡£

1.7.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÈôÊDZØÒª¶ÔIPv6Óû§½Ó¼ûÍøÂç×ÊÔ´µÄ½ÚÔì £¬ÔòÄܹ»ÅäÖÃIPv6 ACL¡£

l  IPv6 ACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£IPv6 ACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

1.7.3? ÅäÖù¤×÷¼ò½é

IPv6 ACLÅäÖù¤×÷ÈçÏ£º

(1)  ´´½¨IPv6 ACL

(2)  ÀûÓÃIPv6 ACL

1.7.4? ´´½¨IPv6 ACL

1.    Ö°Äܼò½é

´´½¨IPv6 ACL²¢ÅäÖÃÆä¹æ¶¨¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ´´½¨IPv6 ACLʱֻÄÜÖ¸¶¨Ãû³Æ £¬²»ÄÜÖ¸¶¨±àºÅ¡£

l  IPv6 ACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ £¬IPv6 ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨ £¬²»ÈݳýND±¨ÎÄÒÔ±íµÄËùÓÐIPv6±¨ÎĽøÈëÉ豸¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æ¶¨ÔÚÖ¸¶¨µÄ¹¦·òÉúЧ £¬»òÔÚÖ¸¶¨µÄ¹¦·òÄÚʧЧ £¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩ¹¦·ò¶ÎÄÚÉúЧµÈ¡ £Äܹ»ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨¡£

l  ÅäÖôøtime-rangeÑ¡ÏîµÄACL¹æ¶¨Ê± £¬±ØÒªÅäÖöÔÓ¦µÄ¹¦·ò¶ÎÑ¡Ïî¡£¹ØÓÚ¹¦·ò¶ÎµÄÅäÖÃÇë°Ý¼û¡°»ù´¡ÅäÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£

l  ÅäÖôølogÑ¡ÏîµÄACL¹æ¶¨»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´ £¬ÈôÊÇÅäÖõÄËùÓй涨¶¼´øÓÐlogÑ¡Ïî £¬Ôò»áµ¼ÖÂÉ豸µÄÓ²¼þÕ½ÊõÈÝÁ¿¼õ°ë¡£

l  ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ £¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£ÔÚÅäÖÃACL¹æ¶¨Ê±Ö¸¶¨ÁËlogÑ¡Ïîºó £¬»¹±ØÒªÅäÖÃÊä³ö¾àÀë £¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£

l  ¶ÔÓÚ´ølogÑ¡ÏîµÄ¹æ¶¨ £¬ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ £¬Ôò²»»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»ÈôÊÇÖ¸¶¨µÄ¹¦·ò¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ £¬Ôò¹¦·ò¾àÀëµ½ÆÚºó £¬»áÊä³öÓë¸Ã¹æ¶¨Óйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£ÆäÖеı¨ÎÄÉäÖÐÊýÁ¿Îª¸Ã¹¦·ò¾àÀëÄڸù涨ƥÅäµ½µÄ±¨ÎÄ×ÜÊý £¬¼´Îª¸Ã¹æ¶¨ÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÉäÖеı¨ÎÄÊý¡£

l  ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨ £¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖÐ £¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢ £¬Äܹ»·½±ãÀí½âACLÓô¦¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ´´½¨IPv6 ACL £¬²¢½øÈëIPv6 ACLÅäÖÃģʽ¡£

ipv6 access-list acl-name

ȱʡÇé¿öÏ £¬²»´æÔÚIPv6 ACL¡£

(4)   ÅäÖÃIPv6 ACL¹æ¶¨¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ÅäÖÃIPv6 ACL¹æ¶¨¡£

[ sequence-number ] { deny | permit } [ protocol { source-ipv6-prefix / prefix-length | source-ipv6-address source-ipv6-mask | host source-ipv6-address | any } { destination-ipv6-prefix / prefix-length | destination-ipv6-address destination-ipv6-mask | host destination-ipv6-address | any } ] [ cos cos-value [ inner cos-value] ] [ { any | host source-mac-address | source-mac-address source-mac-wildcard } { any | host destination-mac-address | destination-mac-address destination-mac-wildcard } ] [ dscp dscp ] [ flow-label flow-label ] [ fragment ] [ VID [ vlan-id ] [ inner vlan-id ] ] [ udf udf-id header pos value mask ] [ time-range time-range-name ]¡¡[ log ]

ȱʡÇé¿öÏ £¬IPv6 ACL´æÔÚÒ»Ìõ»Ø¾øÀàÐ͵Ĺ涨¡£

(5)   £¨¿ÉÑ¡£©ÅäÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£

ipv6 access-list log-update interval time-value

ȱʡÇé¿öÏ £¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ £¬°µÊ¾²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£

(6)   £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£

list-remark text

ȱʡÇé¿öÏ £¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(7)   £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£

remark text

ȱʡÇé¿öÏ £¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(8)   £¨¿ÉÑ¡£©¿ªÆôIPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ¡£

ipv6 access-list counter acl-name

ȱʡÇé¿öÏ £¬IPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼ÆÖ°ÄÜ´¦ÓڹعØ×´Ì¬¡£

(9)   £¨¿ÉÑ¡£©ÅäÖÃIPv6 ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµºÍ²½³¤¡£

ipv6 access-list resequence acl-name start-value step-value

ȱʡÇé¿öÏ £¬IPv6 ACLµÄ¹æ¶¨ÐòºÅÕØÊ¼ÖµÎª10 £¬²½³¤Îª10¡£

1.7.5? ÀûÓÃIPv6 ACL

1.    Ö°Äܼò½é

½«IPv6 ACLÀûÓõ½È«¾ÖÅäÖÃģʽ¡¢½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ £¬Ê¹IPv6 ACLÉúЧ¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  É豸½Ó¿ÚµÄÈë·½Ïò»ò³ö·½ÏòÉÏÖ»ÄÜÀûÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©´óACL £¬»òÕßÀûÓÃÒ»Ìõר¼Ò¼¶ACL¡£³ý´ËÖ®±í £¬»¹Äܹ»ÔÙÀûÓÃÒ»ÌõIPv6 ACL¡£

l  ÅäÖôøin»òoutÑ¡Ïî £¬°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ £¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£

l  ÅäÖôøcounter-onlyÑ¡ÏîÄܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL½Ó¼ûÀà±ðÖеÄPermit¹æ¶¨ÉúЧ £¬DenyÀàÐ͹涨²»ÉúЧ¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó £¬¸ÃÌõACL²»ÄÜÔÚÈ«¾Ö¿ªÆô¼ÆÊýÖ°ÄÜ £¬Ò²²»ÄÜÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÀûÓÃͨ³£ACL £¬¼´Ò»Ñùacl-number»òacl-nameµÄACL²»ÄÜͬʱÓÃ×öcounter-only ACLºÍͨ³£ACL¡£

l  ÅäÖôøcontrol-planeÑ¡Ïî £¬°µÊ¾½öÈí¼þÉúЧACL £¬´ïµ½½ÚÔ¼Ó²¼þ×ÊÔ´µÄÖ÷ÕÅ¡£

l  ÅäÖôøforward-planeÑ¡Ïî £¬°µÊ¾½öÓ²¼þÉúЧACL¡£

l  ÅäÖôøforward-control-planeÑ¡Ïî £¬°µÊ¾Èí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   £¨¿ÉÑ¡£©È«¾ÖÀûÓÃIPv6 ACL¡£

ipv6 traffic-filter acl-name { in | out } { control-plane | forward-control-plane | forward-plane }

ȱʡÇé¿öÏ £¬È«¾ÖδÀûÓÃIPv6 ACL¡£

(4)   ½øÈë½Ó¿ÚÅäÖÃģʽ¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÅäÖÃģʽ¡£

vxlan vni-number

(5)   ½Ó¿ÚÀûÓÃIPv6 ACL¡£

ipv6 traffic-filter acl-name { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇé¿öÏ £¬½Ó¿ÚδÀûÓÃIPv6 ACL¡£

1.8?? ÅäÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©

1.8.1? Ö°Äܼò½é

µ±¹Ì¶¨Æ¥ÅäÓòµÄIP³ß¶ÈACL¡¢IPÀ©´óACL¡¢MACÀ©´óACL¡¢×¨¼Ò¼¶À©´óACLÒÔ¼°IPv6 ACL¶¼ÎÞ·¨Âú×ãÒªÇóʱ £¬Äܹ»Í¨¹ýÅäÖÃר¼Ò¼¶¸ß¼¶ACL £¬¼´ACL80 £¬ÓÉÓû§½ç˵±ØÒªÆ¥ÅäµÄ±¨ÎÄÓò £¬´Ó¶øÊµÏÖ×Ô½ç˵ƥÅäÓòµÄÖ÷ÕÅ¡£

1.8.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ר¼Ò¼¶¸ß¼¶ACLÄܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖá£×¨¼Ò¼¶¸ß¼¶ACLÖ»¶Ô±»ÅäÖõÄÉ豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

1.8.3? ÅäÖù¤×÷¼ò½é

ר¼Ò¼¶¸ß¼¶ACLÅäÖù¤×÷ÈçÏ£º

(1)   ´´½¨×¨¼Ò¼¶¸ß¼¶ACL

(2)   ÀûÓÃר¼Ò¼¶¸ß¼¶ACL

1.8.4? ´´½¨×¨¼Ò¼¶¸ß¼¶ACL

1.    Ö°Äܼò½é

´´½¨ACL80²¢ÅäÖÃÆä¹æ¶¨¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ACL80Äܹ»Ö§³Ôì¥ÅäEthernet IIÖ¡¡¢802.2 LLCÖ¡ºÍ802.2 SNAPÖ¡¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪAAAA03 £¬Ôò°µÊ¾Æ¥Åä802.2 SNAPÖ¡¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪE0E003 £¬Ôò°µÊ¾Æ¥Åä802.2 LLCÖ¡¡£ÈôÊÇÆ¥ÅäEthernet IIÖ¡²»ÄÜÉèÖÃDSAPµ½Cntl×ֶεÄÖµ¡£

l  ÓÉÓÚÓ²¼þµÄÔ­Òò £¬µ±Ç°ACL80²¢²»ÄܶԱ¨ÎÄǰ80¸ö×Ö½ÚµÄËÁÒâ×Ö½ÚÆ¥Åä £¬Ö»Ö§³Ö±¨ÎÄÖÐÖ÷ÕÅMAC¡¢Ô´MAC¡¢VLAN ID¡¢ETYPE¡¢IPºÍ̸ºÅ¡¢Ô´IPv4µØÖ·¡¢Ö÷ÕÅIPv4µØÖ·¡¢Ô´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڡ¢ICMP_TYPE¡¢ICMP_CODE¡¢PPPOE_IPTYPEÕâЩ×Ö¶ÎµØµãµØÎ»µÄÆ¥Åä¡£

l  ACL80Æ¥ÅäIP¡¢ARPµÈÐÅϢʱ £¬±ØÒªÏÈÅäÖ÷â×°µÄÊý¾ÝÀàÐͺÍÊý¾ÝÀàÐÍÑÚÂë £¬¼´±ØÒªÏÈÅäÖÃÆ«ÒÆÁ¿Îª24µÄ×Ö¶Î £¬²¢ÇÒÑÚÂëҪΪȫF¡£ÀýÈç·ÅÐÐÔ´IPΪ192.168.1.2µÄ±¨ÎÄ £¬¶ÔÓ¦µÄÅäÖúÅÁîΪpermit 0800 FFFF 24 C0A80102 FFFFFFFF 38¡£

l  ר¼Ò¼¶¸ß¼¶ACLÖÐÔÊÐíÎ޹涨¡£Ã»ÓÐÅäÖù涨ʱ £¬ACLÒþº¬Ò»Ìõ¡°»Ø¾øËùº±¼û¾ÝÁ÷¡±µÄ¹æ¶¨ £¬²»ÈÝËùÓб¨ÎĽøÈëÉ豸¡£

l  ÈôÊÇÅäÖÃÁ˺öàACL»ò¹æ¶¨ £¬µ«Ã»ÓÐΪÕâЩACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢¡£ÔÚÏÖʵµÄÍøÂçÊØ»¤¹ý³ÌÖÐ £¬½«ÄÑÒÔ·Ö±æÕâЩACL»ò¹æ¶¨µÄÓô¦¡£ÎªACL»ò¹æ¶¨ÅäÖÃ×¢½âÐÅÏ¢ £¬Äܹ»·½±ãÀí½âACLÓô¦¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ´´½¨×¨¼Ò¼¶¸ß¼¶ACL £¬²¢½øÈëר¼Ò¼¶¸ß¼¶ACLÅäÖÃģʽ¡£

expert access-list advanced acl-name

ȱʡÇé¿öÏ £¬²»´æÔÚר¼Ò¼¶¸ß¼¶ACL¡£

(4)   £¨¿ÉÑ¡£©ÅäÖÃר¼Ò¼¶¸ß¼¶ACL¹æ¶¨¡£

[ sequence-number ] { deny | permit } hex hex-mask offset

ȱʡÇé¿öÏ £¬Î´ÅäÖÃר¼Ò¼¶¸ß¼¶ACL¹æ¶¨¡£

(5)   £¨¿ÉÑ¡£©ÅäÖÃACL×¢½âÐÅÏ¢¡£

list-remark text

ȱʡÇé¿öÏ £¬ACLûÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

(6)   £¨¿ÉÑ¡£©ÅäÖÃACL¹æ¶¨×¢½âÐÅÏ¢¡£

remark text

ȱʡÇé¿öÏ £¬ACL¹æ¶¨Ã»ÓÐÅäÖÃ×¢½âÐÅÏ¢¡£

1.8.5? ÀûÓÃר¼Ò¼¶¸ß¼¶ACL

1.    Ö°Äܼò½é

½«×¨¼Ò¼¶¸ß¼¶ACLÀûÓõ½½Ó¿ÚÅäÖÃģʽ¡¢SVI½Ó¿ÚÅäÖÃģʽ¡¢VXLANÅäÖÃģʽÏ £¬Ê¹×¨¼Ò¼¶¸ß¼¶ACLÉúЧ¡£

2.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÅäÖôøin»òoutÑ¡Ïî £¬°µÊ¾±ØÒªÖ¸¶¨ÊǶԽøÈëÉ豸µÄ±¨ÎÄÉúЧ £¬»¹ÊÇ´ÓÉ豸ת·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£

3.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ½øÈë½Ó¿ÚÅäÖÃģʽ¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÅäÖÃģʽ¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÅäÖÃģʽ¡£

vxlan vni-number

(4)   ½Ó¿ÚÀûÓÃר¼Ò¼¶¸ß¼¶ACL¡£

expert access-group { acl-name | acl-number } { in | out }

ȱʡÇé¿öÏ £¬½Ó¿ÚδÀûÓÃר¼Ò¼¶¸ß¼¶ACL¡£

1.9?? ÅäÖÃACL³Á¶¨Ïò

1.9.1? Ö°Äܼò½é

ÔÚÖ¸¶¨½Ó¿ÚÉÏÅäÖÃACL³Á¶¨ÏòÖ°ÄÜ £¬¶Ô½øÈë¸Ã½Ó¿ÚµÄÆ¥Å䱨ÎÄ £¬³Á¶¨Ïòµ½Ö¸¶¨½Ó¿Úת·¢³öÈ¥¡£

1.9.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ACL³Á¶¨ÏòÖ°ÄܽöÔÚ½Ó¿ÚÈë·½ÏòÉúЧ¡£

l  ACLÖÐûÓÐÅäÖù涨ʱ £¬ACL³Á¶¨ÏòÖ°Äܲ»ÉúЧ¡£

l  Ö»Ö§³ÖÔÚÒÔÌ«Íø½Ó¿Ú¡¢¾ÛºÏ½Ó¿ÚÉÏÅäÖÃACL³Á¶¨ÏòÖ°ÄÜ¡£

l  ´ý³Á¶¨ÏòµÄ±¨ÎıØÐëÊǶþ²ãת·¢ £¬Í¬Ê±³Á¶¨ÏòµÄÖ÷ÕŽӿڱØÐëºÍÔ´½Ó¿ÚÔÚͳһ¸öVLANÄÜÁ¦ÉúЧ¡£ÀýÈçÈç¹û±¨ÎÄÊÇ´ÓVLAN 2ת·¢µ½VLAN 3 £¬Ôò²»ÄܽøÐгÁ¶¨Ïò¡£

l  Äܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖÃACL³Á¶¨ÏòÖ°ÄÜ¡£ÅäÖýö¶Ô±¾É豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

1.9.3? ÅäÖóﱸ

ʵÏÖACL³Á¶¨ÏòÖ°ÄÜ £¬±ØÒªÏÈÅäÖÃACL¡£

1.9.4? ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ÅäÖÃACL³Á¶¨Ïò¡£

¡ð         ÅäÖýӿÚACL³Á¶¨Ïò¡£Çë˳´ÎÖ´ÐÐÒÔϺÅÁîÅäÖýӿÚACL³Á¶¨Ïò¡£

interface interface-type interface-number

redirect destination interface interface-type interface-number acl { acl-name | acl-number } in

ȱʡÇé¿öÏ £¬½Ó¿Ú²»´æÔÚACL³Á¶¨ÏòÅäÖá£

1.10?? ÅäÖÃÈ«¾Ö°²È«ACL

1.10.1? Ö°Äܼò½é

ÅäÖÃÈ«¾Ö°²È«ACLÖ°ÄÜ £¬Äܹ»×èÖ¹ÆóÒµÄÚ²¿½Ó¼û·¸·¨ÍøÕ¾ £¬»òÕß×èÖ¹²¡¶¾½øÈëÆóÒµÄÚ²¿ÍøÂ硣ͨ¹ýÅäÖÃÈ«¾Ö°²È«ACLÀý±í¿Ú £¬ÔÊÐíÆóÒµÄÚ²¿ÌØÊⲿÃŽӼû±í²¿Ä³Ð©Õ¾µã¡£

1.10.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ACLÖÐûÓÐÅäÖù涨ʱ £¬È«¾Ö°²È«ACLÖ°Äܲ»´æÔÚ¡£

l  ÓÉÓÚÈ«¾Ö°²È«ACLÖØÒªÓÃÓÚ²¡¶¾¹ýÂË £¬Òò¶ø±»¹ØÁªÓÚÈ«¾Ö°²È«ACLµÄACEÖÐ £¬Ö»ÓÐDenyÀàÐ͵ÄACE»áÉúЧ £¬PermitÀàÐ͵ÄACE²»»áÉúЧ¡£

l  Óë¶Ë¿Ú°²È«ACL·ÖÆç £¬È«¾Ö°²È«ACLûÓÐĬÈϵÄDenyËùÓбíÏî £¬¼´Ã»ÉäÖй涨µÄ±¨ÎͼÄܹ»Í¨¹ý¡£

l  È«¾Ö°²È«ACLÖ»Ö§³Ö¹ØÁªIP³ß¶ÈACL¡¢IPÀ©´óACL¡¢MACÀ©´óACL¡¢×¨¼Ò¼¶À©´óACL¡£

l  È«¾ÖACLÄܹ»ÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ £¬Ò²Äܹ»ÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¼´Äܹ»ÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢¶þ²ãÒÔÌ«Íø½Ó¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£ÔÚSVI½Ó¿ÚÉϲ»ÉúЧ¡£

l  ÔÊÐíÔÚÎïÀí½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿ÚÉ϶ÀÁ¢¹Ø¹ØÈ«¾Ö°²È«ACLÖ°ÄÜ £¬²»Ö§³ÖÔھۺϳÉÔ±½Ó¿ÚÉϹعØÈ«¾Ö°²È«ACLÖ°ÄÜ¡£

l  Äܹ»Æ¾¾ÝÓû§µÄÉ¢²¼Çé¿ö £¬ÔÚ½ÓÈë¡¢»ã¾Û»òÖ÷ÌâÉ豸ÉÏÅäÖÃÈ«¾Ö°²È«ACLÖ°ÄÜ¡£ÅäÖýö¶Ô±¾É豸ÓÐЧ £¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËûÉ豸¡£

l  ͨ¹ýÅäÖÃÈ«¾Ö°²È«ACLÎÞЧְÄÜ £¬Äܹ»ÊµÏÖ²»ÈÝÅäÖÃÈ«¾Ö°²È«ACL¡£

l  ½«½Ó¿ÚÅäÖÃΪÀý±í¿Ú £¬¿Éʹȫ¾Ö°²È«ACLÔÚ½Ó¿ÚÉϲ»ÉúЧ¡£

1.10.3? ÅäÖóﱸ

ʵÏÖÈ«¾Ö°²È«ACLÖ°ÄÜ £¬±ØÒªÏÈÅäÖÃACL¡£

1.10.4? ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   £¨¿ÉÑ¡£©ÅäÖÃÈ«¾Ö°²È«ACLÎÞЧ¡£

global access-group disable

ȱʡÇé¿öÏ £¬²»´æÔÚÈ«¾Ö°²È«ACLÎÞЧÅäÖá£

1.11?? ÅäÖ÷Ô쬱¨ÎÄÆ¥Åäģʽ

1.11.1? Ö°Äܼò½é

ÅäÖøÃÖ°ÄÜÄܹ»Ê¹ACL¶Ô·Ô쬱¨ÎĽøÐиü¾«ÃÜ»¯µÄ½ÚÔì¡£

1.11.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÅäÖ÷Ô쬱¨ÎÄÆ¥ÅäģʽÇл»Ê± £¬»áµ¼ÖÂACLµÄ¶ÌʱʧЧ¡£

l  ÔÚеķÔ쬱¨ÎÄÆ¥ÅäģʽÏ £¬ÈôÊÇACL¹æ¶¨²»´øFragment±êʶ £¬ÇÒÆ¥Åä×÷ΪÊÇPermit £¬ÕâÑùµÄACL¹æ¶¨±ØÒªÕ¼Óøü¶àµÄÓ²¼þ±íÏî×ÊÔ´ £¬¼«¶ËÇé¿öÏ»áʹӲ¼þÕ½Êõ±íÏîÈÝÁ¿¼õ°ë¡£ÈôÊÇÕâÑùµÄACEÅäÖÃÁËTCP Flag¹ýÂ˽ÚÔìµÄEstablished £¬Ôò»¹»áÕ¼Óøü¶àµÄÓ²¼þÕ½Êõ±íÏî¡£

l  ÔÚеķÔ쬱¨ÎÄÆ¥ÅäģʽÏ £¬ÈôÊÇACL¹æ¶¨²»´øFragment±êʶ²¢ÇÒ±ØÒªÆ¥Å䱨ÎĵÄËIJãÐÅϢʱ £¬µ±Æ¥Åä×÷ΪΪPermitʱ £¬ACL¹æ¶¨»á²é³­Êׯ¬±¨ÎÄÈý²ãºÍËIJãÐÅÏ¢ £¬¶ÔÓÚ·ÇÊׯ¬±¨ÎÄÖ»»á²é³­±¨ÎĵÄÈý²ãÐÅÏ¢¡£µ±Æ¥Åä×÷ΪΪDenyʱ £¬ACL¹æ¶¨Ö»»á²é³­Êׯ¬±¨ÎÄ £¬²»»á²é³­·ÇÊׯ¬·Ô쬱¨ÎÄ¡£

l  ÔÚеķÔ쬱¨ÎÄÐÂÆ¥ÅäģʽÏ £¬ÈôÊÇACL¹æ¶¨´øÓÐFragment±êʶ £¬²»ÂÛACL¹æ¶¨µÄÆ¥Åä×÷ΪÊÇPermit»¹ÊÇDeny £¬¶¼Ö»²é³­·ÇÊׯ¬±¨ÎÄ £¬¶ø²»»á²é³­Êׯ¬±¨ÎÄ¡£

1.11.3? ÅäÖóﱸ

ÅäÖ÷Ô쬱¨ÎÄÆ¥ÅäģʽÇл»Ê± £¬±ØÒªÏÈÅäÖÃACL¡£

1.11.4? ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ÅäÖÃеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ÅäÖÃIP ACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£

ip access-list new-fragment-mode { acl-name | acl-number }

ȱʡÇé¿öÏ £¬Î´ÅäÖÃIP ACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£

¡ð         ÅäÖÃר¼Ò¼¶À©´óACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£

expert access-list new-fragment-mode { acl-name | acl-number }

ȱʡÇé¿öÏ £¬Î´ÅäÖÃר¼Ò¼¶À©´óACLеķÔ쬱¨ÎÄÆ¥Åäģʽ¡£

1.12?? ÅäÖÃSVI Router ACL

1.12.1? Ö°Äܼò½é

ÅäÖøÃÖ°ÄÜ £¬Äܹ»Ê¹ÀûÓÃÔÚSVI½Ó¿ÚÉϵÄACL½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£

1.12.2? ÅäÖóﱸ

ʵÏÖ¸ÃÖ°ÄÜ £¬±ØÒªÏÈÅäÖÃACL¡£

1.12.3? ÅäÖò½Öè

(1)  ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)  ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)  ÅäÖÃSVI Router ACL¡£

svi router-acls enable

1.13?? ÅäÖÃACL¹ÊÕϸ´Ô­

1.13.1? Ö°Äܼò½é

µ±É豸Èí¼þ±íÏîÈÝÁ¿´óÓÚÓ²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ê± £¬±íÏîÔö³¤½«Ê§°Ü¡£µ±É豸±íÏîÈÝÁ¿½µµÍµ½Ó²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ö®ÏÂʱ £¬Ô­ÏÈÔö³¤Ê§°ÜµÄ±íÏîÒ²²»»á³ÁÐÂÔö³¤¡£Í¨¹ý±¾ºÅÁî³ÁË¢ÅäÖà £¬´¥°ä·¢ÏîµÄ³ÁÐÂÔö³¤ £¬´Ó¶ø¸´Ô­ACL¹ÊÕÏ¡£

1.13.2? ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ÅäÖÃACL¹ÊÕϸ´Ô­¡£

acl ref synchronize all

1.14?? ¼à¶½ÓëÊØ»¤

Äܹ»Í¨¹ýshowºÅÁîÐв鿴ְÄÜÅäÖúóµÄÔËÐÐÇé¿öÒÔÑéÖ¤ÅäÖóÉЧ¡£

Äܹ»Í¨¹ýÖ´ÐÐclearºÅÁîÀ´¶Ï¸ù¸÷ÀàÐÅÏ¢¡£

*    °ÑÎÈ

ÔÚÉ豸ÔËÐйý³ÌÖÐÖ´ÐÐclearºÅÁî £¬¿ÉÄÜÓÉÓÚ³ÁÒªÐÅÏ¢ÃÔʧ¶øµ¼ÖÂÒµÎñÖжÏ¡£

 

Äܹ»Í¨¹ýdebugºÅÁîÐÐÁоÙÊä³öµÄ¸÷Ààµ÷ÊÔÐÅÏ¢¡£

*    °ÑÎÈ

Êä³öµ÷ÊÔÐÅÏ¢ £¬»áÕ¼ÓÃϵͳ×ÊÔ´¡£Ê¹ÓýáÊøºó £¬Çëµ±¼´¹Ø¹Øµ÷ÊÔ¿ª¹Ø¡£

 

±í1-5     ACL¼à¶½ÓëÊØ»¤

×÷ÓÃ

ºÅÁî

²é¿´¸ù»ùACL

show access-lists [ acl-name | acl-number ] [ summary ]

²é¿´Ö¸¶¨½Ó¿ÚÉϰ󶨵ijÁ¶¨Ïò±íÏî £¬²»ÊäÈë½Ó¿ÚÔò²é¿´ËùÓнӿÚÉϰ󶨵ijÁ¶¨Ïò±íÏî

show redirect [ interface interface-type interface-number ]

²é¿´½Ó¿ÚÉÏÀûÓõÄACLÅäÏàÐÅÏ¢

show access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

²é¿´½Ó¿ÚÉÏÀûÓõÄIP³ß¶ÈACLºÍÀ©´óACLÅäÏàÐÅÏ¢

show ip access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

²é¿´½Ó¿ÚÉÏÀûÓõÄMACÀ©´óACLÅäÏàÐÅÏ¢

show mac access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

²é¿´½Ó¿ÚÉÏÀûÓõÄר¼Ò¼¶À©´óACLÅäÏàÐÅÏ¢

show expert access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

²é¿´½Ó¿ÚÉÏÀûÓõÄIPv6 ACLÅäÏàÐÅÏ¢

show ipv6 traffic-filter [ interface interface-type interface-number | vlan vlan-id ]

²é¿´ËùÓеÄTCAMÐÅÏ¢»òÖ¸¶¨µÄTCAMÐÅÏ¢

show acl res [ dev dev-number [ slot slot-number ] ]

ÏÔʾµ±Ç°É豸µÄÄÜÁ¦ÖµÇé¿ö

show acl capability

²é¿´SVI½Ó¿ÚACLÀûÓõĶþÈý²ãÉúЧÇé¿ö

show svi router-acls state

²é¿´ËùÓеÄTCAM¾ßÌåʹÓÃÐÅÏ¢»òÖ¸¶¨µÄTCAM¾ßÌåʹÓÃÐÅÏ¢

show acl res detail [ dev dev-number [ slot slot-number ] ]

¶Ï¸ùTCAM×ÊԴʹÓÃÁ¿µÄº¹Çà·åÖµÊý¾Ý

clear acl res

¶Ï¸ùACL±¨ÎÄÆ¥Å伯Êý

clear counters access-list [ acl-name | acl-number ]

¶Ï¸ùACL deny±¨ÎÄÆ¥Å伯Êý

clear access-list counters [ acl-name | acl-number ]

´ò¿ªACLÔËÐйý³Ìµ÷ÊÔ¿ª¹Ø

debug acl acld event

²é¿´ACL¿Í»§¶ËÐÅÏ¢

debug acl acld client-show

²é¿´ËùÓÐACL¿Í»§¶Ë´´½¨µÄACL

debug acl acld acl-show

 

1.15?? µäÐÍÅäÖþÙÀý

1.15.1? IP³ß¶ÈACLÅäÖþÙÀý

1.    ×éÍøÐèÒª

ͨ¹ýÅäÖÃIP³ß¶ÈACL £¬²»ÈݲÆÕþ²¿ÒÔ±íµÄ²¿ÃŽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£

2.    ×éÍøÍ¼

ͼ1-3     IP³ß¶ÈACLÀûÓó¡¾°×éÍøÍ¼

image015

 

3.    ÅäÖÃÖØµã

l  Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

l  Device A½«IP³ß¶ÈACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# ip access-list standard 1

DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255

DeviceA(config-std-nacl)# deny 11.1.1.1 0.0.0.255

DeviceA(config-std-nacl)# exit

(2)   ½«IP³ß¶ÈACLÀûÓõ½½Ó¿ÚÉÏ¡£

# Device A½«ACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£

DeviceA(config)# interface gigabitethernet 0/3

DeviceA(config-if-GigabitEthernet 0/3)# ip access-group 1 out

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ²é³­Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£

DeviceA# show access-lists

 

ip access-list standard 1

10 permit 10.1.1.0 0.0.0.255

20 deny 11.1.1.0 0.0.0.255

 

DeviceA# show access-group

ip access-group 1 out

Applied On interface GigabitEthernet 0/3

# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷ £¬È·ÈÏping²»Í¨¡£

# ´Ó²ÆÕþ²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷ £¬È·ÈÏÄÜpingͨ¡£

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

ip access-list standard 1

?10 permit 10.1.1.0 0.0.0.255

?20 deny 11.1.1.0 0.0.0.255

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip access-group 1 out

?ip address 12.1.1.1 255.255.255.0

!

1.15.2? IPÀ©´óACLÅäÖþÙÀý

1.    ×éÍøÐèÒª

Device A£¨VLAN 1£©¡¢Device B£¨VLAN 2£©ºÍDevice C£¨VLAN 3£©Ö±Á¬Device D £¬Device DÊÇËùÓÐÖ÷»úµÄÍø¹Ø¡£ÐèÒª1£ºVLAN2ÓëVLAN3Ö®¼ä²»³ÉÒÔPingͨ £¬VLAN1ÓëVLAN2Äܹ»Pingͨ £¬VLAN1ÓëVLAN3Äܹ»Pingͨ¡£ÐèÒª2£ºVLAN1ÓëVLAN2µÄDHCP±¨ÎÄÏ໥²»³É´ï £¬ÆäËûÕý³£Í¨Ñ¶¡£ÐèÒª3£ºVLAN1²»ÄÜͨ¹ýTelnet»òÕßSSH½Ó¼ûVLAN3 £¬ÆäËûÕý³£Í¨Ñ¶¡£

2.    ×éÍøÍ¼

ͼ1-4     IPÀ©´óACLÀûÓó¡¾°×éÍøÍ¼

image017

 

3.    ÅäÖÃÖØµã

l  Device DÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨ £¬¹ýÂËUDP¶Ë±êÓï67»òÕß68Äܹ»ÊµÏÖÐèÒª2¡£Device CÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨ £¬¹ýÂËTCP¶Ë¿Ú23ºÍ22Äܹ»ÊµÏÖÐèÒª3¡£

l  Device D½«IPÀ©´óACL±ðÀëÀûÓÃÔÚVLAN1½Ó¿Ú¡¢VLAN2½Ó¿ÚºÍVLAN3½Ó¿ÚÉÏ¡£Device C½«IPÀ©´óACLÀûÓÃÔÚÓëDevice DÏàÏß·ÉÏ¡£

4.    ÅäÖò½Öè

(1)  ÅäÖÃËùÓÐÉ豸½Ó¿ÚµÄIPµØÖ·£¨ÂÔ£©¡£

(2)  ÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device DÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceD> enable

DeviceD# configure terminal

DeviceD(config)# ip access-list extended inter_vlan_access1

DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc

DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps

DeviceD(config-ext-nacl)# remark »Ø¾øDHCP±¨ÎÄ

DeviceD(config-ext-nacl)# permit ip any any

DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ

DeviceD(config-ext-nacl)# exit

DeviceD(config)# ip access-list extended inter_vlan_access2

DeviceD(config-ext-nacl)# deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255

DeviceD(config-ext-nacl)# remark »Ø¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping

DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps

DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc

DeviceD(config-ext-nacl)# remark »Ø¾øDHCP±¨ÎÄ

DeviceD(config-ext-nacl)# permit ip any any

DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ

DeviceD(config-ext-nacl)# exit

DeviceD(config)# ip access-list extended inter_vlan_access3

DeviceD(config-ext-nacl)# deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255

DeviceD(config-ext-nacl)# remark »Ø¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping

DeviceD(config-ext-nacl)# permit ip any any

DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ

DeviceD(config-ext-nacl)# exit

# Device CÅäÖÃIPÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceC> enable

DeviceC# configure terminal

DeviceC(config)# ip access-list extended access_deny

DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet

DeviceC(config-ext-nacl)# remark »Ø¾øVLAN1ͨ¹ýTelnet½Ó¼ûVLAN 3

DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22

DeviceC(config-ext-nacl)# remark »Ø¾øVLAN1ͨ¹ýSSH½Ó¼ûVLAN 3

DeviceC(config-ext-nacl)# exit

(3)  ÀûÓÃIPÀ©´óACL¡£

# Device D½«IPÀ©´óACLÀûÓõ½¶ÔÓ¦½Ó¿ÚÉÏ¡£

DeviceD(config)# interface vlan 1

DeviceD(config-if-VLAN 1)# ip access-group inter_vlan_access1 in

DeviceD(config-if-VLAN 1)# exit

DeviceD(config)# interface vlan 2

DeviceD(config-if-VLAN 2)# ip access-group inter_vlan_access2 in

DeviceD(config-if-VLAN 2)# exit

DeviceD(config)# interface vlan 3

DeviceD(config-if-VLAN 3)# ip access-group inter_vlan_access3 in

DeviceD(config-if-VLAN 3)# exit

# Device C½«IPÀ©´óACLÀûÓõ½ÓëDevice DÏàÁ¬Ïß·ÉÏ¡£

DeviceC(config)# line vty 0

DeviceC(config-line)# access-class access_deny in

DeviceC(config-line)# exit

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

(1)  ÑéÖ¤Á¬Í¨ÐÔ¡£

# VLAN 1ÓëVLAN 2Ö®¼äÄܹ»Pingͨ £¬VLAN 1ÓëVLAN 3Ö®¼äÄܹ»Pingͨ¡£

DeviceA# ping 192.168.2.2

Sending 5, 100-byte ICMP Echoes to 192.168.2.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms

DeviceA#

DeviceA# ping 192.168.3.2

Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms

# VLAN 2ÓëVLAN 3Ö®¼ä²»³ÉÒÔPingͨ¡£

DeviceB# ping 192.168.3.2

Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

.....

Success rate is 0 percent (0/5)

(2)  VLAN 1²»ÄÜͨ¹ýTelnet½Ó¼ûVLAN 3¡£

DeviceA# ping 192.168.3.2

Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms

DeviceA#

DeviceA# telnet 192.168.3.2

Trying 192.168.3.2, 23...

% Destination unreachable; gateway or host down

6.    ÅäÖÃÎļþ

l  Device DµÄÅäÖÃÎļþ

hostname DeviceD

!

vlan 1

!

vlan 2

!

vlan 3

!

ip access-list extended inter_vlan_access1

?10 deny udp any eq bootps any eq bootpc

?20 deny udp any eq bootpc any eq bootps

?remark »Ø¾øDHCP±¨ÎÄ

?30 permit ip any any

?remarkÔÊÐíÆäËû±¨ÎÄͨѶ

!

ip access-list extended inter_vlan_access2

?10 deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255

?remark »Ø¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping

?20 deny udp any eq bootpc any eq bootps

?30 deny udp any eq bootps any eq bootpc

?remark »Ø¾øDHCP±¨ÎÄ

?40 permit ip any any

?remark ÔÊÐíÆäËû±¨ÎÄͨѶ

!

ip access-list extended inter_vlan_access3

?10 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255

?remark »Ø¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping

?20 permit ip any any

?remark ÔÊÐíÆäËû±¨ÎÄͨѶ

!

interface GigabitEthernet 1/0

?switchport access vlan 1

?description link_to_DeviceA

!

interface GigabitEthernet 1/1

?switchport access vlan 2

?description link_to_DeviceB

!

interface GigabitEthernet 1/2

?switchport access vlan 3

?description link_to_DeviceC

!

interface VLAN 1

?ip access-group inter_vlan_access1 in

?ip address 192.168.1.1 255.255.255.0

!

interface VLAN 2

?ip access-group inter_vlan_access2 in

?ip address 192.168.2.1 255.255.255.0

!

interface VLAN 3

?ip access-group inter_vlan_access3 in

?ip address 192.168.3.1 255.255.255.0

!

l  Device AµÄÅäÖÃÎļþ

hostname DeviceA

!

interface GigabitEthernet 0/1

?ip address 192.168.1.2 255.255.255.0

!

l  Device BµÄÅäÖÃÎļþ

hostname DeviceB

!

interface GigabitEthernet 0/1

?ip address 192.168.2.2 255.255.255.0

!

l  Device CµÄÅäÖÃÎļþ

hostname DeviceC

!

ip access-list extended access_deny

?10 deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet

?remark »Ø¾øVLAN1ͨ¹ýTelnet½Ó¼ûVLAN 3

?20 deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22

?remark »Ø¾øVLAN1ͨ¹ýSSH½Ó¼ûVLAN 3

!

interface GigabitEthernet 0/1

?ip address 192.168.3.2 255.255.255.0

!

line vty 0

?access-class access_deny in

?login

?password abcdef

!

1.15.3? MACÀ©´óACLÅäÖþÙÀý

1.    ×éÍøÐèÒª

ͨ¹ýMACÀ©´óACL £¬ÏÞ¶ÈÀ´·Ã¿Í»§¿É½Ó¼ûµÄ×ÊÔ´¡£

2.    ×éÍøÍ¼

ͼ1-5     MACÀ©´óACLÀûÓó¡¾°×éÍøÍ¼

image019

 

3.    ÅäÖÃÖØµã

l  Device AÅäÖÃMACÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£ÔÊÐí·Ã¿ÍÇøPC½Ó¼ûInternetÒÔ¼°¹«Ë¾ÄÚ²¿µÄ¹«¹²·þÎñÆ÷ £¬µ«²»ÔÊÐí½Ó¼û¹«Ë¾µÄ²ÆÕþÊý¾Ý·þÎñÆ÷ £¬¼´²»ÈݽӼûMACµØÖ·Îª00e0.f800.000dµÄ·þÎñÆ÷¡£

l  Device A½«MACÀ©´óACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃMACÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device AÅäÖÃMACÀ©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# mac access-list extended 700

DeviceA(config-mac-nacl)# deny any host 00e0.f800.000d

DeviceA(config-mac-nacl)# permit any any

DeviceA(config-mac-nacl)# exit

(2)   ½«MACÀ©´óACLÀûÓõ½½Ó¿ÚÉÏ¡£

# Device A½«ACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# mac access-group 700 in

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ²é³­Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£

DeviceA# show access-lists

mac access-list extended 700

10 deny any host 00e0.f800.000d etype-any

20 permit any any etype-any

DeviceA# show access-group

mac access-group 700 in

Applied On interface GigabitEthernet 0/2

# ´Ó·Ã¿ÍPC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷ £¬È·ÈÏping²»Í¨¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷ £¬È·ÈÏÄܹ»pingµÃͨ¡£

# ÔڷÿÍPC»úÉϽӼûInternet £¬ÀýÈç½Ó¼û°Ù¶È £¬È·ÈÏÄܹ»´ò¿ªÖ÷Ò³¡£

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

mac access-list extended 700

?10 deny any host 00e0.f800.000d

?20 permit any any

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?mac access-group 700 in

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip address 12.1.1.1 255.255.255.0

!

1.15.4? ר¼Ò¼¶À©´óACLÅäÖþÙÀý

1.    ×éÍøÐèÒª

ͨ¹ýÅäÖÃר¼Ò¼¶À©´óACL £¬ÏÞ¶ÈÀ´·Ã¿Í»§¿É½Ó¼ûµÄ×ÊÔ´¡£ÒªÇó·Ã¿Í²»ÄܽӼû¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÕþÊý¾Ý·þÎñÆ÷ £¬µ«ÄܽӼû¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£

2.    ×éÍøÍ¼

ͼ1-6     ר¼Ò¼¶À©´óACLÀûÓó¡¾°×éÍøÍ¼

image021

 

3.    ÅäÖÃÖØµã

l  Device AÅäÖÃר¼Ò¼¶À©´óACL²¢Ôö³¤¹æ¶¨ £¬Ô̺¬£º

¡ð         ²»ÈݷÿÍÇøÄÚÖ÷»ú·¢³öÖ¸±êΪ¹«Ë¾ÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£

¡ð         ²»ÈݷÿͽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£

¡ð         ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£

l  Device A½«ACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃר¼Ò¼¶À©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device AÅäÖÃר¼Ò¼¶À©´óACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# expert access-list extended 2700

DeviceA(config-exp-nacl)# deny ip any any 10.1.1.0 0.0.0.255 any

DeviceA(config-exp-nacl)# deny ip any any host 12.1.1.2 any

DeviceA(config-exp-nacl)# permit any any any any

DeviceA(config-exp-nacl)# exit

(2)   ½«×¨¼Ò¼¶À©´óACLÀûÓõ½½Ó¿ÚÉÏ¡£

# Device A½«ACLÀûÓÃÔÚÓë·Ã¿ÍÇøÏàÏνӿڵÄÈë·½ÏòÉÏ¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# expert access-group 2700 in

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ²é³­Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£

DeviceA(config)# show access-lists

expert access-list extended 2700

?10 deny ip any any 192.168.1.0 0.0.0.255 any

20 deny ip any any host 10.1.1.1 any

30 permit ip any any any any

 

DeviceA(config)# show access-group

expert access-group 2700in

Applied On interface GigabitEthernet 0/2

# ´Ó·Ã¿ÍPC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷ £¬È·ÈÏping²»Í¨¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷ £¬È·Èϲ»ÄÜpingͨ¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1 £¬È·¶¨ping²»Í¨¡£

# ÔڷÿÍPC»úÉϽӼûInternet £¬ÀýÈç½Ó¼û°Ù¶È £¬È·ÈÏÄܹ»´ò¿ªÖ÷Ò³¡£

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

expert access-list extended 2700

?10 deny ip any any 10.1.1.0 0.0.0.255 any

?20 deny ip any any host 12.1.1.2 any

?30 permit ip any any any any

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?expert access-group 2700 in

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip address 12.1.1.1 255.255.255.0

!

1.15.5? IPv6 ACLÅäÖþÙÀý

1.    ×éÍøÐèÒª

ͨ¹ýÅäÖÃIPv6 ACL £¬²»ÈÝ¿ª·¢²¿ÃŽӼûÊÓÆµ·þÎñÆ÷¡£

2.    ×éÍøÍ¼

ͼ1-7     IPv6 ACLÀûÓó¡¾°×éÍøÍ¼

image023

 

3.    ÅäÖÃÖØµã

l  Device AÅäÖÃIPv6 ACL²¢Ôö³¤¹æ¶¨ £¬Ô̺¬£º

¡ð         ²»ÈݽӼûÊÓÆµ·þÎñÆ÷IPv6µØÖ·¹æ¶¨¡£

¡ð         ÔÚIPv6 ACLÖÐÔö³¤ÔÊÐíËùÓÐIPv6±¨ÎÄͨ¹ý¹æ¶¨¡£

l  Device A½«IPv6 ACLÀûÓÃÔÚÏνӿª·¢²¿ÃŽӿڵÄÈë·½ÏòÉÏ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃIPv6 ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device AÅäÖÃIPv6 ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# ipv6 access-list dev_deny_ipv6video

DeviceA(config-ipv6-nacl)# deny ipv6 any host 1002::2

DeviceA(config-ipv6-nacl)# permit ipv6 any any

DeviceA(config-ipv6-nacl)# exit

(2)   ½«IPv6 ACLÀûÓõ½½Ó¿ÚÉÏ¡£

# Device A½«ACLÀûÓÃÔÚÏνӿª·¢²¿Ãŵصã½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# ipv6 traffic-filter dev_deny_ipv6video in

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ²é³­Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£

DeviceA(config)# show access-lists

 

ipv6 access-list dev_deny_ipv6video

10 deny ipv6 any host 200::1

20 permit ipv6 any any

 

DeviceA(config)# show access-group

ipv6 traffic-filter dev_deny_ipv6video in

Applied On interface GigabitEthernet 0/2

# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏpingÊÓÆµ·þÎñÆ÷ £¬È·ÈÏping²»Í¨¡£

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

ipv6 access-list dev_deny_ipv6video

?10 deny ipv6 any host 1002::2

?20 permit ipv6 any any

!

interface GigabitEthernet 0/1

?no switchport

?ipv6 address 1000::1/96

!

interface GigabitEthernet 0/2

?no switchport

?ipv6 traffic-filter dev_deny_ipv6video in

?ipv6 address 1001::1/96

!

interface GigabitEthernet 0/3

?no switchport

?ipv6 address 1002::1/96

!

1.15.6? ACL80ÅäÖþÙÀý

1.    ×éÍøÐèÒª

ͨ¹ýACL80¼´×¨¼Ò¼¶¸ß¼¶ACL £¬ÏÞ¶ÈÀ´·Ã¿Í»§¿É½Ó¼ûµÄ×ÊÔ´¡£ÒªÇó·Ã¿Í²»ÄܽӼû¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÕþÊý¾Ý·þÎñÆ÷ £¬µ«ÄܽӼû¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£

2.    ×éÍøÍ¼

ͼ1-8     ACL80ÀûÓó¡¾°×éÍøÍ¼

image021

 

3.    ÅäÖÃÖØµã

l  Device AÅäÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ôö³¤¹æ¶¨ £¬Ô̺¬£º

¡ð         ²»ÈݷÿÍÇøÄÚÖ÷»ú·¢³öÖ¸±êΪÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£

¡ð         ²»ÈݷÿͽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£

¡ð         ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£

l  Device A½«ACLÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device AÅäÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# expert access-list advanced acl80-guest

DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0A0101 FFFFFF 42

DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0C010102 FFFFFFFF 42

DeviceA(config-exp-dacl)# permit 0806 FFFF 24

DeviceA(config-exp-dacl)# permit 0800 FFFF 24

DeviceA(config-exp-dacl)# exit

(2)   ½«×¨¼Ò¼¶¸ß¼¶ACLÀûÓõ½½Ó¿ÚÉÏ¡£

# Device A½«ACL80ÀûÓÃÔÚÏνӷÿÍÇø½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# expert access-group acl80-guest in

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ²é³­Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£

DeviceA(config)# show access-lists

expert access-list advanced sss

?10 deny 0800 FFFF 24 0A0101 FFFFFF 42

?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42

?30 permit 0806 FFFF 24

?40 permit 0800 FFFF 24

 

expert access-group acl80-guest in

Applied On interface GigabitEthernet 0/2

# ´Ó·Ã¿ÍPC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷ £¬È·ÈÏping²»Í¨¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷ £¬È·ÈÏÄܹ»pingµÃͨ¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1 £¬È·¶¨ping²»Í¨¡£

# ÔڷÿÍPC»úÉϽӼûInternet £¬ÀýÈç½Ó¼û°Ù¶È £¬È·ÈÏÄܹ»´ò¿ªÖ÷Ò³¡£

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

expert access-list advanced acl80-guest

?10 deny 0800 FFFF 24 0A0101 FFFFFF 42

?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42

?30 permit 0806 FFFF 24

?40 permit 0800 FFFF 24

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?expert access-group 2700 in

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip address 12.1.1.1 255.255.255.0

!

1.15.7? »ùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨ÅäÖþÙÀý

1.    ×éÍøÐèÒª

ÅäÖûùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨ £¬Ö»ÔÊÐíÑз¢²¿ÃÅÔÚÿÌìµÄ12:00µ½13:30½Ó¼ûInternet¡£

2.    ×éÍøÍ¼

ͼ1-9     »ùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨ÀûÓó¡¾°×éÍøÍ¼

image026

 

3.    ÅäÖÃÖØµã

l  Device AÅäÖù¦·ò¶Î £¬²¢Ôö³¤Ã¿Ìì12:00µ½13:30µÄ¹¦·ò¶Î±íÏî¡£

l  Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤¹æ¶¨ £¬Ô̺¬£º

¡ð         Ôö³¤ÔÊÐíÔ´IPÍø¶ÎµØÖ·Îª10.1.1.0/24µÄ¹æ¶¨ £¬¹ØÁªµÄ¹¦·ò¶ÎΪaccess-internet¡£

¡ð         Ôö³¤²»ÈÝÔ´IPÍø¶ÎµØÖ·Îª10.1.1.0/24µÄ¹æ¶¨¡£Åú×¢¹¦·ò¶ÎÖ®±í¶¼²»ÔÊÐí½Ó¼ûInternet¡£

¡ð         Ôö³¤ÔÊÐí³ýÑз¢Íø¶ÎµØÖ·±í £¬ÆäËûËùÓÐÍø¶ÎµØÖ·µÄ¹æ¶¨¡£

l  Device A½«ACLÀûÓÃÔÚÏνÓÑз¢²¿½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖù¦·òÇø¡£

# Device AÅäÖù¦·ò¶Î¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# time-range access-internet

DeviceA(config-time-range)# periodic daily 12:00 to 13:30

DeviceA(config-time-range)# exit

(2)   ÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceA(config)# ip access-list standard ip_std_internet_acl

DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255 time-range access-internet

DeviceA(config-std-nacl)# deny 10.1.1.0 0.0.0.255

DeviceA(config-std-nacl)# permit any

DeviceA(config-std-nacl)# exit

(3)   ½«IP³ß¶ÈACLÀûÓõ½½Ó¿ÚÉÏ¡£

# Device A½«ACLÀûÓÃÔÚÏνÓÑз¢²¿½Ó¿ÚµÄÈë·½ÏòÉÏ¡£

DeviceA(config)# interface gigabitethernet 0/1

DeviceA(config-if-GigabitEthernet 0/1)# ip access-group ip_std_internet_acl in

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ²é³­Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£

DeviceA# show time-range

 

time-range entry: access-internet (inactive)

¡¡periodic Daily 12:00 to 13:30

 

DeviceA# show access-lists

 

ip access-list standard ip_std_internet_acl

?10 permit 10.1.1.0 0.0.0.255 time-range access-internet (inactive)

?20 deny 10.1.1.0 0.0.0.255

?30 permit any

 

DeviceA# show access-group

ip access-group ip_std_internet_acl in

Applied On interface GigabitEthernet 0/1

# ÔÚ¹¦·ò¶ÎÉúЧÆÚÄÚ£¨12:00ÖÁ13:30£© £¬´ÓÑз¢²¿ÃÅÄÚµÄij̨PC»ú½Ó¼û°Ù¶ÈÖ÷Ò³ £¬È·ÈÏÄܹ»½Ó¼û¡£

# ÔÚ¹¦·ò¶ÎʧЧÆÚ£¨12:00ÖÁ13:30ʱ¶Î±í£© £¬´ÓÑз¢²¿ÃÅÄÚµÄij̨PC»ú½Ó¼û°Ù¶ÈÖ÷Ò³ £¬È·Èϲ»ÄܽӼû¡£

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

ip access-list standard ip_std_internet_acl

?10 permit 10.1.1.0 0.0.0.255 time-range access-internet

?20 deny 10.1.1.0 0.0.0.255

?30 permit any

!

time-range access-internet

?periodic daily 12:00 to 13:30

!

interface GigabitEthernet 0/1

?no switchport

?ip access-group ip_std_internet_acl in

?ip address 10.1.1.1 255.255.255.0

!

1.15.8? SVI Router ACLÅäÖþÙÀý

1.    ×éÍøÐèÒª

ÅäÖÃVRRP+VLANÀûÓó¡¾° £¬Ö»ÔÊÐíÖ÷»úÓëÖ÷»úÖ®¼äµÄÈý²ãͨѶ¡£ÅäÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä½Ó¼ûµÄACL £¬»Ø¾øÆäËûËùÓÐÍø¶ÎµÄACL¡£

2.    ×éÍøÍ¼

ͼ1-10   VRRP+VLANÀûÓó¡¾°×éÍøÍ¼

image028

 

3.    ÅäÖÃÖØµã

l  DeviceAºÍDeviceB×é³ÉVRRP³¡¾°¡£Ö÷»úPC1ºÍPC2È«Êý½ÓÈëµ½DeviceC¡£

l  ÅäÖÃÌìÉúÊ÷ºÍ̸ £¬½â³ýDeviceA¡¢DeviceBºÍDeviceCÖ®¼äµÄ»·Â·¡£

l  Ö÷»úPC1ºÍPC2µÄÍø¹ØÑ¡È¡SVI½Ó¿ÚµÄµØÖ·¡£

l  ÅäÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä½Ó¼ûµÄACL £¬»Ø¾øÆäËûËùÓÐÍø¶ÎµÄACL £¬²¢½«ACLÀûÓÃÔÚSVI½Ó¿ÚÉÏ¡£´Ëʱ»áµ¼ÖÂVRRP×éÄÚDeviceAºÍDeviceBÐγÉË«Ö÷¡£

l  ÅäÖÃsvi router-acls enableºÅÁîºó £¬VRRP×éÄÚDeviceAºÍDeviceBÐγÉÒ»Ö÷Ò»±¸ £¬VRRPºÍ̸¸´Ô­Õý³£¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃVLAN¡£

# DeviceAÅäÖÃVLAN¡£DeviceA¡¢DeviceBºÍDeviceCÅäÖÃÆëȫһÑù £¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# vlan 10

DeviceA(config-vlan)# exit

DeviceA(config)# vlan 20

DeviceA(config-vlan)# exit

(2)   ÅäÖÃVRRP×é¡£

# DeviceAÅäÖÃVRRP¡£

DeviceA(config)# interface VLAN 10

DeviceA(config-if-VLAN 10)# ip address 172.16.1.3 255.255.255.0

DeviceA(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1

DeviceA(config-if-VLAN 10)# vrrp 10 priority 120

DeviceA(config-if-VLAN 10)# exit

DeviceA(config)# interface VLAN 20

DeviceA(config-if-VLAN 20)# ip address 172.31.1.4 255.255.255.0

DeviceA(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1

# DeviceBÅäÖÃVRRP¡£

DeviceB(config)# interface VLAN 10

DeviceB(config-if-VLAN 10)# ip address 172.16.1.4 255.255.255.0

DeviceB(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1

DeviceB(config-if-VLAN 10)# exit

DeviceB(config)# interface VLAN 20

DeviceB(config-if-VLAN 20)# ip address 172.31.1.3 255.255.255.0

DeviceB(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1

DeviceB(config-if-VLAN 20)# vrrp 20 priority 120

DeviceB(config-if-VLAN 20)# exit

(3)   ÅäÖÃÌìÉúÊ÷ºÍ̸ £¬½â³ý»·Â·¡£

# DeviceAÅäÖÃÌìÉúÊ÷ºÍ̸¡£DeviceA¡¢DeviceBºÍDeviceCÅäÖÃÆëȫһÑù £¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£

DeviceA(config)# spanning-tree

(4)   ÅäÖÃACL¡£

# DeviceAÅäÖÃACL¡£DeviceAºÍDeviceBÅäÖÃÆëȫһÑù £¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£

DeviceA(config)# ip access-list standard 10

DeviceA(config-std-nacl)# permit host 3.3.3.3

DeviceA(config-std-nacl)# deny any

DeviceA(config-std-nacl)# exit

(5)   ½«ACLÀûÓõ½SVI½Ó¿Ú¡£

# DeviceAÀûÓÃACL¡£DeviceAºÍDeviceBÅäÖÃÆëȫһÑù £¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£

DeviceA(config)# int vlan 20

DeviceA(config-if-VLAN 20)# ip access-group 10 in

(6)   ÅäÖúÅÁîsvi router-acls enable¡£

# DeviceAÅäÖúÅÁîsvi router-acls enable¡£DeviceAºÍDeviceBÅäÖÃÆëȫһÑù £¬ÒÔÏÂÒÔDeviceAÅäÖÃΪÀý¡£

DeviceA(config)# svi router-acls enable

 

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ²é³­DeviceAÉ豸VRRPºÍ̸״̬¡£

DeviceA# show vrrp

Interface¡¡¡¡Grp¡¡Pri¡¡ timer¡¡ Own¡¡Pre¡¡ State¡¡ Master addr¡¡¡¡ Group addr¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡

VLAN 10¡¡¡¡¡¡10¡¡ 120¡¡ 3.53¡¡¡¡-¡¡¡¡P¡¡¡¡ Master¡¡172.16.1.3¡¡¡¡¡¡172.16.1.1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡

VLAN 20¡¡¡¡¡¡20¡¡ 100¡¡ 3.60¡¡¡¡-¡¡¡¡P¡¡¡¡ Backup¡¡172.31.1.3¡¡¡¡¡¡172.31.1.1

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ¡£

hostname DeviceA

!

vlan 1

!

vlan 10

!

vlan 20

!

spanning-tree

!

ip access-list standard 10

?10 permit host 3.3.3.3

?20 deny any

!

svi router-acls enable

!

interface GigabitEthernet 0/1

?switchport mode trunk

!

interface GigabitEthernet 0/3

?switchport mode trunk

!

interface VLAN 1

?ip address 192.168.1.2 255.255.255.0

!

interface VLAN 10

?ip address 172.16.1.3 255.255.255.0

?vrrp 10 priority 120

?vrrp 10 ip 172.16.1.1

!

interface VLAN 20

?ip access-group 10 in

?ip address 172.31.1.4 255.255.255.0

?vrrp 20 ip 172.31.1.1

!

ip route 3.3.3.0 255.255.255.0 192.168.1.1

!

l  DeviceBµÄÅäÖÃÎļþ¡£

hostname DeviceB

!

vlan 1

!

vlan 10

!

vlan 20

!

spanning-tree

!

ip access-list standard 10

?10 permit host 3.3.3.3

?20 deny any

!

svi router-acls enable

!

interface GigabitEthernet 0/1

?switchport mode trunk

!

interface GigabitEthernet 0/3

?switchport mode trunk

!

interface VLAN 1

?ip address 192.168.2.2 255.255.255.0

!

interface VLAN 10

?ip access-group 10 in

?ip address 172.16.1.4 255.255.255.0

?vrrp 10 ip 172.16.1.1

!

interface VLAN 20

?ip address 172.31.1.3 255.255.255.0

?vrrp 20 priority 120

?vrrp 20 ip 172.31.1.1

!

ip route 3.3.3.0 255.255.255.0 192.168.2.1

!

l  DeviceCµÄÅäÖÃÎļþ¡£

hostname DeviceC

!

vlan 1

!

vlan 10

!

vlan 20

!

interface GigabitEthernet 0/1

?switchport access vlan 10

!

interface GigabitEthernet 0/2

?switchport access vlan 20

!

interface GigabitEthernet 0/3

?switchport mode trunk

!

interface GigabitEthernet 0/4

?switchport mode trunk

!

l  ServerAµÄÅäÖÃÎļþ¡£

hostname ServerA

!

interface GigabitEthernet 0/1

?ip address 192.168.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?ip address 192.168.2.1 255.255.255.0

!

interface Loopback 0

?ip address 3.3.3.3 255.255.255.0

!

ip route 172.16.1.0 255.255.255.0 192.168.1.2

ip route 172.31.1.0 255.255.255.0 192.168.2.2

!

1.15.9? ACL±¨ÎļÆÊýͳ¼ÆÅäÖþÙÀý

1.    ×éÍøÐèÒª

ÀûÓÃACLʱÈôÊÇÅäÖôøcounter-onlyÑ¡Ïî £¬Äܹ»¶ÔÄ³Ð©ÌØµãµÄ±¨ÎĽøÐмÆÊýͳ¼Æ¡£ÒÔPC pingÍø¹ØÅׯúICMP±¨ÎÄΪÀý½øÐмÆÊýͳ¼Æ £¬²¢¶¨Î»¶ª°üµØÎ»¡£

2.    ×éÍøÍ¼

image030

 

3.    ÅäÖÃÖØµã

l  DeviceÉÏG0/1ºÍG0/2µÄÈë·½ÏòºÍ³ö·½Ïò¶¼ÒªÀûÓÃACL £¬ËùÒÔDevice±ØÒªÅäÖÃ4ÌõACL £¬±ðÀëÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£

l  GatewayÉ豸G0/1µÄÈë·½ÏòºÍ³ö·½Ïò¶¼ÒªÀûÓÃACL £¬ËùÒÔGatewayÅäÖÃ2ÌõACL £¬±ðÀëÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£

l  ÀûÓÃACLʱÅäÖñØÒªcounter-onlyÑ¡Ïî¡£

l  ¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACLÖеÄPermit¹æ¶¨ÉúЧ £¬Deny¹æ¶¨²»ÉúЧ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃACL¡£

# DeviceÉ豸ÅäÖÃ4ÌõACL £¬±ðÀëÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£

Device> enable

Device# configure terminal

Device(config)# ip access-list extend 100

Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254

Device(config-ext-nacl)# exit

Device(config)# ip access-list extend 101

Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1

Device(config-ext-nacl)# exit

Device(config)# ip access-list extend 102

Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254

Device(config-ext-nacl)# exit

Device(config)# ip access-list extend 103

Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1

Device(config-ext-nacl)# exit

# GatewayÉ豸ÅäÖÃ2ÌõACL £¬±ðÀëÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£

Gateway> enable

Gateway #configure terminal

Gateway(config)# ip access-list extend 100

Gateway(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254

Gateway(config-ext-nacl)# exit

Gateway(config)# ip access-list extend 101

Gateway(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1

Gateway(config-ext-nacl)# exit

(2)   ÀûÓÃACL¡£

# ÔÚGatewayÉ豸ºÍDeviceÉ豸»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòºÍ³ö·½ÏòÀûÓÃACL¡£

Gateway(config)# interface gigabitEthernet 0/1

Gateway(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only

Gateway(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only

Gateway(config-if-GigabitEthernet 0/1)# exit

# ÔÚDeviceÉ豸ºÍGatewayÉ豸»¥Áª½Ó¿ÚG0/2µÄÈë·½ÏòºÍ³ö·½ÏòÀûÓÃACL¡£

Device# configure terminal

Device(config)# interface gigabitEthernet 0/2

Device(config-if-GigabitEthernet 0/2)# ip access-group 103 in counter-only

Device(config-if-GigabitEthernet 0/2)# ip access-group 102 out counter-only

Device(config-if-GigabitEthernet 0/2)# exit

# ÔÚDeviceÉ豸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòºÍ³ö·½ÏòÀûÓÃACL¡£

Device# configure terminal

Device(config)# interface gigabitEthernet 0/1

Device(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only

Device(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only

Device(config-if-GigabitEthernet 0/1)# exit

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ÔÚPCÉÏpingÍø¹ØµØÖ·10.10.10.254 £¬3´Î¹²·¢³ö15¸öICMP±¨ÎÄ¡£±ðÀë²é¿´DeviceÉ豸ºÍGatewayÉ豸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£²é¿´DeviceÉ豸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£

Device# show access-list

ip access-list extended 100

¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)

ip access-list extended 101

¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)

ip access-list extended 102¡¡

¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)

ip access-list extended 103¡¡

¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)

# ²é¿´GatewayÉ豸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£

Gateway# show access-list

ip access-list extended 100

¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)

ip access-list extended 101

¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (15 matches)

# ·ÖÎö±¨ÎÄͳ¼Æ¼ÆÊý £¬¶¨Î»±¨ÎÄÅׯúµØÎ»¡£

DeviceÉ豸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòÊÕµ½15¸ö±¨ÎÄ£¨DeviceÉ豸ACL 100£©¡£

DeviceÉ豸ºÍGatewayÉ豸»¥Áª½Ó¿ÚG0/2µÄ³ö·½Ïò·¢³ö15¸ö±¨ÎÄ£¨DeviceÉ豸ACL 102£©¡£

GatewayÉ豸ºÍDeviceÉ豸»¥Áª½Ó¿ÚG0/1µÄÈë·½ÏòÊÕµ½15¸ö±¨ÎÄ£¨GatewayÉ豸ACL 100£©¡£

GatewayÉ豸ºÍDeviceÉ豸»¥Áª½Ó¿ÚG0/1µÄ³ö·½Ïò·¢³ö15¸ö±¨ÎÄ£¨GatewayÉ豸ACL 101£©¡£

DeviceÉ豸ºÍGatewayÉ豸»¥Áª½Ó¿ÚG0/2µÄÈë·½ÏòÊÕµ½10¸ö±¨ÎÄ£¨DeviceÉ豸ACL 103£©¡£

×¢Ã÷±¨ÎÄÅׯúÔÚDeviceÉ豸ºÍGatewayÉ豸֮¼äµÄÁ´Â·ÉÏ¡£

6.    ÅäÖÃÎļþ

l  DeviceµÄÅäÖÃÎļþ¡£

hostname Device

!

ip access-list extended 100

?10 permit icmp host 10.10.10.1 host 10.10.10.254

!

ip access-list extended 101

?10 permit icmp host 10.10.10.254 host 10.10.10.1

!

ip access-list extended 102

?10 permit icmp host 10.10.10.1 host 10.10.10.254

!

ip access-list extended 103

?10 permit icmp host 10.10.10.254 host 10.10.10.1

!

interface GigabitEthernet 0/1

?ip access-group 100 in counter-only

?ip access-group 101 out counter-only

!

interface GigabitEthernet 0/2

?ip access-group 103 in counter-only

?ip access-group 104 out counter-only

!

l  GatewayµÄÅäÖÃÎļþ¡£

hostname Gateway

!

ip access-list extended 100

?10 permit icmp host 10.10.10.1 host 10.10.10.254

!

ip access-list extended 101

?10 permit icmp host 10.10.10.254 host 10.10.10.1

!

interface GigabitEthernet 0/1

?ip access-group 100 in counter-only

?ip access-group 101 out counter-only

?ip address 10.10.10.254 255.255.255.0

!

 

¡¾ÍøÕ¾µØÍ¼¡¿