ACL的基本应用

vlan10可以与任意通讯,剩余之间互相不能通讯

核心

vlan batch 10 50 60 70 80 90

int vlan 10

ip add 192.168.10.1 22                        

int vlan 50

ip add 192.168.50.1 24

int vlan 60

ip add 192.168.60.1 24

Int vlan 70

ip add 192.168.70.1 24

Int vlan 80

ip add 192.168.80.1 24

Int vlan 90

ip add 192.168.90.1 24

#创建vlan 跟ip

Int g0/0/1

port link-type trunk

port trunk allow-pass vlan all

Int g0/0/2

port link-type trunk

port trunk allow-pass vlan 50

Int g0/0/3

port link-type trunk

port trunk allow-pass vlan 60

Int g0/0/4

port link-type trunk

port trunk allow-pass vlan 70

Int g0/0/5

port link-type trunk

port trunk allow-pass vlan 80

Int g0/0/6

port link-type trunk

port trunk allow-pass vlan 90

#创建接口类型

Vlan 200

Int vlan 200

Ip add 192.168.1.2 24

Int g0/0/24

Port link-type access

Port default vlan 200

#创建与路由器的连接

Dhcp enabl

Ip pool yisa10

Gateway-list 192.168.10.1

Network 192.168.10.0 mask 255.255.252.0

Dns-list 114.114.114.114 223.5.5.5

Ip pool yisa50

Gateway-list 192.168.50.1

Network 192.168.50.0 mask 255.255.255.0

Dns-list 114.114.114.114 223.5.5.5

Ip pool yisa60

Gateway-list 192.168.60.1

Network 192.168.60.0 mask 255.255.255.0

Dns-list 114.114.114.114 223.5.5.5

Ip pool yisa70

Gateway-list 192.168.70.1

Network 192.168.70.0 mask 255.255.255.0

Dns-list 114.114.114.114 223.5.5.5

Ip pool yisa80

Gateway-list 192.168.80.1

Network 192.168.80.0 mask 255.255.255.0

Dns-list 114.114.114.114 223.5.5.5

Ip pool yisa90

Gateway-list 192.168.90.1

Network 192.168.90.0 mask 255.255.255.0

Dns-list 114.114.114.114 223.5.5.5

#创建IP地址池

Int vlan 10

dhcp select global

Int vlan 50

dhcp select global

Int vlan 60

dhcp select global

Int vlan 70

dhcp select global

Int vlan 80

dhcp select global

Int vlan 90

dhcp select global

#开启每个vlan的dhcp

Acl 3050

Rule 10 deny ip source 192.168.50.0 0.0.0.255 destination 192.168.60.0 0.0.0.255

Rule 20 deny ip source 192.168.50.0 0.0.0.255 destination 192.168.70.0 0.0.0.255

Rule 30 deny ip source 192.168.50.0 0.0.0.255 destination 192.168.80.0 0.0.0.255

Rule 40 deny ip source 192.168.50.0 0.0.0.255 destination 192.168.90.0 0.0.0.255

Acl 3060

Rule 10 deny ip source 192.168.60.0 0.0.0.255 destination 192.168.50.0 0.0.0.255

Rule 20 deny ip source 192.168.60.0 0.0.0.255 destination 192.168.70.0 0.0.0.255

Rule 30 deny ip source 192.168.60.0 0.0.0.255 destination 192.168.80.0 0.0.0.255

Rule 40 deny ip source 192.168.60.0 0.0.0.255 destination 192.168.90.0 0.0.0.255

Acl 3070

Rule 10 deny ip source 192.168.70.0 0.0.0.255 destination 192.168.50.0 0.0.0.255

Rule 20 deny ip source 192.168.70.0 0.0.0.255 destination 192.168.60.0 0.0.0.255

Rule 30 deny ip source 192.168.70.0 0.0.0.255 destination 192.168.80.0 0.0.0.255

Rule 40 deny ip source 192.168.70.0 0.0.0.255 destination 192.168.90.0 0.0.0.255

Acl 3080

Rule 10 deny ip source 192.168.80.0 0.0.0.255 destination 192.168.50.0 0.0.0.255

Rule 20 deny ip source 192.168.80.0 0.0.0.255 destination 192.168.60.0 0.0.0.255

Rule 30 deny ip source 192.168.80.0 0.0.0.255 destination 192.168.70.0 0.0.0.255

Rule 40 deny ip source 192.168.80.0 0.0.0.255 destination 192.168.90.0 0.0.0.255

Acl 3090

Rule 10 deny ip source 192.168.90.0 0.0.0.255 destination 192.168.50.0 0.0.0.255

Rule 20 deny ip source 192.168.90.0 0.0.0.255 destination 192.168.60.0 0.0.0.255

Rule 30 deny ip source 192.168.90.0 0.0.0.255 destination 192.168.70.0 0.0.0.255

Rule 40 deny ip source 192.168.90.0 0.0.0.255 destination 192.168.80.0 0.0.0.255

#写acl规则

Int g0/0/2

Traffic-filter inbound acl 3000

Int g0/0/3

Traffic-filter inbound acl 3001

Int g0/0/4

Traffic-filter inbound acl 3002

Int g0/0/5

Traffic-filter inbound acl 3003

#把acl应用到各接口

路由器

Vlan 200

Int vlan 200

Ip add 192.168.1.1 24

Int e0/0/1

Port link-type access

Port default vlan 200

#建立与核心交换机的连接

ip route-static 192.168.8.0 255.255.252.0 192.168.1.2

ip route-static 192.168.50.0 255.255.255.0 192.168.1.2

ip route-static 192.168.60.0 255.255.255.0 192.168.1.2

ip route-static 192.168.70.0 255.255.255.0 192.168.1.2

ip route-static 192.168.80.0 255.255.255.0 192.168.1.2

ip route-static 192.168.90.0 255.255.255.0 192.168.1.2

建立与各vlan的连接

vlan 10

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 10

interface GigabitEthernet0/0/2

port link-type access

port default vlan 10

vlan 50

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 50

interface GigabitEthernet0/0/2

port link-type access

port default vlan 50

vlan 60

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 60

interface GigabitEthernet0/0/2

port link-type access

port default vlan 60

vlan 70

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 70

interface GigabitEthernet0/0/2

port link-type access

port default vlan 70

vlan 80

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 80

interface GigabitEthernet0/0/2

port link-type access

port default vlan 80

vlan 90

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 90

interface GigabitEthernet0/0/2

port link-type access

port default vlan 90

  • 1
    点赞
  • 4
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值