ACL技术报告

实验拓扑

  • 实验需求
  1. 全网互通;
  2. PC1可以访问Telnet R1,不能ping R1
  3. PC1不能访问Telnet R2,但可以ping R2
  4. PC2和PC1相反
  • 实验步骤
  1. 配置IP。

[Huawei]sys

[Huawei]sysname pc1

[pc1]int g0/0/0

[pc1-GigabitEthernet0/0/0]ip add 192.168.1.10 24

[pc1]ip rou

[pc1]ip route

[pc1]ip route-static 0.0.0.0 0 192.168.1.254

[Huawei]sys

[Huawei]sysname pc2

[pc2]int g0/0/0

[pc2-GigabitEthernet0/0/0]ip add 192.168.1.11 24

[pc2]ip rou

[pc2]ip route

[pc2]ip route-static 0.0.0.0 0 192.168.1.254

[Huawei]sys

[Huawei]sysname R1

[R1]int g0/0/0

[R1-GigabitEthernet0/0/0]ip add 192.168.1.1 24

[R1]int g0/0/1

[R1-GigabitEthernet0/0/1]ip add 192.168.2.1 24

[R2]int g0/0/0

[R2-GigabitEthernet0/0/0]ip add 192.168.2.2 24

[R2]ip rou

[R2]ip route

[R2]ip route-static 192.168.1.0 24 192.168.2.1

  1. 、配置Telnet

[R1]aaa

[R1-aaa]lo

[R1-aaa]local-user wangdaye pri

[R1-aaa]local-user wangdaye privilege l

[R1-aaa]local-user wangdaye privilege level 15 pa

[R1-aaa]local-user wangdaye privilege level 15 password ci

[R1-aaa]local-user wangdaye privilege level 15 password cipher wdy12345

Info: Add a new user.

[R1-aaa]lo

[R1-aaa]local-user wangdaye se

[R1-aaa]local-user wangdaye service-type te

[R1-aaa]local-user wangdaye service-type telnet

[R1-aaa]

[R1-aaa]

[R1-aaa]

[R1-aaa]quit

[R1]us

[R1]user-group

[R1]user-interface vty 0 4

[R1-ui-vty0-4]au

[R1-ui-vty0-4]authentication-mode aaa

[R1-ui-vty0-4]quit

[R2]aaa

[R2-aaa]lo

[R2-aaa]local-user zhangdaye pri

[R2-aaa]local-user zhangdaye privilege l

[R2-aaa]local-user zhangdaye privilege level 15 pa

[R2-aaa]local-user zhangdaye privilege level 15 password se

[R2-aaa]local-user zhangdaye privilege level 15 password ci

[R2-aaa]local-user zhangdaye privilege level 15 password cipher zdy12345

Info: Add a new user.

[R2-aaa]lo

[R2-aaa]local-user zhangdaye se

[R2-aaa]local-user zhangdaye service-type te

[R2-aaa]local-user zhangdaye service-type telnet

[R2-aaa]quit

[R2]us

[R2]user-group

[R2]user-interface vty 0 4

[R2-ui-vty0-4]au

[R2-ui-vty0-4]authentication-mode aaa

[R2-ui-vty0-4]quit

配置ACL

[R1]acl 3000

[R1-acl-adv-3000]

[R1-acl-adv-3000]

[R1-acl-adv-3000]rule deny?

  deny  Specify matched packet deny

[R1-acl-adv-3000]rule deny ?

  <1-255>  Protocol number

  gre      GRE tunneling(47)

  icmp     Internet Control Message Protocol(1)

  igmp     Internet Group Management Protocol(2)

  ip       Any IP protocol

  ipinip   IP in IP tunneling(4)

  ospf     OSPF routing protocol(89)

  tcp      Transmission Control Protocol (6)

  udp      User Datagram Protocol (17)

[R1-acl-adv-3000]rule deny icmp sou

[R1-acl-adv-3000]rule deny icmp source 192.168.1.10 0.0.0.0 dest

[R1-acl-adv-3000]rule deny icmp source 192.168.1.10 0.0.0.0 destination 192.168.

1.254 0.0.0.0

[R1-acl-adv-3000]rule deny icmp source 192.168.1.10 0.0.0.0 destination 192.168.

2.1 0.0.0.0

[R1-acl-adv-3000]rule deny ?

  <1-255>  Protocol number

  gre      GRE tunneling(47)

  icmp     Internet Control Message Protocol(1)

  igmp     Internet Group Management Protocol(2)

  ip       Any IP protocol

  ipinip   IP in IP tunneling(4)

  ospf     OSPF routing protocol(89)

  tcp      Transmission Control Protocol (6)

  udp      User Datagram Protocol (17)

[R1-acl-adv-3000]rule deny tcp so

[R1-acl-adv-3000]rule deny tcp source 192.168.1.10 0.0.0.0 desrt

[R1-acl-adv-3000]rule deny tcp source 192.168.1.10 0.0.0.0 dest

[R1-acl-adv-3000]rule deny tcp source 192.168.1.10 0.0.0.0 destination 192.168.2

.2 0.0.0.0 de

[R1-acl-adv-3000]rule deny tcp source 192.168.1.10 0.0.0.0 destination 192.168.2

.2 0.0.0.0 destination-port eq 23

[R1-acl-adv-3000]rule deny tcp so

[R1-acl-adv-3000]rule deny tcp source192.168.1.11 0.0.0.0 dest

[R1-acl-adv-3000]rule deny tcp source192.168.1.11 0.0.0.0 dest

[R1-acl-adv-3000]rule deny tcp source 192.168.1.11 0.0.0.0 dest

[R1-acl-adv-3000]rule deny tcp source 192.168.1.11 0.0.0.0 destination 192.168.1

.254 0.0.0.0 de

[R1-acl-adv-3000]rule deny tcp source 192.168.1.11 0.0.0.0 destination 192.168.1

.254 0.0.0.0 destination-port eq 23

[R1-acl-adv-3000]rule deny tcp source 192.168.1.11 0.0.0.0 destination 192.168.

2.1 0.0.0.0 destination-port eq 23

[R1-acl-adv-3000]rule deny icmp 192.168.1.11 0.0.0.0 dest

[R1-acl-adv-3000]rule deny icmp so                    

      

[R1-acl-adv-3000]rule deny icmp source 192.168.1.11 0.0.0.0 dest

[R1-acl-adv-3000]rule deny icmp source 192.168.1.11 0.0.0.0 destination 192.168.

2.2 0.0.0.0

 

配置入口

[R1-acl-adv-3000]

[R1-acl-adv-3000]quit

[R1]int g0/0/0

[R1-GigabitEthernet0/0/0]tr

[R1-GigabitEthernet0/0/0]tracert

[R1-GigabitEthernet0/0/0]traffic-filter in

[R1-GigabitEthernet0/0/0]traffic-filter inbound  acl 3000

[R1-GigabitEthernet0/0/0]quit

检测

  • 18
    点赞
  • 24
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值