网络拓扑图:
相关配置:
所有子网掩码:255.255.255.0
HostA: 10.1.1.1
GW: 10.1.1.2
HostB: 10.1.2.1
GW: 10.1.2.2
RouteA:
[RouteA]int e0
[RouteA-Ethernet0/0]ip addr 10.1.2.2 255.255.255.0
[RouteA-Ethernet0/0]undo shut
[RouteA-Ethernet0/0]int s0
[RouteA-Serial0/1]ip addr 10.1.3.1 255.255.255.0
[RouteA-Serial0/1]undo shut
[RouteA-Serial0/1]quit
[RouteA]ospf
[RouteA-ospf-1]area 0
[RouteA-ospf-1-area-0.0.0.0]network 10.1.2.0 0.0.0.255
[RouteA-ospf-1-area-0.0.0.0]network 10.1.3.0 0.0.0.255
[RouteA-ospf-1-area-0.0.0.0]quit
[RouteA]acl 100
[RouteA-acl-100]rule deny source any destination any
[RouteA-acl-100]quit
[RouteA]firewall enable
[RouteA]firewall default enable
[RouteA]int e0
[RouteA-Ethernet0/0]firewall packet-filter 100 inbound
[RouteA-Ethernet0/0]quit
RouteB:
[RouteB]int e0
[RouteB-Ethernet0/0]ip addr 10.1.1.1 netmask 255.255.255.0
[RouteB-Ethernet0/0]undo shut
[RouteB-Ethernet0/0]int s0
[RouteB-Serial0/0]ip addr 10.1.3.1 netmask 255.255.255.0
[RouteB-Serial0/0]undo shut
[RouteB-Serial0/0]quit
[RouteB]ospf
[RouteB-ospf-1]area 0
[RouteB-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
[RouteB-ospf-1-area-0.0.0.0]network 10.1.3.0 0.0.0.255
[RouteB-ospf-1-area-0.0.0.0]quit
[RouteB]acl 200
[RouteB-acl-200]rule permit source any destination any
[RouteB-acl-200]quit
[RouteB]firewall enable
[RouteB]firewall permit enable
[RouteB]int s0
[RouteB-Serial0/0]firewall packet-filter 200 outbound
[RouteB-Serial0/0]quit
[RouteB]
实验结果:
HostB ping HostA 不通
HostA ping HostB 通