1.通过给接口配ip地址,书写静态路由使全网连通
pc1:sys pc2:sys
int g 0/0/0 int g 0/0/0
ip add 192.168.1.10 24 192.168.1.11 24
AR1:sys AR2:sys
int g 0/0/0 int g 0/0/0
ip add 192.168.1.1 24 ip add 192.168.2.2 24
int g 0/0/1
ip add 192.168.2.1 24
pc1静态:
ip route-static 192.168.2.0 24 192.168.1.1
pc2静态:
ip route-static 192.168.2.0 24 192.168.1.1
r2静态:
ip route-static 192.168.1.0 24 192.168.2.1
pc1能telnet r1:
[r1]aaa
[r1-aaa]local-user zz privilege level 15 password cipher 123456
[r1-aaa]local-user zz service-type telnet
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mode aaa
pc1不能ping r1:
[r1]acl 3000
[r1-acl-adv-3000]rule deny ip source 192.168.1.10 0.0.0.0 destination 192.168.1.
1 0.0.0.0
[r1]int g 0/0/0
[r1-GigabitEthernet0/0/0]traffic-filter inbound acl 3000
pc1能ping r2:
pc1不能telent r2:
[r2]acl 3001
[r2-acl-adv-3001]rule deny tcp source 192.168.1.10 0.0.0.0 destination 192.168.2
.2 0.0.0.0 destination-port eq 23
[r2-GigabitEthernet0/0/0]traffic-filter inbound acl 3001
pc2能telnet r2:
[r2]aaa
[r2-aaa]local-user zz privilege level 15 password cipher 123456
[r2-aaa]local-user zz service-type telnet
[r2]user-interface vty 0 4
[r2-ui-vty0-4]authentication-mode aaa
pc2不能ping r2:
[r2]acl 3010
[r2-acl-adv-3010]rule deny ip source 192.168.1.11 0.0.0.0 destination 192.168.2.
2 0.0.0.0
[r2-GigabitEthernet0/0/0]traffic-filter inbound acl 3010
pc2不能telent r1:
[r1]acl 3009
[r1-acl-adv-3009]rule deny tcp source 192.168.1.11 0.0.0.0 destination 192.168.1
.1 0.0.0.0 destination-port eq 23
[r1-GigabitEthernet0/0/0]traffic-filter inbound acl 3009
pc2能ping r1: