信息屏蔽和远程登陆
要求
1.PC1不能ping通PC2,但PC2可以ping通PC1
2.R1可以ping通R3但不能登陆R3
3.R3可以登陆R1但不能ping通R1
简单配置并且OSPF宣告
[R1]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.1 24
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 12.1.1.1 24
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 1.1.1.1 32
[Huawei]ospf 100 router-id 1.1.1.1
[Huawei-ospf-100]area 0
[Huawei-ospf-100-area-0.0.0.0]network 0.0.0.0 255.255.255.255
PC1不能ping通PC2,但PC2可以ping通PC1
在R1上设置只能回包不能发送包
[R1]acl 3000
[Huawei-acl-adv-3000]rule deny icmp source 192.168.1.2 0.0.0.0 destination 182.1
68.1.2 0.0.0.0 icmp-type echo
[Huawei-acl-adv-3000]rule permit ip source any destination any
[Huawei-acl-adv-3000]quit
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]traffic-filter inbound acl 3000
[Huawei-GigabitEthernet0/0/1]quit
R1可以ping通R3但不能登陆R3
在R3上开启远程控制权限,在R2上断开R1登陆R3权限
1.在R3开启远程登陆设置
[R3]telnet server enable //打开远程登陆服务
[Huawei]aaa //创建aaa
[Huawei-aaa]local-user xx privilege level 15 password cipher huawei //将远程登陆等级化为最高权限15
[Huawei-aaa]quit
[Huawei]user-interface vty 0 4 //vty 虚拟线路 0 4 远程登陆最多可以同时登陆5个路由器
[Huawei-ui-vty0-4]authentication-mode aaa//调用aaa
2.在R2上禁止R1远程登陆R3
[R2]acl 3000
[Huawei-acl-adv-3000]rule deny tcp source 12.1.1.1 0.0.0.0 destination 23.1.1.2
0.0.0.0 destination-port eq telnet
[Huawei-acl-adv-3000]rule permit ip source any destination any
[Huawei]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]traffic-filter inbound acl 3000
3.R1可以ping通但不能访问,R2可以远程登陆
R3可以登陆R1但不能ping通R1
1.在R1开启远程登陆设置
[R1]telnet server enable
[Huawei]aaa
[Huawei-aaa]local-user yy privilege level 15 password cipher 123
Info: Add a new user.
[Huawei-aaa]quit
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]au
[Huawei-ui-vty0-4]authentication-mode aaa
[Huawei-ui-vty0-4]quit
2.在R2上禁止R3通往R1上的发送包
[R2]acl 3001
[Huawei-acl-adv-3001]rule deny icmp source 23.1.1.2 0.0.0.0 destination 12.1.1.1
0.0.0.0 icmp-type echo
[Huawei-acl-adv-3001]rule permit ip source any destination any
[Huawei-acl-adv-3001]quit
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]traffic-filter inbound acl 3001
[Huawei-GigabitEthernet0/0/1]quit
3.结果