看着老板不在,抓紧时间赶出来的,匆匆忙忙的,有点不太好,请大家多指教!!!(此实验删除了上面实验的标准ACL)
R1:
interface FastEthernet0/1
ip address 192.168.2.1 255.255.255.0
ip access-group 100 in
duplex auto
speed auto
access-list 100 permit tcp 192.168.2.0 0.0.0.255 host 2.2.2.2 eq www
access-list 100 permit tcp 192.168.2.0 0.0.0.255 host 10.1.1.2 eq www
access-list 100 permit tcp 192.168.2.0 0.0.0.255 host 2.2.2.2 eq telnet
access-list 100 permit tcp 192.168.2.0 0.0.0.255 host 10.1.1.2 eq telnet
R4:
interface FastEthernet0/0
ip address 192.168.3.1 255.255.255.0
ip access-group 101 in
duplex auto
speed auto
access-list 101 deny icmp 192.168.3.0 0.0.0.255 host 2.2.2.2
access-list 101 deny icmp 192.168.3.0 0.0.0.255 host 10.1.2.1
access-list 101 permit ip any any
转载于:https://blog.51cto.com/canglang/412025