要求:PC1不能访问服务器,PC2可以。
1、配置ACL及服务器的网关及IP地址(已写在拓扑上)
2、验证网络的互通性
PC1>ping 200.1.1.1
Ping 200.1.1.1: 32 data bytes, Press Ctrl_C to break
Request timeout!
From 200.1.1.1: bytes=32 seq=2 ttl=254 time=16 ms
From 200.1.1.1: bytes=32 seq=3 ttl=254 time=16 ms
From 200.1.1.1: bytes=32 seq=4 ttl=254 time=15 ms
From 200.1.1.1: bytes=32 seq=5 ttl=254 time<1 ms
--- 200.1.1.1 ping statistics ---
5 packet(s) transmitted
4 packet(s) received
20.00% packet loss
round-trip min/avg/max = 0/11/16 ms
PC2>ping 200.1.1.1
Ping 200.1.1.1: 32 data bytes, Press Ctrl_C to break
From 200.1.1.1: bytes=32 seq=1 ttl=254 time=15 ms
From 200.1.1.1: bytes=32 seq=2 ttl=254 time=16 ms
From 200.1.1.1: bytes=32 seq=3 ttl=254 time=16 ms
From 200.1.1.1: bytes=32 seq=4 ttl=254 time<1 ms
From 200.1.1.1: bytes=32 seq=5 ttl=254 time=15 ms
--- 200.1.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 0/12/16 ms
3、在路由器R1配置acl规则
acl number 2000
rule 5 deny source 192.168.1.0 0.0.0.255
rule 10 permit
4、将acl规则应用到g0/0/0端口上
interface GigabitEthernet0/0/0
ip address 192.168.1.254 255.255.255.0
traffic-filter inbound acl 2000
验证:
PC2>ping 200.1.1.1
Ping 200.1.1.1: 32 data bytes, Press Ctrl_C to break
From 200.1.1.1: bytes=32 seq=1 ttl=254 time=15 ms
From 200.1.1.1: bytes=32 seq=2 ttl=254 time=16 ms
From 200.1.1.1: bytes=32 seq=3 ttl=254 time=16 ms
From 200.1.1.1: bytes=32 seq=4 ttl=254 time=15 ms
From 200.1.1.1: bytes=32 seq=5 ttl=254 time<1 ms
--- 200.1.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 0/12/16 ms
PC1>ping 200.1.1.1
Ping 200.1.1.1: 32 data bytes, Press Ctrl_C to break
Request timeout!
Request timeout!
Request timeout!
Request timeout!
Request timeout!
--- 200.1.1.1 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
实验成功。