ACL的最后会隐藏一条deny any
接口下只能应用一条ACL序列号
标准ACL配置命令:
access-list 1 deny 10.1.1.1
access-list 1 deny host 10.1.1.1
access-list 1 deny 10.1.1.1 0.0.0.0
access-list 1 permit any
int f0/0
ip access-group 1 in/out
扩展ACL配置命令:
access-list 100 permit ip host 10.1.1.1 host 20.1.1.1
int f0/0
ip access-group 100 in/out
删除ACL:
no access-list 100
int f0/0
no ip access-group 100 in/out
查看ACL :show access-lists /show run /show run int f0/0
ACL的作用:抓取所匹配网段,控制流量能否通过
标准ACL:离目的设备越近越好(ACL的命令所写的位置)
扩展ACL:离源设备越近越好