|
发表于 2018-12-8 17:22:33
|
显示全部楼层
HI,
先說一下 Router套用 ACL的in跟out觀念
下方這段是您提供的,
access-list 100 permit ip 192.168.1.0 0.0.0.255 host 172.16.10.5
access-list 100 deny ip 192.168.1.0 0.0.0.255 host 10.1.1.5
access-list 100 permit ip any any
f0/2/0 ip access-group 100 in
f0/2/0 ip access-group 100 in
表示當ACL 100 套用在Router Fa 0/2/0 in的方向時,
如果有 packet 從Fa0/2/0 進入Router 的話會用ACL 100進行過濾,
例如我想讓Packet進入Fa0/2/0時ˊ進行ACL過濾,
那我會打Fa0/2/0 ip access-group 100 in
如果我想讓Packet離開Fa0/2/0時進行ACL過濾,
我會打Fa0/2/0 ip access-group 100 out
ACL 100中
access-list 100 permit ip 192.168.1.0 0.0.0.255 host 172.16.10.5
access-list 100 permit ip 來源IP 目的IP
進入Fa0/2/0的IP只會有172.16.10.5,
所以來源IP是172.16.10.5,
目的IP要打10.1.1.5或192.168.1.5
例如:
ACL 200
access-list 200 permit ip host 172.16.10.5 host 10.1.1.5
access-list 200 permit ip host 172.16.10.5 host 192.168.1.5
Fa0/2/0 ip access-group 100 in
依照你Topology的要求
PC1 ping PC2 ->通
PC2 ping PC1 ->不通
PC3 ping PC1 ->不通
....
我的設定如下,供您參考
ip access-list extended F010_IN
permit icmp host 192.168.1.5 host 172.16.10.5 echo
permit icmp host 192.168.1.5 host 10.1.1.5 echo-reply
deny ip any any
ip access-list extended F020_IN
permit icmp host 172.16.10.5 host 10.1.1.5 echo
permit icmp host 172.16.10.5 host 192.168.1.5 echo-reply
deny ip any any
ip access-list extended F030_IN
permit icmp host 10.1.1.5 host 192.168.1.5 echo
permit icmp host 10.1.1.5 host 172.16.10.5 echo-reply
deny ip any any
interface Fa0/1/0
ip address 192.168.1.1 255.255.255.0
ip access-group F010_IN in
!
interface Fa0/2/0
ip address 172.16.10.1 255.255.255.0
ip access-group F020_IN in
!
interface Fa0/3/0
ip address 10.1.1.1 255.255.255.0
ip access-group F030_IN in
icmp echo 表示ping 過去的方向
icmp echo-replay 表示ping回來的方向
因為ping是雙向的
ping 過去 (echo)
對方會回應我(echo-replay)
|
11#
2018-12-8 17:22:33
回复(0)
收起回复
|