Ä¿¡¡Â¼
1.8 ÉèÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©
1.15.7 »ùÓÚʱ¼ä¶ÎµÄACL¹æÔòÉèÖþÙÀý
1.15.9 ACL±¨ÎļÆÊýͳ¼ÆÉèÖþÙÀý
ACL£¨Access Control List£¬£¬£¬£¬£¬£¬£¬»á¼û¿ØÖÆÁÐ±í£©Ò²³ÆÎª»á¼ûÁÐ±í£¬£¬£¬£¬£¬£¬£¬ÓеÄÎĵµÖл¹³ÆÖ®Îª°ü¹ýÂË¡£¡£¡£¡£¡£¡£¡£ACLͨ¹ý½ç˵һϵÁаüÀ¨¡°ÔÊÐí¡±»ò¡°¾Ü¾ø¡±µÄ¹æÔòÓï¾ä£¬£¬£¬£¬£¬£¬£¬²¢½«ÕâЩ¹æÔòÓ¦Óõ½×°±¸½Ó¿ÚÉÏ£¬£¬£¬£¬£¬£¬£¬¶ÔÊÕÖ§½Ó¿ÚµÄÊý¾Ý°ü¾ÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÌáÉýÍøÂç×°±¸µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£
ÉèÖÃACLÄܹ»°ü¹ÜÍøÂçÇå¾²¡¢¿É¿¿ºÍÎȹ̣¬£¬£¬£¬£¬£¬£¬ÀýÈ磺
l ±ÜÃⱨÎĹ¥»÷£ºÕë¶ÔIP¡¢TCP»òÕßICMP±¨ÎĵĹ¥»÷£¬£¬£¬£¬£¬£¬£¬¶ÔÕâЩ¹¥»÷±¨ÎÄ×ö¡°¾Ü¾ø¡±´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£
l ÍøÂç»á¼û¿ØÖÆ£ºÏÞÖÆÓû§»á¼û·þÎñ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÖ»ÔÊÐí»á¼ûWWWºÍµç×ÓÓʼþ·þÎñ£¬£¬£¬£¬£¬£¬£¬ÆäËû·þÎñÈçTelnetÔòեȡ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»òÕßÖ»ÔÊÐíÔÚ¸ø¶¨µÄʱ¼ä¶ÎÄÚ»á¼û£¬£¬£¬£¬£¬£¬£¬»òÕßÖ»ÔÊÐíÌØ¶¨Ö÷ʱ»ú¼ûÍøÂçµÈ¡£¡£¡£¡£¡£¡£¡£
l ÍøÂçÁ÷Á¿¿ØÖÆ£ºÍŽáQoS¿ÉÒÔΪÖ÷ÒªµÄÊý¾ÝÁ÷¾ÙÐÐÓÅÏÈ·þÎñ°ü¹Ü¡£¡£¡£¡£¡£¡£¡£¹ØÓÚQoSµÄÉèÖÃÇë°Ý¼û¡°QoS¡±¡£¡£¡£¡£¡£¡£¡£
l »á¼ûÁбí
»á¼ûÁбíÓУº»ù±¾»á¼ûÁбíºÍ¶¯Ì¬»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£
Óû§¿ÉÒÔÆ¾Ö¤ÐèҪѡÔñ»ù±¾»á¼ûÁбí»ò¶¯Ì¬»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£Ò»Ñùƽ³£ÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Ê¹Óûù±¾»á¼ûÁбíÒѾÄܹ»Öª×ãÇå¾²ÐèÒª¡£¡£¡£¡£¡£¡£¡£µ«¹¥»÷Õß¿ÉÄÜͨ¹ýÈí¼þð³äÔ´µØµãÓկװ±¸£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»á¼ûÍøÂç¡£¡£¡£¡£¡£¡£¡£¶ø¶¯Ì¬»á¼ûÁбíÔÚÓû§»á¼ûÍøÂçÒÔǰ£¬£¬£¬£¬£¬£¬£¬ÒªÇóͨ¹ýÉí·ÝÈÏÖ¤£¬£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄÑÒÔ»á¼ûÍøÂç¡£¡£¡£¡£¡£¡£¡£ÔÚÃô¸ÐÇøÓò¿ÉÒÔʹÓö¯Ì¬»á¼ûÁбí°ü¹ÜÍøÂçÇå¾²¡£¡£¡£¡£¡£¡£¡£
˵Ã÷
ͨ¹ýð³äÔ´µØµãÓկװ±¸¼´µç×ÓÓÕÆÊÇËùÓлá¼ûÁбí¹ÌÓеÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬Ê¹Óö¯Ì¬ÁбíÒ²»áÔâÓöµç×ÓÓÕÆÎÊÌ⣺¹¥»÷Õß¿ÉÄÜÔÚÓû§Í¨¹ýÉí·ÝÈÏÖ¤µÄÓÐÓûá¼ûʱ´ú£¬£¬£¬£¬£¬£¬£¬Ã°³äÓû§µÄµØµã»á¼ûÍøÂç¡£¡£¡£¡£¡£¡£¡£½â¾ö¸ÃÎÊÌâµÄÒªÁìÓÐÁ½ÖÖ£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖÊÇÖ»¹ÜÉèÖøü¶ÌµÄÓû§»á¼û¿ÕÏÐʱ¼ä£»£»£»£»£»ÁíÒ»ÖÖÊÇʹÓÃIPsec¼ÓÃÜÐÒé¶ÔÍøÂçÊý¾Ý¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬È·±£½øÈë×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬ËùÓеÄÊý¾Ý¶¼ÊǼÓÃܵġ£¡£¡£¡£¡£¡£¡£
»á¼ûÁбíÒ»Ñùƽ³£ÉèÖÃÔÚÒÔÏÂλÖõÄÍøÂç×°±¸ÉÏ£º
¡ð ÄÚ²¿ÍøºÍÍâ²¿Íø£¨ÈçInternet£©Ö®¼äµÄ×°±¸
¡ð Á½¸öÍøÂç½ÓÈÀ²¿·ÖµÄ×°±¸
¡ð ½ÓÈë¿ØÖÆ¶Ë¿ÚµÄ×°±¸
ACE£¨Access Control Entry£¬£¬£¬£¬£¬£¬£¬»á¼û¿ØÖÆÌõÄ¿£©ÊǰüÀ¨¡°ÔÊÐí£¨Permit£©¡±»ò¡°¾Ü¾ø£¨Deny£©¡±Á½ÖÖÐж¯£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°¹ýÂ˹æÔòµÄÒ»ÌõÓï¾ä¡£¡£¡£¡£¡£¡£¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ£¬£¬£¬£¬£¬£¬£¬¸ÃÐòºÅ¿ÉÓÉ×°±¸×Ô¶¯·ÖÅÉ»òÕßÊÖ¶¯ÉèÖᣡ£¡£¡£¡£¡£¡£Ò»ÌõACLÖаüÀ¨Ò»¸ö»òÕß¶à¸öACE¡£¡£¡£¡£¡£¡£¡£ACLͨ¹ýACE¶ÔÊý¾Ý°ü¾ÙÐбêʶ¹ýÂË¡£¡£¡£¡£¡£¡£¡£
ACLÖÐACEµÄ˳Ðò¾öÒéÁ˸ÃACEÔÚ»á¼ûÁбíÖÐµÄÆ¥ÅäÓÅÏȼ¶¡£¡£¡£¡£¡£¡£¡£ÍøÂç×°±¸ÔÚ´¦Öóͷ£±¨ÎÄʱ£¬£¬£¬£¬£¬£¬£¬°´ACEµÄÐòºÅ´ÓСµ½´ó¾ÙÐйæÔòÆ¥Å䣬£¬£¬£¬£¬£¬£¬µ±ÕÒµ½Æ¥ÅäµÄACEºóÔò×èÖ¹¼ì²éºóÐøµÄACE¡£¡£¡£¡£¡£¡£¡£
ÀýÈ罨ÉèÒ»ÌõÐòºÅΪ10µÄACE£¬£¬£¬£¬£¬£¬£¬Ëü¾Ü¾øËùÓеÄÊý¾ÝÁ÷ͨ¹ý¡£¡£¡£¡£¡£¡£¡£
10 deny ip any any
20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
ÓÉÓÚÐòºÅΪ10µÄACE¾Ü¾øÁËËùÓеÄIP±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬×ÝÈ»192.168.12.0/24ÍøÂçµÄÖ÷»úTelnet±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ±»ÐòºÅΪ20µÄACEÆ¥Å䣬£¬£¬£¬£¬£¬£¬¸Ã±¨ÎÄÒ²½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ×°±¸ÔÚ¼ì²éµ½±¨ÎĺÍÐòºÅΪ10µÄACEÆ¥Åäºó£¬£¬£¬£¬£¬£¬£¬±ã×èÖ¹¼ì²éºóÃæÐòºÅΪ20µÄACE¡£¡£¡£¡£¡£¡£¡£
ÓÖÀýÈ罨ÉèÒ»Ìõ±àºÅΪ10µÄACE£¬£¬£¬£¬£¬£¬£¬ËüÔÊÐíËùÓеÄIPv6Êý¾ÝÁ÷ͨ¹ý¡£¡£¡£¡£¡£¡£¡£
10 permit ipv6 any any
20 deny ipv6 host 200::1 any
ÓÉÓÚÐòºÅΪ10µÄACEÔÊÐíËùÓеÄIPv6±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬Ö÷»ú200::1·¢³öµÄIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬×ÝȻƥÅäÐòºÅΪ20µÄACE£¬£¬£¬£¬£¬£¬£¬¸Ã±¨ÎÄÒ²½«±»ÔÊÐíͨ¹ý¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ×°±¸ÔÚ¼ì²éµ½±¨Îĺ͵ÚÒ»ÌõACEÆ¥Å䣬£¬£¬£¬£¬£¬£¬±ã×èÖ¹¼ì²éºóÃæÐòºÅΪ20µÄACE¡£¡£¡£¡£¡£¡£¡£
l ²½³¤
µ±×°±¸ÎªACE×Ô¶¯·ÖÅÉÐòºÅʱ£¬£¬£¬£¬£¬£¬£¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ£¬£¬£¬£¬£¬£¬£¬³ÆÎª²½³¤¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬ÈôÊǽ«²½³¤É趨Ϊ5£¬£¬£¬£¬£¬£¬£¬Ôò×°±¸Æ¾Ö¤5¡¢10¡¢15¡ÕâÑùµÄµÝÔö˳Ðò×Ô¶¯ÎªACE·ÖÅÉÐòºÅ¡£¡£¡£¡£¡£¡£¡£ÈçÏÂËùʾ¡£¡£¡£¡£¡£¡£¡£
5 deny ip any any
10 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
µ±²½³¤¸Ä±äºó£¬£¬£¬£¬£¬£¬£¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤ÖµÖØÐ·ÖÅÉ¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬µ±°Ñ²½³¤¸ÄΪ10ºó£¬£¬£¬£¬£¬£¬£¬ÔÀ´ACEÐòºÅ´Ó5¡¢10¡¢15Äð³É5¡¢15¡¢25¡£¡£¡£¡£¡£¡£¡£
ͨ¹ý¸Ä±ä²½³¤¿ÉÒÔÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£¡£¡£¡£¡£¡£¡£ÀýÈ罨ÉèÁË4¸öACE£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÊÖ¶¯ÉèÖÃACEÐòºÅ»®·ÖΪ1¡¢2¡¢3ºÍ4¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÏ£ÍûÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÏȽ«²½³¤ÐÞ¸ÄΪ2£¬£¬£¬£¬£¬£¬£¬´ËʱÔÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7£¬£¬£¬£¬£¬£¬£¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÉèÖõÄÐòºÅΪ2µÄACE¡£¡£¡£¡£¡£¡£¡£
l ¹ýÂËÓòÄ£°å
¹ýÂËÓòÖ¸µÄÊÇÌìÉúÒ»ÌõACEʱ£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎľÙÐÐʶ±ð¡¢·ÖÀà¡£¡£¡£¡£¡£¡£¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£¡£¡£¡£¡£¡£¡£ACEƾ֤ÒÔÌ«Íø±¨ÎĵÄijЩ×Ö¶ÎÀ´±êʶÒÔÌ«Íø±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÕâЩ×ֶΰüÀ¨£º
¶þ²ã×ֶΣ¨Layer 2 Fields£©£º
¡ð 48λµÄÔ´MACµØµã£¨±ØÐè˵Ã÷ËùÓÐ48룩
¡ð 48λµÄÄ¿µÄMACµØµã£¨±ØÐè˵Ã÷ËùÓÐ48룩
¡ð 16λµÄ¶þ²ãÀàÐÍ×Ö¶Î
Èý²ã×ֶΣ¨Layer 3 Fields£©£º
¡ð Ô´IPµØµã×ֶΣ¨¿ÉÒÔ˵Ã÷ËùÓÐÔ´IPµØµãÖµ£¬£¬£¬£¬£¬£¬£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©
¡ð Ä¿µÄIPµØµã×ֶΣ¨¿ÉÒÔ˵Ã÷ËùÓÐÄ¿µÄIPµØµãÖµ£¬£¬£¬£¬£¬£¬£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©
¡ð ÐÒéÀàÐÍ×Ö¶Î
ËIJã×ֶΣ¨Layer 4 Fields£©£º
¡ð ¿ÉÒÔ˵Ã÷Ò»¸öTCPµÄÔ´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú»òÕß¶¼ËµÃ÷£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔ˵Ã÷Ô´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚµÄ¹æÄ£¡£¡£¡£¡£¡£¡£¡£
¡ð ¿ÉÒÔ˵Ã÷Ò»¸öUDPµÄÔ´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú»òÕß¶¼ËµÃ÷£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔ˵Ã÷Ô´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚµÄ¹æÄ£¡£¡£¡£¡£¡£¡£¡£
ÀýÈ磬£¬£¬£¬£¬£¬£¬ÔÚ½¨ÉèÒ»ÌõACEʱÐèҪƾ֤±¨ÎĵÄÄ¿µÄIP×ֶΣ¬£¬£¬£¬£¬£¬£¬¶Ô±¨ÎľÙÐÐʶ±ðºÍ·ÖÀà¡£¡£¡£¡£¡£¡£¡£¶øÔÚ½¨ÉèÁíÒ»ÌõACEʱ£¬£¬£¬£¬£¬£¬£¬ÐèҪƾ֤±¨ÎĵÄÔ´IPµØµã×ֶκÍUDPµÄÔ´¶Ë¿Ú×ֶΣ¬£¬£¬£¬£¬£¬£¬¶Ô±¨ÎľÙÐÐʶ±ðºÍ·ÖÀà¡£¡£¡£¡£¡£¡£¡£ÕâÁ½ÌõACE¾ÍʹÓÃÁ˲î±ðµÄ¹ýÂËÓòÄ£°å¡£¡£¡£¡£¡£¡£¡£
l ¹æÔò
¹æÔò£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬Ò»ÌõACEµÄÄÚÈÝÈçÏ£º
10 permit tcp host 192.168.12.2 any eq telnet
ÔÚÕâÌõACEÖУ¬£¬£¬£¬£¬£¬£¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεÄÜöÝÍ£ºÔ´IPµØµã×ֶΡ¢Ä¿µÄIPµØµã×ֶΡ¢IPÐÒé×ֶΡ¢TCPÄ¿µÄ¶Ë¿Ú×ֶΡ£¡£¡£¡£¡£¡£¡£¶ÔÓ¦µÄÖµ£¨¼´¹æÔò£©»®·ÖΪ£ºÔ´IPµØµãΪHost 192.168.12.2¡¢Ä¿µÄIPµØµãΪAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPÐÒéΪTCP¡¢TCPÄ¿µÄ¶Ë¿ÚΪTelnet¡£¡£¡£¡£¡£¡£¡£Èçͼ1-1Ëùʾ¡£¡£¡£¡£¡£¡£¡£
ͼ1-1 ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄÆÊÎö
˵Ã÷
¡ñ ¹ýÂËÓòÄ£°å¿ÉÒÔÊÇÈý²ã×ֶΣ¨Layer 3 Field£©ºÍËIJã×ֶΣ¨Layer 4 Field£©µÄÜöÝÍ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÊǶà¸ö¶þ²ã×ֶΣ¨Layer 2 Field£©µÄÜöÝÍ¡£¡£¡£¡£¡£¡£¡£µ«±ê×¼ÓëÀ©Õ¹ACLµÄ¹ýÂËÓòÄ£°å²»¿ÉÊǶþ²ãºÍÈý²ã×ֶΡ¢¶þ²ãºÍËIJã×ֶΡ¢¶þ²ãºÍÈý²ã×ֶΡ¢ËIJã×ֶεÄÜöÝÍ¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹Óöþ²ã¡¢Èý²ã¡¢ËIJã×Ö¶ÎÜöÝÍ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓÃר¼Ò¼¶À©Õ¹»á¼û¿ØÖÆÁÐ±í¡£¡£¡£¡£¡£¡£¡£
¡ñ ³öÆ«ÏòACL¹ØÁªSVI½Ó¿Ú£¨Switch Virtual Interface£¬£¬£¬£¬£¬£¬£¬½»Á÷×°±¸ÐéÄâ½Ó¿Ú£©µÄ×¢ÖØÊÂÏ֧³ÖIP±ê×¼¡¢IPÀ©Õ¹¡¢MACÀ©Õ¹ºÍר¼Ò¼¶ACLÓ¦Óᣡ£¡£¡£¡£¡£¡£
¡ñ ÈôÊÇÔÚMACÀ©Õ¹ºÍר¼Ò¼¶ACLÖÐÆ¥ÅäÄ¿µÄMAC£¬£¬£¬£¬£¬£¬£¬½«ÕâÑùµÄACLÓ¦Óõ½SVI½Ó¿ÚµÄ³öÆ«Ïòʱ£¬£¬£¬£¬£¬£¬£¬±íÏî»á±»ÉèÖ㬣¬£¬£¬£¬£¬£¬µ«ÎÞ·¨ÉúЧ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÏëÒªÔÚIPÀ©Õ¹£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶ACLÖÐÆ¥ÅäÄ¿µÄIP£¬£¬£¬£¬£¬£¬£¬¶øÄ¿µÄIP²»ÔÚËù¹ØÁªµÄSVI½Ó¿ÚµÄ×ÓÍøIP¹æÄ£ÄÚʱ£¬£¬£¬£¬£¬£¬£¬ÉèÖõÄACL½«ÎÞ·¨ÉúЧ¡£¡£¡£¡£¡£¡£¡£ÀýÈçVLAN 1µÄµØµãΪ192.168.64.1 255.255.255.0£¬£¬£¬£¬£¬£¬£¬½¨ÉèÒ»ÌõIPÀ©Õ¹µÄACL£¬£¬£¬£¬£¬£¬£¬ACEΪdeny udp any 192.168.65.1 0.0.0.255 eq 255£¬£¬£¬£¬£¬£¬£¬½«¸ÃACLÓ¦Óõ½VLAN 1µÄ³ö¿Ú£¬£¬£¬£¬£¬£¬£¬½«ÎÞ·¨ÉúЧ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÄ¿µÄIP²»ÔÚVLAN 1×ÓÍøIP¹æÄ£ÄÚ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACEΪdeny udp any 192.168.64.1 0.0.0.255 eq 255½«¿ÉÒÔÉúЧ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÄ¿µÄIPÇкϻ®¶¨¡£¡£¡£¡£¡£¡£¡£
¡ñ ÓÉÓÚACL×ÊÔ´£¨TCAM/KEY/¶Ë¿Ú×é/RangeµÈ£©Êô¶¯Ì¬·ÖÅÉ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬¼´ÓªÒµÏ·¢Ê±Õ½ÂÔÕûºÏ×ÊÔ´Ä£¿£¿£¿£¿£¿£¿éƾ֤Ŀ½ñµÄACL×ÊÔ´ÇéÐξÙÐзÖÅÉ£¬£¬£¬£¬£¬£¬£¬Ïȵ½µÄÓªÒµÏÈ·ÖÅÉACL×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ºóµ½µÄÓªÒµÈôÊÇACL×ÊÔ´²»·ó¾Í»á±£´æACL×ÊÔ´·ÖÅÉʧ°Ü£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐѹýʧsyslog¡£¡£¡£¡£¡£¡£¡£×°±¸ÖØÆôÀú³Ì»òÈȰβåµÈ´¥·¢Êý¾Ýͬ²½µÄÀú³Ì£¬£¬£¬£¬£¬£¬£¬¸÷ÓªÒµÎÞ·¨°ü¹Ü°´ÔÀ´µÄʱÐò½«ÓªÒµÍ¬²½£¬£¬£¬£¬£¬£¬£¬ÓпÉÄÜ´¥·¢ÓÉÓÚӪҵʱÐò·×ÆçÑùµ¼ÖÂÔ±¾¿ÉÒÔ·ÖÅɵ½ACL×ÊÔ´µÄÓªÒµ·ÖÅɲ»µ½ACL×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ACL×ÊԴȱ·¦»áÌáÐѹýʧsyslog¡£¡£¡£¡£¡£¡£¡£
²úÆ·/°æ±¾Ö§³ÖÇéÐÎ
¡ñ ×÷ÓÃÔÚÎïÀí¿ÚºÍÈý²ã¾ÛºÏ½Ó¿ÚÉϵijöÆ«ÏòACL£¬£¬£¬£¬£¬£¬£¬½öÖ§³ÖÆ¥Åä×ÅÃû±¨ÎÄ£¨µ¥²¥¡¢×é²¥£©£¬£¬£¬£¬£¬£¬£¬²»Ö§³ÖÆ¥Åäδ×ÅÃûµ¥²¥£¬£¬£¬£¬£¬£¬£¬¼´¹ØÓÚδ×ÅÃû±¨ÎÄ»òÕ߹㲥±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚÉÏÉèÖõijöÆ«ÏòACL²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
¡ñ ÈëÆ«ÏòACLºÍ802.1x£¬£¬£¬£¬£¬£¬£¬È«¾ÖIPºÍMAC°ó¶¨£¬£¬£¬£¬£¬£¬£¬¶Ë¿ÚÇå¾²£¬£¬£¬£¬£¬£¬£¬IP Source Guard¹²ÓÃʱ£¬£¬£¬£¬£¬£¬£¬PermitºÍĬÈÏDenyµÄACE²»ÉúЧ£¬£¬£¬£¬£¬£¬£¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ¡£¡£¡£¡£¡£¡£¡£
¡ñ ÈëÆ«ÏòACLºÍQoS¹²ÓÃʱ£¬£¬£¬£¬£¬£¬£¬Permit±íÏîµÄACE²»ÉúЧ£¬£¬£¬£¬£¬£¬£¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ£»£»£»£»£»Ä¬ÈÏDeny±íÏîµÄACEÔÚQoS±íÏîºóÉúЧ¡£¡£¡£¡£¡£¡£¡£
¡ñ ÓÉÓÚÓ²¼þÈÝÁ¿µÄÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬×÷ÓÃÔÚ¶à¸öSVI½Ó¿ÚµÄÈëÆ«ÏòACL£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÔÙÌí¼ÓACE£¬£¬£¬£¬£¬£¬£¬ÉúÑÄÉèÖÃÖØÆôºó¿ÉÄܵ¼Ö²¿·ÖSVI½Ó¿ÚÉϵÄACLÎÞ·¨ÉèÖÃÀֳɡ£¡£¡£¡£¡£¡£¡£
˵Ã÷
¡ñ µ±ÉèÖÃר¼Ò¼¶µÄACL£¬£¬£¬£¬£¬£¬£¬²¢Ó¦ÓÃÔڽӿڵijöÆ«Ïòʱ£¬£¬£¬£¬£¬£¬£¬ÈôÊǸÃACLÖеÄijЩACE°üÀ¨Èý²ãÆ¥ÅäÐÅÏ¢£¨ÀýÈçIP£¬£¬£¬£¬£¬£¬£¬L4portµÈ£©£¬£¬£¬£¬£¬£¬£¬½«µ¼Ö´ÓÓ¦ÓýӿڽøÈëµÄ·ÇIP±¨ÎÄÎÞ·¨ÊܸÃACLµÄPermitºÍDeny¹æÔò¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£
¡ñ Ó¦ÓÃACLʱ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL£¨°üÀ¨IP ACLºÍר¼Ò¼¶À©Õ¹ACL£©ÖеÄACEÆ¥ÅäÁ˷Ƕþ²ã×ֶΣ¬£¬£¬£¬£¬£¬£¬ÀýÈçÔ´IP£¬£¬£¬£¬£¬£¬£¬Ä¿µÄIPʱ£¬£¬£¬£¬£¬£¬£¬¹ØÓÚ´ø±êÇ©µÄMPLS±¨ÎÄÆ¥ÅäÊÇÎÞЧµÄ¡£¡£¡£¡£¡£¡£¡£
IP ACLÖ÷ÒªÓÃÓÚ¶ÔÊÕÖ§×°±¸µÄIPv4±¨ÎľÙÐÐϸÄ廯¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÆ¾Ö¤ÏÖʵÐèÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
ÔÚIP ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬²¢½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ¶ÔIP ACL¾ÙÐÐÈ«¾ÖÓ¦Óᣡ£¡£¡£¡£¡£¡£µ±IPv4±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸Í¨¹ýÅжϱ¨ÎÄÊÇ·ñÓë¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
ÒªÔÚ×°±¸ÉÏÉèÖÃIP ACL£¬£¬£¬£¬£¬£¬£¬±ØÐèΪ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãΨһ±êʶÿ¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£
IP ACL·ÖΪIP±ê×¼ACLºÍIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£±í1-1ÁгöÁËIP±ê×¼ACLºÍIPÀ©Õ¹ACL¿ÉÒÔʹÓõıàºÅ¹æÄ£¡£¡£¡£¡£¡£¡£¡£
±í1-1 IP±ê×¼ACLºÍIPÀ©Õ¹ACL±àºÅ¹æÄ£
|
ÀàÐÍ |
±àºÅ¹æÄ£ |
Æ¥ÅäÓò |
|
IP±ê×¼ACL |
1~99£¬£¬£¬£¬£¬£¬£¬1300~1999 |
Ô´IPµØµã |
|
IPÀ©Õ¹ACL |
100~199£¬£¬£¬£¬£¬£¬£¬2000~2699 |
¡ñ Ô´IPµØµã ¡ñ Ä¿µÄIPµØµã ¡ñ IPÐÒéºÅ ¡ñ ËIJãÔ´¶Ë¿ÚºÅ»òICMP type ¡ñ ËIJãÄ¿µÄ¶Ë¿ÚºÅ»òICMP code |
IP±ê×¼ACLÖ÷Ҫƾ֤ԴIPµØµã¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£IPÀ©Õ¹ACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓòµÄ×éºÏ£¬£¬£¬£¬£¬£¬£¬¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚ¼òµ¥µÄ»á¼ûÁбíÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓöàÌõ×ÔÁ¦µÄ»á¼ûÁбíÓï¾äÀ´½ç˵¶àÖÖ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬£¬£¬£¬£¬£¬£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£
˵Ã÷
ACL¹æÔòÖеÄICMP codeÆ¥ÅäÓò¶ÔICMP typeΪ3µÄICMP±¨ÎÄÎÞЧ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇACL¹æÔòÖÐÉèÖÃÁËҪƥÅäICMP±¨ÎĵÄcode×ֶΣ¬£¬£¬£¬£¬£¬£¬µ±TypeΪ3µÄICMP±¨ÎĽøÈë×°±¸Ö´ÐÐACLÆ¥Åäʱ£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäЧ¹û¿ÉÄÜÓëÔ¤ÆÚµÄ·×ÆçÑù¡£¡£¡£¡£¡£¡£¡£
ÿ¸öIP ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔòÓï¾ä¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º
access-list 1 permit host 192.168.4.12
´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ192.168.4.12µÄ±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÆäËüÖ÷»ú¶¼½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º
access-list 1 deny any
ÓÖÀýÈ磺
access-list 1 deny host 192.168.4.12
ÈôÊÇÁбíÖ»°üÀ¨ÒÔÉÏÕâÒ»ÌõÓï¾ä£¬£¬£¬£¬£¬£¬£¬ÔòÈκÎÖ÷»ú±¨ÎÄͨ¹ý¸Ã½Ó¿Úʱ¶¼½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£
×¢ÖØ
ÔÚ½ç˵»á¼ûÁбíµÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬ÒªË¼Á¿µ½Â·Óɸüеı¨ÎÄ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ»á¼ûÁбíĩβ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂËùÓеÄ·Óɸüб¨Îı»×è¶Ï¡£¡£¡£¡£¡£¡£¡£
MACÀ©Õ¹ACL»ùÓÚ±¨ÎĵĶþ²ãÐÅÏ¢À´¶ÔÊÕÖ§×°±¸µÄ±¨ÎľÙÐÐϸÄ廯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔÆ¾Ö¤ÏÖʵÐèÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖƱ£»£»£»£»£»¤ÍøÂç×ÊÔ´²»Êܹ¥»÷»òÕß¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
ÔÚMACÀ©Õ¹ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£µ±±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸Åжϱ¨ÎÄÊÇ·ñÓë¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
ÒªÔÚ×°±¸ÉÏÉèÖÃMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬±ØÐèΪ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãΨһ±êʶÿ¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£±í1-2ÁгöMACÀ©Õ¹ACLµÄ±àºÅ¹æÄ£¡£¡£¡£¡£¡£¡£¡£
±í1-2 MACÀ©Õ¹ACL±àºÅ¹æÄ£
|
ÐÒé |
±àºÅ¹æÄ£ |
Æ¥ÅäÓò |
|
MACÀ©Õ¹ACL |
700~799 |
¡ñ Ô´MACµØµã ¡ñ Ä¿µÄMACµØµã ¡ñ ÒÔÌ«ÍøÐÒéÀàÐÍ |
MACÀ©Õ¹ACLƾ֤Դ»òÄ¿µÄMACµØµãÒÔ¼°±¨ÎĵÄÒÔÌ«ÍøÀàÐÍÀ´¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚ¼òµ¥µÄMACÀ©Õ¹ACLÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓöàÌõ×ÔÁ¦µÄ»á¼ûÁбíÓï¾äÀ´½ç˵¶àÖÖ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬£¬£¬£¬£¬£¬£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£
˵Ã÷
ÈôÊÇMACÀ©Õ¹ACL¹æÔòÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλò½ç˵µÄÒÔÌ«ÍøÀàÐÍ×Ö¶ÎÖµ²»ÊÇ0x86dd£¬£¬£¬£¬£¬£¬£¬ÄÇôMACÀ©Õ¹ACL²»Æ¥ÅäIPv6±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÇëʹÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
ÿ¸öMACÀ©Õ¹ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔòÓï¾ä¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º
access-list 700 permit host 00d0.f800.0001 any
´ËÁбíÖ»ÔÊÐíÀ´×ÔMACµØµãΪ00d0.f800.0001µÄÖ÷»ú·¢³öµÄ±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬À´×ÔÆäËüÖ÷»úµÄ±¨Îͼ½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º
access-list 700 deny any any
ר¼Ò¼¶À©Õ¹ACL»ùÓÚ±¨ÎĵĶþ²ãºÍÈý²ãÐÅÏ¢¶ÔÊÕÖ§×°±¸µÄ±¨ÎľÙÐÐϸÄ廯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔ½«×¨¼Ò¼¶À©Õ¹ACL¿´×÷ÊÇIP ACLºÍMACÀ©Õ¹ACLµÄÒ»ÖÖÍŽáÓëÔöÇ¿¡£¡£¡£¡£¡£¡£¡£×¨¼Ò¼¶À©Õ¹ACLÖеĹæÔò²»µ«¿ÉÒÔ°üÀ¨IP ACL¹æÔòºÍMACÀ©Õ¹ACL¹æÔò£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÖ¸¶¨»ùÓÚVLAN IDÀ´Æ¥Å䱨ÎÄ¡£¡£¡£¡£¡£¡£¡£
ÔÚר¼Ò¼¶À©Õ¹ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬²¢½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸¾Í»áͨ¹ýÅжϱ¨ÎÄÊÇ·ñÓë»á¼û¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
ÒªÔÚ×°±¸ÉÏÉèÖÃר¼Ò¼¶À©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬±ØÐèΪÐÒéµÄ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÔÚÐÒéÄÚ²¿Äܹ»Î¨Ò»±êʶÿ¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£±í1-3Áгöר¼Ò¼¶À©Õ¹ACLµÄ±àºÅ¹æÄ£¡£¡£¡£¡£¡£¡£¡£
±í1-3 ר¼Ò¼¶À©Õ¹ACLµÄ±àºÅ¹æÄ£
|
ÐÒé |
±àºÅ¹æÄ£ |
Æ¥ÅäÓò |
|
ר¼Ò¼¶À©Õ¹ACL |
2700~2899 |
¡ñ Ô´IPµØµã ¡ñ Ä¿µÄIPµØµã ¡ñ IPÐÒéºÅ ¡ñ ËIJãÔ´¶Ë¿ÚºÅ»òICMP type ¡ñ ËIJãÄ¿µÄ¶Ë¿ÚºÅ»òICMP code ¡ñ Ô´MACµØµã ¡ñ Ä¿µÄMACµØµã ¡ñ ÒÔÌ«ÍøÐÒéÀàÐÍ ¡ñ VLAN ID |
ר¼Ò¼¶À©Õ¹ACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓò¾ÙÐÐ×éºÏ£¬£¬£¬£¬£¬£¬£¬¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚ¼òµ¥µÄר¼Ò¼¶À©Õ¹ACLÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓöàÌõ×ÔÁ¦µÄ»á¼ûÁбíÓï¾äÀ´½ç˵¶àÖÖ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐËùÓеÄÓï¾äÐèÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬£¬£¬£¬£¬£¬£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£
˵Ã÷
ÈôÊÇר¼Ò¼¶À©Õ¹ACL¹æÔòÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλòÒÔÌ«ÍøÀàÐÍ×ֶβ»ÊÇ0x86dd£¬£¬£¬£¬£¬£¬£¬ÄÇôר¼Ò¼¶À©Õ¹ACL²»Æ¥ÅäIPv6±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÇëʹÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
²úÆ·/°æ±¾Ö§³ÖÇéÐÎ
¡ñ
Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©Õ¹ACLÖУ¬£¬£¬£¬£¬£¬£¬VXLAN×Ö¶ÎÑ¡ÏîÖ÷ÒªÊÇΪÁËÆ¥ÅäVXLANµÄÄڲ㱨ÎÄ£¬£¬£¬£¬£¬£¬£¬Òò´ËVXLANģʽÏ¿ÉÒÔÓ¦ÓÃר¼Ò¼¶ACLÆ¥ÅäVXLANµÄÄÚ²ãIP×ֶΡ£¡£¡£¡£¡£¡£¡£
¡ñ µ±×°±¸ÐèҪƥÅäVXLAN±¨ÎÄʱ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÖ¸¶¨VXLANÐÒéÄ¿µÄ¶Ë¿ÚºÅÓÃÓÚÈ·ÈÏVXLAN±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±¿ÉÒÔÖ¸¶¨Æ¥Åä¸ÃVXLAN±¨ÎÄÊÇ·ñЯ´øTag¡£¡£¡£¡£¡£¡£¡£
²úÆ·/°æ±¾Ö§³ÖÇéÐÎ
Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©Õ¹ACLÖÐUDFÑ¡ÏîÊÇÓû§×Ô½ç˵×Ö¶ÎÆ¥ÅäÓò£¬£¬£¬£¬£¬£¬£¬ÓÉÓû§Ö¸¶¨ÐèҪƥÅäµÄÐÒé²ã¡¢Æ«ÒÆÖµ¡¢Êý¾ÝºÍÑÚÂë¡£¡£¡£¡£¡£¡£¡£
ÿ¸öר¼Ò¼¶À©Õ¹ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±¹æÔòÓï¾ä¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º
access-list 2700 permit 0x0806 any any any any any
´ËÁбíÖ»ÔÊÐíÒÔÌ«ÍøÀàÐÍΪ0x0806£¨¼´ARP£©µÄ±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÆäËûÀàÐ͵ı¨Îͼ½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º
access-list 2700 deny any any any any
IPv6 ACLÖ÷ÒªÓÃÓÚ¶ÔÊÕÖ§×°±¸µÄIPv6±¨ÎľÙÐÐϸÄ廯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔÆ¾Ö¤ÏÖʵÐèÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPv6Óû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
ÔÚIPv6 ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬²¢½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£µ±IPv6±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸Åжϱ¨ÎÄÊÇ·ñÓë¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
ÒªÔÚ×°±¸ÉÏÉèÖûá¼ûÁÐ±í£¬£¬£¬£¬£¬£¬£¬±ØÐèΪÐÒéµÄ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£
ÿ¸öIPv6 ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐIPv6Êý¾ÝÁ÷¡±¹æÔòÓï¾ä£¬£¬£¬£¬£¬£¬£¬Òò´ËÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º
ipv6 access-list ipv6_acl
?10 permit ipv6 host 200::1 any
´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ200::1µÄIPv6±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÆäËüÖ÷»ú·¢³öµÄIPv6±¨Îͼ½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º
deny ipv6 any any
ר¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬¼´ACL80£¬£¬£¬£¬£¬£¬£¬Ò²³ÆÎª×Ô½ç˵ACL¡£¡£¡£¡£¡£¡£¡£ACL80Ö§³Ö¶Ô±¨ÎĵÄǰ80¸ö×Ö½ÚÖеÄÖ¸¶¨×Ö½Ú°´±ÈÌØÎ»¾ÙÐÐÆ¥Åä¡£¡£¡£¡£¡£¡£¡£
ACL80Æ¥ÅäʱÓÐÈý¸öÒªËØ£ºÆ¥ÅäÓòÄÚÈÝ¡¢Æ¥ÅäÓòÑÚÂëÒÔ¼°Æ¥ÅäµÄÆðʼλÖ㨼´Æ«ÒÆÁ¿offset£©¡£¡£¡£¡£¡£¡£¡£Æ¥ÅäÓòÄÚÈÝºÍÆ¥ÅäÓòÑÚÂëÁ½ÕߵıÈÌØÎ»ÊÇÖðÒ»¶ÔÓ¦µÄ¡£¡£¡£¡£¡£¡£¡£Æ¥ÅäÓòÄÚÈÝÖ¸Ã÷ÐèҪƥÅäµÄ×Ö¶ÎÖµ£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂëÖ¸Ã÷¶ÔÓ¦±ÈÌØÎ»ÊÇ·ñÐèҪƥÅä¡£¡£¡£¡£¡£¡£¡£µ±ÐèҪƥÅäij¸ö±ÈÌØÎ»Ê±£¬£¬£¬£¬£¬£¬£¬±ØÐ轫ƥÅäÓòÑÚÂëÖжÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ1¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÆ¥ÅäÓòÑÚÂë¶ÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ0£¬£¬£¬£¬£¬£¬£¬ÎÞÂÛÆ¥ÅäÓòÄÚÈÝÖжÔÓ¦µÄ±ÈÌØÎ»ÊÇʲô£¬£¬£¬£¬£¬£¬£¬¶¼²»»áÆ¥Åä¡£¡£¡£¡£¡£¡£¡£ÀýÈ磺
10 permit 00d0f8123456 ffffffffffff 0
20 deny 00d0f8654321 ffffffffffff 6
ÔÚÐòºÅΪ10µÄACEÖУ¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8123456£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂëΪffffffffffff£¬£¬£¬£¬£¬£¬£¬Æ«ÒÆÁ¿Îª0¡£¡£¡£¡£¡£¡£¡£ÕâÌõ¹æÔòÌåÏÖÈôÊDZ¨ÎĵÄÄ¿µÄMACΪ00d0f8123456£¬£¬£¬£¬£¬£¬£¬ÔòÔÊÐí±¨ÎÄת·¢¡£¡£¡£¡£¡£¡£¡£
ÔÚÐòºÅΪ20µÄACEÖУ¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8654321£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂëΪffffffffffff£¬£¬£¬£¬£¬£¬£¬Æ«ÒÆÁ¿Îª6¡£¡£¡£¡£¡£¡£¡£ÕâÌõ¹æÔòÌåÏÖÈôÊDZ¨ÎĵÄÔ´MACΪ00d0f8654321£¬£¬£¬£¬£¬£¬£¬Ôò×è¶Ï¸Ã±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
׼ȷʹÓÃ×Ô½ç˵»á¼û¿ØÖÆÁбíÐèÒª¶Ô¶þ²ãÊý¾ÝÖ¡½á¹¹ÓÐÉîÈëµÄÏàʶ¡£¡£¡£¡£¡£¡£¡£¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâÈçͼ1-2Ëùʾ¡£¡£¡£¡£¡£¡£¡£Í¼ÖÐÿ¸ö×Öĸ´ú±íÒ»¸öÊ®Áù½øÖÆÊý£¬£¬£¬£¬£¬£¬£¬Ã¿Á½¸ö×Öĸ´ú±íÒ»¸ö×Ö½Ú¡£¡£¡£¡£¡£¡£¡£
ͼ1-2 ¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâͼ

¸÷¸ö×ÖĸµÄ¼ÄÒå¼°Æ«ÒÆÁ¿È¡ÖµÈç±í1-4Ëùʾ¡£¡£¡£¡£¡£¡£¡£
|
×Öĸ |
¼ÄÒå |
Æ«ÒÆÁ¿ |
×Öĸ |
¼ÄÒå |
Æ«ÒÆÁ¿ |
|
A |
Ä¿µÄMAC |
0 |
O |
TTL×Ö¶Î |
34 |
|
B |
Ô´MAC |
6 |
P |
ÐÒéºÅ |
35 |
|
C |
VLAN Tag×Ö¶Î |
12 |
Q |
IPУÑéºÍ |
36 |
|
D |
Êý¾ÝÖ¡³¤¶È×Ö¶Î |
16 |
R |
Ô´IPµØµã |
38 |
|
E |
DSAP(Ä¿µÄ·þÎñ»á¼ûµã)×Ö¶Î |
18 |
S |
Ä¿µÄIPµØµã |
42 |
|
F |
SSAP(Ô´·þÎñ»á¼ûµã)×Ö¶Î |
19 |
T |
TCPÔ´¶Ë¿Ú |
46 |
|
G |
Ctrl×Ö¶Î |
20 |
U |
TCPÄ¿µÄ¶Ë¿Ú |
48 |
|
H |
Org Code×Ö¶Î |
21 |
V |
ÐòÁкŠ|
50 |
|
I |
·â×°µÄÊý¾ÝÀàÐÍ |
24 |
W |
È·ÈÏ×Ö¶Î |
54 |
|
J |
IP°æ±¾ºÅ |
26 |
XY |
IPÍ·³¤¶ÈºÍ±£´æ±ÈÌØÎ» |
58 |
|
K |
TOS×Ö¶Î |
27 |
Z |
±£´æ±ÈÌØÎ»ºÍFlags±ÈÌØÎ» |
59 |
|
L |
IP°üµÄ³¤¶È |
28 |
a |
Windows Size×Ö¶Î |
60 |
|
M |
IDºÅ |
30 |
b |
ÆäËû |
62 |
|
N |
Flags×Ö¶Î |
32 |
|
|
|
±íÖи÷¸ö×Ö¶ÎµÄÆ«ÒÆÁ¿ÊÇËüÃÇÔÚSNAP£«TagµÄ802.3Êý¾ÝÖ¡ÖÐµÄÆ«ÒÆÁ¿¡£¡£¡£¡£¡£¡£¡£ÔÚ×Ô½ç˵»á¼û¿ØÖÆÁбíÖУ¬£¬£¬£¬£¬£¬£¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿£¬£¬£¬£¬£¬£¬£¬´ÓÊý¾ÝÖ¡µÄǰ80¸ö×Ö½ÚÖÐÌáȡָ¶¨×Ö½Ú£¬£¬£¬£¬£¬£¬£¬ÔÙºÍÆ¥ÅäÓòÄÚÈݽÏÁ¿£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¶Ô±¨ÎÄ×÷ÏìÓ¦µÄ´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬Óû§ÔÊÐíËùÓеÄTCP±¨ÎÄת·¢£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔ½«Æ¥ÅäÓòÄÚÈݽç˵Ϊ¡°06¡±£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂë½ç˵Ϊ¡°ff¡±£¬£¬£¬£¬£¬£¬£¬Æ«ÒÆÁ¿½ç˵Ϊ35¡£¡£¡£¡£¡£¡£¡£½¨ÉèÐòºÅΪ10µÄACEÈçÏ¡£¡£¡£¡£¡£¡£¡£
10 permit 06 ff 35
½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£µ±±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿£¬£¬£¬£¬£¬£¬£¬´ÓÊý¾ÝÖ¡Öн«TCPÐÒéºÅ×ֶεÄÄÚÈÝÌáÈ¡³öÀ´£¬£¬£¬£¬£¬£¬£¬ÔÙºÍÆ¥ÅäÓòÄÚÈݽÏÁ¿£¬£¬£¬£¬£¬£¬£¬Æ¥Åä³öËùÓеÄTCP±¨ÎIJ¢¾ÙÐÐת·¢¡£¡£¡£¡£¡£¡£¡£
ACLÖØ¶¨ÏòµÄ×÷ÓÃÊǽ«ÇкϹæÔòµÄ±¨ÎÄÖØ¶¨ÏòÖÁÖ¸¶¨½Ó¿Úת·¢£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨½Ó¿ÚÉÏץȡ±¨ÎļÓÒÔÆÊÎö¡£¡£¡£¡£¡£¡£¡£
ACLÖØ¶¨ÏòÔÚÖ¸¶¨½Ó¿ÚÉϰ󶨲î±ðµÄACLÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬²¢¸øÃ¿¸öÕ½ÂÔÖ¸¶¨Ò»¸öÊä³ö½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£µ±¸Ã½Ó¿ÚÊÕµ½±¨ÎÄʱ£¬£¬£¬£¬£¬£¬£¬½«ÖðÌõ²éÕÒ°ó¶¨ÔڸýӿÚÉϵÄACLÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÇкÏijÌõÕ½ÂÔÐÎòµÄÌØÕ÷£¬£¬£¬£¬£¬£¬£¬½«´Ó¸ÃÕ½ÂÔËùÖ¸¶¨µÄÊä³ö½Ó¿Úת·¢¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚÍøÂçÖб£´æÖݪֲ¡¶¾±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÇÒ¸÷¶Ë¿ÚϵIJ¡¶¾±¨ÎÄʶ±ðÌØÕ÷Ïàͬ»òÏàËÆ¡£¡£¡£¡£¡£¡£¡£¶Ë¿ÚÇå¾²ACL³£±»ÉèÖÃ×÷Ϊ²¡¶¾±¨ÎĹýÂ˼°Ìá·ÀʹÓ㬣¬£¬£¬£¬£¬£¬ÓÃÓÚ¹ýÂËÇкÏÄ³Ð©ÌØÕ÷µÄ±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÀýÈ磺αÔìµÄTCP¹¥»÷±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£Í¨¹ý½¨ÉèACL²¢Ìí¼ÓÆ¥ÅäÖݪֲ¡¶¾±¨ÎÄÌØÕ÷µÄACEºó£¬£¬£¬£¬£¬£¬£¬½«ACLÓ¦Óõ½×°±¸¸÷¸ö¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬µÖ´ï¹ýÂ˲¡¶¾±¨ÎĵÄ×÷Óᣡ£¡£¡£¡£¡£¡£¶Ë¿ÚÇå¾²ACLÓÃÓÚ²¡¶¾¹ýÂ˵ȿ¹¹¥»÷³¡¾°Ê±£¬£¬£¬£¬£¬£¬£¬±£´æ½Ï¶àδ±ã¡£¡£¡£¡£¡£¡£¡£
l ¶Ë¿ÚÐèÒªÖð¸öÉèÖᣡ£¡£¡£¡£¡£¡£±£´æÖظ´ÉèÖᢲÙ×÷ÐÔÄܵÍϼ°ACL×ÊÔ´Ì«¹ýÏûºÄµÄÇéÐΡ£¡£¡£¡£¡£¡£¡£
l Çå¾²ACLµÄ»á¼û¿ØÖÆ×÷Óñ»Èõ»¯¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ±»ÓÃÓÚ²¡¶¾¹ýÂË£¬£¬£¬£¬£¬£¬£¬Çå¾²ACLµÄÏÞÖÆÂ·ÓɸüС¢ÏÞÖÆÍøÂç»á¼ûµÈ»ù±¾¹¦Ð§ÎÞ·¨Õý³£Ê¹Óᣡ£¡£¡£¡£¡£¡£
È«¾ÖÇå¾²ACL¿ÉÒÔÔÚ²»Ó°Ïì¶Ë¿ÚÇå¾²ACLµÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬¾ÙÐÐÈ«¾Ö¿¹²¡¶¾°²Åż°·ÀÓù¡£¡£¡£¡£¡£¡£¡£È«¾ÖÇå¾²ACLÖ»ÐèÒªÒ»ÌõÏÂÁî¼´ÔÚËùÓжþ²ã½Ó¿ÚÉÏÉúЧ¡£¡£¡£¡£¡£¡£¡£
µ±È«¾ÖÇå¾²ACLÓë¶Ë¿ÚÇå¾²ACLͬʱÉèÖÃʱ£¬£¬£¬£¬£¬£¬£¬Á½ÕßÅäºÏÉúЧ¡£¡£¡£¡£¡£¡£¡£¹ØÓÚÆ¥ÅäÈ«¾ÖÇå¾²ACL¹æÔòµÄ±¨ÎĽ«±»¿´³É²¡¶¾±¨ÎÄÖ±½Ó¹ýÂË£¬£¬£¬£¬£¬£¬£¬¹ØÓÚûÓÐÆ¥ÅäÈ«¾ÖÇå¾²ACL¹æÔòµÄ±¨ÎĽ«¼ÌÐøÊܶ˿ÚÇå¾²ACL¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÏëÈÃijЩ¶Ë¿Ú²»ÊÜÈ«¾ÖÇå¾²ACLµÄ¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÕâЩ½Ó¿ÚÉÏ×ÔÁ¦¹Ø±ÕÈ«¾ÖÇå¾²ACL¹¦Ð§¡£¡£¡£¡£¡£¡£¡£µ±È«¾Ö¡¢½Ó¿ÚºÍVLANµÄÇå¾²ACLͬʱӦÓÃʱ£¬£¬£¬£¬£¬£¬£¬ÓÅÏȼ¶½Ó¿Ú > VLAN > È«¾Ö¡£¡£¡£¡£¡£¡£¡£
ΪÁË×èֹȫ¾ÖÇå¾²ACL±»ÎóÉèÖ㬣¬£¬£¬£¬£¬£¬ÐÂÔöÈ«¾ÖÇå¾²ACLÎÞЧ¿ª¹Ø¡£¡£¡£¡£¡£¡£¡£ÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧºó£¬£¬£¬£¬£¬£¬£¬ÔÙÉèÖÃÈ«¾ÖÇå¾²ACL£¬£¬£¬£¬£¬£¬£¬»áÌáÐÑÉèÖÃʧ°Ü¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÒѾÉèÖÃÁËÈ«¾ÖÇå¾²ACL£¬£¬£¬£¬£¬£¬£¬ÔÙÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧ£¬£¬£¬£¬£¬£¬£¬ÄÇô»á½«Ä¿½ñËùÓÐÈ«¾ÖÇå¾²ACLɾ³ý£¬£¬£¬£¬£¬£¬£¬²¢¸ø³öÈÕÖ¾ÌáÐÑ¡£¡£¡£¡£¡£¡£¡£
Ó¦ÓÃÔÚSVI½Ó¿ÚÉϵĻá¼ûÁÐ±í£¨¼´SVI ACL£©»áͬʱ¶ÔVLANÄÚ¶þ²ãת·¢µÄ±¨Îļ°VLAN¼äµÄ·Óɱ¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂͳһVLANÄÚ²î±ðÓû§Ö®¼äÎÞ·¨Õý³£Í¨Ñ¶µÈÒì³£Õ÷Ï󡣡£¡£¡£¡£¡£¡£Ê¹ÓÃSVI Router ACL¹¦Ð§¿ÉÒÔʹӦÓÃÔÚSVI½Ó¿ÚÉϵĻá¼ûÁбí½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬SVI Router ACL¹¦Ð§Ä¬ÈϹرա£¡£¡£¡£¡£¡£¡£SVI ACLͬʱ¶ÔVLAN¼äµÄÈý²ãת·¢±¨Îļ°VLANÄÚµÄÇÅת·¢±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£SVI Router ACL¹¦Ð§¿ªÆôºó£¬£¬£¬£¬£¬£¬£¬SVI ACL½ö¶ÔVLAN¼äµÄÈý²ãת·¢±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
±¨ÎÄÆ¥ÅäÈÕÖ¾ÓÃÓÚ¼à¿Ø»á¼ûÁÐ±í¹æÔòµÄÔËÐÐ״̬£¬£¬£¬£¬£¬£¬£¬ÎªÒ»Ñùƽ³£ÍøÂçά»¤ÒÔ¼°ÍøÂçÓÅ»¯ÌṩÐëÒªµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ΪÁËÈÃÓû§¸üºÃµÄÕÆÎÕACLÔÚ×°±¸ÖеÄÔËÐÐ״̬£¬£¬£¬£¬£¬£¬£¬ÔÚÌí¼ÓACEʱ¿ÉÒÔÆ¾Ö¤ÐèÒª¾öÒéÊÇ·ñÖ¸¶¨±¨ÎÄÆ¥ÅäÈÕÖ¾Êä³öÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÖ¸¶¨Á˸ÃÑ¡Ï£¬£¬£¬£¬£¬£¬Ôòµ±ACEÆ¥Åäµ½±¨ÎÄʱÊä³öÆ¥ÅäÈÕÖ¾ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ACL»ùÓÚACE´òÓ¡ÈÕÖ¾ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¼´×°±¸ÖÜÆÚÐԵĴòÓ¡Æ¥Å䱨ÎĵÄACEÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Æ¥ÅäµÄ±¨ÎÄÊýÄ¿¡£¡£¡£¡£¡£¡£¡£ÈçÏ£º
*Sep¡¡9 16:23:06: %ACL-6-MATCH: ACL 100 ACE 10 permit icmp any any, match 78 packets.
ΪºÏÀí¿ØÖÆÈÕÖ¾Êä³öµÄÊýÄ¿ºÍƵÂÊ£¬£¬£¬£¬£¬£¬£¬ACLÖ§³ÖÉèÖÃÈÕÖ¾Êä³ö¾àÀëµÄÉèÖᣡ£¡£¡£¡£¡£¡£
×¢ÖØ
¡ñ ´øÈÕ־ѡÏîµÄ»á¼ûÁÐ±í¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐÈÕ־ѡÏ£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£
¡ñ ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖûá¼ûÁÐ±í¹æÔòʱָ¶¨ÁËÈÕ־ѡÏîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
¡ñ ¹ØÓÚ´øÈÕ־ѡÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£
²úÆ·/°æ±¾Ö§³ÖÇéÐÎ
½öÖ§³ÖΪIP ACLºÍIPv6 ACL¹æÔòÉèÖÃÈÕ־ѡÏî¡£¡£¡£¡£¡£¡£¡£
³öÓÚÍøÂçÖÎÀíµÄÐèÒª£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÄÜÏëÖªµÀijÌõ»á¼ûÁÐ±í¹æÔòÊÇ·ñÆ¥Åäµ½±¨ÎÄÒÔ¼°Æ¥ÅäÊýÄ¿¡£¡£¡£¡£¡£¡£¡£ACLÌṩÁË»ùÓÚ¹æÔòµÄ±¨ÎÄÆ¥Å伯Êý¹¦Ð§¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔ»ùÓÚACL¿ªÆôºÍ¹Ø±Õ¸ÃACLϵÄËùÓйæÔòµÄ±¨ÎÄÆ¥Å伯Êý¹¦Ð§¡£¡£¡£¡£¡£¡£¡£µ±Óб¨ÎÄÆ¥Åäµ½ÁËÕâÌõ¹æÔò£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦µÄÆ¥Å伯Êý¾ÍÏìÓ¦µØÔöÌí¡£¡£¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýACLµÄͳ¼ÆÉ¨³ýÏÂÁ¸ÃACLÏÂËùÓйæÔòµÄ±¨ÎÄÆ¥Å伯ÊýÇåÁ㣬£¬£¬£¬£¬£¬£¬ÒÔ±ãÖØÐÂͳ¼Æ¡£¡£¡£¡£¡£¡£¡£
×¢ÖØ
¿ªÆôACLµÄ±¨ÎÄÆ¥Å伯Êý¹¦Ð§ÐèÒª¸ü¶àµÄÓ²¼þ±íÏ£¬£¬£¬£¬£¬£¬¼«¶ËÇéÐÎÏ»áʹװ±¸¿ÉÒÔÉèÖõÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£
²úÆ·/°æ±¾Ö§³ÖÇéÐÎ
ÔÚIP ACL¡¢MACÀ©Õ¹ACL¡¢×¨¼Ò¼¶À©Õ¹ACLºÍIPv6 ACLÉÏ¿ªÆô±¨ÎÄÆ¥Å伯Êý¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇÓû§ÐèÒªÔÚÖ¸¶¨µÄʱ¼ä¶ÎÄÚ¶ÔijЩÁ÷Á¿¾ÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬Õ¥È¡ÔÚÊÂÇéʱ¼äʹÓÃ̸Ì칤¾ß¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔͨ¹ýÉèÖÃACEµÄÉúЧʱ¼ä¶Î£¬£¬£¬£¬£¬£¬£¬¿ØÖÆÁ÷Á¿Í¨¹ýµÄʱ¼ä¡£¡£¡£¡£¡£¡£¡£Ê±¼ä¶Î·ÖΪ¾ø¶Ôʱ¼äºÍÖÜÆÚʱ¼äÁ½ÖÖ¡£¡£¡£¡£¡£¡£¡£
¾ø¶Ôʱ¼äÌåÏÖÒ»¸öÖ¸¶¨Æðʼʱ¼äÒÔ¼°¿¢ÊÂʱ¼äµÄʱ¼äÇø¼ä¡£¡£¡£¡£¡£¡£¡£¸Ãʱ¼äÇø¼ä²»»áÑ»··ºÆð£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÖÜÆÚ¡£¡£¡£¡£¡£¡£¡£ÀýÈç¡°2000Äê1ÔÂ1ÈÕ12£º00£º00ÖÁ2001Äê1ÔÂ1ÈÕ12£º00£º00¡±¡£¡£¡£¡£¡£¡£¡£
ÖÜÆÚʱ¼äÌåÏÖÒ»¸öÖÜÆÚÐÔµÄʱ¼äÇø¼ä¡£¡£¡£¡£¡£¡£¡£ÀýÈ硰ÿÖÜÒ»8£º00µ½Ã¿ÖÜÎå17£º00¡±¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£
ʹÓÃ·ÖÆ¬±¨ÎÄÆ¥Åäģʽ¿ÉÒÔʹ»á¼ûÁбí¶Ô·ÖƬ±¨ÎľÙÐиüϸÄ廯µÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚIP±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÔÚÍøÂç´«ÊäʱÖпÉÄܻᱻ·ÖƬ¡£¡£¡£¡£¡£¡£¡£±¨Îı¬·¢·ÖƬʱ£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐÊׯ¬±¨ÎÄ´øÓÐËIJãÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçTCP»òUDP¶Ë¿ÚºÅ¡¢ICMPÀàÐͺÍICMP±àÂëµÈ£¬£¬£¬£¬£¬£¬£¬ÆäËûµÄ·ÖƬ±¨Îͼ²»´øÓÐÕâЩËIJãÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚĬÈ쵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò´øÓÐFagment±êʶ£¬£¬£¬£¬£¬£¬£¬ÔòÖ»»áÆ¥Åä·ÇÊׯ¬±¨ÎÄ£»£»£»£»£»ÈôÊÇACL¹æÔò²»´øÓÐFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÔòÆ¥ÅäËùÓб¨ÎÄ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Êׯ¬±¨ÎĺͺóÐøµÄËùÓÐ·ÖÆ¬±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£³ýÁËĬÈ쵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÍ⣬£¬£¬£¬£¬£¬£¬»¹ÌṩÁíÒ»ÖÖÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäÒªÁ죬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÆ¾Ö¤ÐèÒªÔÚÖ¸¶¨µÄACLÉϾÙÐÐÇл»¡£¡£¡£¡£¡£¡£¡£ÔÚÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬µ±ACL¹æÔò²»´øÓÐFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÈôÊDZ¨Îı»·ÖƬ£¬£¬£¬£¬£¬£¬£¬Êׯ¬±¨ÎÄ»áÆ¥Å乿ÔòÖÐÓû§½ç˵µÄËùÓÐÆ¥ÅäÓò(°üÀ¨Èý²ãºÍËIJãÐÅÏ¢)£¬£¬£¬£¬£¬£¬£¬¶ø·ÇÊׯ¬±¨ÎÄÔòÖ»»áÆ¥Å乿ÔòÖеķÇËIJãÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
²úÆ·/°æ±¾Ö§³ÖÇéÐÎ
¡ñ ½öÔÚIPÀ©Õ¹ACLºÍר¼Ò¼¶À©Õ¹ACLÉÏÖ§³Ö·ÖƬ±¨ÎÄÆ¥ÅäģʽµÄÇл»¡£¡£¡£¡£¡£¡£¡£
ÔÚijЩӦÓó¡¾°ÖУ¬£¬£¬£¬£¬£¬£¬ÐèÒª°ó¶¨ACLÏÞÖÆÔ´IP¶ÔTCPÎÕÊÖÊ×°ü¾ÙÐд¦Öóͷ££¬£¬£¬£¬£¬£¬£¬¶ø²»Êǽ¨ÉèTCPÅþÁ¬ºóÔÙ¾ÙÐÐÏÞÖÆ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÈ«¾Ö¿ØÖÆÃæACLʵÏÖ½öÈí¼þ¹ýÂË£¬£¬£¬£¬£¬£¬£¬²»µ«¿ÉÒÔïÔ̶ÔÓ²¼þ×ÊÔ´µÄÏûºÄ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÄܹ»Öª×ã¶ÔTCPÊ×°ü¾ÙÐд¦Öóͷ£µÄÐèÇ󡣡£¡£¡£¡£¡£¡£½«Çå¾²ACLͨ¹ý¿ØÖÆÃæÓ¦ÓÃÏÂÁîÓ¦Óõ½È«¾Ö£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ¸ÃACL½öÈí¼þÉúЧ¡£¡£¡£¡£¡£¡£¡£
È«¾Ö¿ØÖÆÃæACLÔÚËùÓжþ²ãÒÔÌ«Íø½Ó¿ÚÉÏÉúЧ£¬£¬£¬£¬£¬£¬£¬ACL±íÏî²»Ó¦Óõ½Ó²¼þ£¬£¬£¬£¬£¬£¬£¬½ö¶ÔÈí¼þÉúЧ£¬£¬£¬£¬£¬£¬£¬´Ó¶øïÔ̶ÔÓ²¼þ×ÊÔ´µÄÏûºÄ£»£»£»£»£»µ±¾ÙÐÐTCPÎÕÊÖʱ£¬£¬£¬£¬£¬£¬£¬Èí¼þACL¶ÔTCPÊ×°ü¾ÙÐмì²é£¬£¬£¬£¬£¬£¬£¬¹ØÓÚÖÀÖÐACLµÄTCP±¨ÎľÙÐйýÂË£¬£¬£¬£¬£¬£¬£¬ÊµÏÖ¶ÔÊ×°ü¹ýÂ˵ÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
˵Ã÷
¡ñ È«¾Ö¿ØÖÆÃæACL½ö¶ÔÈí¼þ¹ýÂËÉúЧ¡£¡£¡£¡£¡£¡£¡£
¡ñ È«¾Ö¿ØÖÆÃæACL²»ÊÜÈ«¾ÖACLÆÆÀý¿ÚÉèÖÃÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬ÉèÖÃÆÆÀý¿ÚºóÈ«¾Ö¿ØÖÆÃæACLÈÔÈ»ÉúЧ
¡ñ È«¾Ö¿ØÖÆÃæACL¿ÉÒÔÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¡£¡£¡£¡£¡£¡£¼´¿ÉÒÔÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£ÔÚSVI½Ó¿ÚºÍ¾ÛºÏ³ÉÔ±½Ó¿ÚÉϲ»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
ACLÉèÖÃʹÃüÈçÏ£º
(1) ÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£ÒÔÏÂÉèÖÃʹÃüÇëÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð
ÉèÖÃIPv6 ACL
(2)
£¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACLÖØ¶¨Ïò
(3)
£¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃÈ«¾ÖÇå¾²ACL
(4)
£¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥Åäģʽ
(5)
£¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃSVI Router ACL
(6) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹ÊÕϻָ´
½¨ÉèºÍÓ¦ÓÃIP±ê×¼ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄIPv4±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÖ»Ïëͨ¹ý¼ì²é±¨ÎĵÄÔ´IPµØµãÀ´¿ØÖÆÓû§µÄÍøÂç×ÊÔ´»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÄÇô¿ÉÒÔÉèÖÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£
l IP±ê×¼ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£IP±ê×¼ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
IP±ê×¼ACLÉèÖÃʹÃüÈçÏ£º
(1)
½¨ÉèIP±ê×¼ACL
(2)
Ó¦ÓÃIP±ê×¼ACL
½¨ÉèIP±ê×¼ACL²¢ÉèÖùæÔò¡£¡£¡£¡£¡£¡£¡£
l IP±ê×¼ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓÐIPv4±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôølogÑ¡ÏîµÄACL¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐlogÑ¡Ï£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£
l ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖÃACL¹æÔòʱָ¶¨ÁËlogÑ¡Ïîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
l ¹ØÓÚ´ølogÑ¡ÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ½¨ÉèIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷ÒýµÄIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
access-list acl-number { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
ip access-list standard { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£
[ sequence-number ] { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IP±ê×¼ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£
(4) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖñ¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀë¡£¡£¡£¡£¡£¡£¡£
ip access-list
log-update interval time-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
(5) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄIP±ê×¼ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄIP±ê×¼ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
list-remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(6) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIP±ê×¼ACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄIP±ê×¼ACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄIP±ê×¼ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(7) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôIP±ê×¼ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
ip access-list counter { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IP±ê×¼ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£
(8) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIP±ê×¼ACL¹æÔò²½³¤¡£¡£¡£¡£¡£¡£¡£
ip access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IP±ê×¼ACL¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬¹æÔòÐòºÅÔöÁ¿ÖµÎª10¡£¡£¡£¡£¡£¡£¡£
½«IP±ê×¼ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹IP±ê×¼ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɶԴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£
(4) ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface vlan interface-number
¡ð ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
vxlan vni-number
(5) ½Ó¿ÚÓ¦ÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£
½¨ÉèºÍÓ¦ÓÃIPÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄIPv4±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÐèҪͨ¹ý¼ì²é±¨ÎĵÄÔ´IPµØµã¡¢Ä¿µÄIPµØµã¡¢±¨ÎĵÄÐÒéºÅ¡¢TCP/UDPÔ´»òÄ¿µÄ¶Ë¿ÚºÅ£¬£¬£¬£¬£¬£¬£¬À´¿ØÖÆÓû§µÄÍøÂç×ÊÔ´»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬¿ÉÉèÖÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
l IPÀ©Õ¹ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉèÖᣡ£¡£¡£¡£¡£¡£IPÀ©Õ¹ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
IPÀ©Õ¹ACLÉèÖÃʹÃüÈçÏ£º
(1)
½¨ÉèIPÀ©Õ¹ACL
(2)
Ó¦ÓÃIPÀ©Õ¹ACL
½¨ÉèIPÀ©Õ¹ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£
l IPÀ©Õ¹ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓÐIPv4±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôølogÑ¡ÏîµÄACL¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐlogÑ¡Ï£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£
l ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖÃACL¹æÔòʱָ¶¨ÁËlogÑ¡Ïîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
l ¹ØÓÚ´ølogÑ¡ÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ½¨ÉèIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷ÒýµÄIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
access-list acl-number { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
ip access-list extended { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
[ sequence-number ] { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPÀ©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£
(4) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£¡£¡£¡£¡£¡£¡£
ip
access-list log-update interval time-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
(5) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPÀ©Õ¹ACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄIPÀ©Õ¹ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄIPÀ©Õ¹ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
list-remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(6) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPÀ©Õ¹ACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄIPÀ©Õ¹ACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(7) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôIPÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
ip access-list counter { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£
(8) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPÀ©Õ¹ACL¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£
ip access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPÀ©Õ¹ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£
½«IPÀ©Õ¹ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹IPÀ©Õ¹ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
(4) ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface vlan interface-number
¡ð ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
vxlan vni-number
(5) ½Ó¿ÚÓ¦ÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
½¨ÉèºÍÓ¦ÓÃMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄ¶þ²ã±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ»ùÓÚ¶þ²ã±¨ÎÄÍ·À´¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÐèҪͨ¹ý¶þ²ã±¨ÎÄÐÅÏ¢£¨ÀýÈçÓû§PCµÄMACµØµã£©£¬£¬£¬£¬£¬£¬£¬À´¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÉèÖÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
l MACÀ©Õ¹ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉèÖᣡ£¡£¡£¡£¡£¡£MACÀ©Õ¹ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
MACÀ©Õ¹ACLÉèÖÃʹÃüÈçÏ£º
(1)
½¨ÉèMACÀ©Õ¹ACL
(2)
Ó¦ÓÃMACÀ©Õ¹ACL
½¨ÉèMACÀ©Õ¹ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£
l MACÀ©Õ¹ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓÐÒÔÌ«Íø¶þ²ã±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ½¨ÉèMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷ÒýµÄMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
access-list acl-number { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
mac access-list extended { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
[ sequence-number ] { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬MACÀ©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£
(4) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
list-remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(5) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(6) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôMACÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
mac access-list counter { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬MACÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£
(7) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©MACÀ©Õ¹ACLµÄ¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£
mac access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬MACÀ©Õ¹ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£
½«MACÀ©Õ¹ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹MACÀ©Õ¹ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
mac access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
(4) ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface vlan interface-number
¡ð ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
vxlan vni-number
(5) ½Ó¿ÚÓ¦ÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
mac access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
½¨ÉèºÍÓ¦ÓÃר¼Ò¼¶À©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄ±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄ±¨ÎĽøÈëÍøÂç¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÐèҪͨ¹ý»ìÏýʹÓÃIP ACL¹æÔò¡¢MACÀ©Õ¹ACL¹æÔòºÍVLAN£¬£¬£¬£¬£¬£¬£¬À´¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÉèÖÃר¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
l ר¼Ò¼¶À©Õ¹ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£×¨¼Ò¼¶À©Õ¹ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
ר¼Ò¼¶À©Õ¹ACLÉèÖÃʹÃüÈçÏ£º
½¨Éèר¼Ò¼¶À©Õ¹ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ר¼Ò¼¶À©Õ¹ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓб¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ½¨Éèר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷ÒýµÄר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
access-list acl-number { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
¡ð ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£
expert access-list extended { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
[ sequence-number ] { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶À©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£
¡ð ½¨Éèר¼Ò¼¶À©Õ¹ACL¼°VXLANÄÚ²ãÎåÔª×鹿Ôò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃר¼Ò¼¶À©Õ¹ACL¼°VXLANÄÚ²ãÎåÔª×鹿Ôò¡£¡£¡£¡£¡£¡£¡£
expert access-list extended { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
[ sequence-number ] { deny | permit } { vxlan | vxlan-ignore-dport } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port ] [ tagged ] [ udp-dport dport ] [ match-all tcp-flag | established ] [ time-range time-range-name ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶À©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£
(4) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number list-remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
list-remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(5) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ΪÊý×ÖË÷ÒýµÄACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
access-list acl-number remark text
¡ð ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(6) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôר¼Ò¼¶ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
expert access-list counter { acl-name | acl-number }
(7) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃר¼Ò¼¶ACLµÄ¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£
expert access-list resequence { acl-name | acl-number
} start-value step-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£
½«×¨¼Ò¼¶À©Õ¹ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹×¨¼Ò¼¶À©Õ¹ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-onlyºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-onlyºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£
expert access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£
(4) ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface vlan interface-number
¡ð ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
vxlan vni-number
(5) Ó¦ÓÃר¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
expert access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃר¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
½¨ÉèºÍÓ¦ÓÃIPv6 ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄIPv6±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPv6Óû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÐèÒª¶ÔIPv6Óû§»á¼ûÍøÂç×ÊÔ´µÄ¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÉèÖÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
l IPv6 ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£IPv6 ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
IPv6 ACLÉèÖÃʹÃüÈçÏ£º
(1)
½¨ÉèIPv6 ACL
(2)
Ó¦ÓÃIPv6 ACL
½¨ÉèIPv6 ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ½¨ÉèIPv6 ACLʱֻÄÜÖ¸ÃüÃû³Æ£¬£¬£¬£¬£¬£¬£¬²»¿ÉÖ¸¶¨±àºÅ¡£¡£¡£¡£¡£¡£¡£
l IPv6 ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬IPv6 ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡³ýND±¨ÎÄÒÔÍâµÄËùÓÐIPv6±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôølogÑ¡ÏîµÄACL¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐlogÑ¡Ï£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£
l ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖÃACL¹æÔòʱָ¶¨ÁËlogÑ¡Ïîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
l ¹ØÓÚ´ølogÑ¡ÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ½¨ÉèIPv6 ACL£¬£¬£¬£¬£¬£¬£¬²¢½øÈëIPv6 ACLÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
ipv6 access-list acl-name
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
(4) ÉèÖÃIPv6 ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ÉèÖÃIPv6 ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
[ sequence-number ] { deny | permit } [ protocol { source-ipv6-prefix / prefix-length | source-ipv6-address source-ipv6-mask | host source-ipv6-address | any } { destination-ipv6-prefix / prefix-length | destination-ipv6-address destination-ipv6-mask | host destination-ipv6-address | any } ] [ cos cos-value [ inner cos-value] ] [ { any | host source-mac-address | source-mac-address source-mac-wildcard } { any | host destination-mac-address | destination-mac-address destination-mac-wildcard } ] [ dscp dscp ] [ flow-label flow-label ] [ fragment ] [ VID [ vlan-id ] [ inner vlan-id ] ] [ udf udf-id header pos value mask ] [ time-range time-range-name ]¡¡[ log ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPv6 ACL±£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£
(5) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£¡£¡£¡£¡£¡£¡£
ipv6
access-list log-update interval time-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
(6) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
list-remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(7) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(8) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôIPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
ipv6 access-list counter acl-name
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£
(9) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPv6 ACLµÄ¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£
ipv6 access-list resequence acl-name start-value step-value
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPv6 ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£
½«IPv6 ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹IPv6 ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬DenyÀàÐ͹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
l µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
ipv6 traffic-filter acl-name { in | out } { control-plane | forward-control-plane | forward-plane }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
(4) ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface vlan interface-number
¡ð ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
vxlan vni-number
(5) ½Ó¿ÚÓ¦ÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
ipv6 traffic-filter acl-name { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£
µ±Àο¿Æ¥ÅäÓòµÄIP±ê×¼ACL¡¢IPÀ©Õ¹ACL¡¢MACÀ©Õ¹ACL¡¢×¨¼Ò¼¶À©Õ¹ACLÒÔ¼°IPv6 ACL¶¼ÎÞ·¨Öª×ãÒªÇóʱ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÉèÖÃר¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬¼´ACL80£¬£¬£¬£¬£¬£¬£¬ÓÉÓû§½ç˵ÐèҪƥÅäµÄ±¨ÎÄÓò£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ×Ô½ç˵ƥÅäÓòµÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
l ר¼Ò¼¶¸ß¼¶ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£×¨¼Ò¼¶¸ß¼¶ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
ר¼Ò¼¶¸ß¼¶ACLÉèÖÃʹÃüÈçÏ£º
½¨ÉèACL80²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£
l ACL80¿ÉÒÔÖ§³ÖÆ¥ÅäEthernet IIÖ¡¡¢802.2 LLCÖ¡ºÍ802.2 SNAPÖ¡¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪAAAA03£¬£¬£¬£¬£¬£¬£¬ÔòÌåÏÖÆ¥Åä802.2 SNAPÖ¡¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪE0E003£¬£¬£¬£¬£¬£¬£¬ÔòÌåÏÖÆ¥Åä802.2 LLCÖ¡¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÆ¥ÅäEthernet IIÖ¡²»¿ÉÉèÖÃDSAPµ½Cntl×ֶεÄÖµ¡£¡£¡£¡£¡£¡£¡£
l ÓÉÓÚÓ²¼þµÄÔµ¹ÊÔÓÉ£¬£¬£¬£¬£¬£¬£¬Ä¿½ñACL80²¢²»¿É¶Ô±¨ÎÄǰ80¸ö×Ö½ÚµÄí§Òâ×Ö½ÚÆ¥Å䣬£¬£¬£¬£¬£¬£¬Ö»Ö§³Ö±¨ÎÄÖÐÄ¿µÄMAC¡¢Ô´MAC¡¢VLAN ID¡¢ETYPE¡¢IPÐÒéºÅ¡¢Ô´IPv4µØµã¡¢Ä¿µÄIPv4µØµã¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú¡¢ICMP_TYPE¡¢ICMP_CODE¡¢PPPOE_IPTYPEÕâЩ×Ö¶ÎËùÔÚλÖÃµÄÆ¥Åä¡£¡£¡£¡£¡£¡£¡£
l ACL80Æ¥ÅäIP¡¢ARPµÈÐÅϢʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖ÷â×°µÄÊý¾ÝÀàÐͺÍÊý¾ÝÀàÐÍÑÚÂ룬£¬£¬£¬£¬£¬£¬¼´ÐèÒªÏÈÉèÖÃÆ«ÒÆÁ¿Îª24µÄ×ֶΣ¬£¬£¬£¬£¬£¬£¬²¢ÇÒÑÚÂëҪΪȫF¡£¡£¡£¡£¡£¡£¡£ÀýÈç·ÅÐÐÔ´IPΪ192.168.1.2µÄ±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦µÄÉèÖÃÏÂÁîΪpermit 0800 FFFF 24 C0A80102 FFFFFFFF 38¡£¡£¡£¡£¡£¡£¡£
l ר¼Ò¼¶¸ß¼¶ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓб¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£
l ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ½¨Éèר¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬²¢½øÈëר¼Ò¼¶¸ß¼¶ACLÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
expert access-list advanced
acl-name
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶¸ß¼¶ACL¡£¡£¡£¡£¡£¡£¡£
(4) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃר¼Ò¼¶¸ß¼¶ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
[ sequence-number ]
{ deny | permit } hex hex-mask offset
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Î´ÉèÖÃר¼Ò¼¶¸ß¼¶ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£
(5) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
list-remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
(6) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
remark text
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
½«×¨¼Ò¼¶¸ß¼¶ACLÓ¦Óõ½½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹×¨¼Ò¼¶¸ß¼¶ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
¡ð ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface ethernet-type interface-number
¡ð ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
interface vlan interface-number
¡ð ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
vxlan vni-number
(4) ½Ó¿ÚÓ¦ÓÃר¼Ò¼¶¸ß¼¶ACL¡£¡£¡£¡£¡£¡£¡£
expert access-group { acl-name | acl-number } { in |
out }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃר¼Ò¼¶¸ß¼¶ACL¡£¡£¡£¡£¡£¡£¡£
ÔÚÖ¸¶¨½Ó¿ÚÉÏÉèÖÃACLÖØ¶¨Ïò¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¶Ô½øÈë¸Ã½Ó¿ÚµÄÆ¥Å䱨ÎÄ£¬£¬£¬£¬£¬£¬£¬Öض¨Ïòµ½Ö¸¶¨½Ó¿Úת·¢³öÈ¥¡£¡£¡£¡£¡£¡£¡£
l ACLÖØ¶¨Ïò¹¦Ð§½öÔÚ½Ó¿ÚÈëÆ«ÏòÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ACLÖÐûÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÖØ¶¨Ïò¹¦Ð§²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
l Ö»Ö§³ÖÔÚÒÔÌ«Íø½Ó¿Ú¡¢¾ÛºÏ½Ó¿ÚÉÏÉèÖÃACLÖØ¶¨Ïò¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
l ´ýÖØ¶¨ÏòµÄ±¨ÎıØÐèÊǶþ²ãת·¢£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Öض¨ÏòµÄÄ¿µÄ½Ó¿Ú±ØÐèºÍÔ´½Ó¿ÚÔÚͳһ¸öVLAN²Å»ªÉúЧ¡£¡£¡£¡£¡£¡£¡£ÀýÈç¼ÙÉ豨ÎÄÊÇ´ÓVLAN 2ת·¢µ½VLAN 3£¬£¬£¬£¬£¬£¬£¬Ôò²»¿É¾ÙÐÐÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£
l ¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖÃACLÖØ¶¨Ïò¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ÉèÖýö¶Ô±¾×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
ʵÏÖACLÖØ¶¨Ïò¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ÉèÖÃACLÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£
¡ð ÉèÖýӿÚACLÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖýӿÚACLÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£
interface interface-type interface-number
redirect destination interface interface-type interface-number acl { acl-name
| acl-number } in
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿Ú²»±£´æACLÖØ¶¨ÏòÉèÖᣡ£¡£¡£¡£¡£¡£
ÉèÖÃÈ«¾ÖÇå¾²ACL¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ×èÖ¹ÆóÒµÄÚ²¿»á¼û²»·¨ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬»òÕß×èÖ¹²¡¶¾½øÈëÆóÒµÄÚ²¿ÍøÂç¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÉèÖÃÈ«¾ÖÇå¾²ACLÆÆÀý¿Ú£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÆóÒµÄÚ²¿ÌØÊⲿ·Ö»á¼ûÍⲿijЩվµã¡£¡£¡£¡£¡£¡£¡£
l ACLÖÐûÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬È«¾ÖÇå¾²ACL¹¦Ð§²»±£´æ¡£¡£¡£¡£¡£¡£¡£
l ÓÉÓÚÈ«¾ÖÇå¾²ACLÖ÷ÒªÓÃÓÚ²¡¶¾¹ýÂË£¬£¬£¬£¬£¬£¬£¬Òò´Ë±»¹ØÁªÓÚÈ«¾ÖÇå¾²ACLµÄACEÖУ¬£¬£¬£¬£¬£¬£¬Ö»ÓÐDenyÀàÐ͵ÄACE»áÉúЧ£¬£¬£¬£¬£¬£¬£¬PermitÀàÐ͵ÄACE²»»áÉúЧ¡£¡£¡£¡£¡£¡£¡£
l Óë¶Ë¿ÚÇå¾²ACL²î±ð£¬£¬£¬£¬£¬£¬£¬È«¾ÖÇå¾²ACLûÓÐĬÈϵÄDenyËùÓбíÏ£¬£¬£¬£¬£¬£¬¼´Ã»ÖÀÖйæÔòµÄ±¨Îͼ¿ÉÒÔͨ¹ý¡£¡£¡£¡£¡£¡£¡£
l È«¾ÖÇå¾²ACLÖ»Ö§³Ö¹ØÁªIP±ê×¼ACL¡¢IPÀ©Õ¹ACL¡¢MACÀ©Õ¹ACL¡¢×¨¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
l È«¾ÖACL¿ÉÒÔÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¡£¡£¡£¡£¡£¡£¼´¿ÉÒÔÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢¶þ²ãÒÔÌ«Íø½Ó¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£ÔÚSVI½Ó¿ÚÉϲ»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
l ÔÊÐíÔÚÎïÀí½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿ÚÉÏ×ÔÁ¦¹Ø±ÕÈ«¾ÖÇå¾²ACL¹¦Ð§£¬£¬£¬£¬£¬£¬£¬²»Ö§³ÖÔھۺϳÉÔ±½Ó¿ÚÉϹرÕÈ«¾ÖÇå¾²ACL¹¦Ð§¡£¡£¡£¡£¡£¡£¡£
l ¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖÃÈ«¾ÖÇå¾²ACL¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ÉèÖýö¶Ô±¾×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£
l ͨ¹ýÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʵÏÖեȡÉèÖÃÈ«¾ÖÇå¾²ACL¡£¡£¡£¡£¡£¡£¡£
l ½«½Ó¿ÚÉèÖÃÎªÆÆÀý¿Ú£¬£¬£¬£¬£¬£¬£¬¿Éʹȫ¾ÖÇå¾²ACLÔÚ½Ó¿ÚÉϲ»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
ʵÏÖÈ«¾ÖÇå¾²ACL¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧ¡£¡£¡£¡£¡£¡£¡£
global access-group disable
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æÈ«¾ÖÇå¾²ACLÎÞЧÉèÖᣡ£¡£¡£¡£¡£¡£
ÉèÖøù¦Ð§¿ÉÒÔʹACL¶Ô·ÖƬ±¨ÎľÙÐиüϸÄ廯µÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£
l ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥ÅäģʽÇл»Ê±£¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂACLµÄ¶ÌʱʧЧ¡£¡£¡£¡£¡£¡£¡£
l ÔÚÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò²»´øFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÇÒÆ¥ÅäÐж¯ÊÇPermit£¬£¬£¬£¬£¬£¬£¬ÕâÑùµÄACL¹æÔòÐèÒªÕ¼Óøü¶àµÄÓ²¼þ±íÏî×ÊÔ´£¬£¬£¬£¬£¬£¬£¬¼«¶ËÇéÐÎÏ»áʹӲ¼þÕ½ÂÔ±íÏîÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÕâÑùµÄACEÉèÖÃÁËTCP Flag¹ýÂË¿ØÖƵÄEstablished£¬£¬£¬£¬£¬£¬£¬Ôò»¹»áÕ¼Óøü¶àµÄÓ²¼þÕ½ÂÔ±íÏî¡£¡£¡£¡£¡£¡£¡£
l ÔÚÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò²»´øFragment±êʶ²¢ÇÒÐèҪƥÅ䱨ÎĵÄËIJãÐÅϢʱ£¬£¬£¬£¬£¬£¬£¬µ±Æ¥ÅäÐж¯ÎªPermitʱ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔò»á¼ì²éÊׯ¬±¨ÎÄÈý²ãºÍËIJãÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¹ØÓÚ·ÇÊׯ¬±¨ÎÄÖ»»á¼ì²é±¨ÎĵÄÈý²ãÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µ±Æ¥ÅäÐж¯ÎªDenyʱ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòÖ»»á¼ì²éÊׯ¬±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬²»»á¼ì²é·ÇÊׯ¬·ÖƬ±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
l ÔÚÐ嵀ᅮ¬±¨ÎÄÐÂÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò´øÓÐFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÆñÂÛACL¹æÔòµÄÆ¥ÅäÐж¯ÊÇPermitÕÕ¾ÉDeny£¬£¬£¬£¬£¬£¬£¬¶¼Ö»¼ì²é·ÇÊׯ¬±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¶ø²»»á¼ì²éÊׯ¬±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥ÅäģʽÇл»Ê±£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ÉèÖÃÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£
¡ð ÉèÖÃIP ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£
ip access-list new-fragment-mode { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Î´ÉèÖÃIP ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£
¡ð ÉèÖÃר¼Ò¼¶À©Õ¹ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£
expert access-list new-fragment-mode { acl-name | acl-number }
ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Î´ÉèÖÃר¼Ò¼¶À©Õ¹ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£
ÉèÖøù¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹӦÓÃÔÚSVI½Ó¿ÚÉϵÄACL½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£
ʵÏָù¦Ð§£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£
configure terminal
(3) ÉèÖÃSVI Router ACL¡£¡£¡£¡£¡£¡£¡£
svi router-acls enable
µ±×°±¸Èí¼þ±íÏîÈÝÁ¿´óÓÚÓ²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ê±£¬£¬£¬£¬£¬£¬£¬±íÏîÌí¼Ó½«Ê§°Ü¡£¡£¡£¡£¡£¡£¡£µ±×°±¸±íÏîÈÝÁ¿½µµÍµ½Ó²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ö®ÏÂʱ£¬£¬£¬£¬£¬£¬£¬ÔÏÈÌí¼Óʧ°ÜµÄ±íÏîÒ²²»»áÖØÐÂÌí¼Ó¡£¡£¡£¡£¡£¡£¡£Í¨¹ý±¾ÏÂÁîÖØË¢ÉèÖ㬣¬£¬£¬£¬£¬£¬´¥½ÒÏþÏîµÄÖØÐÂÌí¼Ó£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»Ö¸´ACL¹ÊÕÏ¡£¡£¡£¡£¡£¡£¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£
enable
(2) ÉèÖÃACL¹ÊÕϻָ´¡£¡£¡£¡£¡£¡£¡£
acl ref synchronize all
¿ÉÒÔͨ¹ýshowÏÂÁîÐÐÉó²é¹¦Ð§ÉèÖúóµÄÔËÐÐÇéÐÎÒÔÑéÖ¤ÉèÖÃЧ¹û¡£¡£¡£¡£¡£¡£¡£
¿ÉÒÔͨ¹ýÖ´ÐÐclearÏÂÁîÀ´É¨³ýÖÖÖÖÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
×¢ÖØ
ÔÚ×°±¸ÔËÐÐÀú³ÌÖÐÖ´ÐÐclearÏÂÁ£¬£¬£¬£¬£¬£¬¿ÉÄÜÓÉÓÚÖ÷ÒªÐÅϢɥʧ¶øµ¼ÖÂÓªÒµÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£
¿ÉÒÔͨ¹ýdebugÏÂÁîÐÐö¾ÙÊä³öµÄÖÖÖÖµ÷ÊÔÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
×¢ÖØ
Êä³öµ÷ÊÔÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»áÕ¼ÓÃϵͳ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÍê±Ïºó£¬£¬£¬£¬£¬£¬£¬ÇëÁ¬Ã¦¹Ø±Õµ÷ÊÔ¿ª¹Ø¡£¡£¡£¡£¡£¡£¡£
±í1-5 ACL¼àÊÓÓëά»¤
|
×÷ÓÃ |
ÏÂÁî |
|
Éó²é»ù±¾ACL |
show access-lists [ acl-name | acl-number ] [ summary ] |
|
Éó²éÖ¸¶¨½Ó¿ÚÉϰ󶨵ÄÖØ¶¨Ïò±íÏ£¬£¬£¬£¬£¬£¬²»ÊäÈë½Ó¿ÚÔòÉó²éËùÓнӿÚÉϰ󶨵ÄÖØ¶¨Ïò±íÏî |
show redirect [ interface interface-type interface-number ] |
|
Éó²é½Ó¿ÚÉÏÓ¦ÓõÄACLÉèÖÃÐÅÏ¢ |
show access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
Éó²é½Ó¿ÚÉÏÓ¦ÓõÄIP±ê×¼ACLºÍÀ©Õ¹ACLÉèÖÃÐÅÏ¢ |
show ip access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
Éó²é½Ó¿ÚÉÏÓ¦ÓõÄMACÀ©Õ¹ACLÉèÖÃÐÅÏ¢ |
show mac access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
Éó²é½Ó¿ÚÉÏÓ¦ÓõÄר¼Ò¼¶À©Õ¹ACLÉèÖÃÐÅÏ¢ |
show expert access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ] |
|
Éó²é½Ó¿ÚÉÏÓ¦ÓõÄIPv6 ACLÉèÖÃÐÅÏ¢ |
show ipv6 traffic-filter [ interface interface-type interface-number | vlan vlan-id ] |
|
Éó²éËùÓеÄTCAMÐÅÏ¢»òÖ¸¶¨µÄTCAMÐÅÏ¢ |
show acl res [ dev dev-number [ slot slot-number ] ] |
|
ÏÔʾĿ½ñ×°±¸µÄÄÜÁ¦ÖµÇéÐÎ |
show acl capability |
|
Éó²éSVI½Ó¿ÚACLÓ¦ÓõĶþÈý²ãÉúЧÇéÐÎ |
show svi router-acls state |
|
Éó²éËùÓеÄTCAMÏêϸʹÓÃÐÅÏ¢»òÖ¸¶¨µÄTCAMÏêϸʹÓÃÐÅÏ¢ |
show acl res detail [ dev dev-number [ slot slot-number ] ] |
|
ɨ³ýTCAM×ÊԴʹÓÃÁ¿µÄÀúÊ··åÖµÊý¾Ý |
clear acl res |
|
ɨ³ýACL±¨ÎÄÆ¥Å伯Êý |
clear counters access-list [ acl-name | acl-number ] |
|
ɨ³ýACL deny±¨ÎÄÆ¥Å伯Êý |
clear access-list counters [ acl-name | acl-number ] |
|
·¿ªACLÔËÐÐÀú³Ìµ÷ÊÔ¿ª¹Ø |
debug acl acld event |
|
Éó²éACL¿Í»§¶ËÐÅÏ¢ |
debug acl acld client-show |
|
Éó²éËùÓÐACL¿Í»§¶Ë½¨ÉèµÄACL |
debug acl acld acl-show |
ͨ¹ýÉèÖÃIP±ê×¼ACL£¬£¬£¬£¬£¬£¬£¬Õ¥È¡²ÆÎñ²¿ÒÔÍâµÄ²¿·Ö»á¼û²ÆÎñÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
ͼ1-3 IP±ê×¼ACLÓ¦Óó¡¾°×éÍøÍ¼

l Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
l Device A½«IP±ê×¼ACLÓ¦ÓÃÔÚÅþÁ¬²ÆÎñÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
# Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# ip access-list standard 1
DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255
DeviceA(config-std-nacl)# deny 11.1.1.1 0.0.0.255
DeviceA(config-std-nacl)# exit
(2) ½«IP±ê×¼ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£
# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬²ÆÎñÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# interface gigabitethernet 0/3
DeviceA(config-if-GigabitEthernet 0/3)# ip access-group 1 out
# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£
DeviceA# show access-lists
ip access-list standard 1
10 permit 10.1.1.0 0.0.0.255
20 deny 11.1.1.0 0.0.0.255
DeviceA# show access-group
ip access-group 1 out
Applied
On interface GigabitEthernet 0/3
# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£
# ´Ó²ÆÎñ²¿µÄij̨PC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏÄÜpingͨ¡£¡£¡£¡£¡£¡£¡£
l DeviceAµÄÉèÖÃÎļþ
hostname DeviceA
!
ip access-list standard 1
?10 permit 10.1.1.0 0.0.0.255
?20 deny 11.1.1.0 0.0.0.255
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip access-group 1 out
?ip address 12.1.1.1 255.255.255.0
!
Device A£¨VLAN 1£©¡¢Device B£¨VLAN 2£©ºÍDevice C£¨VLAN 3£©Ö±Á¬Device D£¬£¬£¬£¬£¬£¬£¬Device DÊÇËùÓÐÖ÷»úµÄÍø¹Ø¡£¡£¡£¡£¡£¡£¡£ÐèÇó1£ºVLAN2ÓëVLAN3Ö®¼ä²»¿ÉÒÔPingͨ£¬£¬£¬£¬£¬£¬£¬VLAN1ÓëVLAN2¿ÉÒÔPingͨ£¬£¬£¬£¬£¬£¬£¬VLAN1ÓëVLAN3¿ÉÒÔPingͨ¡£¡£¡£¡£¡£¡£¡£ÐèÇó2£ºVLAN1ÓëVLAN2µÄDHCP±¨ÎÄÏ໥²»¿É´ï£¬£¬£¬£¬£¬£¬£¬ÆäËûÕý³£Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£ÐèÇó3£ºVLAN1²»¿Éͨ¹ýTelnet»òÕßSSH»á¼ûVLAN3£¬£¬£¬£¬£¬£¬£¬ÆäËûÕý³£Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£
ͼ1-4 IPÀ©Õ¹ACLÓ¦Óó¡¾°×éÍøÍ¼

l Device DÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬¹ýÂËUDP¶Ë¿ÚºÅ67»òÕß68¿ÉÒÔʵÏÖÐèÇó2¡£¡£¡£¡£¡£¡£¡£Device CÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬¹ýÂËTCP¶Ë¿Ú23ºÍ22¿ÉÒÔʵÏÖÐèÇó3¡£¡£¡£¡£¡£¡£¡£
l Device D½«IPÀ©Õ¹ACL»®·ÖÓ¦ÓÃÔÚVLAN1½Ó¿Ú¡¢VLAN2½Ó¿ÚºÍVLAN3½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£Device C½«IPÀ©Õ¹ACLÓ¦ÓÃÔÚÓëDevice DÏàÏß·ÉÏ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃËùÓÐ×°±¸½Ó¿ÚµÄIPµØµã£¨ÂÔ£©¡£¡£¡£¡£¡£¡£¡£
(2) ÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
# Device DÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceD> enable
DeviceD# configure terminal
DeviceD(config)# ip access-list extended inter_vlan_access1
DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc
DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps
DeviceD(config-ext-nacl)# remark ¾Ü¾øDHCP±¨ÎÄ
DeviceD(config-ext-nacl)# permit ip any any
DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ
DeviceD(config-ext-nacl)# exit
DeviceD(config)# ip access-list extended inter_vlan_access2
DeviceD(config-ext-nacl)# deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255
DeviceD(config-ext-nacl)# remark ¾Ü¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping
DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps
DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc
DeviceD(config-ext-nacl)# remark ¾Ü¾øDHCP±¨ÎÄ
DeviceD(config-ext-nacl)# permit ip any any
DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ
DeviceD(config-ext-nacl)# exit
DeviceD(config)# ip access-list extended inter_vlan_access3
DeviceD(config-ext-nacl)# deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
DeviceD(config-ext-nacl)# remark ¾Ü¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping
DeviceD(config-ext-nacl)# permit ip any any
DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ
DeviceD(config-ext-nacl)# exit
# Device CÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceC> enable
DeviceC# configure terminal
DeviceC(config)# ip access-list extended access_deny
DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet
DeviceC(config-ext-nacl)# remark ¾Ü¾øVLAN1ͨ¹ýTelnet»á¼ûVLAN 3
DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22
DeviceC(config-ext-nacl)# remark ¾Ü¾øVLAN1ͨ¹ýSSH»á¼ûVLAN 3
DeviceC(config-ext-nacl)# exit
(3) Ó¦ÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£
# Device D½«IPÀ©Õ¹ACLÓ¦Óõ½¶ÔÓ¦½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceD(config)# interface vlan 1
DeviceD(config-if-VLAN 1)# ip access-group inter_vlan_access1 in
DeviceD(config-if-VLAN 1)# exit
DeviceD(config)# interface vlan 2
DeviceD(config-if-VLAN 2)# ip access-group inter_vlan_access2 in
DeviceD(config-if-VLAN 2)# exit
DeviceD(config)# interface vlan 3
DeviceD(config-if-VLAN 3)# ip access-group inter_vlan_access3 in
DeviceD(config-if-VLAN 3)# exit
# Device C½«IPÀ©Õ¹ACLÓ¦Óõ½ÓëDevice DÏàÁ¬Ïß·ÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceC(config)# line vty 0
DeviceC(config-line)# access-class access_deny in
DeviceC(config-line)# exit
(1) ÑéÖ¤Á¬Í¨ÐÔ¡£¡£¡£¡£¡£¡£¡£
# VLAN 1ÓëVLAN 2Ö®¼ä¿ÉÒÔPingͨ£¬£¬£¬£¬£¬£¬£¬VLAN 1ÓëVLAN 3Ö®¼ä¿ÉÒÔPingͨ¡£¡£¡£¡£¡£¡£¡£
DeviceA# ping 192.168.2.2
Sending 5, 100-byte ICMP Echoes to 192.168.2.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
DeviceA#
DeviceA# ping 192.168.3.2
Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
# VLAN 2ÓëVLAN 3Ö®¼ä²»¿ÉÒÔPingͨ¡£¡£¡£¡£¡£¡£¡£
DeviceB# ping 192.168.3.2
Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
.....
Success rate is 0 percent (0/5)
(2) VLAN 1²»¿Éͨ¹ýTelnet»á¼ûVLAN 3¡£¡£¡£¡£¡£¡£¡£
DeviceA# ping 192.168.3.2
Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
DeviceA#
DeviceA# telnet 192.168.3.2
Trying 192.168.3.2, 23...
% Destination unreachable; gateway or host down
l Device DµÄÉèÖÃÎļþ
hostname DeviceD
!
vlan 1
!
vlan 2
!
vlan 3
!
ip access-list extended inter_vlan_access1
?10 deny udp any eq bootps any eq bootpc
?20 deny udp any eq bootpc any eq bootps
?remark ¾Ü¾øDHCP±¨ÎÄ
?30 permit ip any any
?remarkÔÊÐíÆäËû±¨ÎÄͨѶ
!
ip access-list extended inter_vlan_access2
?10 deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255
?remark ¾Ü¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping
?20 deny udp any eq bootpc any eq bootps
?30 deny udp any eq bootps any eq bootpc
?remark ¾Ü¾øDHCP±¨ÎÄ
?40 permit ip any any
?remark ÔÊÐíÆäËû±¨ÎÄͨѶ
!
ip access-list extended inter_vlan_access3
?10 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
?remark ¾Ü¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping
?20 permit ip any any
?remark ÔÊÐíÆäËû±¨ÎÄͨѶ
!
interface GigabitEthernet 1/0
?switchport access vlan 1
?description link_to_DeviceA
!
interface GigabitEthernet 1/1
?switchport access vlan 2
?description link_to_DeviceB
!
interface GigabitEthernet 1/2
?switchport access vlan 3
?description link_to_DeviceC
!
interface VLAN 1
?ip access-group inter_vlan_access1 in
?ip address 192.168.1.1 255.255.255.0
!
interface VLAN 2
?ip access-group inter_vlan_access2 in
?ip address 192.168.2.1 255.255.255.0
!
interface VLAN 3
?ip access-group inter_vlan_access3 in
?ip address 192.168.3.1 255.255.255.0
!
l Device AµÄÉèÖÃÎļþ
hostname DeviceA
!
interface GigabitEthernet 0/1
?ip address 192.168.1.2 255.255.255.0
!
l Device BµÄÉèÖÃÎļþ
hostname DeviceB
!
interface GigabitEthernet 0/1
?ip address 192.168.2.2 255.255.255.0
!
l Device CµÄÉèÖÃÎļþ
hostname DeviceC
!
ip access-list extended access_deny
?10 deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet
?remark ¾Ü¾øVLAN1ͨ¹ýTelnet»á¼ûVLAN 3
?20 deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22
?remark ¾Ü¾øVLAN1ͨ¹ýSSH»á¼ûVLAN 3
!
interface GigabitEthernet 0/1
?ip address 192.168.3.2 255.255.255.0
!
line vty 0
?access-class access_deny in
?login
?password abcdef
!
ͨ¹ýMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÀ´·Ã¿Í»§¿É»á¼ûµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£
ͼ1-5 MACÀ©Õ¹ACLÓ¦Óó¡¾°×éÍøÍ¼

l Device AÉèÖÃMACÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£ÔÊÐí·Ã¿ÍÇøPC»á¼ûInternetÒÔ¼°¹«Ë¾ÄÚ²¿µÄ¹«¹²·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬µ«²»ÔÊÐí»á¼û¹«Ë¾µÄ²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¼´Õ¥È¡»á¼ûMACµØµãΪ00e0.f800.000dµÄ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
l Device A½«MACÀ©Õ¹ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃMACÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
# Device AÉèÖÃMACÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# mac access-list extended 700
DeviceA(config-mac-nacl)# deny any host 00e0.f800.000d
DeviceA(config-mac-nacl)# permit any any
DeviceA(config-mac-nacl)# exit
(2) ½«MACÀ©Õ¹ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£
# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# mac access-group 700 in
# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£
DeviceA# show access-lists
mac access-list extended 700
10 deny any host 00e0.f800.000d etype-any
20 permit any any etype-any
DeviceA# show access-group
mac access-group 700 in
Applied On interface GigabitEthernet 0/2
# ´Ó·Ã¿ÍPC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔpingµÃͨ¡£¡£¡£¡£¡£¡£¡£
# ÔڷÿÍPC»úÉÏ»á¼ûInternet£¬£¬£¬£¬£¬£¬£¬ÀýÈç»á¼û°Ù¶È£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ·¿ªÖ÷Ò³¡£¡£¡£¡£¡£¡£¡£
l DeviceAµÄÉèÖÃÎļþ
hostname DeviceA
!
mac access-list extended 700
?10 deny any host 00e0.f800.000d
?20 permit any any
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?mac access-group 700 in
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip address 12.1.1.1 255.255.255.0
!
ͨ¹ýÉèÖÃר¼Ò¼¶À©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÀ´·Ã¿Í»§¿É»á¼ûµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ÒªÇó·Ã¿Í²»¿É»á¼û¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬µ«ÄÜ»á¼û¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£¡£¡£¡£¡£¡£¡£
ͼ1-6 ר¼Ò¼¶À©Õ¹ACLÓ¦Óó¡¾°×éÍøÍ¼

l Device AÉèÖÃר¼Ò¼¶À©Õ¹ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º
¡ð եȡ·Ã¿ÍÇøÄÚÖ÷»ú·¢³öÄ¿µÄΪ¹«Ë¾ÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
¡ð եȡ·Ã¿Í»á¼û²ÆÎñÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
¡ð ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£¡£¡£¡£¡£¡£¡£
l Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃר¼Ò¼¶À©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
# Device AÉèÖÃר¼Ò¼¶À©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# expert access-list extended 2700
DeviceA(config-exp-nacl)# deny ip any any 10.1.1.0 0.0.0.255 any
DeviceA(config-exp-nacl)# deny ip any any host 12.1.1.2 any
DeviceA(config-exp-nacl)# permit any any any any
DeviceA(config-exp-nacl)# exit
(2) ½«×¨¼Ò¼¶À©Õ¹ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£
# Device A½«ACLÓ¦ÓÃÔÚÓë·Ã¿ÍÇøÏàÅþÁ¬¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# expert access-group 2700 in
# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# show access-lists
expert access-list extended 2700
?10 deny ip any any 192.168.1.0 0.0.0.255 any
20 deny ip any any host 10.1.1.1 any
30 permit ip any any any any
DeviceA(config)# show access-group
expert access-group 2700in
Applied On interface GigabitEthernet 0/2
# ´Ó·Ã¿ÍPC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·Èϲ»¿Épingͨ¡£¡£¡£¡£¡£¡£¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1£¬£¬£¬£¬£¬£¬£¬È·¶¨pingÇ·ºà¡£¡£¡£¡£¡£¡£¡£
# ÔڷÿÍPC»úÉÏ»á¼ûInternet£¬£¬£¬£¬£¬£¬£¬ÀýÈç»á¼û°Ù¶È£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ·¿ªÖ÷Ò³¡£¡£¡£¡£¡£¡£¡£
l DeviceAµÄÉèÖÃÎļþ
hostname DeviceA
!
expert access-list extended 2700
?10 deny ip any any 10.1.1.0 0.0.0.255 any
?20 deny ip any any host 12.1.1.2 any
?30 permit ip any any any any
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?expert access-group 2700 in
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip address 12.1.1.1 255.255.255.0
!
ͨ¹ýÉèÖÃIPv6 ACL£¬£¬£¬£¬£¬£¬£¬Õ¥È¡¿ª·¢²¿·Ö»á¼ûÊÓÆµ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
ͼ1-7 IPv6 ACLÓ¦Óó¡¾°×éÍøÍ¼

l Device AÉèÖÃIPv6 ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º
¡ð եȡ»á¼ûÊÓÆµ·þÎñÆ÷IPv6µØµã¹æÔò¡£¡£¡£¡£¡£¡£¡£
¡ð ÔÚIPv6 ACLÖÐÌí¼ÓÔÊÐíËùÓÐIPv6±¨ÎÄͨ¹ý¹æÔò¡£¡£¡£¡£¡£¡£¡£
l Device A½«IPv6 ACLÓ¦ÓÃÔÚÅþÁ¬¿ª·¢²¿·Ö½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃIPv6 ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
# Device AÉèÖÃIPv6 ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# ipv6 access-list dev_deny_ipv6video
DeviceA(config-ipv6-nacl)# deny ipv6 any host 1002::2
DeviceA(config-ipv6-nacl)# permit ipv6 any any
DeviceA(config-ipv6-nacl)# exit
(2) ½«IPv6 ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£
# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬¿ª·¢²¿·ÖËùÔÚ½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# ipv6 traffic-filter dev_deny_ipv6video in
# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# show access-lists
ipv6 access-list dev_deny_ipv6video
10 deny ipv6 any host 200::1
20 permit ipv6 any any
DeviceA(config)# show access-group
ipv6 traffic-filter dev_deny_ipv6video in
Applied On interface GigabitEthernet 0/2
# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏpingÊÓÆµ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£
l DeviceAµÄÉèÖÃÎļþ
hostname DeviceA
!
ipv6 access-list dev_deny_ipv6video
?10 deny ipv6 any host 1002::2
?20 permit ipv6 any any
!
interface GigabitEthernet 0/1
?no switchport
?ipv6 address 1000::1/96
!
interface GigabitEthernet 0/2
?no switchport
?ipv6 traffic-filter dev_deny_ipv6video in
?ipv6 address 1001::1/96
!
interface GigabitEthernet 0/3
?no switchport
?ipv6 address 1002::1/96
!
ͨ¹ýACL80¼´×¨¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÀ´·Ã¿Í»§¿É»á¼ûµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ÒªÇó·Ã¿Í²»¿É»á¼û¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬µ«ÄÜ»á¼û¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£¡£¡£¡£¡£¡£¡£
ͼ1-8 ACL80Ó¦Óó¡¾°×éÍøÍ¼

l Device AÉèÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º
¡ð եȡ·Ã¿ÍÇøÄÚÖ÷»ú·¢³öÄ¿µÄΪÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
¡ð եȡ·Ã¿Í»á¼û²ÆÎñÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
¡ð ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£¡£¡£¡£¡£¡£¡£
l Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
# Device AÉèÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# expert access-list advanced acl80-guest
DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0A0101 FFFFFF 42
DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0C010102 FFFFFFFF 42
DeviceA(config-exp-dacl)# permit 0806 FFFF 24
DeviceA(config-exp-dacl)# permit 0800 FFFF 24
DeviceA(config-exp-dacl)# exit
(2) ½«×¨¼Ò¼¶¸ß¼¶ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£
# Device A½«ACL80Ó¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if-GigabitEthernet 0/2)# expert access-group acl80-guest in
# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# show access-lists
expert access-list advanced sss
?10 deny 0800 FFFF 24 0A0101 FFFFFF 42
?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42
?30 permit 0806 FFFF 24
?40 permit 0800 FFFF 24
expert access-group acl80-guest in
Applied On interface GigabitEthernet 0/2
# ´Ó·Ã¿ÍPC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔpingµÃͨ¡£¡£¡£¡£¡£¡£¡£
# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1£¬£¬£¬£¬£¬£¬£¬È·¶¨pingÇ·ºà¡£¡£¡£¡£¡£¡£¡£
# ÔڷÿÍPC»úÉÏ»á¼ûInternet£¬£¬£¬£¬£¬£¬£¬ÀýÈç»á¼û°Ù¶È£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ·¿ªÖ÷Ò³¡£¡£¡£¡£¡£¡£¡£
l DeviceAµÄÉèÖÃÎļþ
hostname DeviceA
!
expert access-list advanced acl80-guest
?10 deny 0800 FFFF 24 0A0101 FFFFFF 42
?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42
?30 permit 0806 FFFF 24
?40 permit 0800 FFFF 24
!
interface GigabitEthernet 0/1
?no switchport
?ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?no switchport
?expert access-group 2700 in
?ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?no switchport
?ip address 12.1.1.1 255.255.255.0
!
ÉèÖûùÓÚʱ¼ä¶ÎµÄACL¹æÔò£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÑз¢²¿·ÖÔÚÌìÌìµÄ12:00µ½13:30»á¼ûInternet¡£¡£¡£¡£¡£¡£¡£
ͼ1-9 »ùÓÚʱ¼ä¶ÎµÄACL¹æÔòÓ¦Óó¡¾°×éÍøÍ¼

l Device AÉèÖÃʱ¼ä¶Î£¬£¬£¬£¬£¬£¬£¬²¢Ìí¼ÓÌìÌì12:00µ½13:30µÄʱ¼ä¶Î±íÏî¡£¡£¡£¡£¡£¡£¡£
l Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º
¡ð Ìí¼ÓÔÊÐíÔ´IPÍø¶ÎµØµãΪ10.1.1.0/24µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬¹ØÁªµÄʱ¼ä¶ÎΪaccess-internet¡£¡£¡£¡£¡£¡£¡£
¡ð Ìí¼ÓեȡԴIPÍø¶ÎµØµãΪ10.1.1.0/24µÄ¹æÔò¡£¡£¡£¡£¡£¡£¡£Åúעʱ¼ä¶ÎÖ®Íâ¶¼²»ÔÊÐí»á¼ûInternet¡£¡£¡£¡£¡£¡£¡£
¡ð Ìí¼ÓÔÊÐí³ýÑз¢Íø¶ÎµØµãÍ⣬£¬£¬£¬£¬£¬£¬ÆäËûËùÓÐÍø¶ÎµØµãµÄ¹æÔò¡£¡£¡£¡£¡£¡£¡£
l Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬Ñз¢²¿½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃʱ¼äÇø¡£¡£¡£¡£¡£¡£¡£
# Device AÉèÖÃʱ¼ä¶Î¡£¡£¡£¡£¡£¡£¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# time-range access-internet
DeviceA(config-time-range)# periodic daily 12:00 to 13:30
DeviceA(config-time-range)# exit
(2) ÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
# Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# ip access-list standard ip_std_internet_acl
DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255 time-range access-internet
DeviceA(config-std-nacl)# deny 10.1.1.0 0.0.0.255
DeviceA(config-std-nacl)# permit any
DeviceA(config-std-nacl)# exit
(3) ½«IP±ê×¼ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£
# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬Ñз¢²¿½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# interface gigabitethernet 0/1
DeviceA(config-if-GigabitEthernet 0/1)# ip access-group ip_std_internet_acl in
# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£
DeviceA# show time-range
time-range entry: access-internet (inactive)
¡¡periodic Daily 12:00 to 13:30
DeviceA# show access-lists
ip access-list standard ip_std_internet_acl
?10 permit 10.1.1.0 0.0.0.255 time-range access-internet (inactive)
?20 deny 10.1.1.0 0.0.0.255
?30 permit any
DeviceA# show access-group
ip access-group ip_std_internet_acl in
Applied On interface GigabitEthernet 0/1
# ÔÚʱ¼ä¶ÎÉúЧÆÚÄÚ£¨12:00ÖÁ13:30£©£¬£¬£¬£¬£¬£¬£¬´ÓÑз¢²¿·ÖÄÚµÄij̨PCʱ»ú¼û°Ù¶ÈÖ÷Ò³£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ»á¼û¡£¡£¡£¡£¡£¡£¡£
# ÔÚʱ¼ä¶ÎʧЧÆÚ£¨12:00ÖÁ13:30ʱ¶ÎÍ⣩£¬£¬£¬£¬£¬£¬£¬´ÓÑз¢²¿·ÖÄÚµÄij̨PCʱ»ú¼û°Ù¶ÈÖ÷Ò³£¬£¬£¬£¬£¬£¬£¬È·Èϲ»¿É»á¼û¡£¡£¡£¡£¡£¡£¡£
l DeviceAµÄÉèÖÃÎļþ
hostname DeviceA
!
ip access-list standard ip_std_internet_acl
?10 permit 10.1.1.0 0.0.0.255 time-range access-internet
?20 deny 10.1.1.0 0.0.0.255
?30 permit any
!
time-range access-internet
?periodic daily 12:00 to 13:30
!
interface GigabitEthernet 0/1
?no switchport
?ip access-group ip_std_internet_acl in
?ip address 10.1.1.1 255.255.255.0
!
ÉèÖÃVRRP+VLANÓ¦Óó¡¾°£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÖ÷»úÓëÖ÷»úÖ®¼äµÄÈý²ãͨѶ¡£¡£¡£¡£¡£¡£¡£ÉèÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä»á¼ûµÄACL£¬£¬£¬£¬£¬£¬£¬¾Ü¾øÆäËûËùÓÐÍø¶ÎµÄACL¡£¡£¡£¡£¡£¡£¡£
ͼ1-10 VRRP+VLANÓ¦Óó¡¾°×éÍøÍ¼

l DeviceAºÍDeviceB×é³ÉVRRP³¡¾°¡£¡£¡£¡£¡£¡£¡£Ö÷»úPC1ºÍPC2ËùÓнÓÈëµ½DeviceC¡£¡£¡£¡£¡£¡£¡£
l ÉèÖÃÌìÉúÊ÷ÐÒ飬£¬£¬£¬£¬£¬£¬Ïû³ýDeviceA¡¢DeviceBºÍDeviceCÖ®¼äµÄ»·Â·¡£¡£¡£¡£¡£¡£¡£
l Ö÷»úPC1ºÍPC2µÄÍø¹Ø½ÓÄÉSVI½Ó¿ÚµÄµØµã¡£¡£¡£¡£¡£¡£¡£
l ÉèÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä»á¼ûµÄACL£¬£¬£¬£¬£¬£¬£¬¾Ü¾øÆäËûËùÓÐÍø¶ÎµÄACL£¬£¬£¬£¬£¬£¬£¬²¢½«ACLÓ¦ÓÃÔÚSVI½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£´Ëʱ»áµ¼ÖÂVRRP×éÄÚDeviceAºÍDeviceBÐγÉË«Ö÷¡£¡£¡£¡£¡£¡£¡£
l ÉèÖÃsvi router-acls enableÏÂÁîºó£¬£¬£¬£¬£¬£¬£¬VRRP×éÄÚDeviceAºÍDeviceBÐγÉÒ»Ö÷Ò»±¸£¬£¬£¬£¬£¬£¬£¬VRRPÐÒé»Ö¸´Õý³£¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃVLAN¡£¡£¡£¡£¡£¡£¡£
# DeviceAÉèÖÃVLAN¡£¡£¡£¡£¡£¡£¡£DeviceA¡¢DeviceBºÍDeviceCÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# vlan 10
DeviceA(config-vlan)# exit
DeviceA(config)# vlan 20
DeviceA(config-vlan)# exit
(2) ÉèÖÃVRRP×é¡£¡£¡£¡£¡£¡£¡£
# DeviceAÉèÖÃVRRP¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# interface VLAN 10
DeviceA(config-if-VLAN 10)# ip address 172.16.1.3 255.255.255.0
DeviceA(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1
DeviceA(config-if-VLAN 10)# vrrp 10 priority 120
DeviceA(config-if-VLAN 10)# exit
DeviceA(config)# interface VLAN 20
DeviceA(config-if-VLAN 20)# ip address 172.31.1.4 255.255.255.0
DeviceA(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1
# DeviceBÉèÖÃVRRP¡£¡£¡£¡£¡£¡£¡£
DeviceB(config)# interface VLAN 10
DeviceB(config-if-VLAN 10)# ip address 172.16.1.4 255.255.255.0
DeviceB(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1
DeviceB(config-if-VLAN 10)# exit
DeviceB(config)# interface VLAN 20
DeviceB(config-if-VLAN 20)# ip address 172.31.1.3 255.255.255.0
DeviceB(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1
DeviceB(config-if-VLAN 20)# vrrp 20 priority 120
DeviceB(config-if-VLAN 20)# exit
(3) ÉèÖÃÌìÉúÊ÷ÐÒ飬£¬£¬£¬£¬£¬£¬Ïû³ý»·Â·¡£¡£¡£¡£¡£¡£¡£
# DeviceAÉèÖÃÌìÉúÊ÷ÐÒé¡£¡£¡£¡£¡£¡£¡£DeviceA¡¢DeviceBºÍDeviceCÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# spanning-tree
(4) ÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£
# DeviceAÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£DeviceAºÍDeviceBÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# ip access-list standard 10
DeviceA(config-std-nacl)# permit host 3.3.3.3
DeviceA(config-std-nacl)# deny any
DeviceA(config-std-nacl)# exit
(5) ½«ACLÓ¦Óõ½SVI½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£
# DeviceAÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£DeviceAºÍDeviceBÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# int vlan 20
DeviceA(config-if-VLAN 20)# ip access-group 10 in
(6)
ÉèÖÃÏÂÁîsvi router-acls enable¡£¡£¡£¡£¡£¡£¡£
# DeviceAÉèÖÃÏÂÁîsvi router-acls enable¡£¡£¡£¡£¡£¡£¡£DeviceAºÍDeviceBÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£
DeviceA(config)# svi router-acls enable
# ¼ì²éDeviceA×°±¸VRRPÐÒé״̬¡£¡£¡£¡£¡£¡£¡£
DeviceA# show vrrp
Interface¡¡¡¡Grp¡¡Pri¡¡ timer¡¡ Own¡¡Pre¡¡ State¡¡ Master addr¡¡¡¡ Group addr¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡
VLAN 10¡¡¡¡¡¡10¡¡ 120¡¡ 3.53¡¡¡¡-¡¡¡¡P¡¡¡¡ Master¡¡172.16.1.3¡¡¡¡¡¡172.16.1.1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡
VLAN 20¡¡¡¡¡¡20¡¡ 100¡¡ 3.60¡¡¡¡-¡¡¡¡P¡¡¡¡ Backup¡¡172.31.1.3¡¡¡¡¡¡172.31.1.1
l DeviceAµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£
hostname DeviceA
!
vlan 1
!
vlan 10
!
vlan 20
!
spanning-tree
!
ip access-list standard 10
?10 permit host 3.3.3.3
?20 deny any
!
svi router-acls enable
!
interface GigabitEthernet 0/1
?switchport mode trunk
!
interface GigabitEthernet 0/3
?switchport mode trunk
!
interface VLAN 1
?ip address 192.168.1.2 255.255.255.0
!
interface VLAN 10
?ip address 172.16.1.3 255.255.255.0
?vrrp 10 priority 120
?vrrp 10 ip 172.16.1.1
!
interface VLAN 20
?ip access-group 10 in
?ip address 172.31.1.4 255.255.255.0
?vrrp 20 ip 172.31.1.1
!
ip route 3.3.3.0 255.255.255.0 192.168.1.1
!
l DeviceBµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£
hostname DeviceB
!
vlan 1
!
vlan 10
!
vlan 20
!
spanning-tree
!
ip access-list standard 10
?10 permit host 3.3.3.3
?20 deny any
!
svi router-acls enable
!
interface GigabitEthernet 0/1
?switchport mode trunk
!
interface GigabitEthernet 0/3
?switchport mode trunk
!
interface VLAN 1
?ip address 192.168.2.2 255.255.255.0
!
interface VLAN 10
?ip access-group 10 in
?ip address 172.16.1.4 255.255.255.0
?vrrp 10 ip 172.16.1.1
!
interface VLAN 20
?ip address 172.31.1.3 255.255.255.0
?vrrp 20 priority 120
?vrrp 20 ip 172.31.1.1
!
ip route 3.3.3.0 255.255.255.0 192.168.2.1
!
l DeviceCµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£
hostname DeviceC
!
vlan 1
!
vlan 10
!
vlan 20
!
interface GigabitEthernet 0/1
?switchport access vlan 10
!
interface GigabitEthernet 0/2
?switchport access vlan 20
!
interface GigabitEthernet 0/3
?switchport mode trunk
!
interface GigabitEthernet 0/4
?switchport mode trunk
!
l ServerAµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£
hostname ServerA
!
interface GigabitEthernet 0/1
?ip address 192.168.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?ip address 192.168.2.1 255.255.255.0
!
interface Loopback 0
?ip address 3.3.3.3 255.255.255.0
!
ip route 172.16.1.0 255.255.255.0 192.168.1.2
ip route 172.31.1.0 255.255.255.0 192.168.2.2
!
Ó¦ÓÃACLʱÈôÊÇÉèÖôøcounter-onlyÑ¡Ï£¬£¬£¬£¬£¬£¬¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£ÒÔPC pingÍø¹ØÑïÆúICMP±¨ÎÄΪÀý¾ÙÐмÆÊýͳ¼Æ£¬£¬£¬£¬£¬£¬£¬²¢¶¨Î»¶ª°üλÖᣡ£¡£¡£¡£¡£¡£

l DeviceÉÏG0/1ºÍG0/2µÄÈëÆ«ÏòºÍ³öÆ«Ïò¶¼ÒªÓ¦ÓÃACL£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇDeviceÐèÒªÉèÖÃ4ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
l Gateway×°±¸G0/1µÄÈëÆ«ÏòºÍ³öÆ«Ïò¶¼ÒªÓ¦ÓÃACL£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇGatewayÉèÖÃ2ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
l Ó¦ÓÃACLʱÉèÖÃÐèÒªcounter-onlyÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£
l ¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACLÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£
(1) ÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£
# Device×°±¸ÉèÖÃ4ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
Device> enable
Device# configure terminal
Device(config)# ip access-list extend 100
Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254
Device(config-ext-nacl)# exit
Device(config)# ip access-list extend 101
Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1
Device(config-ext-nacl)# exit
Device(config)# ip access-list extend 102
Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254
Device(config-ext-nacl)# exit
Device(config)# ip access-list extend 103
Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1
Device(config-ext-nacl)# exit
# Gateway×°±¸ÉèÖÃ2ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£
Gateway> enable
Gateway #configure terminal
Gateway(config)# ip access-list extend 100
Gateway(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254
Gateway(config-ext-nacl)# exit
Gateway(config)# ip access-list extend 101
Gateway(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1
Gateway(config-ext-nacl)# exit
(2) Ó¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£
# ÔÚGateway×°±¸ºÍDevice×°±¸»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòºÍ³öÆ«ÏòÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£
Gateway(config)# interface gigabitEthernet 0/1
Gateway(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only
Gateway(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only
Gateway(config-if-GigabitEthernet 0/1)# exit
# ÔÚDevice×°±¸ºÍGateway×°±¸»¥Áª½Ó¿ÚG0/2µÄÈëÆ«ÏòºÍ³öÆ«ÏòÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£
Device# configure terminal
Device(config)# interface gigabitEthernet 0/2
Device(config-if-GigabitEthernet 0/2)# ip access-group 103 in counter-only
Device(config-if-GigabitEthernet 0/2)# ip access-group 102 out counter-only
Device(config-if-GigabitEthernet 0/2)# exit
# ÔÚDevice×°±¸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòºÍ³öÆ«ÏòÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£
Device# configure terminal
Device(config)# interface gigabitEthernet 0/1
Device(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only
Device(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only
Device(config-if-GigabitEthernet 0/1)# exit
# ÔÚPCÉÏpingÍø¹ØµØµã10.10.10.254£¬£¬£¬£¬£¬£¬£¬3´Î¹²·¢³ö15¸öICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£»®·ÖÉó²éDevice×°±¸ºÍGateway×°±¸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£¡£¡£¡£¡£¡£¡£Éó²éDevice×°±¸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£¡£¡£¡£¡£¡£¡£
Device# show access-list
ip access-list extended 100
¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)
ip access-list extended 101
¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)
ip access-list extended 102¡¡
¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)
ip access-list extended 103¡¡
¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)
# Éó²éGateway×°±¸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£¡£¡£¡£¡£¡£¡£
Gateway# show access-list
ip access-list extended 100
¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)
ip access-list extended 101
¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (15 matches)
# ÆÊÎö±¨ÎÄͳ¼Æ¼ÆÊý£¬£¬£¬£¬£¬£¬£¬¶¨Î»±¨ÎÄÑïÆúλÖᣡ£¡£¡£¡£¡£¡£
Device×°±¸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòÊÕµ½15¸ö±¨ÎÄ£¨Device×°±¸ACL 100£©¡£¡£¡£¡£¡£¡£¡£
Device×°±¸ºÍGateway×°±¸»¥Áª½Ó¿ÚG0/2µÄ³öÆ«Ïò·¢³ö15¸ö±¨ÎÄ£¨Device×°±¸ACL 102£©¡£¡£¡£¡£¡£¡£¡£
Gateway×°±¸ºÍDevice×°±¸»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòÊÕµ½15¸ö±¨ÎÄ£¨Gateway×°±¸ACL 100£©¡£¡£¡£¡£¡£¡£¡£
Gateway×°±¸ºÍDevice×°±¸»¥Áª½Ó¿ÚG0/1µÄ³öÆ«Ïò·¢³ö15¸ö±¨ÎÄ£¨Gateway×°±¸ACL 101£©¡£¡£¡£¡£¡£¡£¡£
Device×°±¸ºÍGateway×°±¸»¥Áª½Ó¿ÚG0/2µÄÈëÆ«ÏòÊÕµ½10¸ö±¨ÎÄ£¨Device×°±¸ACL 103£©¡£¡£¡£¡£¡£¡£¡£
˵Ã÷±¨ÎÄÑïÆúÔÚDevice×°±¸ºÍGateway×°±¸Ö®¼äµÄÁ´Â·ÉÏ¡£¡£¡£¡£¡£¡£¡£
l DeviceµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£
hostname Device
!
ip access-list extended 100
?10 permit icmp host 10.10.10.1 host 10.10.10.254
!
ip access-list extended 101
?10 permit icmp host 10.10.10.254 host 10.10.10.1
!
ip access-list extended 102
?10 permit icmp host 10.10.10.1 host 10.10.10.254
!
ip access-list extended 103
?10 permit icmp host 10.10.10.254 host 10.10.10.1
!
interface GigabitEthernet 0/1
?ip access-group 100 in counter-only
?ip access-group 101 out counter-only
!
interface GigabitEthernet 0/2
?ip access-group 103 in counter-only
?ip access-group 104 out counter-only
!
l GatewayµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£
hostname Gateway
!
ip access-list extended 100
?10 permit icmp host 10.10.10.1 host 10.10.10.254
!
ip access-list extended 101
?10 permit icmp host 10.10.10.254 host 10.10.10.1
!
interface GigabitEthernet 0/1
?ip access-group 100 in counter-only
?ip access-group 101 out counter-only
?ip address 10.10.10.254 255.255.255.0
!