Ä¿¡¡Â¼

1 ACL. 1

1.1 ¹¦Ð§ÏÈÈÝ... 1

1.1.1 ACL¸ÅÊö... 1

1.1.2 ÊÂÇéÔ­Àí... 1

1.2 ÉèÖÃʹÃü¸ÅÀÀ... 10

1.3 ÉèÖÃIP±ê×¼ACL. 11

1.3.1 ¹¦Ð§¼ò½é... 11

1.3.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 11

1.3.3 ÉèÖÃʹÃü¼ò½é... 11

1.3.4 ½¨ÉèIP±ê×¼ACL. 11

1.3.5 Ó¦ÓÃIP±ê×¼ACL. 13

1.4 ÉèÖÃIPÀ©Õ¹ACL. 14

1.4.1 ¹¦Ð§¼ò½é... 14

1.4.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 14

1.4.3 ÉèÖÃʹÃü¼ò½é... 14

1.4.4 ½¨ÉèIPÀ©Õ¹ACL. 14

1.4.5 Ó¦ÓÃIPÀ©Õ¹ACL. 16

1.5 ÉèÖÃMACÀ©Õ¹ACL. 17

1.5.1 ¹¦Ð§¼ò½é... 17

1.5.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 17

1.5.3 ÉèÖÃʹÃü¼ò½é... 17

1.5.4 ½¨ÉèMACÀ©Õ¹ACL. 17

1.5.5 Ó¦ÓÃMACÀ©Õ¹ACL. 18

1.6 ÉèÖÃר¼Ò¼¶À©Õ¹ACL. 19

1.6.1 ¹¦Ð§¼ò½é... 19

1.6.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 19

1.6.3 ÉèÖÃʹÃü¼ò½é... 19

1.6.4 ½¨Éèר¼Ò¼¶À©Õ¹ACL. 19

1.6.5 Ó¦ÓÃר¼Ò¼¶À©Õ¹ACL. 21

1.7 ÉèÖÃIPv6 ACL. 22

1.7.1 ¹¦Ð§¼ò½é... 22

1.7.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 22

1.7.3 ÉèÖÃʹÃü¼ò½é... 22

1.7.4 ½¨ÉèIPv6 ACL. 22

1.7.5 Ó¦ÓÃIPv6 ACL. 24

1.8 ÉèÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©... 24

1.8.1 ¹¦Ð§¼ò½é... 24

1.8.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 25

1.8.3 ÉèÖÃʹÃü¼ò½é... 25

1.8.4 ½¨Éèר¼Ò¼¶¸ß¼¶ACL. 25

1.8.5 Ó¦ÓÃר¼Ò¼¶¸ß¼¶ACL. 26

1.9 ÉèÖÃACLÖØ¶¨Ïò... 26

1.9.1 ¹¦Ð§¼ò½é... 26

1.9.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 26

1.9.3 ÉèÖÃ×¼±¸... 27

1.9.4 ÉèÖð취... 27

1.10 ÉèÖÃÈ«¾ÖÇå¾²ACL. 27

1.10.1 ¹¦Ð§¼ò½é... 27

1.10.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 27

1.10.3 ÉèÖÃ×¼±¸... 27

1.10.4 ÉèÖð취... 27

1.11 ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥Åäģʽ... 28

1.11.1 ¹¦Ð§¼ò½é... 28

1.11.2 ÉèÖÃÏÞÖÆÓëÖ¸µ¼... 28

1.11.3 ÉèÖÃ×¼±¸... 28

1.11.4 ÉèÖð취... 28

1.12 ÉèÖÃSVI Router ACL. 29

1.12.1 ¹¦Ð§¼ò½é... 29

1.12.2 ÉèÖÃ×¼±¸... 29

1.12.3 ÉèÖð취... 29

1.13 ÉèÖÃACL¹ÊÕϻָ´... 29

1.13.1 ¹¦Ð§¼ò½é... 29

1.13.2 ÉèÖð취... 29

1.14 ¼àÊÓÓëά»¤... 29

1.15 µä·¶ÉèÖþÙÀý... 30

1.15.1 IP±ê×¼ACLÉèÖþÙÀý... 30

1.15.2 IPÀ©Õ¹ACLÉèÖþÙÀý... 32

1.15.3 MACÀ©Õ¹ACLÉèÖþÙÀý... 37

1.15.4 ר¼Ò¼¶À©Õ¹ACLÉèÖþÙÀý... 39

1.15.5 IPv6 ACLÉèÖþÙÀý... 41

1.15.6 ACL80ÉèÖþÙÀý... 43

1.15.7 »ùÓÚʱ¼ä¶ÎµÄACL¹æÔòÉèÖþÙÀý... 45

1.15.8 SVI Router ACLÉèÖþÙÀý... 47

1.15.9 ACL±¨ÎļÆÊýͳ¼ÆÉèÖþÙÀý... 51

 


1 ACL

1.1?? ¹¦Ð§ÏÈÈÝ

1.1.1? ACL¸ÅÊö

ACL£¨Access Control List£¬£¬£¬£¬£¬£¬£¬»á¼û¿ØÖÆÁÐ±í£©Ò²³ÆÎª»á¼ûÁбí£¬£¬£¬£¬£¬£¬£¬ÓеÄÎĵµÖл¹³ÆÖ®Îª°ü¹ýÂË¡£¡£¡£¡£¡£¡£¡£ACLͨ¹ý½ç˵һϵÁаüÀ¨¡°ÔÊÐí¡±»ò¡°¾Ü¾ø¡±µÄ¹æÔòÓï¾ä£¬£¬£¬£¬£¬£¬£¬²¢½«ÕâЩ¹æÔòÓ¦Óõ½×°±¸½Ó¿ÚÉÏ£¬£¬£¬£¬£¬£¬£¬¶ÔÊÕÖ§½Ó¿ÚµÄÊý¾Ý°ü¾ÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÌáÉýÍøÂç×°±¸µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£

ÉèÖÃACLÄܹ»°ü¹ÜÍøÂçÇå¾²¡¢¿É¿¿ºÍÎȹÌ£¬£¬£¬£¬£¬£¬£¬ÀýÈ磺

l  ±ÜÃⱨÎĹ¥»÷£ºÕë¶ÔIP¡¢TCP»òÕßICMP±¨ÎĵĹ¥»÷£¬£¬£¬£¬£¬£¬£¬¶ÔÕâЩ¹¥»÷±¨ÎÄ×ö¡°¾Ü¾ø¡±´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£

l  ÍøÂç»á¼û¿ØÖÆ£ºÏÞÖÆÓû§»á¼û·þÎñ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÖ»ÔÊÐí»á¼ûWWWºÍµç×ÓÓʼþ·þÎñ£¬£¬£¬£¬£¬£¬£¬ÆäËû·þÎñÈçTelnetÔòեȡ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»òÕßÖ»ÔÊÐíÔÚ¸ø¶¨µÄʱ¼ä¶ÎÄÚ»á¼û£¬£¬£¬£¬£¬£¬£¬»òÕßÖ»ÔÊÐíÌØ¶¨Ö÷ʱ»ú¼ûÍøÂçµÈ¡£¡£¡£¡£¡£¡£¡£

l  ÍøÂçÁ÷Á¿¿ØÖÆ£ºÍŽáQoS¿ÉÒÔΪÖ÷ÒªµÄÊý¾ÝÁ÷¾ÙÐÐÓÅÏÈ·þÎñ°ü¹Ü¡£¡£¡£¡£¡£¡£¡£¹ØÓÚQoSµÄÉèÖÃÇë°Ý¼û¡°QoS¡±¡£¡£¡£¡£¡£¡£¡£

1.1.2? ÊÂÇéÔ­Àí

1.    »ù±¾¿´·¨

l  »á¼ûÁбí

»á¼ûÁбíÓУº»ù±¾»á¼ûÁбíºÍ¶¯Ì¬»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£

Óû§¿ÉÒÔÆ¾Ö¤ÐèҪѡÔñ»ù±¾»á¼ûÁбí»ò¶¯Ì¬»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£Ò»Ñùƽ³£ÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Ê¹Óûù±¾»á¼ûÁбíÒѾ­Äܹ»Öª×ãÇå¾²ÐèÒª¡£¡£¡£¡£¡£¡£¡£µ«¹¥»÷Õß¿ÉÄÜͨ¹ýÈí¼þð³äÔ´µØµãÓÕÆ­×°±¸£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»á¼ûÍøÂç¡£¡£¡£¡£¡£¡£¡£¶ø¶¯Ì¬»á¼ûÁбíÔÚÓû§»á¼ûÍøÂçÒÔǰ£¬£¬£¬£¬£¬£¬£¬ÒªÇóͨ¹ýÉí·ÝÈÏÖ¤£¬£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄÑÒÔ»á¼ûÍøÂç¡£¡£¡£¡£¡£¡£¡£ÔÚÃô¸ÐÇøÓò¿ÉÒÔʹÓö¯Ì¬»á¼ûÁбí°ü¹ÜÍøÂçÇå¾²¡£¡£¡£¡£¡£¡£¡£

*     ˵Ã÷

ͨ¹ýð³äÔ´µØµãÓÕÆ­×°±¸¼´µç×ÓÓÕÆ­ÊÇËùÓлá¼ûÁбí¹ÌÓеÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬Ê¹Óö¯Ì¬ÁбíÒ²»áÔâÓöµç×ÓÓÕÆ­ÎÊÌ⣺¹¥»÷Õß¿ÉÄÜÔÚÓû§Í¨¹ýÉí·ÝÈÏÖ¤µÄÓÐÓûá¼ûʱ´ú£¬£¬£¬£¬£¬£¬£¬Ã°³äÓû§µÄµØµã»á¼ûÍøÂç¡£¡£¡£¡£¡£¡£¡£½â¾ö¸ÃÎÊÌâµÄÒªÁìÓÐÁ½ÖÖ£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖÊÇÖ»¹ÜÉèÖøü¶ÌµÄÓû§»á¼û¿ÕÏÐʱ¼ä£»£»£»£»£»ÁíÒ»ÖÖÊÇʹÓÃIPsec¼ÓÃÜЭÒé¶ÔÍøÂçÊý¾Ý¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬È·±£½øÈë×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬ËùÓеÄÊý¾Ý¶¼ÊǼÓÃܵġ£¡£¡£¡£¡£¡£¡£

 

»á¼ûÁбíÒ»Ñùƽ³£ÉèÖÃÔÚÒÔÏÂλÖõÄÍøÂç×°±¸ÉÏ£º

¡ð         ÄÚ²¿ÍøºÍÍâ²¿Íø£¨ÈçInternet£©Ö®¼äµÄ×°±¸

¡ð         Á½¸öÍøÂç½ÓÈÀ²¿·ÖµÄ×°±¸

¡ð         ½ÓÈë¿ØÖÆ¶Ë¿ÚµÄ×°±¸

l  ACE

ACE£¨Access Control Entry£¬£¬£¬£¬£¬£¬£¬»á¼û¿ØÖÆÌõÄ¿£©ÊǰüÀ¨¡°ÔÊÐí£¨Permit£©¡±»ò¡°¾Ü¾ø£¨Deny£©¡±Á½ÖÖÐж¯£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°¹ýÂ˹æÔòµÄÒ»ÌõÓï¾ä¡£¡£¡£¡£¡£¡£¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ£¬£¬£¬£¬£¬£¬£¬¸ÃÐòºÅ¿ÉÓÉ×°±¸×Ô¶¯·ÖÅÉ»òÕßÊÖ¶¯ÉèÖᣡ£¡£¡£¡£¡£¡£Ò»ÌõACLÖаüÀ¨Ò»¸ö»òÕß¶à¸öACE¡£¡£¡£¡£¡£¡£¡£ACLͨ¹ýACE¶ÔÊý¾Ý°ü¾ÙÐбêʶ¹ýÂË¡£¡£¡£¡£¡£¡£¡£

ACLÖÐACEµÄ˳Ðò¾öÒéÁ˸ÃACEÔÚ»á¼ûÁбíÖÐµÄÆ¥ÅäÓÅÏȼ¶¡£¡£¡£¡£¡£¡£¡£ÍøÂç×°±¸ÔÚ´¦Öóͷ£±¨ÎÄʱ£¬£¬£¬£¬£¬£¬£¬°´ACEµÄÐòºÅ´ÓСµ½´ó¾ÙÐйæÔòÆ¥Å䣬£¬£¬£¬£¬£¬£¬µ±ÕÒµ½Æ¥ÅäµÄACEºóÔò×èÖ¹¼ì²éºóÐøµÄACE¡£¡£¡£¡£¡£¡£¡£

ÀýÈ罨ÉèÒ»ÌõÐòºÅΪ10µÄACE£¬£¬£¬£¬£¬£¬£¬Ëü¾Ü¾øËùÓеÄÊý¾ÝÁ÷ͨ¹ý¡£¡£¡£¡£¡£¡£¡£

10 deny ip any any

20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any

ÓÉÓÚÐòºÅΪ10µÄACE¾Ü¾øÁËËùÓеÄIP±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬×ÝÈ»192.168.12.0/24ÍøÂçµÄÖ÷»úTelnet±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ±»ÐòºÅΪ20µÄACEÆ¥Å䣬£¬£¬£¬£¬£¬£¬¸Ã±¨ÎÄÒ²½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ×°±¸ÔÚ¼ì²éµ½±¨ÎĺÍÐòºÅΪ10µÄACEÆ¥Åäºó£¬£¬£¬£¬£¬£¬£¬±ã×èÖ¹¼ì²éºóÃæÐòºÅΪ20µÄACE¡£¡£¡£¡£¡£¡£¡£

ÓÖÀýÈ罨ÉèÒ»Ìõ±àºÅΪ10µÄACE£¬£¬£¬£¬£¬£¬£¬ËüÔÊÐíËùÓеÄIPv6Êý¾ÝÁ÷ͨ¹ý¡£¡£¡£¡£¡£¡£¡£

10 permit ipv6 any any

20 deny ipv6 host 200::1 any

ÓÉÓÚÐòºÅΪ10µÄACEÔÊÐíËùÓеÄIPv6±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬Ö÷»ú200::1·¢³öµÄIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬×ÝȻƥÅäÐòºÅΪ20µÄACE£¬£¬£¬£¬£¬£¬£¬¸Ã±¨ÎÄÒ²½«±»ÔÊÐíͨ¹ý¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ×°±¸ÔÚ¼ì²éµ½±¨Îĺ͵ÚÒ»ÌõACEÆ¥Å䣬£¬£¬£¬£¬£¬£¬±ã×èÖ¹¼ì²éºóÃæÐòºÅΪ20µÄACE¡£¡£¡£¡£¡£¡£¡£

l  ²½³¤

µ±×°±¸ÎªACE×Ô¶¯·ÖÅÉÐòºÅʱ£¬£¬£¬£¬£¬£¬£¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ£¬£¬£¬£¬£¬£¬£¬³ÆÎª²½³¤¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬ÈôÊǽ«²½³¤É趨Ϊ5£¬£¬£¬£¬£¬£¬£¬Ôò×°±¸Æ¾Ö¤5¡¢10¡¢15¡­ÕâÑùµÄµÝÔö˳Ðò×Ô¶¯ÎªACE·ÖÅÉÐòºÅ¡£¡£¡£¡£¡£¡£¡£ÈçÏÂËùʾ¡£¡£¡£¡£¡£¡£¡£

5 deny ip any any

10 permit tcp 192.168.12.0 0.0.0.255 eq telnet any

µ±²½³¤¸Ä±äºó£¬£¬£¬£¬£¬£¬£¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤ÖµÖØÐ·ÖÅÉ¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬µ±°Ñ²½³¤¸ÄΪ10ºó£¬£¬£¬£¬£¬£¬£¬Ô­À´ACEÐòºÅ´Ó5¡¢10¡¢15Äð³É5¡¢15¡¢25¡£¡£¡£¡£¡£¡£¡£

ͨ¹ý¸Ä±ä²½³¤¿ÉÒÔÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£¡£¡£¡£¡£¡£¡£ÀýÈ罨ÉèÁË4¸öACE£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÊÖ¶¯ÉèÖÃACEÐòºÅ»®·ÖΪ1¡¢2¡¢3ºÍ4¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÏ£ÍûÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÏȽ«²½³¤ÐÞ¸ÄΪ2£¬£¬£¬£¬£¬£¬£¬´ËʱԭÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7£¬£¬£¬£¬£¬£¬£¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÉèÖõÄÐòºÅΪ2µÄACE¡£¡£¡£¡£¡£¡£¡£

l  ¹ýÂËÓòÄ£°å

¹ýÂËÓòÖ¸µÄÊÇÌìÉúÒ»ÌõACEʱ£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎľÙÐÐʶ±ð¡¢·ÖÀà¡£¡£¡£¡£¡£¡£¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£¡£¡£¡£¡£¡£¡£ACEƾ֤ÒÔÌ«Íø±¨ÎĵÄijЩ×Ö¶ÎÀ´±êʶÒÔÌ«Íø±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÕâЩ×ֶΰüÀ¨£º

¶þ²ã×ֶΣ¨Layer 2 Fields£©£º

¡ð         48λµÄÔ´MACµØµã£¨±ØÐè˵Ã÷ËùÓÐ48룩

¡ð         48λµÄÄ¿µÄMACµØµã£¨±ØÐè˵Ã÷ËùÓÐ48룩

¡ð         16λµÄ¶þ²ãÀàÐÍ×Ö¶Î

Èý²ã×ֶΣ¨Layer 3 Fields£©£º

¡ð         Ô´IPµØµã×ֶΣ¨¿ÉÒÔ˵Ã÷ËùÓÐÔ´IPµØµãÖµ£¬£¬£¬£¬£¬£¬£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©

¡ð         Ä¿µÄIPµØµã×ֶΣ¨¿ÉÒÔ˵Ã÷ËùÓÐÄ¿µÄIPµØµãÖµ£¬£¬£¬£¬£¬£¬£¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©

¡ð         ЭÒéÀàÐÍ×Ö¶Î

ËIJã×ֶΣ¨Layer 4 Fields£©£º

¡ð         ¿ÉÒÔ˵Ã÷Ò»¸öTCPµÄÔ´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú»òÕß¶¼ËµÃ÷£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔ˵Ã÷Ô´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚµÄ¹æÄ£¡£¡£¡£¡£¡£¡£¡£

¡ð         ¿ÉÒÔ˵Ã÷Ò»¸öUDPµÄÔ´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú»òÕß¶¼ËµÃ÷£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔ˵Ã÷Ô´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚµÄ¹æÄ£¡£¡£¡£¡£¡£¡£¡£

ÀýÈ磬£¬£¬£¬£¬£¬£¬ÔÚ½¨ÉèÒ»ÌõACEʱÐèҪƾ֤±¨ÎĵÄÄ¿µÄIP×ֶΣ¬£¬£¬£¬£¬£¬£¬¶Ô±¨ÎľÙÐÐʶ±ðºÍ·ÖÀà¡£¡£¡£¡£¡£¡£¡£¶øÔÚ½¨ÉèÁíÒ»ÌõACEʱ£¬£¬£¬£¬£¬£¬£¬ÐèҪƾ֤±¨ÎĵÄÔ´IPµØµã×ֶκÍUDPµÄÔ´¶Ë¿Ú×ֶΣ¬£¬£¬£¬£¬£¬£¬¶Ô±¨ÎľÙÐÐʶ±ðºÍ·ÖÀà¡£¡£¡£¡£¡£¡£¡£ÕâÁ½ÌõACE¾ÍʹÓÃÁ˲î±ðµÄ¹ýÂËÓòÄ£°å¡£¡£¡£¡£¡£¡£¡£

l  ¹æÔò

¹æÔò£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬Ò»ÌõACEµÄÄÚÈÝÈçÏ£º

10 permit tcp host 192.168.12.2 any eq telnet

ÔÚÕâÌõACEÖУ¬£¬£¬£¬£¬£¬£¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεÄÜöÝÍ£ºÔ´IPµØµã×ֶΡ¢Ä¿µÄIPµØµã×ֶΡ¢IPЭÒé×ֶΡ¢TCPÄ¿µÄ¶Ë¿Ú×ֶΡ£¡£¡£¡£¡£¡£¡£¶ÔÓ¦µÄÖµ£¨¼´¹æÔò£©»®·ÖΪ£ºÔ´IPµØµãΪHost 192.168.12.2¡¢Ä¿µÄIPµØµãΪAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPЭÒéΪTCP¡¢TCPÄ¿µÄ¶Ë¿ÚΪTelnet¡£¡£¡£¡£¡£¡£¡£Èçͼ1-1Ëùʾ¡£¡£¡£¡£¡£¡£¡£

ͼ1-1     ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄÆÊÎö

 

*     ˵Ã÷

¡ñ     ¹ýÂËÓòÄ£°å¿ÉÒÔÊÇÈý²ã×ֶΣ¨Layer 3 Field£©ºÍËIJã×ֶΣ¨Layer 4 Field£©µÄÜöÝÍ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÊǶà¸ö¶þ²ã×ֶΣ¨Layer 2 Field£©µÄÜöÝÍ¡£¡£¡£¡£¡£¡£¡£µ«±ê×¼ÓëÀ©Õ¹ACLµÄ¹ýÂËÓòÄ£°å²»¿ÉÊǶþ²ãºÍÈý²ã×ֶΡ¢¶þ²ãºÍËIJã×ֶΡ¢¶þ²ãºÍÈý²ã×ֶΡ¢ËIJã×ֶεÄÜöÝÍ¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹Óöþ²ã¡¢Èý²ã¡¢ËIJã×Ö¶ÎÜöÝÍ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓÃר¼Ò¼¶À©Õ¹»á¼û¿ØÖÆÁÐ±í¡£¡£¡£¡£¡£¡£¡£

¡ñ     ³öÆ«ÏòACL¹ØÁªSVI½Ó¿Ú£¨Switch Virtual Interface£¬£¬£¬£¬£¬£¬£¬½»Á÷×°±¸ÐéÄâ½Ó¿Ú£©µÄ×¢ÖØÊÂÏ֧³ÖIP±ê×¼¡¢IPÀ©Õ¹¡¢MACÀ©Õ¹ºÍר¼Ò¼¶ACLÓ¦Óᣡ£¡£¡£¡£¡£¡£

¡ñ     ÈôÊÇÔÚMACÀ©Õ¹ºÍר¼Ò¼¶ACLÖÐÆ¥ÅäÄ¿µÄMAC£¬£¬£¬£¬£¬£¬£¬½«ÕâÑùµÄACLÓ¦Óõ½SVI½Ó¿ÚµÄ³öÆ«Ïòʱ£¬£¬£¬£¬£¬£¬£¬±íÏî»á±»ÉèÖ㬣¬£¬£¬£¬£¬£¬µ«ÎÞ·¨ÉúЧ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÏëÒªÔÚIPÀ©Õ¹£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶ACLÖÐÆ¥ÅäÄ¿µÄIP£¬£¬£¬£¬£¬£¬£¬¶øÄ¿µÄIP²»ÔÚËù¹ØÁªµÄSVI½Ó¿ÚµÄ×ÓÍøIP¹æÄ£ÄÚʱ£¬£¬£¬£¬£¬£¬£¬ÉèÖõÄACL½«ÎÞ·¨ÉúЧ¡£¡£¡£¡£¡£¡£¡£ÀýÈçVLAN 1µÄµØµãΪ192.168.64.1 255.255.255.0£¬£¬£¬£¬£¬£¬£¬½¨ÉèÒ»ÌõIPÀ©Õ¹µÄACL£¬£¬£¬£¬£¬£¬£¬ACEΪdeny udp any 192.168.65.1 0.0.0.255 eq 255£¬£¬£¬£¬£¬£¬£¬½«¸ÃACLÓ¦Óõ½VLAN 1µÄ³ö¿Ú£¬£¬£¬£¬£¬£¬£¬½«ÎÞ·¨ÉúЧ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÄ¿µÄIP²»ÔÚVLAN 1×ÓÍøIP¹æÄ£ÄÚ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACEΪdeny udp any 192.168.64.1 0.0.0.255 eq 255½«¿ÉÒÔÉúЧ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÄ¿µÄIPÇкϻ®¶¨¡£¡£¡£¡£¡£¡£¡£

¡ñ     ÓÉÓÚACL×ÊÔ´£¨TCAM/KEY/¶Ë¿Ú×é/RangeµÈ£©Êô¶¯Ì¬·ÖÅÉ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬¼´ÓªÒµÏ·¢Ê±Õ½ÂÔÕûºÏ×ÊÔ´Ä£¿£¿£¿£¿£¿£¿éƾ֤Ŀ½ñµÄACL×ÊÔ´ÇéÐξÙÐзÖÅÉ£¬£¬£¬£¬£¬£¬£¬Ïȵ½µÄÓªÒµÏÈ·ÖÅÉACL×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ºóµ½µÄÓªÒµÈôÊÇACL×ÊÔ´²»·ó¾Í»á±£´æACL×ÊÔ´·ÖÅÉʧ°Ü£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐѹýʧsyslog¡£¡£¡£¡£¡£¡£¡£×°±¸ÖØÆôÀú³Ì»òÈȰβåµÈ´¥·¢Êý¾Ýͬ²½µÄÀú³Ì£¬£¬£¬£¬£¬£¬£¬¸÷ÓªÒµÎÞ·¨°ü¹Ü°´Ô­À´µÄʱÐò½«ÓªÒµÍ¬²½£¬£¬£¬£¬£¬£¬£¬ÓпÉÄÜ´¥·¢ÓÉÓÚӪҵʱÐò·×ÆçÑùµ¼ÖÂÔ­±¾¿ÉÒÔ·ÖÅɵ½ACL×ÊÔ´µÄÓªÒµ·ÖÅɲ»µ½ACL×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ACL×ÊԴȱ·¦»áÌáÐѹýʧsyslog¡£¡£¡£¡£¡£¡£¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇéÐÎ

¡ñ     ×÷ÓÃÔÚÎïÀí¿ÚºÍÈý²ã¾ÛºÏ½Ó¿ÚÉϵijöÆ«ÏòACL£¬£¬£¬£¬£¬£¬£¬½öÖ§³ÖÆ¥Åä×ÅÃû±¨ÎÄ£¨µ¥²¥¡¢×é²¥£©£¬£¬£¬£¬£¬£¬£¬²»Ö§³ÖÆ¥Åäδ×ÅÃûµ¥²¥£¬£¬£¬£¬£¬£¬£¬¼´¹ØÓÚδ×ÅÃû±¨ÎÄ»òÕ߹㲥±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚÉÏÉèÖõijöÆ«ÏòACL²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

¡ñ     ÈëÆ«ÏòACLºÍ802.1x£¬£¬£¬£¬£¬£¬£¬È«¾ÖIPºÍMAC°ó¶¨£¬£¬£¬£¬£¬£¬£¬¶Ë¿ÚÇå¾²£¬£¬£¬£¬£¬£¬£¬IP Source Guard¹²ÓÃʱ£¬£¬£¬£¬£¬£¬£¬PermitºÍĬÈÏDenyµÄACE²»ÉúЧ£¬£¬£¬£¬£¬£¬£¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ¡£¡£¡£¡£¡£¡£¡£

¡ñ     ÈëÆ«ÏòACLºÍQoS¹²ÓÃʱ£¬£¬£¬£¬£¬£¬£¬Permit±íÏîµÄACE²»ÉúЧ£¬£¬£¬£¬£¬£¬£¬ÆäËûDeny±íÏîµÄACEÕý³£ÉúЧ£»£»£»£»£»Ä¬ÈÏDeny±íÏîµÄACEÔÚQoS±íÏîºóÉúЧ¡£¡£¡£¡£¡£¡£¡£

¡ñ     ÓÉÓÚÓ²¼þÈÝÁ¿µÄÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬×÷ÓÃÔÚ¶à¸öSVI½Ó¿ÚµÄÈëÆ«ÏòACL£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÔÙÌí¼ÓACE£¬£¬£¬£¬£¬£¬£¬ÉúÑÄÉèÖÃÖØÆôºó¿ÉÄܵ¼Ö²¿·ÖSVI½Ó¿ÚÉϵÄACLÎÞ·¨ÉèÖÃÀֳɡ£¡£¡£¡£¡£¡£¡£

 

*     ˵Ã÷

¡ñ     µ±ÉèÖÃר¼Ò¼¶µÄACL£¬£¬£¬£¬£¬£¬£¬²¢Ó¦ÓÃÔڽӿڵijöÆ«Ïòʱ£¬£¬£¬£¬£¬£¬£¬ÈôÊǸÃACLÖеÄijЩACE°üÀ¨Èý²ãÆ¥ÅäÐÅÏ¢£¨ÀýÈçIP£¬£¬£¬£¬£¬£¬£¬L4portµÈ£©£¬£¬£¬£¬£¬£¬£¬½«µ¼Ö´ÓÓ¦ÓýӿڽøÈëµÄ·ÇIP±¨ÎÄÎÞ·¨ÊܸÃACLµÄPermitºÍDeny¹æÔò¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£

¡ñ     Ó¦ÓÃACLʱ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL£¨°üÀ¨IP ACLºÍר¼Ò¼¶À©Õ¹ACL£©ÖеÄACEÆ¥ÅäÁ˷Ƕþ²ã×ֶΣ¬£¬£¬£¬£¬£¬£¬ÀýÈçÔ´IP£¬£¬£¬£¬£¬£¬£¬Ä¿µÄIPʱ£¬£¬£¬£¬£¬£¬£¬¹ØÓÚ´ø±êÇ©µÄMPLS±¨ÎÄÆ¥ÅäÊÇÎÞЧµÄ¡£¡£¡£¡£¡£¡£¡£

 

2.    IP ACL

IP ACLÖ÷ÒªÓÃÓÚ¶ÔÊÕÖ§×°±¸µÄIPv4±¨ÎľÙÐÐϸÄ廯¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÆ¾Ö¤ÏÖʵÐèÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

ÔÚIP ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬²¢½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ¶ÔIP ACL¾ÙÐÐÈ«¾ÖÓ¦Óᣡ£¡£¡£¡£¡£¡£µ±IPv4±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸Í¨¹ýÅжϱ¨ÎÄÊÇ·ñÓë¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

ÒªÔÚ×°±¸ÉÏÉèÖÃIP ACL£¬£¬£¬£¬£¬£¬£¬±ØÐèΪ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãΨһ±êʶÿ¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£

IP ACL·ÖΪIP±ê×¼ACLºÍIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£±í1-1ÁгöÁËIP±ê×¼ACLºÍIPÀ©Õ¹ACL¿ÉÒÔʹÓõıàºÅ¹æÄ£¡£¡£¡£¡£¡£¡£¡£

±í1-1     IP±ê×¼ACLºÍIPÀ©Õ¹ACL±àºÅ¹æÄ£

ÀàÐÍ

±àºÅ¹æÄ£

Æ¥ÅäÓò

IP±ê×¼ACL

1~99£¬£¬£¬£¬£¬£¬£¬1300~1999

Ô´IPµØµã

IPÀ©Õ¹ACL

100~199£¬£¬£¬£¬£¬£¬£¬2000~2699

¡ñ    Ô´IPµØµã

¡ñ    Ä¿µÄIPµØµã

¡ñ    IPЭÒéºÅ

¡ñ    ËIJãÔ´¶Ë¿ÚºÅ»òICMP type

¡ñ    ËIJãÄ¿µÄ¶Ë¿ÚºÅ»òICMP code

 

IP±ê×¼ACLÖ÷Ҫƾ֤ԴIPµØµã¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£IPÀ©Õ¹ACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓòµÄ×éºÏ£¬£¬£¬£¬£¬£¬£¬¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£

¹ØÓÚ¼òµ¥µÄ»á¼ûÁбíÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓöàÌõ×ÔÁ¦µÄ»á¼ûÁбíÓï¾äÀ´½ç˵¶àÖÖ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬£¬£¬£¬£¬£¬£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£

*     ˵Ã÷

ACL¹æÔòÖеÄICMP codeÆ¥ÅäÓò¶ÔICMP typeΪ3µÄICMP±¨ÎÄÎÞЧ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇACL¹æÔòÖÐÉèÖÃÁËҪƥÅäICMP±¨ÎĵÄcode×ֶΣ¬£¬£¬£¬£¬£¬£¬µ±TypeΪ3µÄICMP±¨ÎĽøÈë×°±¸Ö´ÐÐACLÆ¥Åäʱ£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäЧ¹û¿ÉÄÜÓëÔ¤ÆÚµÄ·×ÆçÑù¡£¡£¡£¡£¡£¡£¡£

 

ÿ¸öIP ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔòÓï¾ä¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º

access-list 1 permit host 192.168.4.12

´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ192.168.4.12µÄ±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÆäËüÖ÷»ú¶¼½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º

access-list 1 deny any

ÓÖÀýÈ磺

access-list 1 deny host 192.168.4.12

ÈôÊÇÁбíÖ»°üÀ¨ÒÔÉÏÕâÒ»ÌõÓï¾ä£¬£¬£¬£¬£¬£¬£¬ÔòÈκÎÖ÷»ú±¨ÎÄͨ¹ý¸Ã½Ó¿Úʱ¶¼½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£

*    ×¢ÖØ

ÔÚ½ç˵»á¼ûÁбíµÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬ÒªË¼Á¿µ½Â·Óɸüеı¨ÎÄ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ»á¼ûÁбíĩβ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂËùÓеÄ·Óɸüб¨Îı»×è¶Ï¡£¡£¡£¡£¡£¡£¡£

 

3.    MACÀ©Õ¹ACL

MACÀ©Õ¹ACL»ùÓÚ±¨ÎĵĶþ²ãÐÅÏ¢À´¶ÔÊÕÖ§×°±¸µÄ±¨ÎľÙÐÐϸÄ廯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔÆ¾Ö¤ÏÖʵÐèÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖƱ£»£»£»£»£»¤ÍøÂç×ÊÔ´²»Êܹ¥»÷»òÕß¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

ÔÚMACÀ©Õ¹ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£µ±±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸Åжϱ¨ÎÄÊÇ·ñÓë¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

ÒªÔÚ×°±¸ÉÏÉèÖÃMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬±ØÐèΪ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãΨһ±êʶÿ¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£±í1-2ÁгöMACÀ©Õ¹ACLµÄ±àºÅ¹æÄ£¡£¡£¡£¡£¡£¡£¡£

±í1-2     MACÀ©Õ¹ACL±àºÅ¹æÄ£

ЭÒé

±àºÅ¹æÄ£

Æ¥ÅäÓò

MACÀ©Õ¹ACL

700~799

¡ñ    Ô´MACµØµã

¡ñ    Ä¿µÄMACµØµã

¡ñ    ÒÔÌ«ÍøÐ­ÒéÀàÐÍ

 

MACÀ©Õ¹ACLƾ֤Դ»òÄ¿µÄMACµØµãÒÔ¼°±¨ÎĵÄÒÔÌ«ÍøÀàÐÍÀ´¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£

¹ØÓÚ¼òµ¥µÄMACÀ©Õ¹ACLÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓöàÌõ×ÔÁ¦µÄ»á¼ûÁбíÓï¾äÀ´½ç˵¶àÖÖ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐËùÓеÄÓï¾äÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬£¬£¬£¬£¬£¬£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£

*     ˵Ã÷

ÈôÊÇMACÀ©Õ¹ACL¹æÔòÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλò½ç˵µÄÒÔÌ«ÍøÀàÐÍ×Ö¶ÎÖµ²»ÊÇ0x86dd£¬£¬£¬£¬£¬£¬£¬ÄÇôMACÀ©Õ¹ACL²»Æ¥ÅäIPv6±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÇëʹÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

 

ÿ¸öMACÀ©Õ¹ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔòÓï¾ä¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º

access-list 700 permit host 00d0.f800.0001 any

´ËÁбíÖ»ÔÊÐíÀ´×ÔMACµØµãΪ00d0.f800.0001µÄÖ÷»ú·¢³öµÄ±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬À´×ÔÆäËüÖ÷»úµÄ±¨Îͼ½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º

access-list 700 deny any any

4.    ר¼Ò¼¶À©Õ¹ACL

ר¼Ò¼¶À©Õ¹ACL»ùÓÚ±¨ÎĵĶþ²ãºÍÈý²ãÐÅÏ¢¶ÔÊÕÖ§×°±¸µÄ±¨ÎľÙÐÐϸÄ廯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔ½«×¨¼Ò¼¶À©Õ¹ACL¿´×÷ÊÇIP ACLºÍMACÀ©Õ¹ACLµÄÒ»ÖÖÍŽáÓëÔöÇ¿¡£¡£¡£¡£¡£¡£¡£×¨¼Ò¼¶À©Õ¹ACLÖеĹæÔò²»µ«¿ÉÒÔ°üÀ¨IP ACL¹æÔòºÍMACÀ©Õ¹ACL¹æÔò£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÖ¸¶¨»ùÓÚVLAN IDÀ´Æ¥Å䱨ÎÄ¡£¡£¡£¡£¡£¡£¡£

ÔÚר¼Ò¼¶À©Õ¹ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬²¢½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸¾Í»áͨ¹ýÅжϱ¨ÎÄÊÇ·ñÓë»á¼û¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

ÒªÔÚ×°±¸ÉÏÉèÖÃר¼Ò¼¶À©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬±ØÐèΪЭÒéµÄ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ»ò±àºÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÔÚЭÒéÄÚ²¿Äܹ»Î¨Ò»±êʶÿ¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£±í1-3Áгöר¼Ò¼¶À©Õ¹ACLµÄ±àºÅ¹æÄ£¡£¡£¡£¡£¡£¡£¡£

±í1-3     ר¼Ò¼¶À©Õ¹ACLµÄ±àºÅ¹æÄ£

ЭÒé

±àºÅ¹æÄ£

Æ¥ÅäÓò

ר¼Ò¼¶À©Õ¹ACL

2700~2899

¡ñ    Ô´IPµØµã

¡ñ    Ä¿µÄIPµØµã

¡ñ    IPЭÒéºÅ

¡ñ    ËIJãÔ´¶Ë¿ÚºÅ»òICMP type

¡ñ    ËIJãÄ¿µÄ¶Ë¿ÚºÅ»òICMP code

¡ñ    Ô´MACµØµã

¡ñ    Ä¿µÄMACµØµã

¡ñ    ÒÔÌ«ÍøÐ­ÒéÀàÐÍ

¡ñ    VLAN ID

 

ר¼Ò¼¶À©Õ¹ACLͨ¹ý¶Ô±íÖÐÆ¥ÅäÓò¾ÙÐÐ×éºÏ£¬£¬£¬£¬£¬£¬£¬¿ØÖƱ¨ÎĵÄת·¢»ò×è¶Ï¡£¡£¡£¡£¡£¡£¡£

¹ØÓÚ¼òµ¥µÄר¼Ò¼¶À©Õ¹ACLÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓöàÌõ×ÔÁ¦µÄ»á¼ûÁбíÓï¾äÀ´½ç˵¶àÖÖ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÆäÖÐËùÓеÄÓï¾äÐèÒýÓÃͳһ¸ö±àºÅ»òÃû×Ö£¬£¬£¬£¬£¬£¬£¬ÒԱ㽫ÕâЩÓï¾ä°ó¶¨µ½Í³Ò»¸ö»á¼ûÁÐ±í¡£¡£¡£¡£¡£¡£¡£

*     ˵Ã÷

ÈôÊÇר¼Ò¼¶À©Õ¹ACL¹æÔòÖÐûÓÐÖ¸¶¨ÊÇÕë¶ÔIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¼´Ã»Óнç˵ÒÔÌ«ÍøÀàÐÍ×ֶλòÒÔÌ«ÍøÀàÐÍ×ֶβ»ÊÇ0x86dd£¬£¬£¬£¬£¬£¬£¬ÄÇôר¼Ò¼¶À©Õ¹ACL²»Æ¥ÅäIPv6±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§ÏëÆ¥ÅäIPv6±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÇëʹÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇéÐÎ

¡ñ     Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©Õ¹ACLÖУ¬£¬£¬£¬£¬£¬£¬VXLAN×Ö¶ÎÑ¡ÏîÖ÷ÒªÊÇΪÁËÆ¥ÅäVXLANµÄÄڲ㱨ÎÄ£¬£¬£¬£¬£¬£¬£¬Òò´ËVXLANģʽÏ¿ÉÒÔÓ¦ÓÃר¼Ò¼¶ACLÆ¥ÅäVXLANµÄÄÚ²ãIP×ֶΡ£¡£¡£¡£¡£¡£¡£

¡ñ     µ±×°±¸ÐèҪƥÅäVXLAN±¨ÎÄʱ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÖ¸¶¨VXLANЭÒéÄ¿µÄ¶Ë¿ÚºÅÓÃÓÚÈ·ÈÏVXLAN±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±¿ÉÒÔÖ¸¶¨Æ¥Åä¸ÃVXLAN±¨ÎÄÊÇ·ñЯ´øTag¡£¡£¡£¡£¡£¡£¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇéÐÎ

Êý¾ÝÖÐÐIJúÆ·µÄר¼Ò¼¶À©Õ¹ACLÖÐUDFÑ¡ÏîÊÇÓû§×Ô½ç˵×Ö¶ÎÆ¥ÅäÓò£¬£¬£¬£¬£¬£¬£¬ÓÉÓû§Ö¸¶¨ÐèҪƥÅäµÄЭÒé²ã¡¢Æ«ÒÆÖµ¡¢Êý¾ÝºÍÑÚÂë¡£¡£¡£¡£¡£¡£¡£

 

ÿ¸öר¼Ò¼¶À©Õ¹ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±¹æÔòÓï¾ä¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º

access-list 2700 permit 0x0806 any any any any any

´ËÁбíÖ»ÔÊÐíÒÔÌ«ÍøÀàÐÍΪ0x0806£¨¼´ARP£©µÄ±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÆäËûÀàÐ͵ı¨Îͼ½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º

access-list 2700 deny any any any any

5.    IPv6 ACL

IPv6 ACLÖ÷ÒªÓÃÓÚ¶ÔÊÕÖ§×°±¸µÄIPv6±¨ÎľÙÐÐϸÄ廯¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔÆ¾Ö¤ÏÖʵÐèÒª×èÖ¹»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPv6Óû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

ÔÚIPv6 ACLÖнç˵һϵÁеĻá¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬²¢½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£µ±IPv6±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬×°±¸Åжϱ¨ÎÄÊÇ·ñÓë¹æÔòÆ¥ÅäÀ´¾öÒéÊÇ·ñת·¢»ò×è¶Ï±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

ÒªÔÚ×°±¸ÉÏÉèÖûá¼ûÁбí£¬£¬£¬£¬£¬£¬£¬±ØÐèΪЭÒéµÄ»á¼ûÁбíÖ¸¶¨Ò»¸öΨһµÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£

ÿ¸öIPv6 ACLµÄĩβÒþº¬×ÅÒ»Ìõ¡°¾Ü¾øËùÓÐIPv6Êý¾ÝÁ÷¡±¹æÔòÓï¾ä£¬£¬£¬£¬£¬£¬£¬Òò´ËÈôÊDZ¨ÎÄÓëÈκιæÔò¶¼²»Æ¥Å䣬£¬£¬£¬£¬£¬£¬½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÈçÏÂÀý£º

ipv6 access-list ipv6_acl

?10 permit ipv6 host 200::1 any

´ËÁбíÖ»ÔÊÐíÔ´Ö÷»úΪ200::1µÄIPv6±¨ÎÄͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÆäËüÖ÷»ú·¢³öµÄIPv6±¨Îͼ½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÌõ»á¼ûÁбí×îºó°üÀ¨ÁËÒ»Ìõ¹æÔòÓï¾ä£º

deny ipv6 any any

6.    ר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©

ר¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬¼´ACL80£¬£¬£¬£¬£¬£¬£¬Ò²³ÆÎª×Ô½ç˵ACL¡£¡£¡£¡£¡£¡£¡£ACL80Ö§³Ö¶Ô±¨ÎĵÄǰ80¸ö×Ö½ÚÖеÄÖ¸¶¨×Ö½Ú°´±ÈÌØÎ»¾ÙÐÐÆ¥Åä¡£¡£¡£¡£¡£¡£¡£

ACL80Æ¥ÅäʱÓÐÈý¸öÒªËØ£ºÆ¥ÅäÓòÄÚÈÝ¡¢Æ¥ÅäÓòÑÚÂëÒÔ¼°Æ¥ÅäµÄÆðʼλÖ㨼´Æ«ÒÆÁ¿offset£©¡£¡£¡£¡£¡£¡£¡£Æ¥ÅäÓòÄÚÈÝºÍÆ¥ÅäÓòÑÚÂëÁ½ÕߵıÈÌØÎ»ÊÇÖðÒ»¶ÔÓ¦µÄ¡£¡£¡£¡£¡£¡£¡£Æ¥ÅäÓòÄÚÈÝÖ¸Ã÷ÐèҪƥÅäµÄ×Ö¶ÎÖµ£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂëÖ¸Ã÷¶ÔÓ¦±ÈÌØÎ»ÊÇ·ñÐèҪƥÅä¡£¡£¡£¡£¡£¡£¡£µ±ÐèҪƥÅäij¸ö±ÈÌØÎ»Ê±£¬£¬£¬£¬£¬£¬£¬±ØÐ轫ƥÅäÓòÑÚÂëÖжÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ1¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÆ¥ÅäÓòÑÚÂë¶ÔÓ¦µÄ±ÈÌØÎ»ÉèÖÃΪ0£¬£¬£¬£¬£¬£¬£¬ÎÞÂÛÆ¥ÅäÓòÄÚÈÝÖжÔÓ¦µÄ±ÈÌØÎ»ÊÇʲô£¬£¬£¬£¬£¬£¬£¬¶¼²»»áÆ¥Åä¡£¡£¡£¡£¡£¡£¡£ÀýÈ磺

10 permit 00d0f8123456 ffffffffffff 0

20 deny 00d0f8654321 ffffffffffff 6

ÔÚÐòºÅΪ10µÄACEÖУ¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8123456£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂëΪffffffffffff£¬£¬£¬£¬£¬£¬£¬Æ«ÒÆÁ¿Îª0¡£¡£¡£¡£¡£¡£¡£ÕâÌõ¹æÔòÌåÏÖÈôÊDZ¨ÎĵÄÄ¿µÄMACΪ00d0f8123456£¬£¬£¬£¬£¬£¬£¬ÔòÔÊÐí±¨ÎÄת·¢¡£¡£¡£¡£¡£¡£¡£

ÔÚÐòºÅΪ20µÄACEÖУ¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÄÚÈÝΪ00d0f8654321£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂëΪffffffffffff£¬£¬£¬£¬£¬£¬£¬Æ«ÒÆÁ¿Îª6¡£¡£¡£¡£¡£¡£¡£ÕâÌõ¹æÔòÌåÏÖÈôÊDZ¨ÎĵÄÔ´MACΪ00d0f8654321£¬£¬£¬£¬£¬£¬£¬Ôò×è¶Ï¸Ã±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

׼ȷʹÓÃ×Ô½ç˵»á¼û¿ØÖÆÁбíÐèÒª¶Ô¶þ²ãÊý¾ÝÖ¡½á¹¹ÓÐÉîÈëµÄÏàʶ¡£¡£¡£¡£¡£¡£¡£¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâÈçͼ1-2Ëùʾ¡£¡£¡£¡£¡£¡£¡£Í¼ÖÐÿ¸ö×Öĸ´ú±íÒ»¸öÊ®Áù½øÖÆÊý£¬£¬£¬£¬£¬£¬£¬Ã¿Á½¸ö×Öĸ´ú±íÒ»¸ö×Ö½Ú¡£¡£¡£¡£¡£¡£¡£

ͼ1-2     ¶þ²ãÊý¾Ý֡ǰ64¸ö×Ö½ÚʾÒâͼ

 

¸÷¸ö×ÖĸµÄ¼ÄÒå¼°Æ«ÒÆÁ¿È¡ÖµÈç±í1-4Ëùʾ¡£¡£¡£¡£¡£¡£¡£

±í1-4     ×ÖĸµÄ¼ÄÒå¼°Æ«ÒÆÁ¿È¡Öµ

×Öĸ

¼ÄÒå

Æ«ÒÆÁ¿

×Öĸ

¼ÄÒå

Æ«ÒÆÁ¿

A

Ä¿µÄMAC

0

O

TTL×Ö¶Î

34

B

Ô´MAC

6

P

ЭÒéºÅ

35

C

VLAN Tag×Ö¶Î

12

Q

IPУÑéºÍ

36

D

Êý¾ÝÖ¡³¤¶È×Ö¶Î

16

R

Ô´IPµØµã

38

E

DSAP(Ä¿µÄ·þÎñ»á¼ûµã)×Ö¶Î

18

S

Ä¿µÄIPµØµã

42

F

SSAP(Ô´·þÎñ»á¼ûµã)×Ö¶Î

19

T

TCPÔ´¶Ë¿Ú

46

G

Ctrl×Ö¶Î

20

U

TCPÄ¿µÄ¶Ë¿Ú

48

H

Org Code×Ö¶Î

21

V

ÐòÁкÅ

50

I

·â×°µÄÊý¾ÝÀàÐÍ

24

W

È·ÈÏ×Ö¶Î

54

J

IP°æ±¾ºÅ

26

XY

IPÍ·³¤¶ÈºÍ±£´æ±ÈÌØÎ»

58

K

TOS×Ö¶Î

27

Z

±£´æ±ÈÌØÎ»ºÍFlags±ÈÌØÎ»

59

L

IP°üµÄ³¤¶È

28

a

Windows Size×Ö¶Î

60

M

IDºÅ

30

b

ÆäËû

62

N

Flags×Ö¶Î

32

 

 

 

 

±íÖи÷¸ö×Ö¶ÎµÄÆ«ÒÆÁ¿ÊÇËüÃÇÔÚSNAP£«TagµÄ802.3Êý¾ÝÖ¡ÖÐµÄÆ«ÒÆÁ¿¡£¡£¡£¡£¡£¡£¡£ÔÚ×Ô½ç˵»á¼û¿ØÖÆÁбíÖУ¬£¬£¬£¬£¬£¬£¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿£¬£¬£¬£¬£¬£¬£¬´ÓÊý¾ÝÖ¡µÄǰ80¸ö×Ö½ÚÖÐÌáȡָ¶¨×Ö½Ú£¬£¬£¬£¬£¬£¬£¬ÔÙºÍÆ¥ÅäÓòÄÚÈݽÏÁ¿£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¶Ô±¨ÎÄ×÷ÏìÓ¦µÄ´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬Óû§ÔÊÐíËùÓеÄTCP±¨ÎÄת·¢£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔ½«Æ¥ÅäÓòÄÚÈݽç˵Ϊ¡°06¡±£¬£¬£¬£¬£¬£¬£¬Æ¥ÅäÓòÑÚÂë½ç˵Ϊ¡°ff¡±£¬£¬£¬£¬£¬£¬£¬Æ«ÒÆÁ¿½ç˵Ϊ35¡£¡£¡£¡£¡£¡£¡£½¨ÉèÐòºÅΪ10µÄACEÈçÏ¡£¡£¡£¡£¡£¡£¡£

10 permit 06 ff 35

½«»á¼ûÁбíÓ¦ÓÃÔÚ½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£µ±±¨ÎÄÊÕÖ§×°±¸Ê±£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÆ¥ÅäÓòÑÚÂëºÍÆ«ÒÆÁ¿£¬£¬£¬£¬£¬£¬£¬´ÓÊý¾ÝÖ¡Öн«TCPЭÒéºÅ×ֶεÄÄÚÈÝÌáÈ¡³öÀ´£¬£¬£¬£¬£¬£¬£¬ÔÙºÍÆ¥ÅäÓòÄÚÈݽÏÁ¿£¬£¬£¬£¬£¬£¬£¬Æ¥Åä³öËùÓеÄTCP±¨ÎIJ¢¾ÙÐÐת·¢¡£¡£¡£¡£¡£¡£¡£

7.    ACLÖØ¶¨Ïò

ACLÖØ¶¨ÏòµÄ×÷ÓÃÊǽ«ÇкϹæÔòµÄ±¨ÎÄÖØ¶¨ÏòÖÁÖ¸¶¨½Ó¿Úת·¢£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨½Ó¿ÚÉÏץȡ±¨ÎļÓÒÔÆÊÎö¡£¡£¡£¡£¡£¡£¡£

ACLÖØ¶¨ÏòÔÚÖ¸¶¨½Ó¿ÚÉϰ󶨲î±ðµÄACLÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬²¢¸øÃ¿¸öÕ½ÂÔÖ¸¶¨Ò»¸öÊä³ö½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£µ±¸Ã½Ó¿ÚÊÕµ½±¨ÎÄʱ£¬£¬£¬£¬£¬£¬£¬½«ÖðÌõ²éÕÒ°ó¶¨ÔڸýӿÚÉϵÄACLÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£ÈôÊDZ¨ÎÄÇкÏijÌõÕ½ÂÔÐÎòµÄÌØÕ÷£¬£¬£¬£¬£¬£¬£¬½«´Ó¸ÃÕ½ÂÔËùÖ¸¶¨µÄÊä³ö½Ó¿Úת·¢¡£¡£¡£¡£¡£¡£¡£

8.    È«¾ÖÇå¾²ACL

ÓÉÓÚÍøÂçÖб£´æÖݪֲ¡¶¾±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÇÒ¸÷¶Ë¿ÚϵIJ¡¶¾±¨ÎÄʶ±ðÌØÕ÷Ïàͬ»òÏàËÆ¡£¡£¡£¡£¡£¡£¡£¶Ë¿ÚÇå¾²ACL³£±»ÉèÖÃ×÷Ϊ²¡¶¾±¨ÎĹýÂ˼°Ìá·ÀʹÓ㬣¬£¬£¬£¬£¬£¬ÓÃÓÚ¹ýÂËÇкÏÄ³Ð©ÌØÕ÷µÄ±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÀýÈ磺αÔìµÄTCP¹¥»÷±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£Í¨¹ý½¨ÉèACL²¢Ìí¼ÓÆ¥ÅäÖݪֲ¡¶¾±¨ÎÄÌØÕ÷µÄACEºó£¬£¬£¬£¬£¬£¬£¬½«ACLÓ¦Óõ½×°±¸¸÷¸ö¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬µÖ´ï¹ýÂ˲¡¶¾±¨ÎĵÄ×÷Óᣡ£¡£¡£¡£¡£¡£¶Ë¿ÚÇå¾²ACLÓÃÓÚ²¡¶¾¹ýÂ˵ȿ¹¹¥»÷³¡¾°Ê±£¬£¬£¬£¬£¬£¬£¬±£´æ½Ï¶àδ±ã¡£¡£¡£¡£¡£¡£¡£

l  ¶Ë¿ÚÐèÒªÖð¸öÉèÖᣡ£¡£¡£¡£¡£¡£±£´æÖظ´ÉèÖᢲÙ×÷ÐÔÄܵÍϼ°ACL×ÊÔ´Ì«¹ýÏûºÄµÄÇéÐΡ£¡£¡£¡£¡£¡£¡£

l  Çå¾²ACLµÄ»á¼û¿ØÖÆ×÷Óñ»Èõ»¯¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ±»ÓÃÓÚ²¡¶¾¹ýÂË£¬£¬£¬£¬£¬£¬£¬Çå¾²ACLµÄÏÞÖÆÂ·ÓɸüС¢ÏÞÖÆÍøÂç»á¼ûµÈ»ù±¾¹¦Ð§ÎÞ·¨Õý³£Ê¹Óᣡ£¡£¡£¡£¡£¡£

È«¾ÖÇå¾²ACL¿ÉÒÔÔÚ²»Ó°Ïì¶Ë¿ÚÇå¾²ACLµÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬¾ÙÐÐÈ«¾Ö¿¹²¡¶¾°²Åż°·ÀÓù¡£¡£¡£¡£¡£¡£¡£È«¾ÖÇå¾²ACLÖ»ÐèÒªÒ»ÌõÏÂÁî¼´ÔÚËùÓжþ²ã½Ó¿ÚÉÏÉúЧ¡£¡£¡£¡£¡£¡£¡£

µ±È«¾ÖÇå¾²ACLÓë¶Ë¿ÚÇå¾²ACLͬʱÉèÖÃʱ£¬£¬£¬£¬£¬£¬£¬Á½ÕßÅäºÏÉúЧ¡£¡£¡£¡£¡£¡£¡£¹ØÓÚÆ¥ÅäÈ«¾ÖÇå¾²ACL¹æÔòµÄ±¨ÎĽ«±»¿´³É²¡¶¾±¨ÎÄÖ±½Ó¹ýÂË£¬£¬£¬£¬£¬£¬£¬¹ØÓÚûÓÐÆ¥ÅäÈ«¾ÖÇå¾²ACL¹æÔòµÄ±¨ÎĽ«¼ÌÐøÊܶ˿ÚÇå¾²ACL¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÏëÈÃijЩ¶Ë¿Ú²»ÊÜÈ«¾ÖÇå¾²ACLµÄ¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÕâЩ½Ó¿ÚÉÏ×ÔÁ¦¹Ø±ÕÈ«¾ÖÇå¾²ACL¹¦Ð§¡£¡£¡£¡£¡£¡£¡£µ±È«¾Ö¡¢½Ó¿ÚºÍVLANµÄÇå¾²ACLͬʱӦÓÃʱ£¬£¬£¬£¬£¬£¬£¬ÓÅÏȼ¶½Ó¿Ú > VLAN > È«¾Ö¡£¡£¡£¡£¡£¡£¡£

ΪÁË×èֹȫ¾ÖÇå¾²ACL±»ÎóÉèÖ㬣¬£¬£¬£¬£¬£¬ÐÂÔöÈ«¾ÖÇå¾²ACLÎÞЧ¿ª¹Ø¡£¡£¡£¡£¡£¡£¡£ÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧºó£¬£¬£¬£¬£¬£¬£¬ÔÙÉèÖÃÈ«¾ÖÇå¾²ACL£¬£¬£¬£¬£¬£¬£¬»áÌáÐÑÉèÖÃʧ°Ü¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÒѾ­ÉèÖÃÁËÈ«¾ÖÇå¾²ACL£¬£¬£¬£¬£¬£¬£¬ÔÙÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧ£¬£¬£¬£¬£¬£¬£¬ÄÇô»á½«Ä¿½ñËùÓÐÈ«¾ÖÇå¾²ACLɾ³ý£¬£¬£¬£¬£¬£¬£¬²¢¸ø³öÈÕÖ¾ÌáÐÑ¡£¡£¡£¡£¡£¡£¡£

9.    SVI Router ACL

Ó¦ÓÃÔÚSVI½Ó¿ÚÉϵĻá¼ûÁÐ±í£¨¼´SVI ACL£©»áͬʱ¶ÔVLANÄÚ¶þ²ãת·¢µÄ±¨Îļ°VLAN¼äµÄ·Óɱ¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂͳһVLANÄÚ²î±ðÓû§Ö®¼äÎÞ·¨Õý³£Í¨Ñ¶µÈÒì³£Õ÷Ï󡣡£¡£¡£¡£¡£¡£Ê¹ÓÃSVI Router ACL¹¦Ð§¿ÉÒÔʹӦÓÃÔÚSVI½Ó¿ÚÉϵĻá¼ûÁбí½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬SVI Router ACL¹¦Ð§Ä¬ÈϹرա£¡£¡£¡£¡£¡£¡£SVI ACLͬʱ¶ÔVLAN¼äµÄÈý²ãת·¢±¨Îļ°VLANÄÚµÄÇÅת·¢±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£SVI Router ACL¹¦Ð§¿ªÆôºó£¬£¬£¬£¬£¬£¬£¬SVI ACL½ö¶ÔVLAN¼äµÄÈý²ãת·¢±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

10. ?±¨ÎÄÆ¥ÅäÈÕÖ¾

±¨ÎÄÆ¥ÅäÈÕÖ¾ÓÃÓÚ¼à¿Ø»á¼ûÁÐ±í¹æÔòµÄÔËÐÐ״̬£¬£¬£¬£¬£¬£¬£¬ÎªÒ»Ñùƽ³£ÍøÂçά»¤ÒÔ¼°ÍøÂçÓÅ»¯ÌṩÐëÒªµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

ΪÁËÈÃÓû§¸üºÃµÄÕÆÎÕACLÔÚ×°±¸ÖеÄÔËÐÐ״̬£¬£¬£¬£¬£¬£¬£¬ÔÚÌí¼ÓACEʱ¿ÉÒÔÆ¾Ö¤ÐèÒª¾öÒéÊÇ·ñÖ¸¶¨±¨ÎÄÆ¥ÅäÈÕÖ¾Êä³öÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÖ¸¶¨Á˸ÃÑ¡Ï£¬£¬£¬£¬£¬£¬Ôòµ±ACEÆ¥Åäµ½±¨ÎÄʱÊä³öÆ¥ÅäÈÕÖ¾ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ACL»ùÓÚACE´òÓ¡ÈÕÖ¾ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¼´×°±¸ÖÜÆÚÐԵĴòÓ¡Æ¥Å䱨ÎĵÄACEÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Æ¥ÅäµÄ±¨ÎÄÊýÄ¿¡£¡£¡£¡£¡£¡£¡£ÈçÏ£º

*Sep¡¡9 16:23:06: %ACL-6-MATCH: ACL 100 ACE 10 permit icmp any any, match 78 packets.

ΪºÏÀí¿ØÖÆÈÕÖ¾Êä³öµÄÊýÄ¿ºÍƵÂÊ£¬£¬£¬£¬£¬£¬£¬ACLÖ§³ÖÉèÖÃÈÕÖ¾Êä³ö¾àÀëµÄÉèÖᣡ£¡£¡£¡£¡£¡£

*    ×¢ÖØ

¡ñ     ´øÈÕ־ѡÏîµÄ»á¼ûÁÐ±í¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐÈÕ־ѡÏ£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£

¡ñ     ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖûá¼ûÁÐ±í¹æÔòʱָ¶¨ÁËÈÕ־ѡÏîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

¡ñ     ¹ØÓÚ´øÈÕ־ѡÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇéÐÎ

½öÖ§³ÖΪIP ACLºÍIPv6 ACL¹æÔòÉèÖÃÈÕ־ѡÏî¡£¡£¡£¡£¡£¡£¡£

 

11. ?±¨ÎÄÆ¥Å伯Êý

³öÓÚÍøÂçÖÎÀíµÄÐèÒª£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÄÜÏëÖªµÀijÌõ»á¼ûÁÐ±í¹æÔòÊÇ·ñÆ¥Åäµ½±¨ÎÄÒÔ¼°Æ¥ÅäÊýÄ¿¡£¡£¡£¡£¡£¡£¡£ACLÌṩÁË»ùÓÚ¹æÔòµÄ±¨ÎÄÆ¥Å伯Êý¹¦Ð§¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉÒÔ»ùÓÚACL¿ªÆôºÍ¹Ø±Õ¸ÃACLϵÄËùÓйæÔòµÄ±¨ÎÄÆ¥Å伯Êý¹¦Ð§¡£¡£¡£¡£¡£¡£¡£µ±Óб¨ÎÄÆ¥Åäµ½ÁËÕâÌõ¹æÔò£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦µÄÆ¥Å伯Êý¾ÍÏìÓ¦µØÔöÌí¡£¡£¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýACLµÄͳ¼ÆÉ¨³ýÏÂÁ¸ÃACLÏÂËùÓйæÔòµÄ±¨ÎÄÆ¥Å伯ÊýÇåÁ㣬£¬£¬£¬£¬£¬£¬ÒÔ±ãÖØÐÂͳ¼Æ¡£¡£¡£¡£¡£¡£¡£

*    ×¢ÖØ

¿ªÆôACLµÄ±¨ÎÄÆ¥Å伯Êý¹¦Ð§ÐèÒª¸ü¶àµÄÓ²¼þ±íÏ£¬£¬£¬£¬£¬£¬¼«¶ËÇéÐÎÏ»áʹװ±¸¿ÉÒÔÉèÖõÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£

 

*     ²úÆ·/°æ±¾Ö§³ÖÇéÐÎ

ÔÚIP ACL¡¢MACÀ©Õ¹ACL¡¢×¨¼Ò¼¶À©Õ¹ACLºÍIPv6 ACLÉÏ¿ªÆô±¨ÎÄÆ¥Å伯Êý¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

 

12. ?ACLÉúЧʱ¼ä¶Î

ÈôÊÇÓû§ÐèÒªÔÚÖ¸¶¨µÄʱ¼ä¶ÎÄÚ¶ÔijЩÁ÷Á¿¾ÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬ÀýÈ磬£¬£¬£¬£¬£¬£¬Õ¥È¡ÔÚÊÂÇéʱ¼äʹÓÃ̸Ì칤¾ß¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔͨ¹ýÉèÖÃACEµÄÉúЧʱ¼ä¶Î£¬£¬£¬£¬£¬£¬£¬¿ØÖÆÁ÷Á¿Í¨¹ýµÄʱ¼ä¡£¡£¡£¡£¡£¡£¡£Ê±¼ä¶Î·ÖΪ¾ø¶Ôʱ¼äºÍÖÜÆÚʱ¼äÁ½ÖÖ¡£¡£¡£¡£¡£¡£¡£

¾ø¶Ôʱ¼äÌåÏÖÒ»¸öÖ¸¶¨Æðʼʱ¼äÒÔ¼°¿¢ÊÂʱ¼äµÄʱ¼äÇø¼ä¡£¡£¡£¡£¡£¡£¡£¸Ãʱ¼äÇø¼ä²»»áÑ­»··ºÆð£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÖÜÆÚ¡£¡£¡£¡£¡£¡£¡£ÀýÈç¡°2000Äê1ÔÂ1ÈÕ12£º00£º00ÖÁ2001Äê1ÔÂ1ÈÕ12£º00£º00¡±¡£¡£¡£¡£¡£¡£¡£

ÖÜÆÚʱ¼äÌåÏÖÒ»¸öÖÜÆÚÐÔµÄʱ¼äÇø¼ä¡£¡£¡£¡£¡£¡£¡£ÀýÈ硰ÿÖÜÒ»8£º00µ½Ã¿ÖÜÎå17£º00¡±¡£¡£¡£¡£¡£¡£¡£

¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£

13. ?·ÖƬ±¨ÎÄÆ¥Åäģʽ

ʹÓÃ·ÖÆ¬±¨ÎÄÆ¥Åäģʽ¿ÉÒÔʹ»á¼ûÁбí¶Ô·ÖƬ±¨ÎľÙÐиüϸÄ廯µÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£

¹ØÓÚIP±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬ÔÚÍøÂç´«ÊäʱÖпÉÄܻᱻ·ÖƬ¡£¡£¡£¡£¡£¡£¡£±¨Îı¬·¢·ÖƬʱ£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐÊׯ¬±¨ÎÄ´øÓÐËIJãÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçTCP»òUDP¶Ë¿ÚºÅ¡¢ICMPÀàÐͺÍICMP±àÂëµÈ£¬£¬£¬£¬£¬£¬£¬ÆäËûµÄ·ÖƬ±¨Îͼ²»´øÓÐÕâЩËIJãÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚĬÈ쵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò´øÓÐFagment±êʶ£¬£¬£¬£¬£¬£¬£¬ÔòÖ»»áÆ¥Åä·ÇÊׯ¬±¨ÎÄ£»£»£»£»£»ÈôÊÇACL¹æÔò²»´øÓÐFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÔòÆ¥ÅäËùÓб¨ÎÄ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Êׯ¬±¨ÎĺͺóÐøµÄËùÓÐ·ÖÆ¬±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£³ýÁËĬÈ쵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÍ⣬£¬£¬£¬£¬£¬£¬»¹ÌṩÁíÒ»ÖÖÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäÒªÁ죬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÆ¾Ö¤ÐèÒªÔÚÖ¸¶¨µÄACLÉϾÙÐÐÇл»¡£¡£¡£¡£¡£¡£¡£ÔÚÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬µ±ACL¹æÔò²»´øÓÐFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÈôÊDZ¨Îı»·ÖƬ£¬£¬£¬£¬£¬£¬£¬Êׯ¬±¨ÎÄ»áÆ¥Å乿ÔòÖÐÓû§½ç˵µÄËùÓÐÆ¥ÅäÓò(°üÀ¨Èý²ãºÍËIJãÐÅÏ¢)£¬£¬£¬£¬£¬£¬£¬¶ø·ÇÊׯ¬±¨ÎÄÔòÖ»»áÆ¥Å乿ÔòÖеķÇËIJãÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

*     ²úÆ·/°æ±¾Ö§³ÖÇéÐÎ

¡ñ     ½öÔÚIPÀ©Õ¹ACLºÍר¼Ò¼¶À©Õ¹ACLÉÏÖ§³Ö·ÖƬ±¨ÎÄÆ¥ÅäģʽµÄÇл»¡£¡£¡£¡£¡£¡£¡£

 

14. ?È«¾Ö¿ØÖÆÃæÇå¾²ACL

ÔÚijЩӦÓó¡¾°ÖУ¬£¬£¬£¬£¬£¬£¬ÐèÒª°ó¶¨ACLÏÞÖÆÔ´IP¶ÔTCPÎÕÊÖÊ×°ü¾ÙÐд¦Öóͷ££¬£¬£¬£¬£¬£¬£¬¶ø²»Êǽ¨ÉèTCPÅþÁ¬ºóÔÙ¾ÙÐÐÏÞÖÆ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÈ«¾Ö¿ØÖÆÃæACLʵÏÖ½öÈí¼þ¹ýÂË£¬£¬£¬£¬£¬£¬£¬²»µ«¿ÉÒÔïÔÌ­¶ÔÓ²¼þ×ÊÔ´µÄÏûºÄ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÄܹ»Öª×ã¶ÔTCPÊ×°ü¾ÙÐд¦Öóͷ£µÄÐèÇ󡣡£¡£¡£¡£¡£¡£½«Çå¾²ACLͨ¹ý¿ØÖÆÃæÓ¦ÓÃÏÂÁîÓ¦Óõ½È«¾Ö£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ¸ÃACL½öÈí¼þÉúЧ¡£¡£¡£¡£¡£¡£¡£

È«¾Ö¿ØÖÆÃæACLÔÚËùÓжþ²ãÒÔÌ«Íø½Ó¿ÚÉÏÉúЧ£¬£¬£¬£¬£¬£¬£¬ACL±íÏî²»Ó¦Óõ½Ó²¼þ£¬£¬£¬£¬£¬£¬£¬½ö¶ÔÈí¼þÉúЧ£¬£¬£¬£¬£¬£¬£¬´Ó¶øïÔÌ­¶ÔÓ²¼þ×ÊÔ´µÄÏûºÄ£»£»£»£»£»µ±¾ÙÐÐTCPÎÕÊÖʱ£¬£¬£¬£¬£¬£¬£¬Èí¼þACL¶ÔTCPÊ×°ü¾ÙÐмì²é£¬£¬£¬£¬£¬£¬£¬¹ØÓÚÖÀÖÐACLµÄTCP±¨ÎľÙÐйýÂË£¬£¬£¬£¬£¬£¬£¬ÊµÏÖ¶ÔÊ×°ü¹ýÂ˵ÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

*     ˵Ã÷

¡ñ     È«¾Ö¿ØÖÆÃæACL½ö¶ÔÈí¼þ¹ýÂËÉúЧ¡£¡£¡£¡£¡£¡£¡£

¡ñ     È«¾Ö¿ØÖÆÃæACL²»ÊÜÈ«¾ÖACLÆÆÀý¿ÚÉèÖÃÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬ÉèÖÃÆÆÀý¿ÚºóÈ«¾Ö¿ØÖÆÃæACLÈÔÈ»ÉúЧ

¡ñ     È«¾Ö¿ØÖÆÃæACL¿ÉÒÔÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¡£¡£¡£¡£¡£¡£¼´¿ÉÒÔÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£ÔÚSVI½Ó¿ÚºÍ¾ÛºÏ³ÉÔ±½Ó¿ÚÉϲ»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

 

1.2?? ÉèÖÃʹÃü¸ÅÀÀ

ACLÉèÖÃʹÃüÈçÏ£º

(1)   ÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£ÒÔÏÂÉèÖÃʹÃüÇëÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ÉèÖÃIP±ê×¼ACL

¡ð         ÉèÖÃIPÀ©Õ¹ACL

¡ð         ÉèÖÃMACÀ©Õ¹ACL

¡ð         ÉèÖÃר¼Ò¼¶À©Õ¹ACL

¡ð         ÉèÖÃIPv6 ACL

¡ð         ÉèÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©

(2)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACLÖØ¶¨Ïò

(3)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃÈ«¾ÖÇå¾²ACL

(4)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥Åäģʽ

(5)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃSVI Router ACL

(6)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹ÊÕϻָ´

1.3?? ÉèÖÃIP±ê×¼ACL

1.3.1? ¹¦Ð§¼ò½é

½¨ÉèºÍÓ¦ÓÃIP±ê×¼ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄIPv4±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

1.3.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ÈôÊÇÖ»Ïëͨ¹ý¼ì²é±¨ÎĵÄÔ´IPµØµãÀ´¿ØÖÆÓû§µÄÍøÂç×ÊÔ´»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÄÇô¿ÉÒÔÉèÖÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£

l  IP±ê×¼ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£IP±ê×¼ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

1.3.3? ÉèÖÃʹÃü¼ò½é

IP±ê×¼ACLÉèÖÃʹÃüÈçÏ£º

(1)   ½¨ÉèIP±ê×¼ACL

(2)   Ó¦ÓÃIP±ê×¼ACL

1.3.4? ½¨ÉèIP±ê×¼ACL

1.    ¹¦Ð§¼ò½é

½¨ÉèIP±ê×¼ACL²¢ÉèÖùæÔò¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  IP±ê×¼ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓÐIPv4±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôølogÑ¡ÏîµÄACL¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐlogÑ¡Ï£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£

l  ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖÃACL¹æÔòʱָ¶¨ÁËlogÑ¡Ïîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

l  ¹ØÓÚ´ølogÑ¡ÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ½¨ÉèIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷ÒýµÄIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

access-list acl-number { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃIP±ê×¼ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

ip access-list standard { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£

[ sequence-number ] { deny | permit } { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ time-range time-range-name ] [ log ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IP±ê×¼ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£

(4)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖñ¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀë¡£¡£¡£¡£¡£¡£¡£

ip access-list log-update interval time-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

(5)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄIP±ê×¼ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄIP±ê×¼ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

list-remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(6)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIP±ê×¼ACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄIP±ê×¼ACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄIP±ê×¼ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(7)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôIP±ê×¼ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

ip access-list counter { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IP±ê×¼ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£

(8)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIP±ê×¼ACL¹æÔò²½³¤¡£¡£¡£¡£¡£¡£¡£

ip access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IP±ê×¼ACL¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬¹æÔòÐòºÅÔöÁ¿ÖµÎª10¡£¡£¡£¡£¡£¡£¡£

1.3.5? Ó¦ÓÃIP±ê×¼ACL

1.    ¹¦Ð§¼ò½é

½«IP±ê×¼ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹IP±ê×¼ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɶԴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£

(4)   ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

vxlan vni-number

(5)   ½Ó¿ÚÓ¦ÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃIP±ê×¼ACL¡£¡£¡£¡£¡£¡£¡£

1.4?? ÉèÖÃIPÀ©Õ¹ACL

1.4.1? ¹¦Ð§¼ò½é

½¨ÉèºÍÓ¦ÓÃIPÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄIPv4±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄIPv4±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

1.4.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ÈôÊÇÐèҪͨ¹ý¼ì²é±¨ÎĵÄÔ´IPµØµã¡¢Ä¿µÄIPµØµã¡¢±¨ÎĵÄЭÒéºÅ¡¢TCP/UDPÔ´»òÄ¿µÄ¶Ë¿ÚºÅ£¬£¬£¬£¬£¬£¬£¬À´¿ØÖÆÓû§µÄÍøÂç×ÊÔ´»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬¿ÉÉèÖÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

l  IPÀ©Õ¹ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉèÖᣡ£¡£¡£¡£¡£¡£IPÀ©Õ¹ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

1.4.3? ÉèÖÃʹÃü¼ò½é

IPÀ©Õ¹ACLÉèÖÃʹÃüÈçÏ£º

(1)   ½¨ÉèIPÀ©Õ¹ACL

(2)   Ó¦ÓÃIPÀ©Õ¹ACL

1.4.4? ½¨ÉèIPÀ©Õ¹ACL

1.    ¹¦Ð§¼ò½é

½¨ÉèIPÀ©Õ¹ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  IPÀ©Õ¹ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓÐIPv4±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôølogÑ¡ÏîµÄACL¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐlogÑ¡Ï£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£

l  ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖÃACL¹æÔòʱָ¶¨ÁËlogÑ¡Ïîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

l  ¹ØÓÚ´ølogÑ¡ÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ½¨ÉèIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷ÒýµÄIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

access-list acl-number { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port | gt port | lt port | neq port | range lower upper ] [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃIPÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

ip access-list extended { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

[ sequence-number ] { deny | permit } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ time-range time-range-name ] [ log ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPÀ©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£

(4)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£¡£¡£¡£¡£¡£¡£

ip access-list log-update interval time-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

(5)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPÀ©Õ¹ACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄIPÀ©Õ¹ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄIPÀ©Õ¹ACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

list-remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(6)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPÀ©Õ¹ACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄIPÀ©Õ¹ACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(7)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôIPÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

ip access-list counter { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£

(8)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPÀ©Õ¹ACL¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£

ip access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPÀ©Õ¹ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£

1.4.5? Ó¦ÓÃIPÀ©Õ¹ACL

1.    ¹¦Ð§¼ò½é

½«IPÀ©Õ¹ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹IPÀ©Õ¹ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

(4)   ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

vxlan vni-number

(5)   ½Ó¿ÚÓ¦ÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

ip access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

1.5?? ÉèÖÃMACÀ©Õ¹ACL

1.5.1? ¹¦Ð§¼ò½é

½¨ÉèºÍÓ¦ÓÃMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄ¶þ²ã±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄ¶þ²ã±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ»ùÓÚ¶þ²ã±¨ÎÄÍ·À´¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

1.5.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ÈôÊÇÐèҪͨ¹ý¶þ²ã±¨ÎÄÐÅÏ¢£¨ÀýÈçÓû§PCµÄMACµØµã£©£¬£¬£¬£¬£¬£¬£¬À´¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÉèÖÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

l  MACÀ©Õ¹ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉèÖᣡ£¡£¡£¡£¡£¡£MACÀ©Õ¹ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

1.5.3? ÉèÖÃʹÃü¼ò½é

MACÀ©Õ¹ACLÉèÖÃʹÃüÈçÏ£º

(1)   ½¨ÉèMACÀ©Õ¹ACL

(2)   Ó¦ÓÃMACÀ©Õ¹ACL

1.5.4? ½¨ÉèMACÀ©Õ¹ACL

1.    ¹¦Ð§¼ò½é

½¨ÉèMACÀ©Õ¹ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  MACÀ©Õ¹ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓÐÒÔÌ«Íø¶þ²ã±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ½¨ÉèMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷ÒýµÄMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

access-list acl-number { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃMACÀ©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

mac access-list extended { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

[ sequence-number ] { deny | permit } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] [ time-range time-range-name ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬MACÀ©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£

(4)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

list-remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(5)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(6)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôMACÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

mac access-list counter { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬MACÀ©Õ¹ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£

(7)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©MACÀ©Õ¹ACLµÄ¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£

mac access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬MACÀ©Õ¹ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£

1.5.5? Ó¦ÓÃMACÀ©Õ¹ACL

1.    ¹¦Ð§¼ò½é

½«MACÀ©Õ¹ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹MACÀ©Õ¹ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

mac access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

(4)   ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

vxlan vni-number

(5)   ½Ó¿ÚÓ¦ÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

mac access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃMACÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

1.6?? ÉèÖÃר¼Ò¼¶À©Õ¹ACL

1.6.1? ¹¦Ð§¼ò½é

½¨ÉèºÍÓ¦ÓÃר¼Ò¼¶À©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄ±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄ±¨ÎĽøÈëÍøÂç¡£¡£¡£¡£¡£¡£¡£

1.6.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ÈôÊÇÐèҪͨ¹ý»ìÏýʹÓÃIP ACL¹æÔò¡¢MACÀ©Õ¹ACL¹æÔòºÍVLAN£¬£¬£¬£¬£¬£¬£¬À´¿ØÖÆÓû§»á¼ûÍøÂç×ÊÔ´µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÉèÖÃר¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

l  ר¼Ò¼¶À©Õ¹ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£×¨¼Ò¼¶À©Õ¹ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

1.6.3? ÉèÖÃʹÃü¼ò½é

ר¼Ò¼¶À©Õ¹ACLÉèÖÃʹÃüÈçÏ£º

(1)   ½¨Éèר¼Ò¼¶À©Õ¹ACL

(2)   Ó¦ÓÃר¼Ò¼¶À©Õ¹ACL

1.6.4? ½¨Éèר¼Ò¼¶À©Õ¹ACL

1.    ¹¦Ð§¼ò½é

½¨Éèר¼Ò¼¶À©Õ¹ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ר¼Ò¼¶À©Õ¹ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓб¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ½¨Éèר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷ÒýµÄר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

access-list acl-number { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

¡ð         ½¨ÉèÊý×ÖË÷Òý»òÕßÃüÃûµÄר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃר¼Ò¼¶À©Õ¹ACLºÍ¹æÔò¡£¡£¡£¡£¡£¡£¡£

expert access-list extended { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

[ sequence-number ] { deny | permit } [ protocol | [ ethernet-type ] [ cos [ cos-value ] [ inner cos-value ] ] ] [ VID [ vlan-id ] [ inner vlan-id ] ] { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } { source-mac-address source-mac-wildcard | host source-mac-address | any } { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } { destination-mac-address destination-mac-wildcard | host destination-mac-address | any } [ [ precedence precedence ] [ tos tos ] | [ dscp dscp ] [ ecn ecn ] ] [ fragment ] [ [ udf udf-id header pos value mask ] | [ int-flag ] ] [ time-range time-range-name ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶À©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£

¡ð         ½¨Éèר¼Ò¼¶À©Õ¹ACL¼°VXLANÄÚ²ãÎåÔª×鹿Ôò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖÃר¼Ò¼¶À©Õ¹ACL¼°VXLANÄÚ²ãÎåÔª×鹿Ôò¡£¡£¡£¡£¡£¡£¡£

expert access-list extended { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

[ sequence-number ] { deny | permit } { vxlan | vxlan-ignore-dport } protocol { source-ipv4-address source-ipv4-wildcard | host source-ipv4-address | any } [ eq port ] { destination-ipv4-address destination-ipv4-wildcard | host destination-ipv4-address | any } [ eq port ] [ tagged ] [ udp-dport dport ] [ match-all tcp-flag | established ] [ time-range time-range-name ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶À©Õ¹ACLÖб£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£

(4)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number list-remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

list-remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(5)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ΪÊý×ÖË÷ÒýµÄACL¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

access-list acl-number remark text

¡ð         ΪÊý×ÖË÷Òý»òÕßÃüÃûµÄACLÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(6)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôר¼Ò¼¶ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

expert access-list counter { acl-name | acl-number }

(7)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃר¼Ò¼¶ACLµÄ¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£

expert access-list resequence { acl-name | acl-number } start-value step-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬×¨¼Ò¼¶ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£

1.6.5? Ó¦ÓÃר¼Ò¼¶À©Õ¹ACL

1.    ¹¦Ð§¼ò½é

½«×¨¼Ò¼¶À©Õ¹ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹×¨¼Ò¼¶À©Õ¹ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-onlyºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-onlyºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£

expert access-group { acl-name | acl-number } { in | out } [ control-plane | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£

(4)   ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

vxlan vni-number

(5)   Ó¦ÓÃר¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

expert access-group { acl-name | acl-number } { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃר¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

1.7?? ÉèÖÃIPv6 ACL

1.7.1? ¹¦Ð§¼ò½é

½¨ÉèºÍÓ¦ÓÃIPv6 ACL£¬£¬£¬£¬£¬£¬£¬¶Ô½Ó¿ÚÉÏÊÕÖ§µÄIPv6±¨ÎľÙÐпØÖÆ£¬£¬£¬£¬£¬£¬£¬Õ¥È¡»òÔÊÐíÌØ¶¨µÄIPv6±¨ÎĽøÈëÍøÂ磬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ØÖÆIPv6Óû§»á¼ûÍøÂç×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

1.7.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ÈôÊÇÐèÒª¶ÔIPv6Óû§»á¼ûÍøÂç×ÊÔ´µÄ¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÉèÖÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

l  IPv6 ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£IPv6 ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

1.7.3? ÉèÖÃʹÃü¼ò½é

IPv6 ACLÉèÖÃʹÃüÈçÏ£º

(1)  ½¨ÉèIPv6 ACL

(2)  Ó¦ÓÃIPv6 ACL

1.7.4? ½¨ÉèIPv6 ACL

1.    ¹¦Ð§¼ò½é

½¨ÉèIPv6 ACL²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ½¨ÉèIPv6 ACLʱֻÄÜÖ¸ÃüÃû³Æ£¬£¬£¬£¬£¬£¬£¬²»¿ÉÖ¸¶¨±àºÅ¡£¡£¡£¡£¡£¡£¡£

l  IPv6 ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬IPv6 ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡³ýND±¨ÎÄÒÔÍâµÄËùÓÐIPv6±¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÏëÈÃACLµÄijЩ¹æÔòÔÚÖ¸¶¨µÄʱ¼äÉúЧ£¬£¬£¬£¬£¬£¬£¬»òÔÚÖ¸¶¨µÄʱ¼äÄÚʧЧ£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÃACLÔÚÒ»¸öÐÇÆÚµÄijЩʱ¼ä¶ÎÄÚÉúЧµÈ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøtime-rangeÑ¡ÏîµÄACL¹æÔòʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÉèÖöÔÓ¦µÄʱ¼ä¶ÎÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£¹ØÓÚʱ¼ä¶ÎµÄÉèÖÃÇë°Ý¼û¡°»ù´¡ÉèÖÃÖ¸ÄÏ¡±Öеġ°Time Range¡±¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôølogÑ¡ÏîµÄACL¹æÔò»áʹÓøü¶àµÄÓ²¼þ×ÊÔ´£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÉèÖõÄËùÓйæÔò¶¼´øÓÐlogÑ¡Ï£¬£¬£¬£¬£¬£¬Ôò»áµ¼ÖÂ×°±¸µÄÓ²¼þÕ½ÂÔÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£

l  ĬÈϱ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀëÊÇ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬¼´²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÉèÖÃACL¹æÔòʱָ¶¨ÁËlogÑ¡Ïîºó£¬£¬£¬£¬£¬£¬£¬»¹ÐèÒªÉèÖÃÊä³ö¾àÀ룬£¬£¬£¬£¬£¬£¬²»È»²»»áÊä³öÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

l  ¹ØÓÚ´ølogÑ¡ÏîµÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚûÓÐÆ¥Åäµ½Èκα¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôò²»»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾£»£»£»£»£»ÈôÊÇÖ¸¶¨µÄʱ¼ä¾àÀëÄÚÆ¥Åäµ½±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬Ôòʱ¼ä¾àÀëµ½ÆÚºó£¬£¬£¬£¬£¬£¬£¬»áÊä³öÓë¸Ã¹æÔòÓйصı¨ÎÄÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£ÆäÖеı¨ÎÄÖÀÖÐÊýĿΪ¸Ãʱ¼ä¾àÀëÄڸùæÔòÆ¥Åäµ½µÄ±¨ÎÄ×ÜÊý£¬£¬£¬£¬£¬£¬£¬¼´Îª¸Ã¹æÔòÉÏÒ»´ÎÊä³öÈÕÖ¾µ½±¾´ÎÊä³öÈÕÖ¾Ö®¼äÖÀÖеı¨ÎÄÊý¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ½¨ÉèIPv6 ACL£¬£¬£¬£¬£¬£¬£¬²¢½øÈëIPv6 ACLÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

ipv6 access-list acl-name

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

(4)   ÉèÖÃIPv6 ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ÉèÖÃIPv6 ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

[ sequence-number ] { deny | permit } [ protocol { source-ipv6-prefix / prefix-length | source-ipv6-address source-ipv6-mask | host source-ipv6-address | any } { destination-ipv6-prefix / prefix-length | destination-ipv6-address destination-ipv6-mask | host destination-ipv6-address | any } ] [ cos cos-value [ inner cos-value] ] [ { any | host source-mac-address | source-mac-address source-mac-wildcard } { any | host destination-mac-address | destination-mac-address destination-mac-wildcard } ] [ dscp dscp ] [ flow-label flow-label ] [ fragment ] [ VID [ vlan-id ] [ inner vlan-id ] ] [ udf udf-id header pos value mask ] [ time-range time-range-name ]¡¡[ log ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPv6 ACL±£´æÒ»Ìõ¾Ü¾øÀàÐ͵ĹæÔò¡£¡£¡£¡£¡£¡£¡£

(5)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖñ¨ÎÄÆ¥ÅäÈÕÖ¾Êä³ö¾àÀë¡£¡£¡£¡£¡£¡£¡£

ipv6 access-list log-update interval time-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬±¨ÎÄÆ¥ÅäÈÕÖ¾¸üоàÀëΪ0·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ²»Êä³öACLÆ¥ÅäÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£

(6)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

list-remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(7)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(8)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©¿ªÆôIPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

ipv6 access-list counter acl-name

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPv6 ACLµÄ±¨ÎÄÆ¥Åäͳ¼Æ¹¦Ð§´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£

(9)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃIPv6 ACLµÄ¹æÔòÐòºÅÆðʼֵºÍ²½³¤¡£¡£¡£¡£¡£¡£¡£

ipv6 access-list resequence acl-name start-value step-value

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬IPv6 ACLµÄ¹æÔòÐòºÅÆðʼֵΪ10£¬£¬£¬£¬£¬£¬£¬²½³¤Îª10¡£¡£¡£¡£¡£¡£¡£

1.7.5? Ó¦ÓÃIPv6 ACL

1.    ¹¦Ð§¼ò½é

½«IPv6 ACLÓ¦Óõ½È«¾ÖÉèÖÃģʽ¡¢½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹IPv6 ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ×°±¸½Ó¿ÚµÄÈëÆ«Ïò»ò³öÆ«ÏòÉÏÖ»ÄÜÓ¦ÓÃÒ»ÌõIP ACL»òÒ»ÌõMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬»òÕßÓ¦ÓÃÒ»Ìõר¼Ò¼¶ACL¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÔÙÓ¦ÓÃÒ»ÌõIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcounter-onlyÑ¡Ïî¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACL»á¼ûÖÖ±ðÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬DenyÀàÐ͹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  µ±Ò»ÌõACL±»ÓÃ×öcounter-only ACLºó£¬£¬£¬£¬£¬£¬£¬¸ÃÌõACL²»¿ÉÔÚÈ«¾Ö¿ªÆô¼ÆÊý¹¦Ð§£¬£¬£¬£¬£¬£¬£¬Ò²²»¿ÉÔÚÈ«¾ÖºÍ½Ó¿ÚÉÏÓ¦ÓÃͨË×ACL£¬£¬£¬£¬£¬£¬£¬¼´Ïàͬacl-number»òacl-nameµÄACL²»¿ÉͬʱÓÃ×öcounter-only ACLºÍͨË×ACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøcontrol-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÈí¼þÉúЧACL£¬£¬£¬£¬£¬£¬£¬µÖ´ï½ÚÔ¼Ó²¼þ×ÊÔ´µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖ½öÓ²¼þÉúЧACL¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖôøforward-control-planeÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÈí¼þºÍÓ²¼þ¶¼ÉúЧACL¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©È«¾ÖÓ¦ÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

ipv6 traffic-filter acl-name { in | out } { control-plane | forward-control-plane | forward-plane }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬È«¾ÖδӦÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

(4)   ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

vxlan vni-number

(5)   ½Ó¿ÚÓ¦ÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

ipv6 traffic-filter acl-name { in | out } [ control-plane | counter-only | forward-control-plane | forward-plane ]

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃIPv6 ACL¡£¡£¡£¡£¡£¡£¡£

1.8?? ÉèÖÃר¼Ò¼¶¸ß¼¶ACL£¨ACL80£©

1.8.1? ¹¦Ð§¼ò½é

µ±Àο¿Æ¥ÅäÓòµÄIP±ê×¼ACL¡¢IPÀ©Õ¹ACL¡¢MACÀ©Õ¹ACL¡¢×¨¼Ò¼¶À©Õ¹ACLÒÔ¼°IPv6 ACL¶¼ÎÞ·¨Öª×ãÒªÇóʱ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÉèÖÃר¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬¼´ACL80£¬£¬£¬£¬£¬£¬£¬ÓÉÓû§½ç˵ÐèҪƥÅäµÄ±¨ÎÄÓò£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ×Ô½ç˵ƥÅäÓòµÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£

1.8.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ר¼Ò¼¶¸ß¼¶ACL¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖᣡ£¡£¡£¡£¡£¡£×¨¼Ò¼¶¸ß¼¶ACLÖ»¶Ô±»ÉèÖõÄ×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

1.8.3? ÉèÖÃʹÃü¼ò½é

ר¼Ò¼¶¸ß¼¶ACLÉèÖÃʹÃüÈçÏ£º

(1)   ½¨Éèר¼Ò¼¶¸ß¼¶ACL

(2)   Ó¦ÓÃר¼Ò¼¶¸ß¼¶ACL

1.8.4? ½¨Éèר¼Ò¼¶¸ß¼¶ACL

1.    ¹¦Ð§¼ò½é

½¨ÉèACL80²¢ÉèÖÃÆä¹æÔò¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ACL80¿ÉÒÔÖ§³ÖÆ¥ÅäEthernet IIÖ¡¡¢802.2 LLCÖ¡ºÍ802.2 SNAPÖ¡¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪAAAA03£¬£¬£¬£¬£¬£¬£¬ÔòÌåÏÖÆ¥Åä802.2 SNAPÖ¡¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÉèÖÃDSAPµ½Cntl×ֶεÄֵΪE0E003£¬£¬£¬£¬£¬£¬£¬ÔòÌåÏÖÆ¥Åä802.2 LLCÖ¡¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÆ¥ÅäEthernet IIÖ¡²»¿ÉÉèÖÃDSAPµ½Cntl×ֶεÄÖµ¡£¡£¡£¡£¡£¡£¡£

l  ÓÉÓÚÓ²¼þµÄÔµ¹ÊÔ­ÓÉ£¬£¬£¬£¬£¬£¬£¬Ä¿½ñACL80²¢²»¿É¶Ô±¨ÎÄǰ80¸ö×Ö½ÚµÄí§Òâ×Ö½ÚÆ¥Å䣬£¬£¬£¬£¬£¬£¬Ö»Ö§³Ö±¨ÎÄÖÐÄ¿µÄMAC¡¢Ô´MAC¡¢VLAN ID¡¢ETYPE¡¢IPЭÒéºÅ¡¢Ô´IPv4µØµã¡¢Ä¿µÄIPv4µØµã¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú¡¢ICMP_TYPE¡¢ICMP_CODE¡¢PPPOE_IPTYPEÕâЩ×Ö¶ÎËùÔÚλÖÃµÄÆ¥Åä¡£¡£¡£¡£¡£¡£¡£

l  ACL80Æ¥ÅäIP¡¢ARPµÈÐÅϢʱ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖ÷â×°µÄÊý¾ÝÀàÐͺÍÊý¾ÝÀàÐÍÑÚÂ룬£¬£¬£¬£¬£¬£¬¼´ÐèÒªÏÈÉèÖÃÆ«ÒÆÁ¿Îª24µÄ×ֶΣ¬£¬£¬£¬£¬£¬£¬²¢ÇÒÑÚÂëҪΪȫF¡£¡£¡£¡£¡£¡£¡£ÀýÈç·ÅÐÐÔ´IPΪ192.168.1.2µÄ±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦µÄÉèÖÃÏÂÁîΪpermit 0800 FFFF 24 C0A80102 FFFFFFFF 38¡£¡£¡£¡£¡£¡£¡£

l  ר¼Ò¼¶¸ß¼¶ACLÖÐÔÊÐíÎÞ¹æÔò¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÒþº¬Ò»Ìõ¡°¾Ü¾øËùÓÐÊý¾ÝÁ÷¡±µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬Õ¥È¡ËùÓб¨ÎĽøÈë×°±¸¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇÉèÖÃÁËÐí¶àACL»ò¹æÔò£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐΪÕâЩACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÔÚÏÖʵµÄÍøÂçά»¤Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½«ÄÑÒÔÇø·ÖÕâЩACL»ò¹æÔòµÄÓÃ;¡£¡£¡£¡£¡£¡£¡£ÎªACL»ò¹æÔòÉèÖÃ×¢ÊÍÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÀû±ãÃ÷È·ACLÓÃ;¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ½¨Éèר¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬²¢½øÈëר¼Ò¼¶¸ß¼¶ACLÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

expert access-list advanced acl-name

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æ×¨¼Ò¼¶¸ß¼¶ACL¡£¡£¡£¡£¡£¡£¡£

(4)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃר¼Ò¼¶¸ß¼¶ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

[ sequence-number ] { deny | permit } hex hex-mask offset

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Î´ÉèÖÃר¼Ò¼¶¸ß¼¶ACL¹æÔò¡£¡£¡£¡£¡£¡£¡£

(5)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

list-remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACLûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

(6)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃACL¹æÔò×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

remark text

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòûÓÐÉèÖÃ×¢ÊÍÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

1.8.5? Ó¦ÓÃר¼Ò¼¶¸ß¼¶ACL

1.    ¹¦Ð§¼ò½é

½«×¨¼Ò¼¶¸ß¼¶ACLÓ¦Óõ½½Ó¿ÚÉèÖÃģʽ¡¢SVI½Ó¿ÚÉèÖÃģʽ¡¢VXLANÉèÖÃģʽÏ£¬£¬£¬£¬£¬£¬£¬Ê¹×¨¼Ò¼¶¸ß¼¶ACLÉúЧ¡£¡£¡£¡£¡£¡£¡£

2.    ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ÉèÖôøin»òoutÑ¡Ï£¬£¬£¬£¬£¬£¬ÌåÏÖÐèÒªÖ¸¶¨ÊǶԽøÈë×°±¸µÄ±¨ÎÄÉúЧ£¬£¬£¬£¬£¬£¬£¬ÕվɴÓ×°±¸×ª·¢³öÈ¥µÄ±¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

3.    ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ½øÈë½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

¡ð         ½øÈëÒÔÌ«Íø½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface ethernet-type interface-number

¡ð         ½øÈëSVI½Ó¿ÚÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

interface vlan interface-number

¡ð         ½øÈëVXLANÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

vxlan vni-number

(4)   ½Ó¿ÚÓ¦ÓÃר¼Ò¼¶¸ß¼¶ACL¡£¡£¡£¡£¡£¡£¡£

expert access-group { acl-name | acl-number } { in | out }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿ÚδӦÓÃר¼Ò¼¶¸ß¼¶ACL¡£¡£¡£¡£¡£¡£¡£

1.9?? ÉèÖÃACLÖØ¶¨Ïò

1.9.1? ¹¦Ð§¼ò½é

ÔÚÖ¸¶¨½Ó¿ÚÉÏÉèÖÃACLÖØ¶¨Ïò¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¶Ô½øÈë¸Ã½Ó¿ÚµÄÆ¥Å䱨ÎÄ£¬£¬£¬£¬£¬£¬£¬Öض¨Ïòµ½Ö¸¶¨½Ó¿Úת·¢³öÈ¥¡£¡£¡£¡£¡£¡£¡£

1.9.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ACLÖØ¶¨Ïò¹¦Ð§½öÔÚ½Ó¿ÚÈëÆ«ÏòÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  ACLÖÐûÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬ACLÖØ¶¨Ïò¹¦Ð§²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  Ö»Ö§³ÖÔÚÒÔÌ«Íø½Ó¿Ú¡¢¾ÛºÏ½Ó¿ÚÉÏÉèÖÃACLÖØ¶¨Ïò¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

l  ´ýÖØ¶¨ÏòµÄ±¨ÎıØÐèÊǶþ²ãת·¢£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Öض¨ÏòµÄÄ¿µÄ½Ó¿Ú±ØÐèºÍÔ´½Ó¿ÚÔÚͳһ¸öVLAN²Å»ªÉúЧ¡£¡£¡£¡£¡£¡£¡£ÀýÈç¼ÙÉ豨ÎÄÊÇ´ÓVLAN 2ת·¢µ½VLAN 3£¬£¬£¬£¬£¬£¬£¬Ôò²»¿É¾ÙÐÐÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£

l  ¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖÃACLÖØ¶¨Ïò¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ÉèÖýö¶Ô±¾×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

1.9.3? ÉèÖÃ×¼±¸

ʵÏÖACLÖØ¶¨Ïò¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£

1.9.4? ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ÉèÖÃACLÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£

¡ð         ÉèÖýӿÚACLÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£ÇëÒÀ´ÎÖ´ÐÐÒÔÏÂÏÂÁîÉèÖýӿÚACLÖØ¶¨Ïò¡£¡£¡£¡£¡£¡£¡£

interface interface-type interface-number

redirect destination interface interface-type interface-number acl { acl-name | acl-number } in

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½Ó¿Ú²»±£´æACLÖØ¶¨ÏòÉèÖᣡ£¡£¡£¡£¡£¡£

1.10?? ÉèÖÃÈ«¾ÖÇå¾²ACL

1.10.1? ¹¦Ð§¼ò½é

ÉèÖÃÈ«¾ÖÇå¾²ACL¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ×èÖ¹ÆóÒµÄÚ²¿»á¼û²»·¨ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬»òÕß×èÖ¹²¡¶¾½øÈëÆóÒµÄÚ²¿ÍøÂç¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÉèÖÃÈ«¾ÖÇå¾²ACLÆÆÀý¿Ú£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÆóÒµÄÚ²¿ÌØÊⲿ·Ö»á¼ûÍⲿijЩվµã¡£¡£¡£¡£¡£¡£¡£

1.10.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ACLÖÐûÓÐÉèÖùæÔòʱ£¬£¬£¬£¬£¬£¬£¬È«¾ÖÇå¾²ACL¹¦Ð§²»±£´æ¡£¡£¡£¡£¡£¡£¡£

l  ÓÉÓÚÈ«¾ÖÇå¾²ACLÖ÷ÒªÓÃÓÚ²¡¶¾¹ýÂË£¬£¬£¬£¬£¬£¬£¬Òò´Ë±»¹ØÁªÓÚÈ«¾ÖÇå¾²ACLµÄACEÖУ¬£¬£¬£¬£¬£¬£¬Ö»ÓÐDenyÀàÐ͵ÄACE»áÉúЧ£¬£¬£¬£¬£¬£¬£¬PermitÀàÐ͵ÄACE²»»áÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  Óë¶Ë¿ÚÇå¾²ACL²î±ð£¬£¬£¬£¬£¬£¬£¬È«¾ÖÇå¾²ACLûÓÐĬÈϵÄDenyËùÓбíÏ£¬£¬£¬£¬£¬£¬¼´Ã»ÖÀÖйæÔòµÄ±¨Îͼ¿ÉÒÔͨ¹ý¡£¡£¡£¡£¡£¡£¡£

l  È«¾ÖÇå¾²ACLÖ»Ö§³Ö¹ØÁªIP±ê×¼ACL¡¢IPÀ©Õ¹ACL¡¢MACÀ©Õ¹ACL¡¢×¨¼Ò¼¶À©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

l  È«¾ÖACL¿ÉÒÔÔÚ¶þ²ã½Ó¿ÚÉÏÉúЧ£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÔÚÈý²ã½Ó¿ÚÉÏÉúЧ¡£¡£¡£¡£¡£¡£¡£¼´¿ÉÒÔÔÚÒÔÏÂÀàÐ͵ĽӿÚÉ϶¼ÉúЧ£ºAccess¿Ú¡¢Trunk¿Ú¡¢Hybrid¿Ú¡¢¶þ²ãÒÔÌ«Íø½Ó¿Ú¡¢Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£ÔÚSVI½Ó¿ÚÉϲ»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

l  ÔÊÐíÔÚÎïÀí½Ó¿Ú¡¢¶þ²ã¾ÛºÏ½Ó¿Ú»òÈý²ã¾ÛºÏ½Ó¿ÚÉÏ×ÔÁ¦¹Ø±ÕÈ«¾ÖÇå¾²ACL¹¦Ð§£¬£¬£¬£¬£¬£¬£¬²»Ö§³ÖÔھۺϳÉÔ±½Ó¿ÚÉϹرÕÈ«¾ÖÇå¾²ACL¹¦Ð§¡£¡£¡£¡£¡£¡£¡£

l  ¿ÉÒÔÆ¾Ö¤Óû§µÄÂþÑÜÇéÐΣ¬£¬£¬£¬£¬£¬£¬ÔÚ½ÓÈë¡¢»ã¾Û»ò½¹µã×°±¸ÉÏÉèÖÃÈ«¾ÖÇå¾²ACL¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ÉèÖýö¶Ô±¾×°±¸ÓÐÓ㬣¬£¬£¬£¬£¬£¬²»»áÓ°ÏìÍøÂçÖÐµÄÆäËû×°±¸¡£¡£¡£¡£¡£¡£¡£

l  ͨ¹ýÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʵÏÖեȡÉèÖÃÈ«¾ÖÇå¾²ACL¡£¡£¡£¡£¡£¡£¡£

l  ½«½Ó¿ÚÉèÖÃÎªÆÆÀý¿Ú£¬£¬£¬£¬£¬£¬£¬¿Éʹȫ¾ÖÇå¾²ACLÔÚ½Ó¿ÚÉϲ»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

1.10.3? ÉèÖÃ×¼±¸

ʵÏÖÈ«¾ÖÇå¾²ACL¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£

1.10.4? ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   £¨¿ÉÑ¡£¡£¡£¡£¡£¡£¡£©ÉèÖÃÈ«¾ÖÇå¾²ACLÎÞЧ¡£¡£¡£¡£¡£¡£¡£

global access-group disable

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬²»±£´æÈ«¾ÖÇå¾²ACLÎÞЧÉèÖᣡ£¡£¡£¡£¡£¡£

1.11?? ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥Åäģʽ

1.11.1? ¹¦Ð§¼ò½é

ÉèÖøù¦Ð§¿ÉÒÔʹACL¶Ô·ÖƬ±¨ÎľÙÐиüϸÄ廯µÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£

1.11.2? ÉèÖÃÏÞÖÆÓëÖ¸µ¼

l  ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥ÅäģʽÇл»Ê±£¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂACLµÄ¶ÌʱʧЧ¡£¡£¡£¡£¡£¡£¡£

l  ÔÚÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò²»´øFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÇÒÆ¥ÅäÐж¯ÊÇPermit£¬£¬£¬£¬£¬£¬£¬ÕâÑùµÄACL¹æÔòÐèÒªÕ¼Óøü¶àµÄÓ²¼þ±íÏî×ÊÔ´£¬£¬£¬£¬£¬£¬£¬¼«¶ËÇéÐÎÏ»áʹӲ¼þÕ½ÂÔ±íÏîÈÝÁ¿¼õ°ë¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÕâÑùµÄACEÉèÖÃÁËTCP Flag¹ýÂË¿ØÖƵÄEstablished£¬£¬£¬£¬£¬£¬£¬Ôò»¹»áÕ¼Óøü¶àµÄÓ²¼þÕ½ÂÔ±íÏî¡£¡£¡£¡£¡£¡£¡£

l  ÔÚÐ嵀ᅮ¬±¨ÎÄÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò²»´øFragment±êʶ²¢ÇÒÐèҪƥÅ䱨ÎĵÄËIJãÐÅϢʱ£¬£¬£¬£¬£¬£¬£¬µ±Æ¥ÅäÐж¯ÎªPermitʱ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔò»á¼ì²éÊׯ¬±¨ÎÄÈý²ãºÍËIJãÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¹ØÓÚ·ÇÊׯ¬±¨ÎÄÖ»»á¼ì²é±¨ÎĵÄÈý²ãÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µ±Æ¥ÅäÐж¯ÎªDenyʱ£¬£¬£¬£¬£¬£¬£¬ACL¹æÔòÖ»»á¼ì²éÊׯ¬±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬²»»á¼ì²é·ÇÊׯ¬·ÖƬ±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

l  ÔÚÐ嵀ᅮ¬±¨ÎÄÐÂÆ¥ÅäģʽÏ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇACL¹æÔò´øÓÐFragment±êʶ£¬£¬£¬£¬£¬£¬£¬ÆñÂÛACL¹æÔòµÄÆ¥ÅäÐж¯ÊÇPermitÕÕ¾ÉDeny£¬£¬£¬£¬£¬£¬£¬¶¼Ö»¼ì²é·ÇÊׯ¬±¨ÎÄ£¬£¬£¬£¬£¬£¬£¬¶ø²»»á¼ì²éÊׯ¬±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

1.11.3? ÉèÖÃ×¼±¸

ÉèÖÃ·ÖÆ¬±¨ÎÄÆ¥ÅäģʽÇл»Ê±£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£

1.11.4? ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)   ÉèÖÃÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£ÇëÑ¡ÔñÆäÖÐÒ»Ïî¾ÙÐÐÉèÖᣡ£¡£¡£¡£¡£¡£

¡ð         ÉèÖÃIP ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£

ip access-list new-fragment-mode { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Î´ÉèÖÃIP ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£

¡ð         ÉèÖÃר¼Ò¼¶À©Õ¹ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£

expert access-list new-fragment-mode { acl-name | acl-number }

ȱʡÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Î´ÉèÖÃר¼Ò¼¶À©Õ¹ACLÐ嵀ᅮ¬±¨ÎÄÆ¥Åäģʽ¡£¡£¡£¡£¡£¡£¡£

1.12?? ÉèÖÃSVI Router ACL

1.12.1? ¹¦Ð§¼ò½é

ÉèÖøù¦Ð§£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹӦÓÃÔÚSVI½Ó¿ÚÉϵÄACL½ö¶ÔVLAN¼äµÄ·Óɱ¨ÎÄÉúЧ¡£¡£¡£¡£¡£¡£¡£

1.12.2? ÉèÖÃ×¼±¸

ʵÏָù¦Ð§£¬£¬£¬£¬£¬£¬£¬ÐèÒªÏÈÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£

1.12.3? ÉèÖð취

(1)  ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)  ½øÈëÈ«¾ÖÉèÖÃģʽ¡£¡£¡£¡£¡£¡£¡£

configure terminal

(3)  ÉèÖÃSVI Router ACL¡£¡£¡£¡£¡£¡£¡£

svi router-acls enable

1.13?? ÉèÖÃACL¹ÊÕϻָ´

1.13.1? ¹¦Ð§¼ò½é

µ±×°±¸Èí¼þ±íÏîÈÝÁ¿´óÓÚÓ²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ê±£¬£¬£¬£¬£¬£¬£¬±íÏîÌí¼Ó½«Ê§°Ü¡£¡£¡£¡£¡£¡£¡£µ±×°±¸±íÏîÈÝÁ¿½µµÍµ½Ó²¼þÖ§³ÖµÄ±íÏîÈÝÁ¿Ö®ÏÂʱ£¬£¬£¬£¬£¬£¬£¬Ô­ÏÈÌí¼Óʧ°ÜµÄ±íÏîÒ²²»»áÖØÐÂÌí¼Ó¡£¡£¡£¡£¡£¡£¡£Í¨¹ý±¾ÏÂÁîÖØË¢ÉèÖ㬣¬£¬£¬£¬£¬£¬´¥½ÒÏþÏîµÄÖØÐÂÌí¼Ó£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»Ö¸´ACL¹ÊÕÏ¡£¡£¡£¡£¡£¡£¡£

1.13.2? ÉèÖð취

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£¡£¡£¡£¡£¡£¡£

enable

(2)   ÉèÖÃACL¹ÊÕϻָ´¡£¡£¡£¡£¡£¡£¡£

acl ref synchronize all

1.14?? ¼àÊÓÓëά»¤

¿ÉÒÔͨ¹ýshowÏÂÁîÐÐÉó²é¹¦Ð§ÉèÖúóµÄÔËÐÐÇéÐÎÒÔÑéÖ¤ÉèÖÃЧ¹û¡£¡£¡£¡£¡£¡£¡£

¿ÉÒÔͨ¹ýÖ´ÐÐclearÏÂÁîÀ´É¨³ýÖÖÖÖÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

*    ×¢ÖØ

ÔÚ×°±¸ÔËÐÐÀú³ÌÖÐÖ´ÐÐclearÏÂÁ£¬£¬£¬£¬£¬£¬¿ÉÄÜÓÉÓÚÖ÷ÒªÐÅϢɥʧ¶øµ¼ÖÂÓªÒµÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£

 

¿ÉÒÔͨ¹ýdebugÏÂÁîÐÐö¾ÙÊä³öµÄÖÖÖÖµ÷ÊÔÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

*    ×¢ÖØ

Êä³öµ÷ÊÔÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»áÕ¼ÓÃϵͳ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÍê±Ïºó£¬£¬£¬£¬£¬£¬£¬ÇëÁ¬Ã¦¹Ø±Õµ÷ÊÔ¿ª¹Ø¡£¡£¡£¡£¡£¡£¡£

 

±í1-5     ACL¼àÊÓÓëά»¤

×÷ÓÃ

ÏÂÁî

Éó²é»ù±¾ACL

show access-lists [ acl-name | acl-number ] [ summary ]

Éó²éÖ¸¶¨½Ó¿ÚÉϰ󶨵ÄÖØ¶¨Ïò±íÏ£¬£¬£¬£¬£¬£¬²»ÊäÈë½Ó¿ÚÔòÉó²éËùÓнӿÚÉϰ󶨵ÄÖØ¶¨Ïò±íÏî

show redirect [ interface interface-type interface-number ]

Éó²é½Ó¿ÚÉÏÓ¦ÓõÄACLÉèÖÃÐÅÏ¢

show access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

Éó²é½Ó¿ÚÉÏÓ¦ÓõÄIP±ê×¼ACLºÍÀ©Õ¹ACLÉèÖÃÐÅÏ¢

show ip access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

Éó²é½Ó¿ÚÉÏÓ¦ÓõÄMACÀ©Õ¹ACLÉèÖÃÐÅÏ¢

show mac access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

Éó²é½Ó¿ÚÉÏÓ¦ÓõÄר¼Ò¼¶À©Õ¹ACLÉèÖÃÐÅÏ¢

show expert access-group [ interface interface-type interface-number | vlan vlan-id | vxlan vni-number ]

Éó²é½Ó¿ÚÉÏÓ¦ÓõÄIPv6 ACLÉèÖÃÐÅÏ¢

show ipv6 traffic-filter [ interface interface-type interface-number | vlan vlan-id ]

Éó²éËùÓеÄTCAMÐÅÏ¢»òÖ¸¶¨µÄTCAMÐÅÏ¢

show acl res [ dev dev-number [ slot slot-number ] ]

ÏÔʾĿ½ñ×°±¸µÄÄÜÁ¦ÖµÇéÐÎ

show acl capability

Éó²éSVI½Ó¿ÚACLÓ¦ÓõĶþÈý²ãÉúЧÇéÐÎ

show svi router-acls state

Éó²éËùÓеÄTCAMÏêϸʹÓÃÐÅÏ¢»òÖ¸¶¨µÄTCAMÏêϸʹÓÃÐÅÏ¢

show acl res detail [ dev dev-number [ slot slot-number ] ]

ɨ³ýTCAM×ÊԴʹÓÃÁ¿µÄÀúÊ··åÖµÊý¾Ý

clear acl res

ɨ³ýACL±¨ÎÄÆ¥Å伯Êý

clear counters access-list [ acl-name | acl-number ]

ɨ³ýACL deny±¨ÎÄÆ¥Å伯Êý

clear access-list counters [ acl-name | acl-number ]

·­¿ªACLÔËÐÐÀú³Ìµ÷ÊÔ¿ª¹Ø

debug acl acld event

Éó²éACL¿Í»§¶ËÐÅÏ¢

debug acl acld client-show

Éó²éËùÓÐACL¿Í»§¶Ë½¨ÉèµÄACL

debug acl acld acl-show

 

1.15?? µä·¶ÉèÖþÙÀý

1.15.1? IP±ê×¼ACLÉèÖþÙÀý

1.    ×éÍøÐèÇó

ͨ¹ýÉèÖÃIP±ê×¼ACL£¬£¬£¬£¬£¬£¬£¬Õ¥È¡²ÆÎñ²¿ÒÔÍâµÄ²¿·Ö»á¼û²ÆÎñÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-3     IP±ê×¼ACLÓ¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  Device A½«IP±ê×¼ACLÓ¦ÓÃÔÚÅþÁ¬²ÆÎñÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

# Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# ip access-list standard 1

DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255

DeviceA(config-std-nacl)# deny 11.1.1.1 0.0.0.255

DeviceA(config-std-nacl)# exit

(2)   ½«IP±ê×¼ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£

# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬²ÆÎñÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³öÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# interface gigabitethernet 0/3

DeviceA(config-if-GigabitEthernet 0/3)# ip access-group 1 out

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£

DeviceA# show access-lists

 

ip access-list standard 1

10 permit 10.1.1.0 0.0.0.255

20 deny 11.1.1.0 0.0.0.255

 

DeviceA# show access-group

ip access-group 1 out

Applied On interface GigabitEthernet 0/3

# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£

# ´Ó²ÆÎñ²¿µÄij̨PC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏÄÜpingͨ¡£¡£¡£¡£¡£¡£¡£

6.    ÉèÖÃÎļþ

l  DeviceAµÄÉèÖÃÎļþ

hostname DeviceA

!

ip access-list standard 1

?10 permit 10.1.1.0 0.0.0.255

?20 deny 11.1.1.0 0.0.0.255

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip access-group 1 out

?ip address 12.1.1.1 255.255.255.0

!

1.15.2? IPÀ©Õ¹ACLÉèÖþÙÀý

1.    ×éÍøÐèÇó

Device A£¨VLAN 1£©¡¢Device B£¨VLAN 2£©ºÍDevice C£¨VLAN 3£©Ö±Á¬Device D£¬£¬£¬£¬£¬£¬£¬Device DÊÇËùÓÐÖ÷»úµÄÍø¹Ø¡£¡£¡£¡£¡£¡£¡£ÐèÇó1£ºVLAN2ÓëVLAN3Ö®¼ä²»¿ÉÒÔPingͨ£¬£¬£¬£¬£¬£¬£¬VLAN1ÓëVLAN2¿ÉÒÔPingͨ£¬£¬£¬£¬£¬£¬£¬VLAN1ÓëVLAN3¿ÉÒÔPingͨ¡£¡£¡£¡£¡£¡£¡£ÐèÇó2£ºVLAN1ÓëVLAN2µÄDHCP±¨ÎÄÏ໥²»¿É´ï£¬£¬£¬£¬£¬£¬£¬ÆäËûÕý³£Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£ÐèÇó3£ºVLAN1²»¿Éͨ¹ýTelnet»òÕßSSH»á¼ûVLAN3£¬£¬£¬£¬£¬£¬£¬ÆäËûÕý³£Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-4     IPÀ©Õ¹ACLÓ¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  Device DÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬¹ýÂËUDP¶Ë¿ÚºÅ67»òÕß68¿ÉÒÔʵÏÖÐèÇó2¡£¡£¡£¡£¡£¡£¡£Device CÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò£¬£¬£¬£¬£¬£¬£¬¹ýÂËTCP¶Ë¿Ú23ºÍ22¿ÉÒÔʵÏÖÐèÇó3¡£¡£¡£¡£¡£¡£¡£

l  Device D½«IPÀ©Õ¹ACL»®·ÖÓ¦ÓÃÔÚVLAN1½Ó¿Ú¡¢VLAN2½Ó¿ÚºÍVLAN3½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£Device C½«IPÀ©Õ¹ACLÓ¦ÓÃÔÚÓëDevice DÏàÏß·ÉÏ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)  ÉèÖÃËùÓÐ×°±¸½Ó¿ÚµÄIPµØµã£¨ÂÔ£©¡£¡£¡£¡£¡£¡£¡£

(2)  ÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

# Device DÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceD> enable

DeviceD# configure terminal

DeviceD(config)# ip access-list extended inter_vlan_access1

DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc

DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps

DeviceD(config-ext-nacl)# remark ¾Ü¾øDHCP±¨ÎÄ

DeviceD(config-ext-nacl)# permit ip any any

DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ

DeviceD(config-ext-nacl)# exit

DeviceD(config)# ip access-list extended inter_vlan_access2

DeviceD(config-ext-nacl)# deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255

DeviceD(config-ext-nacl)# remark ¾Ü¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping

DeviceD(config-ext-nacl)# deny udp any eq bootpc any eq bootps

DeviceD(config-ext-nacl)# deny udp any eq bootps any eq bootpc

DeviceD(config-ext-nacl)# remark ¾Ü¾øDHCP±¨ÎÄ

DeviceD(config-ext-nacl)# permit ip any any

DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ

DeviceD(config-ext-nacl)# exit

DeviceD(config)# ip access-list extended inter_vlan_access3

DeviceD(config-ext-nacl)# deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255

DeviceD(config-ext-nacl)# remark ¾Ü¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping

DeviceD(config-ext-nacl)# permit ip any any

DeviceD(config-ext-nacl)# remarkÔÊÐíÆäËû±¨ÎÄͨѶ

DeviceD(config-ext-nacl)# exit

# Device CÉèÖÃIPÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceC> enable

DeviceC# configure terminal

DeviceC(config)# ip access-list extended access_deny

DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet

DeviceC(config-ext-nacl)# remark ¾Ü¾øVLAN1ͨ¹ýTelnet»á¼ûVLAN 3

DeviceC(config-ext-nacl)# deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22

DeviceC(config-ext-nacl)# remark ¾Ü¾øVLAN1ͨ¹ýSSH»á¼ûVLAN 3

DeviceC(config-ext-nacl)# exit

(3)  Ó¦ÓÃIPÀ©Õ¹ACL¡£¡£¡£¡£¡£¡£¡£

# Device D½«IPÀ©Õ¹ACLÓ¦Óõ½¶ÔÓ¦½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceD(config)# interface vlan 1

DeviceD(config-if-VLAN 1)# ip access-group inter_vlan_access1 in

DeviceD(config-if-VLAN 1)# exit

DeviceD(config)# interface vlan 2

DeviceD(config-if-VLAN 2)# ip access-group inter_vlan_access2 in

DeviceD(config-if-VLAN 2)# exit

DeviceD(config)# interface vlan 3

DeviceD(config-if-VLAN 3)# ip access-group inter_vlan_access3 in

DeviceD(config-if-VLAN 3)# exit

# Device C½«IPÀ©Õ¹ACLÓ¦Óõ½ÓëDevice DÏàÁ¬Ïß·ÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceC(config)# line vty 0

DeviceC(config-line)# access-class access_deny in

DeviceC(config-line)# exit

5.    ÑéÖ¤ÉèÖÃЧ¹û

(1)  ÑéÖ¤Á¬Í¨ÐÔ¡£¡£¡£¡£¡£¡£¡£

# VLAN 1ÓëVLAN 2Ö®¼ä¿ÉÒÔPingͨ£¬£¬£¬£¬£¬£¬£¬VLAN 1ÓëVLAN 3Ö®¼ä¿ÉÒÔPingͨ¡£¡£¡£¡£¡£¡£¡£

DeviceA# ping 192.168.2.2

Sending 5, 100-byte ICMP Echoes to 192.168.2.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms

DeviceA#

DeviceA# ping 192.168.3.2

Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms

# VLAN 2ÓëVLAN 3Ö®¼ä²»¿ÉÒÔPingͨ¡£¡£¡£¡£¡£¡£¡£

DeviceB# ping 192.168.3.2

Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

.....

Success rate is 0 percent (0/5)

(2)  VLAN 1²»¿Éͨ¹ýTelnet»á¼ûVLAN 3¡£¡£¡£¡£¡£¡£¡£

DeviceA# ping 192.168.3.2

Sending 5, 100-byte ICMP Echoes to 192.168.3.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms

DeviceA#

DeviceA# telnet 192.168.3.2

Trying 192.168.3.2, 23...

% Destination unreachable; gateway or host down

6.    ÉèÖÃÎļþ

l  Device DµÄÉèÖÃÎļþ

hostname DeviceD

!

vlan 1

!

vlan 2

!

vlan 3

!

ip access-list extended inter_vlan_access1

?10 deny udp any eq bootps any eq bootpc

?20 deny udp any eq bootpc any eq bootps

?remark ¾Ü¾øDHCP±¨ÎÄ

?30 permit ip any any

?remarkÔÊÐíÆäËû±¨ÎÄͨѶ

!

ip access-list extended inter_vlan_access2

?10 deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255

?remark ¾Ü¾øVLNN2ºÍVLAN3Ö®¼ä»¥ping

?20 deny udp any eq bootpc any eq bootps

?30 deny udp any eq bootps any eq bootpc

?remark ¾Ü¾øDHCP±¨ÎÄ

?40 permit ip any any

?remark ÔÊÐíÆäËû±¨ÎÄͨѶ

!

ip access-list extended inter_vlan_access3

?10 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255

?remark ¾Ü¾øVLNN3ºÍVLAN2Ö®¼ä»¥ping

?20 permit ip any any

?remark ÔÊÐíÆäËû±¨ÎÄͨѶ

!

interface GigabitEthernet 1/0

?switchport access vlan 1

?description link_to_DeviceA

!

interface GigabitEthernet 1/1

?switchport access vlan 2

?description link_to_DeviceB

!

interface GigabitEthernet 1/2

?switchport access vlan 3

?description link_to_DeviceC

!

interface VLAN 1

?ip access-group inter_vlan_access1 in

?ip address 192.168.1.1 255.255.255.0

!

interface VLAN 2

?ip access-group inter_vlan_access2 in

?ip address 192.168.2.1 255.255.255.0

!

interface VLAN 3

?ip access-group inter_vlan_access3 in

?ip address 192.168.3.1 255.255.255.0

!

l  Device AµÄÉèÖÃÎļþ

hostname DeviceA

!

interface GigabitEthernet 0/1

?ip address 192.168.1.2 255.255.255.0

!

l  Device BµÄÉèÖÃÎļþ

hostname DeviceB

!

interface GigabitEthernet 0/1

?ip address 192.168.2.2 255.255.255.0

!

l  Device CµÄÉèÖÃÎļþ

hostname DeviceC

!

ip access-list extended access_deny

?10 deny tcp 192.168.1.0 0.0.0.255 eq telnet any eq telnet

?remark ¾Ü¾øVLAN1ͨ¹ýTelnet»á¼ûVLAN 3

?20 deny tcp 192.168.1.0 0.0.0.255 eq 22 any eq 22

?remark ¾Ü¾øVLAN1ͨ¹ýSSH»á¼ûVLAN 3

!

interface GigabitEthernet 0/1

?ip address 192.168.3.2 255.255.255.0

!

line vty 0

?access-class access_deny in

?login

?password abcdef

!

1.15.3? MACÀ©Õ¹ACLÉèÖþÙÀý

1.    ×éÍøÐèÇó

ͨ¹ýMACÀ©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÀ´·Ã¿Í»§¿É»á¼ûµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-5     MACÀ©Õ¹ACLÓ¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  Device AÉèÖÃMACÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£ÔÊÐí·Ã¿ÍÇøPC»á¼ûInternetÒÔ¼°¹«Ë¾ÄÚ²¿µÄ¹«¹²·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬µ«²»ÔÊÐí»á¼û¹«Ë¾µÄ²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¼´Õ¥È¡»á¼ûMACµØµãΪ00e0.f800.000dµÄ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£

l  Device A½«MACÀ©Õ¹ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃMACÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

# Device AÉèÖÃMACÀ©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# mac access-list extended 700

DeviceA(config-mac-nacl)# deny any host 00e0.f800.000d

DeviceA(config-mac-nacl)# permit any any

DeviceA(config-mac-nacl)# exit

(2)   ½«MACÀ©Õ¹ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£

# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# mac access-group 700 in

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£

DeviceA# show access-lists

mac access-list extended 700

10 deny any host 00e0.f800.000d etype-any

20 permit any any etype-any

DeviceA# show access-group

mac access-group 700 in

Applied On interface GigabitEthernet 0/2

# ´Ó·Ã¿ÍPC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔpingµÃͨ¡£¡£¡£¡£¡£¡£¡£

# ÔڷÿÍPC»úÉÏ»á¼ûInternet£¬£¬£¬£¬£¬£¬£¬ÀýÈç»á¼û°Ù¶È£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ·­¿ªÖ÷Ò³¡£¡£¡£¡£¡£¡£¡£

6.    ÉèÖÃÎļþ

l  DeviceAµÄÉèÖÃÎļþ

hostname DeviceA

!

mac access-list extended 700

?10 deny any host 00e0.f800.000d

?20 permit any any

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?mac access-group 700 in

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip address 12.1.1.1 255.255.255.0

!

1.15.4? ר¼Ò¼¶À©Õ¹ACLÉèÖþÙÀý

1.    ×éÍøÐèÇó

ͨ¹ýÉèÖÃר¼Ò¼¶À©Õ¹ACL£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÀ´·Ã¿Í»§¿É»á¼ûµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ÒªÇó·Ã¿Í²»¿É»á¼û¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬µ«ÄÜ»á¼û¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-6     ר¼Ò¼¶À©Õ¹ACLÓ¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  Device AÉèÖÃר¼Ò¼¶À©Õ¹ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º

¡ð         եȡ·Ã¿ÍÇøÄÚÖ÷»ú·¢³öÄ¿µÄΪ¹«Ë¾ÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

¡ð         եȡ·Ã¿Í»á¼û²ÆÎñÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£

¡ð         ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£¡£¡£¡£¡£¡£¡£

l  Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃר¼Ò¼¶À©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

# Device AÉèÖÃר¼Ò¼¶À©Õ¹ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# expert access-list extended 2700

DeviceA(config-exp-nacl)# deny ip any any 10.1.1.0 0.0.0.255 any

DeviceA(config-exp-nacl)# deny ip any any host 12.1.1.2 any

DeviceA(config-exp-nacl)# permit any any any any

DeviceA(config-exp-nacl)# exit

(2)   ½«×¨¼Ò¼¶À©Õ¹ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£

# Device A½«ACLÓ¦ÓÃÔÚÓë·Ã¿ÍÇøÏàÅþÁ¬¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# expert access-group 2700 in

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# show access-lists

expert access-list extended 2700

?10 deny ip any any 192.168.1.0 0.0.0.255 any

20 deny ip any any host 10.1.1.1 any

30 permit ip any any any any

 

DeviceA(config)# show access-group

expert access-group 2700in

Applied On interface GigabitEthernet 0/2

# ´Ó·Ã¿ÍPC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·Èϲ»¿Épingͨ¡£¡£¡£¡£¡£¡£¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1£¬£¬£¬£¬£¬£¬£¬È·¶¨pingÇ·ºà¡£¡£¡£¡£¡£¡£¡£

# ÔڷÿÍPC»úÉÏ»á¼ûInternet£¬£¬£¬£¬£¬£¬£¬ÀýÈç»á¼û°Ù¶È£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ·­¿ªÖ÷Ò³¡£¡£¡£¡£¡£¡£¡£

6.    ÉèÖÃÎļþ

l  DeviceAµÄÉèÖÃÎļþ

hostname DeviceA

!

expert access-list extended 2700

?10 deny ip any any 10.1.1.0 0.0.0.255 any

?20 deny ip any any host 12.1.1.2 any

?30 permit ip any any any any

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?expert access-group 2700 in

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip address 12.1.1.1 255.255.255.0

!

1.15.5? IPv6 ACLÉèÖþÙÀý

1.    ×éÍøÐèÇó

ͨ¹ýÉèÖÃIPv6 ACL£¬£¬£¬£¬£¬£¬£¬Õ¥È¡¿ª·¢²¿·Ö»á¼ûÊÓÆµ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-7     IPv6 ACLÓ¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  Device AÉèÖÃIPv6 ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º

¡ð         եȡ»á¼ûÊÓÆµ·þÎñÆ÷IPv6µØµã¹æÔò¡£¡£¡£¡£¡£¡£¡£

¡ð         ÔÚIPv6 ACLÖÐÌí¼ÓÔÊÐíËùÓÐIPv6±¨ÎÄͨ¹ý¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  Device A½«IPv6 ACLÓ¦ÓÃÔÚÅþÁ¬¿ª·¢²¿·Ö½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃIPv6 ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

# Device AÉèÖÃIPv6 ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# ipv6 access-list dev_deny_ipv6video

DeviceA(config-ipv6-nacl)# deny ipv6 any host 1002::2

DeviceA(config-ipv6-nacl)# permit ipv6 any any

DeviceA(config-ipv6-nacl)# exit

(2)   ½«IPv6 ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£

# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬¿ª·¢²¿·ÖËùÔÚ½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# ipv6 traffic-filter dev_deny_ipv6video in

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# show access-lists

 

ipv6 access-list dev_deny_ipv6video

10 deny ipv6 any host 200::1

20 permit ipv6 any any

 

DeviceA(config)# show access-group

ipv6 traffic-filter dev_deny_ipv6video in

Applied On interface GigabitEthernet 0/2

# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏpingÊÓÆµ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£

6.    ÉèÖÃÎļþ

l  DeviceAµÄÉèÖÃÎļþ

hostname DeviceA

!

ipv6 access-list dev_deny_ipv6video

?10 deny ipv6 any host 1002::2

?20 permit ipv6 any any

!

interface GigabitEthernet 0/1

?no switchport

?ipv6 address 1000::1/96

!

interface GigabitEthernet 0/2

?no switchport

?ipv6 traffic-filter dev_deny_ipv6video in

?ipv6 address 1001::1/96

!

interface GigabitEthernet 0/3

?no switchport

?ipv6 address 1002::1/96

!

1.15.6? ACL80ÉèÖþÙÀý

1.    ×éÍøÐèÇó

ͨ¹ýACL80¼´×¨¼Ò¼¶¸ß¼¶ACL£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÀ´·Ã¿Í»§¿É»á¼ûµÄ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ÒªÇó·Ã¿Í²»¿É»á¼û¹«Ë¾ÄÚ²¿Ô±¹¤µÄPCºÍ¹«Ë¾µÄ²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬µ«ÄÜ»á¼û¹«¹²×ÊÔ´·þÎñÆ÷ºÍInternet¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-8     ACL80Ó¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  Device AÉèÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º

¡ð         եȡ·Ã¿ÍÇøÄÚÖ÷»ú·¢³öÄ¿µÄΪÄÚ²¿Ô±¹¤Íø¶ÎµÄ±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

¡ð         եȡ·Ã¿Í»á¼û²ÆÎñÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£

¡ð         ÔÊÐíÆäËûËùÓб¨ÎÄͨ¹ý¡£¡£¡£¡£¡£¡£¡£

l  Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

# Device AÉèÖÃר¼Ò¼¶¸ß¼¶ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# expert access-list advanced acl80-guest

DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0A0101 FFFFFF 42

DeviceA(config-exp-dacl)# deny 0800 FFFF 24 0C010102 FFFFFFFF 42

DeviceA(config-exp-dacl)# permit 0806 FFFF 24

DeviceA(config-exp-dacl)# permit 0800 FFFF 24

DeviceA(config-exp-dacl)# exit

(2)   ½«×¨¼Ò¼¶¸ß¼¶ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£

# Device A½«ACL80Ó¦ÓÃÔÚÅþÁ¬·Ã¿ÍÇø½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if-GigabitEthernet 0/2)# expert access-group acl80-guest in

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# show access-lists

expert access-list advanced sss

?10 deny 0800 FFFF 24 0A0101 FFFFFF 42

?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42

?30 permit 0806 FFFF 24

?40 permit 0800 FFFF 24

 

expert access-group acl80-guest in

Applied On interface GigabitEthernet 0/2

# ´Ó·Ã¿ÍPC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏpingÇ·ºà¡£¡£¡£¡£¡£¡£¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«¹²×ÊÔ´·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔpingµÃͨ¡£¡£¡£¡£¡£¡£¡£

# ´Ó·Ã¿ÍPC»úÉÏping¹«Ë¾ÄÚ²¿Ô±¹¤Íø¹Ø192.168.1.1£¬£¬£¬£¬£¬£¬£¬È·¶¨pingÇ·ºà¡£¡£¡£¡£¡£¡£¡£

# ÔڷÿÍPC»úÉÏ»á¼ûInternet£¬£¬£¬£¬£¬£¬£¬ÀýÈç»á¼û°Ù¶È£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ·­¿ªÖ÷Ò³¡£¡£¡£¡£¡£¡£¡£

6.    ÉèÖÃÎļþ

l  DeviceAµÄÉèÖÃÎļþ

hostname DeviceA

!

expert access-list advanced acl80-guest

?10 deny 0800 FFFF 24 0A0101 FFFFFF 42

?20 deny 0800 FFFF 24 0C010102 FFFFFFFF 42

?30 permit 0806 FFFF 24

?40 permit 0800 FFFF 24

!

interface GigabitEthernet 0/1

?no switchport

?ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?no switchport

?expert access-group 2700 in

?ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?no switchport

?ip address 12.1.1.1 255.255.255.0

!

1.15.7? »ùÓÚʱ¼ä¶ÎµÄACL¹æÔòÉèÖþÙÀý

1.    ×éÍøÐèÇó

ÉèÖûùÓÚʱ¼ä¶ÎµÄACL¹æÔò£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÑз¢²¿·ÖÔÚÌìÌìµÄ12:00µ½13:30»á¼ûInternet¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-9     »ùÓÚʱ¼ä¶ÎµÄACL¹æÔòÓ¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  Device AÉèÖÃʱ¼ä¶Î£¬£¬£¬£¬£¬£¬£¬²¢Ìí¼ÓÌìÌì12:00µ½13:30µÄʱ¼ä¶Î±íÏî¡£¡£¡£¡£¡£¡£¡£

l  Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó¹æÔò£¬£¬£¬£¬£¬£¬£¬°üÀ¨£º

¡ð         Ìí¼ÓÔÊÐíÔ´IPÍø¶ÎµØµãΪ10.1.1.0/24µÄ¹æÔò£¬£¬£¬£¬£¬£¬£¬¹ØÁªµÄʱ¼ä¶ÎΪaccess-internet¡£¡£¡£¡£¡£¡£¡£

¡ð         Ìí¼ÓեȡԴIPÍø¶ÎµØµãΪ10.1.1.0/24µÄ¹æÔò¡£¡£¡£¡£¡£¡£¡£Åúעʱ¼ä¶ÎÖ®Íâ¶¼²»ÔÊÐí»á¼ûInternet¡£¡£¡£¡£¡£¡£¡£

¡ð         Ìí¼ÓÔÊÐí³ýÑз¢Íø¶ÎµØµãÍ⣬£¬£¬£¬£¬£¬£¬ÆäËûËùÓÐÍø¶ÎµØµãµÄ¹æÔò¡£¡£¡£¡£¡£¡£¡£

l  Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬Ñз¢²¿½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃʱ¼äÇø¡£¡£¡£¡£¡£¡£¡£

# Device AÉèÖÃʱ¼ä¶Î¡£¡£¡£¡£¡£¡£¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# time-range access-internet

DeviceA(config-time-range)# periodic daily 12:00 to 13:30

DeviceA(config-time-range)# exit

(2)   ÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

# Device AÉèÖÃIP±ê×¼ACL²¢Ìí¼Ó»á¼û¹æÔò¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# ip access-list standard ip_std_internet_acl

DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255 time-range access-internet

DeviceA(config-std-nacl)# deny 10.1.1.0 0.0.0.255

DeviceA(config-std-nacl)# permit any

DeviceA(config-std-nacl)# exit

(3)   ½«IP±ê×¼ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£

# Device A½«ACLÓ¦ÓÃÔÚÅþÁ¬Ñз¢²¿½Ó¿ÚµÄÈëÆ«ÏòÉÏ¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# interface gigabitethernet 0/1

DeviceA(config-if-GigabitEthernet 0/1)# ip access-group ip_std_internet_acl in

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ¼ì²éDevice A×°±¸ACLÉèÖÃÏÂÁîÊÇ·ñ׼ȷ¡£¡£¡£¡£¡£¡£¡£

DeviceA# show time-range

 

time-range entry: access-internet (inactive)

¡¡periodic Daily 12:00 to 13:30

 

DeviceA# show access-lists

 

ip access-list standard ip_std_internet_acl

?10 permit 10.1.1.0 0.0.0.255 time-range access-internet (inactive)

?20 deny 10.1.1.0 0.0.0.255

?30 permit any

 

DeviceA# show access-group

ip access-group ip_std_internet_acl in

Applied On interface GigabitEthernet 0/1

# ÔÚʱ¼ä¶ÎÉúЧÆÚÄÚ£¨12:00ÖÁ13:30£©£¬£¬£¬£¬£¬£¬£¬´ÓÑз¢²¿·ÖÄÚµÄij̨PCʱ»ú¼û°Ù¶ÈÖ÷Ò³£¬£¬£¬£¬£¬£¬£¬È·ÈÏ¿ÉÒÔ»á¼û¡£¡£¡£¡£¡£¡£¡£

# ÔÚʱ¼ä¶ÎʧЧÆÚ£¨12:00ÖÁ13:30ʱ¶ÎÍ⣩£¬£¬£¬£¬£¬£¬£¬´ÓÑз¢²¿·ÖÄÚµÄij̨PCʱ»ú¼û°Ù¶ÈÖ÷Ò³£¬£¬£¬£¬£¬£¬£¬È·Èϲ»¿É»á¼û¡£¡£¡£¡£¡£¡£¡£

6.    ÉèÖÃÎļþ

l  DeviceAµÄÉèÖÃÎļþ

hostname DeviceA

!

ip access-list standard ip_std_internet_acl

?10 permit 10.1.1.0 0.0.0.255 time-range access-internet

?20 deny 10.1.1.0 0.0.0.255

?30 permit any

!

time-range access-internet

?periodic daily 12:00 to 13:30

!

interface GigabitEthernet 0/1

?no switchport

?ip access-group ip_std_internet_acl in

?ip address 10.1.1.1 255.255.255.0

!

1.15.8? SVI Router ACLÉèÖþÙÀý

1.    ×éÍøÐèÇó

ÉèÖÃVRRP+VLANÓ¦Óó¡¾°£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÖ÷»úÓëÖ÷»úÖ®¼äµÄÈý²ãͨѶ¡£¡£¡£¡£¡£¡£¡£ÉèÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä»á¼ûµÄACL£¬£¬£¬£¬£¬£¬£¬¾Ü¾øÆäËûËùÓÐÍø¶ÎµÄACL¡£¡£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

ͼ1-10   VRRP+VLANÓ¦Óó¡¾°×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  DeviceAºÍDeviceB×é³ÉVRRP³¡¾°¡£¡£¡£¡£¡£¡£¡£Ö÷»úPC1ºÍPC2ËùÓнÓÈëµ½DeviceC¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖÃÌìÉúÊ÷ЭÒ飬£¬£¬£¬£¬£¬£¬Ïû³ýDeviceA¡¢DeviceBºÍDeviceCÖ®¼äµÄ»·Â·¡£¡£¡£¡£¡£¡£¡£

l  Ö÷»úPC1ºÍPC2µÄÍø¹Ø½ÓÄÉSVI½Ó¿ÚµÄµØµã¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖÃÖ»ÔÊÐíÖ÷»úÖ®¼ä»á¼ûµÄACL£¬£¬£¬£¬£¬£¬£¬¾Ü¾øÆäËûËùÓÐÍø¶ÎµÄACL£¬£¬£¬£¬£¬£¬£¬²¢½«ACLÓ¦ÓÃÔÚSVI½Ó¿ÚÉÏ¡£¡£¡£¡£¡£¡£¡£´Ëʱ»áµ¼ÖÂVRRP×éÄÚDeviceAºÍDeviceBÐγÉË«Ö÷¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖÃsvi router-acls enableÏÂÁîºó£¬£¬£¬£¬£¬£¬£¬VRRP×éÄÚDeviceAºÍDeviceBÐγÉÒ»Ö÷Ò»±¸£¬£¬£¬£¬£¬£¬£¬VRRPЭÒé»Ö¸´Õý³£¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃVLAN¡£¡£¡£¡£¡£¡£¡£

# DeviceAÉèÖÃVLAN¡£¡£¡£¡£¡£¡£¡£DeviceA¡¢DeviceBºÍDeviceCÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# vlan 10

DeviceA(config-vlan)# exit

DeviceA(config)# vlan 20

DeviceA(config-vlan)# exit

(2)   ÉèÖÃVRRP×é¡£¡£¡£¡£¡£¡£¡£

# DeviceAÉèÖÃVRRP¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# interface VLAN 10

DeviceA(config-if-VLAN 10)# ip address 172.16.1.3 255.255.255.0

DeviceA(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1

DeviceA(config-if-VLAN 10)# vrrp 10 priority 120

DeviceA(config-if-VLAN 10)# exit

DeviceA(config)# interface VLAN 20

DeviceA(config-if-VLAN 20)# ip address 172.31.1.4 255.255.255.0

DeviceA(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1

# DeviceBÉèÖÃVRRP¡£¡£¡£¡£¡£¡£¡£

DeviceB(config)# interface VLAN 10

DeviceB(config-if-VLAN 10)# ip address 172.16.1.4 255.255.255.0

DeviceB(config-if-VLAN 10)# vrrp 10 ip 172.16.1.1

DeviceB(config-if-VLAN 10)# exit

DeviceB(config)# interface VLAN 20

DeviceB(config-if-VLAN 20)# ip address 172.31.1.3 255.255.255.0

DeviceB(config-if-VLAN 20)# vrrp 20 ip 172.31.1.1

DeviceB(config-if-VLAN 20)# vrrp 20 priority 120

DeviceB(config-if-VLAN 20)# exit

(3)   ÉèÖÃÌìÉúÊ÷ЭÒ飬£¬£¬£¬£¬£¬£¬Ïû³ý»·Â·¡£¡£¡£¡£¡£¡£¡£

# DeviceAÉèÖÃÌìÉúÊ÷ЭÒé¡£¡£¡£¡£¡£¡£¡£DeviceA¡¢DeviceBºÍDeviceCÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# spanning-tree

(4)   ÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£

# DeviceAÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£DeviceAºÍDeviceBÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# ip access-list standard 10

DeviceA(config-std-nacl)# permit host 3.3.3.3

DeviceA(config-std-nacl)# deny any

DeviceA(config-std-nacl)# exit

(5)   ½«ACLÓ¦Óõ½SVI½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£

# DeviceAÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£DeviceAºÍDeviceBÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# int vlan 20

DeviceA(config-if-VLAN 20)# ip access-group 10 in

(6)   ÉèÖÃÏÂÁîsvi router-acls enable¡£¡£¡£¡£¡£¡£¡£

# DeviceAÉèÖÃÏÂÁîsvi router-acls enable¡£¡£¡£¡£¡£¡£¡£DeviceAºÍDeviceBÉèÖÃÍêÈ«Ïàͬ£¬£¬£¬£¬£¬£¬£¬ÒÔÏÂÒÔDeviceAÉèÖÃΪÀý¡£¡£¡£¡£¡£¡£¡£

DeviceA(config)# svi router-acls enable

 

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ¼ì²éDeviceA×°±¸VRRPЭÒé״̬¡£¡£¡£¡£¡£¡£¡£

DeviceA# show vrrp

Interface¡¡¡¡Grp¡¡Pri¡¡ timer¡¡ Own¡¡Pre¡¡ State¡¡ Master addr¡¡¡¡ Group addr¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡

VLAN 10¡¡¡¡¡¡10¡¡ 120¡¡ 3.53¡¡¡¡-¡¡¡¡P¡¡¡¡ Master¡¡172.16.1.3¡¡¡¡¡¡172.16.1.1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡

VLAN 20¡¡¡¡¡¡20¡¡ 100¡¡ 3.60¡¡¡¡-¡¡¡¡P¡¡¡¡ Backup¡¡172.31.1.3¡¡¡¡¡¡172.31.1.1

6.    ÉèÖÃÎļþ

l  DeviceAµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£

hostname DeviceA

!

vlan 1

!

vlan 10

!

vlan 20

!

spanning-tree

!

ip access-list standard 10

?10 permit host 3.3.3.3

?20 deny any

!

svi router-acls enable

!

interface GigabitEthernet 0/1

?switchport mode trunk

!

interface GigabitEthernet 0/3

?switchport mode trunk

!

interface VLAN 1

?ip address 192.168.1.2 255.255.255.0

!

interface VLAN 10

?ip address 172.16.1.3 255.255.255.0

?vrrp 10 priority 120

?vrrp 10 ip 172.16.1.1

!

interface VLAN 20

?ip access-group 10 in

?ip address 172.31.1.4 255.255.255.0

?vrrp 20 ip 172.31.1.1

!

ip route 3.3.3.0 255.255.255.0 192.168.1.1

!

l  DeviceBµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£

hostname DeviceB

!

vlan 1

!

vlan 10

!

vlan 20

!

spanning-tree

!

ip access-list standard 10

?10 permit host 3.3.3.3

?20 deny any

!

svi router-acls enable

!

interface GigabitEthernet 0/1

?switchport mode trunk

!

interface GigabitEthernet 0/3

?switchport mode trunk

!

interface VLAN 1

?ip address 192.168.2.2 255.255.255.0

!

interface VLAN 10

?ip access-group 10 in

?ip address 172.16.1.4 255.255.255.0

?vrrp 10 ip 172.16.1.1

!

interface VLAN 20

?ip address 172.31.1.3 255.255.255.0

?vrrp 20 priority 120

?vrrp 20 ip 172.31.1.1

!

ip route 3.3.3.0 255.255.255.0 192.168.2.1

!

l  DeviceCµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£

hostname DeviceC

!

vlan 1

!

vlan 10

!

vlan 20

!

interface GigabitEthernet 0/1

?switchport access vlan 10

!

interface GigabitEthernet 0/2

?switchport access vlan 20

!

interface GigabitEthernet 0/3

?switchport mode trunk

!

interface GigabitEthernet 0/4

?switchport mode trunk

!

l  ServerAµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£

hostname ServerA

!

interface GigabitEthernet 0/1

?ip address 192.168.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?ip address 192.168.2.1 255.255.255.0

!

interface Loopback 0

?ip address 3.3.3.3 255.255.255.0

!

ip route 172.16.1.0 255.255.255.0 192.168.1.2

ip route 172.31.1.0 255.255.255.0 192.168.2.2

!

1.15.9? ACL±¨ÎļÆÊýͳ¼ÆÉèÖþÙÀý

1.    ×éÍøÐèÇó

Ó¦ÓÃACLʱÈôÊÇÉèÖôøcounter-onlyÑ¡Ï£¬£¬£¬£¬£¬£¬¿ÉÒÔ¶ÔÄ³Ð©ÌØÕ÷µÄ±¨ÎľÙÐмÆÊýͳ¼Æ¡£¡£¡£¡£¡£¡£¡£ÒÔPC pingÍø¹ØÑïÆúICMP±¨ÎÄΪÀý¾ÙÐмÆÊýͳ¼Æ£¬£¬£¬£¬£¬£¬£¬²¢¶¨Î»¶ª°üλÖᣡ£¡£¡£¡£¡£¡£

2.    ×éÍøÍ¼

 

3.    ÉèÖÃÒªµã

l  DeviceÉÏG0/1ºÍG0/2µÄÈëÆ«ÏòºÍ³öÆ«Ïò¶¼ÒªÓ¦ÓÃACL£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇDeviceÐèÒªÉèÖÃ4ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

l  Gateway×°±¸G0/1µÄÈëÆ«ÏòºÍ³öÆ«Ïò¶¼ÒªÓ¦ÓÃACL£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇGatewayÉèÖÃ2ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayºÍ´ÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

l  Ó¦ÓÃACLʱÉèÖÃÐèÒªcounter-onlyÑ¡Ïî¡£¡£¡£¡£¡£¡£¡£

l  ¼ÆÊýͳ¼ÆÖ»¶Ô¸ÃACLÖеÄPermit¹æÔòÉúЧ£¬£¬£¬£¬£¬£¬£¬Deny¹æÔò²»ÉúЧ¡£¡£¡£¡£¡£¡£¡£

4.    ÉèÖð취

(1)   ÉèÖÃACL¡£¡£¡£¡£¡£¡£¡£

# Device×°±¸ÉèÖÃ4ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

Device> enable

Device# configure terminal

Device(config)# ip access-list extend 100

Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254

Device(config-ext-nacl)# exit

Device(config)# ip access-list extend 101

Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1

Device(config-ext-nacl)# exit

Device(config)# ip access-list extend 102

Device(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254

Device(config-ext-nacl)# exit

Device(config)# ip access-list extend 103

Device(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1

Device(config-ext-nacl)# exit

# Gateway×°±¸ÉèÖÃ2ÌõACL£¬£¬£¬£¬£¬£¬£¬»®·ÖÆ¥Åä´ÓPCµ½GatewayµÄICMP±¨ÎĺʹÓGatewayµ½PCµÄICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£

Gateway> enable

Gateway #configure terminal

Gateway(config)# ip access-list extend 100

Gateway(config-ext-nacl)# permit icmp host 10.10.10.1 host 10.10.10.254

Gateway(config-ext-nacl)# exit

Gateway(config)# ip access-list extend 101

Gateway(config-ext-nacl)# permit icmp host 10.10.10.254 host 10.10.10.1

Gateway(config-ext-nacl)# exit

(2)   Ó¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£

# ÔÚGateway×°±¸ºÍDevice×°±¸»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòºÍ³öÆ«ÏòÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£

Gateway(config)# interface gigabitEthernet 0/1

Gateway(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only

Gateway(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only

Gateway(config-if-GigabitEthernet 0/1)# exit

# ÔÚDevice×°±¸ºÍGateway×°±¸»¥Áª½Ó¿ÚG0/2µÄÈëÆ«ÏòºÍ³öÆ«ÏòÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£

Device# configure terminal

Device(config)# interface gigabitEthernet 0/2

Device(config-if-GigabitEthernet 0/2)# ip access-group 103 in counter-only

Device(config-if-GigabitEthernet 0/2)# ip access-group 102 out counter-only

Device(config-if-GigabitEthernet 0/2)# exit

# ÔÚDevice×°±¸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòºÍ³öÆ«ÏòÓ¦ÓÃACL¡£¡£¡£¡£¡£¡£¡£

Device# configure terminal

Device(config)# interface gigabitEthernet 0/1

Device(config-if-GigabitEthernet 0/1)# ip access-group 100 in counter-only

Device(config-if-GigabitEthernet 0/1)# ip access-group 101 out counter-only

Device(config-if-GigabitEthernet 0/1)# exit

5.    ÑéÖ¤ÉèÖÃЧ¹û

# ÔÚPCÉÏpingÍø¹ØµØµã10.10.10.254£¬£¬£¬£¬£¬£¬£¬3´Î¹²·¢³ö15¸öICMP±¨ÎÄ¡£¡£¡£¡£¡£¡£¡£»®·ÖÉó²éDevice×°±¸ºÍGateway×°±¸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£¡£¡£¡£¡£¡£¡£Éó²éDevice×°±¸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£¡£¡£¡£¡£¡£¡£

Device# show access-list

ip access-list extended 100

¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)

ip access-list extended 101

¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)

ip access-list extended 102¡¡

¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)

ip access-list extended 103¡¡

¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (10 matches)

# Éó²éGateway×°±¸ÉÏICMP±¨ÎÄͳ¼Æ¼ÆÊý¡£¡£¡£¡£¡£¡£¡£

Gateway# show access-list

ip access-list extended 100

¡¡ 10 permit ip host 10.10.10.1 host 10.10.10.254 (15 matches)

ip access-list extended 101

¡¡ 10 permit ip host 10.10.10.254 host 10.10.10.1 (15 matches)

# ÆÊÎö±¨ÎÄͳ¼Æ¼ÆÊý£¬£¬£¬£¬£¬£¬£¬¶¨Î»±¨ÎÄÑïÆúλÖᣡ£¡£¡£¡£¡£¡£

Device×°±¸ºÍPC»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòÊÕµ½15¸ö±¨ÎÄ£¨Device×°±¸ACL 100£©¡£¡£¡£¡£¡£¡£¡£

Device×°±¸ºÍGateway×°±¸»¥Áª½Ó¿ÚG0/2µÄ³öÆ«Ïò·¢³ö15¸ö±¨ÎÄ£¨Device×°±¸ACL 102£©¡£¡£¡£¡£¡£¡£¡£

Gateway×°±¸ºÍDevice×°±¸»¥Áª½Ó¿ÚG0/1µÄÈëÆ«ÏòÊÕµ½15¸ö±¨ÎÄ£¨Gateway×°±¸ACL 100£©¡£¡£¡£¡£¡£¡£¡£

Gateway×°±¸ºÍDevice×°±¸»¥Áª½Ó¿ÚG0/1µÄ³öÆ«Ïò·¢³ö15¸ö±¨ÎÄ£¨Gateway×°±¸ACL 101£©¡£¡£¡£¡£¡£¡£¡£

Device×°±¸ºÍGateway×°±¸»¥Áª½Ó¿ÚG0/2µÄÈëÆ«ÏòÊÕµ½10¸ö±¨ÎÄ£¨Device×°±¸ACL 103£©¡£¡£¡£¡£¡£¡£¡£

˵Ã÷±¨ÎÄÑïÆúÔÚDevice×°±¸ºÍGateway×°±¸Ö®¼äµÄÁ´Â·ÉÏ¡£¡£¡£¡£¡£¡£¡£

6.    ÉèÖÃÎļþ

l  DeviceµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£

hostname Device

!

ip access-list extended 100

?10 permit icmp host 10.10.10.1 host 10.10.10.254

!

ip access-list extended 101

?10 permit icmp host 10.10.10.254 host 10.10.10.1

!

ip access-list extended 102

?10 permit icmp host 10.10.10.1 host 10.10.10.254

!

ip access-list extended 103

?10 permit icmp host 10.10.10.254 host 10.10.10.1

!

interface GigabitEthernet 0/1

?ip access-group 100 in counter-only

?ip access-group 101 out counter-only

!

interface GigabitEthernet 0/2

?ip access-group 103 in counter-only

?ip access-group 104 out counter-only

!

l  GatewayµÄÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£

hostname Gateway

!

ip access-list extended 100

?10 permit icmp host 10.10.10.1 host 10.10.10.254

!

ip access-list extended 101

?10 permit icmp host 10.10.10.254 host 10.10.10.1

!

interface GigabitEthernet 0/1

?ip access-group 100 in counter-only

?ip access-group 101 out counter-only

?ip address 10.10.10.254 255.255.255.0

!

 

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿