本文共 1318 字,大约阅读时间需要 4 分钟。
思科:默认deny所有
标准acl,只能检查流量的源IP地址,1-99,扩展acl,同时检查流量的:源IP,目的IP,源port,目的port,protocol,100-199华为:默认permit所有基本adl,只能检查流量的源IP地址,2000-2999高级acl,同时检查流量的:源IP,目的IP,源port,目的port,protocol,3000-3999二层acl,检查流量的源/目的MAC地址以及二层协议类型等,4000-4999通配符掩码:
32bit的数字,使用“0”匹配,“1”忽略,指定与“IP网络前缀”的匹配方式例如:192.168.1.0 0.0.0.255思科ACL配置命令:
(编号式)标准acl配置:access-list 1 permit 172.16.0.0 0.0.255.255interface ethernet 0 ip access-group 1 out(编号式)扩展acl配置:access-list 101 deny tcp 172.16.4.0 0.0.0.255 172.16.3.0 0.0.0.255 eq 21access-list 101 permit any anyinterface ethernet 0ip access-group 101 out(命名式)标准acl配置:ip access-list standard troublemakerdeny host 172.16.4.13permit 172.16.4.0 0.0.0.255interface ethernet 0ip access-group troublemaker out(命名式)扩展acl配置:ip access-list extended badgroupdeny tcp 172.16.4.0 0.0.0.255 any eq 23permit ip any anyinterface ethernet 0ip access-group badgroup out华为ACL配置命令:
基本ACL配置:acl 2000rule deny source 192.168.1.0 0.0.0.255interface ethernet 0/0/0traffic-filter outbound acl 2000高级ACL配置:acl 3000rule deny tcp source 192.168.1.0 0.0.0.255 destination 172.16.10.1 0.0.0.0 destination-port eq 21rule deny tcp source 192.168.2.0 0.0.0.255 destination 172.16.10.0 0.0.0.0rule permit ipinterface ethernet 0/0/0traffic-filter outbound acl 3000转载于:https://blog.51cto.com/12950413/2150826