CCNA ACL 实验

e28a4287b53d4a79acde1aed20d0776f

21d7d0b271d74432906d3dc01c43ad3c

f03811a7aba94006b77e6772c0380d97

d62af16ddb934aaeb7fd12e9ec28e367

59d44c678ca74d7f967c82050e989532

875a0a25b53a45c6abc3bf3dd26dc8c4

41c830a72fed4b3c9e54acbeadc44a37

在CCIE考试中,不能删除原先ACL条目只能修改

39f5f895cdb64c5398f32e5c0459795e

8b68e82f3f2e42cfac99d19d8acd91f6

c24f73ea26f44fd58c7d93ac68c6cfd5

32650f5da2b842a18ff4628e30827732

75100698eebd4456894ceaa1c4d3a9ab

2c587ef277ed498cb0ee60c480459e98

5c815eb9672e4ae0a3e1d4ba44d87fbb

39a74e3abc1a4167b153cfde7b2d320d

实验拓扑

e8d866742a9441449dabaf9e8075a8a9

cf4f272e4a7943149981d8b513be80e5

确保接口和路由协议都是联通

需求如下

ab4b341270f74f31b3c60cb54fdf1563

7aa21e60e835452e8fea46233c228616

R4(config)#access-list 1 deny host 192.168.12.1

R4(config)#access-list 1 permit any

fc03f8b12ffb4d758574d84303785d3b

sh run的结果

把条件应用到e0/2口上

R4(config)#int e0/2

R4(config-if)#ip access-group 1 in

R4(config-if)#end

R1 5个丢包

7c0dff38b2bb4e378920bf220dfcc4cc

删除也很简单

R4(config-if)#no ip access-group 1 in

第一种方法浪费了很多带宽,第二种方法在R2上做

R2(config)#access-list 100 deny ip host 192.168.12.1 host 4.4.4.4

R2(config)#access-list 100 permit ip any any

c43ec84a40224fd19eb978f107ed5241

应用到接口上

R2(config-if)#ip access-group 100 in

R1就无法访问了R4了

50e806124a484c258bc36d3d2ef0e660

编辑方法如下

R2(config)#ip access-list extended 100

R2(config-ext-nacl)#do show access-list

Extended IP access list 100

10 deny ip host 192.168.12.1 host 4.4.4.4 (15 matches)

20 permit ip any any (15 matches)

简单就no 掉

R2(config-ext-nacl)#no 10

R2(config-ext-nacl)#do show access-list

Extended IP access list 100

20 permit ip any any (17 matches)

加回来的时候记得一定要比permit 的数字低

R2(config-ext-nacl)#5 deny ip host 192.168.12.1 host 4.4.4.4

R2(config-ext-nacl)#do show access-list

Extended IP access list 100

5 deny ip host 192.168.12.1 host 4.4.4.4

20 permit ip any any (21 matches)

R2(config-ext-nacl)#

6c9269e956974565b3af059b1b1d70c5

命名方式来实现

R4(config)#ip access-list standard CCIE

R4(config-std-nacl)#deny 192.168.12.1

R4(config-std-nacl)#permit any

45d90c17d69e4b7cb81d96c3cf8e3904

猜你喜欢

转载自blog.51cto.com/433266/2114191