¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
ÌåҪʹÓÃperiodicÃüÁî¡£½«ÔÚÏÂÃæµÄÅäÖÃʵÀýÖÐÏêϸ½éÉÜ¡£
»ùÓÚʱ¼äµÄACLÅäÖó£ÓÃÃüÁî
R1(config)#time-range time //¶¨Òåʱ¼ä·¶Î§
R1(config-time-range)#periodic weekdays 8:00 to 18:00
R1(config)#access-list 111 permit tcp host 172.16.3.1 host 2.2.2.2 eq telnet time-range time
³£ÓÃʵÑéµ÷ÊÔÃüÁî
¢Ù Óá°clock set¡±ÃüÁϵͳʱ¼äµ÷Õûµ½ÖÜÒ»ÖÁÖÜÎåµÄ8£º00-18£º00·¶Î§ÄÚ£¬È»ºóÔÚTelnet·ÓÉÆ÷R1£¬´Ëʱ¿ÉÒԳɹ¦£¬È»ºó²é¿´·ÃÎÊ¿ØÖÆÁбí111£º
R1#show access-lists Extended IP access list 111
10 permit tcp host 172.16.3.1 host 2.2.2.2 eq telnet time-range time (active)
¢Ú Óá°clock set¡±ÃüÁϵͳʱ¼äµ÷Õûµ½8£º00-18£º00·¶Î§Ö®Í⣬ȻºóTelnet·ÓÉÆ÷R1£¬´Ëʱ²»¿ÉÒԳɹ¦£¬È»ºó²é¿´·ÃÎÊ¿ØÖÆÁбí111£º
R1#show access-lists Extended IP access list 111
10 permit tcp host 172.16.3.1 host 2.2.2.2 eq telnet time-range time (inactive)
¢Û show time-range£º¸ÃÃüÁîÓÃÀ´²é¿´¶¨ÒåµÄʱ¼ä·¶Î§¡£ R1#show time-range
time-range entry: time (inactive) periodic weekdays 8:00 to 18:00 used in: IP ACL entry
ÒÔÉÏÊä³ö±íʾÔÚ3ÌõACLÖе÷ÓÃÁ˸Ãtime-range¡£
2.5 ·ÃÎÊ¿ØÖÆÁбíµÄÏÔʾºÍµ÷ÊÔ
ÔÚÌØÈ¨Ä£Ê½Ï£¬
ʹÓá°show access-lists ¡±¿ÉÒÔÏÔʾ·ÓÉÆ÷ÉÏÉèÖõÄËùÓÐACLÌõÄ¿£» ʹÓá°show access-list acl number¡±Ôò¿ÉÒÔÏÔÊ¾ÌØ¶¨ACLºÅµÄACLÌõÄ¿£» ʹÓá°show time-range¡±ÃüÁî¿ÉÒÔÓÃÀ´²é¿´¶¨ÒåµÄʱ¼ä·¶Î§£»
ʹÓá°clear access-list counters¡±ÃüÁî¿ÉÒÔ½«·ÃÎÊ¿ØÖÆÁбíµÄ¼ÆÊýÆ÷ÇåÁã¡£
- 11 -
¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
3¡¢ACLÔÚÐ£Ô°ÍøÖеÄÓ¦ÓÃʵÀý
ͼ6ÊÇÄ³Ñ§Ð£ÍøÂç½á¹¹ÌåµÄÒ»²¿·Ö£¬ÆäÖаüÀ¨½Ìʦ°ì¹«ÊÒ£¬·þÎñÆ÷»ú·¿ºÍѧÉúʵÑéÊÒÈô¸É¡£±¾ÍøÂçÖÐÈ«²¿Ê¹ÓÃ24λ×ÓÍøÑÚÂë¡£
ͼ6.ijѧУµÄÍøÂçÍØÆË½á¹¹Í¼
ÔÚͼ6ÖУ¬Â·ÓÉÆ÷ʹÓÃÒÔÌ«Íø¶Ë¿ÚE0Á¬½Óµ½½Ìʦ°ì¹«ÊÒ(Íø¶ÎΪ192.168.1.0)£¬Ê¹ÓÃÒÔÌ«Íø¶Ë¿ÚE1Á¬½Óµ½Ñ§Ð£µÄ·þÎñÆ÷»ú·¿£¨Íø¶ÎΪ192.168.2.0£©£¬Ê¹ÓÃÒÔÌ«Íø¶Ë¿ÚE2Á¬½Óµ½ÄãѧÉúʵÑéÊÒ£¨Íø¶ÎΪ192.168.3.0£©£¬Ê¹Óô®¿ÚS0Á¬½Óµ½Ð£Ô°Íø¡£Â·ÓÉÆ÷E1¡¢E1ºÍE2¶Ë¿ÚµÄIPµØÖ·Îª192.168.1.1£¬192.168.2.1ºÍ195.168.3.1¡£¼ÆËã»ú1µÄIPµØÖ·Îª192.168.1.11£¬¼ÆËã»ú2µÄIPµØÖ·Îª192.168.1.12£¬¼ÆËã»ú3µÄIP µØÖ·Îª192.168.3.11£¬¼ÆËã»ú4µÄIPµØÖ·Îª192.168.3.12.FTP·þÎñÆ÷µÄIPµØÖ·Îª192.168.2.11£¬WWW·þÎñÆ÷µÄIPµØÖ·Îª192.168.2.12¡£
¸ù¾Ý½ÌÊҰ칫ÊÒ£¬·þÎñÆ÷»ú·¿ºÍѧÉúʵÑéÊÒ¶ÔÍøÂç¼°ÆäÊý¾Ý°²È«µÄÒªÇó²»Í¬£¬ÀûÓÃACL¼¼Êõ¹¹½¨ÁËÒÔϵÄÍøÂ簲ȫ²ßÂÔ¡£
3.1ʵÏÖÍøÂç·ÃÎʵĵ¥Ïò¿ØÖÆ
½ÌÊҰ칫ÊÒ(Íø¶ÎΪ192.168.1.0)ÓÃÓÚ½Ìʦ°ì¹«£¬Ö÷»úÉÏÍùÍù»á´æÒ»Ð©ÊÔ¾íµÈÃô¸ÐÊý¾Ý£¬Òò´Ë²»ÄÜÈÃѧÉúʵÑéÊÒ£¨Íø¶ÎΪ192.168.3.0£©·ÃÎÊ£¬µ«ÊǽÌʦ°ì¹«ÊÒÍø¶Î¿ÉÒÔ·ÃÎÊѧÉúʵÑéÊҵļÆËã»ú£¬ÒÔ±ã¶ÔѧÉú×öʵÑé¡¢ÉϿεÈÇé¿ö½øÐйÜÀíºÍ¼à¿Ø¡£
Ê×ÏÈÔÚ·ÓÉÆ÷ÉϲÉÓÃIP±ê×¼¿ØÖÆÁбíÈçÏ£º
- 12 -
¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
Router(config)#access-list 1 deny 192.168.3.0 0.0.0.255 Router(config)#access-list 1 permit any Router(config)#int E0
Router(config)#ip access-group 1 out
ÔÚ·ÓÉÆ÷ÉÏÅäÖóɹ¦ºó£¬192.168.3.0Íø¶Î²»ÄÜ·ÃÎÊ192.16.1.0Íø¶Î£¬µ«Í¬Ê±192.168.1.0Íø¶ÎÒ²²»ÄÜ·ÃÎÊ192.168.3.0Íø¶Î£¬ÔÒòÊÇÔÚ·ÓÉÆ÷E0¶Ë¿ÚµÄout·½ÏòÉÏÉèÖÃÁË·ÃÎÊ¿ØÖƲßÂÔdeny 192.168.3.0 0.0.0.255Ëü×èÖ¹ÁË´Ó192.168.3.0·¢¸ø192.168.1.0µÄËùÒÔÊý¾Ý°ü£¬¼´Ê¹ÊÇ192.168.3.0¸ø192.168.1.0µÄ»Ø¸´Êý¾Ý°üÒ²Ò»Ñù×èÖ¹ÁË¡£Óɴ˿ɼû£¬¼òµ¥µÄʹÓ÷ÃÎÊ¿ØÖÆÁÐ±í»¹²»Äܽâ¾öÕâ¸öÎÊÌâ¡£
ҪʵÏÖ192.168.1.0Íø¶Îµ½192.168.3.0Íø¶ÎµÄµ¥Ïò·ÃÎÊ¿ØÖÆ£¬²ÉÓ÷ÃÎÊ¿ØÖÆÁбíÅäÖÃÈçÏ£º
Router(config)#access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255 estaelished
Router(config)#access-list 101 permit tcp any any Router(config)#int E2
Router(config)#ip access-group 101 in
¸Ã²ßÂÔµÄÔÀíÊǵ±TCPÁ¬½ÓÒѾ½¨Á¢Ê±£¬ÔÚ·ÓÉÆ÷E2¶Ë¿ÚµÄin·½ÏòÉϼì²éÊý¾Ý°ü£¬Èç¹ûËü±íʾȷÈϵÄÊý¾Ý°ü¼´¿Éͨ¹ý£¬¶øÈç¹ûÊÇ192.168.3.0Íø¶ÎÏò192.168.1.0Íø¶Î·¢ÆðTCPÁ¬½ÓÊý¾Ý°üÔòËü²»±íʾȷÈÏÊý¾Ý°ü£¬Òò´Ë¾Ü¾øÍ¨¹ý¡£ÕâÑùÉèÖÃÒÔºó£¬Ñ§ÉúÔÚʵÑéÊҾͲ»ÄÜ·ÃÎʽÌʦ¼ÆËã»úÉϵÄÊÔ¾íµÈÃô¸Ð×ÊÁÏ£¬¶ø½ÌÊÒ¼ÆËã»úÒÀÈ»¿ÉÒÔ¹ÜÀíѧÉúʵÑéÊÒµÄÉϿκÍÉÏ»úÇé¿ö¡£
3.2½ûÖ¹»òÔÊÐí²¿·ÖÍøÂç·þÎñ
ʵÑéÊÒÒ»µ©Á¬½ÓÁËÐ£Ô°Íø£¬¾Í¿ÉÒÔ·ÃÎʺܶà×ÊÔ´£¬°üÀ¨µçÓ°Ö®ÀàµÄ¡£µ«ÊÇʵÑéÊÒÊÇΪѧÉúÌṩ×öʵÑ顢ѧϰµÄ³¡Ëù£¬ÔÚÉÏ¿ÎÆÚ¼ä²»ÔÊÐíѧÉúÏÂÔØµçÓ°»òÕßÔÚÏß¹Û¡£ÔÚͼ6ÖУ¬¼ÙÉè´ó²¿·ÖµçÓ°Ö®ÀàµÄ×ÊÔ´·ÅÔÚÐ£Ô°ÍøµÄ192.168.2.0Íø¶ÎµÄFTP·þÎñÆ÷ÉÏ£¬Òò´ËÒª½ûֹѧÉúʵÑéÊÒ192.168.3.0Íø¶Î·ÃÎÊ192.168.2.0Íø¶ÎµÄFTP·þÎñ£¬µ«ÒÀÈ»¿ÉÒÔÕý³£·ÃÎÊWWW·þÎñ¡£¿ÉÒÔ²ÉÓÃһϵÄACLÅäÖòßÂÔʵÏÖ¸ÃÒªÇó£º
Router(config)#access-list 102 permit tcp 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255 eq wwww
Router(config)#access-list 102 deny tcp 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255 eq ftp
Router(config)#access-list 102 permit ip any any Router(config)#int E1
- 13 -
¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
Router(config)#ip access-group 102 out
ÔÚѧÉúʵÑéÊÒ£¬ÏñQQÓÎÏ·Ö®ÀàµÄÍøÂçÓ¦ÓÃÒ²ÊDz»ÔÊÐíѧÉúʹÓõģ¬¿ÉÒÔ²ÉÓÃͬÑùµÄÔÀíÀ´½ûÖ¹¸Ã·þÎñ¡£Ê×ÏÈÐèÒª²éÕÒµ½ÒòÌØ¶ûÍøÉÏÌṩQQÓÎÏ·µÄ·þÎñÆ÷µÄIPµØÖ·£¬È»ºó²ÉÓÃACLÃüÁîÀ´½ûֹѧÉúʵÑéÊÒÍø¶Î192.168.3.0ºÍÕâЩIPµØÖ·µÄ·þÎñÆ÷Ö®¼äµÄÍøÂçÁ¬½Ó¡£
3.3½ûֹij̨Ö÷»úµÄͨÐÅ
¾ÖÓòÍøÊܲ¡¶¾¹¥»÷ÊDz»¿É±ÜÃâµÄ£¬Ò»µ©¾ÖÓòÍøÄÚÓÐһ̨¼ÆËã»ú¸ÐȾ²¡¶¾£¬¾ÍÓпÉÄÜÓ°ÏìÕû¸öÍâ¾ÖÓòÍøÄÚµÄͨÐÅ£¬ÑÏÖØÊ±¿ÉÄܵ¼ÖÂÍøÂç̱»¾¡£ËäÈ»²»Äܽ«²¡¶¾¾ÜÖ®ÃÅ£¬µ«ÊÇ¿ÉÒÔÔÚ¾¡Á¿·À¶¾µÄ»ù´¡ÉÏ£¬¼°Ê±¼ì²â²¡¶¾²¢¶ÔÓж¾Ö÷»ú²ÉÈ¡¸ôÀë´ëÊ©ÒÔ±£»¤ÍøÂç¡£
¼ÙÉèѧÉúʵÑéÊҵļÆËã»ú4£¨IPµØÖ·Îª192.168.3.12£©Ö÷»ú¸ÐȾÁ˲¡¶¾£¬ÕýÔÚÏò¾ÖÓòÍøÄ򵀮äËûÖ÷»ú·è¿ñ·¢Êý¾Ý°ü£¬ÄÇô¿ÉÒÔ²ÉȡһÏÂACL²ßÂÔÏÞÖÆ¸ÃÖ÷»úµÄÊý¾Ý´«Ê䣬´Ó¶ø×è¶Ï²¡¶¾ÏòÆäËûÍø¶Î´«²¥£¬½«²¡¶¾¶ÔÍøÂçµÄÓ°Ïì½µµ½×îС£º
Router(config)#access-list 2 deny 192.168.3.12 0.0.0.255 Router(config)#access-list 2 permit any Router(config)#int E2
Router(config)#ip access-group 2 in
3.4±£»¤ÖØÒª¶Ë¿ÚÃâÊܲ¡¶¾¹¥»÷
²Ù×÷ϵͳ¿ª·ÅÁËһЩ¶Ë¿Ú£¬ÀýÈç135£¬136£¬137£¬138£¬139£¬445µÈ¡£²¡¶¾¹¥»÷ÔÀí¾ÍÊÇÏòÕâЩ¿ª·Å¶Ë¿Ú·¢ËÍ´óÁ¿Êý¾ÝʹËùÒÔ²Ù×÷ϵͳ×ÊÔ´ºÍÍøÂç×ÊÔ´ºÄ¾¡£¬×îÖÕÊ¹ÍøÂçÎÞ·¨ÏòºÏ·¨Óû§ÌṩÕý³£µÄ·þÎñ¡£Ê¹ÓÃACL·À·¶²¡¶¾¹¥»÷µÄ²ßÂÔÈçÏ£º
Router(config)#access-list 103 deny tcp any any eq 135 Router(config)#access-list 103 deny udp any any eq 135 Router(config)#access-list 103 deny ip any any eq 135 Router(config)#int S0
Router(config)#ip access-group 103 in
ÒÔÉϲßÂÔÊÇÒÔ135¶Ë¿ÚΪÀý£¬ÆäËû¶Ë¿ÚÅäÖòßÂÔÏàͬ¡£ÔÚ·ÓÉÆ÷ÉÏÏÞÖÆÁË135¶Ë¿Ú»ùÓÚTCP¡¢UDPºÍIPÐÒéµÄ·ÃÎÊ£¬´Ó¶ø½ûÖ¹²¡¶¾´Ó135¶Ë¿Ú¹¥»÷ÄÚÍø¡£µ±È»£¬¸Ã²ßÂÔÒ²½ûÖ¹ÁË135¶Ë¿ÚµÄÆäËûÕý³£¹¦ÄÜ¡£
3.5С½á
ͨ¹ý¶Ô·ÓÉÆ÷ÅäÖÃÒÔÉϲßÂÔ£¬¶ÔÄÚ²¿ÍøÂç¹¹½¨ÁË»ù±¾µÄÍøÂ簲ȫÌåϵ£¬ÔÚÒ»¶¨³Ì¶ÈÉÏ¿ÉÒÔÌá¸ßÍøÂçµÄ°²È«ÐÔ¡£µ«ÊÇACLÊÇÓðü¹ýÂ˼¼ÊõÀ´ÊµÏֵ쬹ýÂ˵ÄÒÀ¾Ý½ö½öÊǵÚ3²ãºÍ
- 14 -