·ÃÎÊ¿ØÖÆÁбíACLÔÚÐ£Ô°ÍøÖеÄÓ¦Óóõ̽ ÏÂÔØ±¾ÎÄ

¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©

ÌåҪʹÓÃperiodicÃüÁî¡£½«ÔÚÏÂÃæµÄÅäÖÃʵÀýÖÐÏêϸ½éÉÜ¡£

»ùÓÚʱ¼äµÄACLÅäÖó£ÓÃÃüÁî

R1(config)#time-range time //¶¨Òåʱ¼ä·¶Î§

R1(config-time-range)#periodic weekdays 8:00 to 18:00

R1(config)#access-list 111 permit tcp host 172.16.3.1 host 2.2.2.2 eq telnet time-range time

³£ÓÃʵÑéµ÷ÊÔÃüÁî

¢Ù Óá°clock set¡±ÃüÁϵͳʱ¼äµ÷Õûµ½ÖÜÒ»ÖÁÖÜÎåµÄ8£º00-18£º00·¶Î§ÄÚ£¬È»ºóÔÚTelnet·ÓÉÆ÷R1£¬´Ëʱ¿ÉÒԳɹ¦£¬È»ºó²é¿´·ÃÎÊ¿ØÖÆÁбí111£º

R1#show access-lists Extended IP access list 111

10 permit tcp host 172.16.3.1 host 2.2.2.2 eq telnet time-range time (active)

¢Ú Óá°clock set¡±ÃüÁϵͳʱ¼äµ÷Õûµ½8£º00-18£º00·¶Î§Ö®Í⣬ȻºóTelnet·ÓÉÆ÷R1£¬´Ëʱ²»¿ÉÒԳɹ¦£¬È»ºó²é¿´·ÃÎÊ¿ØÖÆÁбí111£º

R1#show access-lists Extended IP access list 111

10 permit tcp host 172.16.3.1 host 2.2.2.2 eq telnet time-range time (inactive)

¢Û show time-range£º¸ÃÃüÁîÓÃÀ´²é¿´¶¨ÒåµÄʱ¼ä·¶Î§¡£ R1#show time-range

time-range entry: time (inactive) periodic weekdays 8:00 to 18:00 used in: IP ACL entry

ÒÔÉÏÊä³ö±íʾÔÚ3ÌõACLÖе÷ÓÃÁ˸Ãtime-range¡£

2.5 ·ÃÎÊ¿ØÖÆÁбíµÄÏÔʾºÍµ÷ÊÔ

ÔÚÌØÈ¨Ä£Ê½Ï£¬

ʹÓá°show access-lists ¡±¿ÉÒÔÏÔʾ·ÓÉÆ÷ÉÏÉèÖõÄËùÓÐACLÌõÄ¿£» ʹÓá°show access-list acl number¡±Ôò¿ÉÒÔÏÔÊ¾ÌØ¶¨ACLºÅµÄACLÌõÄ¿£» ʹÓá°show time-range¡±ÃüÁî¿ÉÒÔÓÃÀ´²é¿´¶¨ÒåµÄʱ¼ä·¶Î§£»

ʹÓá°clear access-list counters¡±ÃüÁî¿ÉÒÔ½«·ÃÎÊ¿ØÖÆÁбíµÄ¼ÆÊýÆ÷ÇåÁã¡£

- 11 -

¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©

3¡¢ACLÔÚÐ£Ô°ÍøÖеÄÓ¦ÓÃʵÀý

ͼ6ÊÇÄ³Ñ§Ð£ÍøÂç½á¹¹ÌåµÄÒ»²¿·Ö£¬ÆäÖаüÀ¨½Ìʦ°ì¹«ÊÒ£¬·þÎñÆ÷»ú·¿ºÍѧÉúʵÑéÊÒÈô¸É¡£±¾ÍøÂçÖÐÈ«²¿Ê¹ÓÃ24λ×ÓÍøÑÚÂë¡£

ͼ6.ijѧУµÄÍøÂçÍØÆË½á¹¹Í¼

ÔÚͼ6ÖУ¬Â·ÓÉÆ÷ʹÓÃÒÔÌ«Íø¶Ë¿ÚE0Á¬½Óµ½½Ìʦ°ì¹«ÊÒ(Íø¶ÎΪ192.168.1.0)£¬Ê¹ÓÃÒÔÌ«Íø¶Ë¿ÚE1Á¬½Óµ½Ñ§Ð£µÄ·þÎñÆ÷»ú·¿£¨Íø¶ÎΪ192.168.2.0£©£¬Ê¹ÓÃÒÔÌ«Íø¶Ë¿ÚE2Á¬½Óµ½ÄãѧÉúʵÑéÊÒ£¨Íø¶ÎΪ192.168.3.0£©£¬Ê¹Óô®¿ÚS0Á¬½Óµ½Ð£Ô°Íø¡£Â·ÓÉÆ÷E1¡¢E1ºÍE2¶Ë¿ÚµÄIPµØÖ·Îª192.168.1.1£¬192.168.2.1ºÍ195.168.3.1¡£¼ÆËã»ú1µÄIPµØÖ·Îª192.168.1.11£¬¼ÆËã»ú2µÄIPµØÖ·Îª192.168.1.12£¬¼ÆËã»ú3µÄIP µØÖ·Îª192.168.3.11£¬¼ÆËã»ú4µÄIPµØÖ·Îª192.168.3.12.FTP·þÎñÆ÷µÄIPµØÖ·Îª192.168.2.11£¬WWW·þÎñÆ÷µÄIPµØÖ·Îª192.168.2.12¡£

¸ù¾Ý½ÌÊҰ칫ÊÒ£¬·þÎñÆ÷»ú·¿ºÍѧÉúʵÑéÊÒ¶ÔÍøÂç¼°ÆäÊý¾Ý°²È«µÄÒªÇó²»Í¬£¬ÀûÓÃACL¼¼Êõ¹¹½¨ÁËÒÔϵÄÍøÂ簲ȫ²ßÂÔ¡£

3.1ʵÏÖÍøÂç·ÃÎʵĵ¥Ïò¿ØÖÆ

½ÌÊҰ칫ÊÒ(Íø¶ÎΪ192.168.1.0)ÓÃÓÚ½Ìʦ°ì¹«£¬Ö÷»úÉÏÍùÍù»á´æÒ»Ð©ÊÔ¾íµÈÃô¸ÐÊý¾Ý£¬Òò´Ë²»ÄÜÈÃѧÉúʵÑéÊÒ£¨Íø¶ÎΪ192.168.3.0£©·ÃÎÊ£¬µ«ÊǽÌʦ°ì¹«ÊÒÍø¶Î¿ÉÒÔ·ÃÎÊѧÉúʵÑéÊҵļÆËã»ú£¬ÒÔ±ã¶ÔѧÉú×öʵÑé¡¢ÉϿεÈÇé¿ö½øÐйÜÀíºÍ¼à¿Ø¡£

Ê×ÏÈÔÚ·ÓÉÆ÷ÉϲÉÓÃIP±ê×¼¿ØÖÆÁбíÈçÏ£º

- 12 -

¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©

Router(config)#access-list 1 deny 192.168.3.0 0.0.0.255 Router(config)#access-list 1 permit any Router(config)#int E0

Router(config)#ip access-group 1 out

ÔÚ·ÓÉÆ÷ÉÏÅäÖóɹ¦ºó£¬192.168.3.0Íø¶Î²»ÄÜ·ÃÎÊ192.16.1.0Íø¶Î£¬µ«Í¬Ê±192.168.1.0Íø¶ÎÒ²²»ÄÜ·ÃÎÊ192.168.3.0Íø¶Î£¬Ô­ÒòÊÇÔÚ·ÓÉÆ÷E0¶Ë¿ÚµÄout·½ÏòÉÏÉèÖÃÁË·ÃÎÊ¿ØÖƲßÂÔdeny 192.168.3.0 0.0.0.255Ëü×èÖ¹ÁË´Ó192.168.3.0·¢¸ø192.168.1.0µÄËùÒÔÊý¾Ý°ü£¬¼´Ê¹ÊÇ192.168.3.0¸ø192.168.1.0µÄ»Ø¸´Êý¾Ý°üÒ²Ò»Ñù×èÖ¹ÁË¡£Óɴ˿ɼû£¬¼òµ¥µÄʹÓ÷ÃÎÊ¿ØÖÆÁÐ±í»¹²»Äܽâ¾öÕâ¸öÎÊÌâ¡£

ҪʵÏÖ192.168.1.0Íø¶Îµ½192.168.3.0Íø¶ÎµÄµ¥Ïò·ÃÎÊ¿ØÖÆ£¬²ÉÓ÷ÃÎÊ¿ØÖÆÁбíÅäÖÃÈçÏ£º

Router(config)#access-list 101 permit tcp 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255 estaelished

Router(config)#access-list 101 permit tcp any any Router(config)#int E2

Router(config)#ip access-group 101 in

¸Ã²ßÂÔµÄÔ­ÀíÊǵ±TCPÁ¬½ÓÒѾ­½¨Á¢Ê±£¬ÔÚ·ÓÉÆ÷E2¶Ë¿ÚµÄin·½ÏòÉϼì²éÊý¾Ý°ü£¬Èç¹ûËü±íʾȷÈϵÄÊý¾Ý°ü¼´¿Éͨ¹ý£¬¶øÈç¹ûÊÇ192.168.3.0Íø¶ÎÏò192.168.1.0Íø¶Î·¢ÆðTCPÁ¬½ÓÊý¾Ý°üÔòËü²»±íʾȷÈÏÊý¾Ý°ü£¬Òò´Ë¾Ü¾øÍ¨¹ý¡£ÕâÑùÉèÖÃÒÔºó£¬Ñ§ÉúÔÚʵÑéÊҾͲ»ÄÜ·ÃÎʽÌʦ¼ÆËã»úÉϵÄÊÔ¾íµÈÃô¸Ð×ÊÁÏ£¬¶ø½ÌÊÒ¼ÆËã»úÒÀÈ»¿ÉÒÔ¹ÜÀíѧÉúʵÑéÊÒµÄÉϿκÍÉÏ»úÇé¿ö¡£

3.2½ûÖ¹»òÔÊÐí²¿·ÖÍøÂç·þÎñ

ʵÑéÊÒÒ»µ©Á¬½ÓÁËÐ£Ô°Íø£¬¾Í¿ÉÒÔ·ÃÎʺܶà×ÊÔ´£¬°üÀ¨µçÓ°Ö®ÀàµÄ¡£µ«ÊÇʵÑéÊÒÊÇΪѧÉúÌṩ×öʵÑ顢ѧϰµÄ³¡Ëù£¬ÔÚÉÏ¿ÎÆÚ¼ä²»ÔÊÐíѧÉúÏÂÔØµçÓ°»òÕßÔÚÏß¹Û¡£ÔÚͼ6ÖУ¬¼ÙÉè´ó²¿·ÖµçÓ°Ö®ÀàµÄ×ÊÔ´·ÅÔÚÐ£Ô°ÍøµÄ192.168.2.0Íø¶ÎµÄFTP·þÎñÆ÷ÉÏ£¬Òò´ËÒª½ûֹѧÉúʵÑéÊÒ192.168.3.0Íø¶Î·ÃÎÊ192.168.2.0Íø¶ÎµÄFTP·þÎñ£¬µ«ÒÀÈ»¿ÉÒÔÕý³£·ÃÎÊWWW·þÎñ¡£¿ÉÒÔ²ÉÓÃһϵÄACLÅäÖòßÂÔʵÏÖ¸ÃÒªÇó£º

Router(config)#access-list 102 permit tcp 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255 eq wwww

Router(config)#access-list 102 deny tcp 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255 eq ftp

Router(config)#access-list 102 permit ip any any Router(config)#int E1

- 13 -

¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©

Router(config)#ip access-group 102 out

ÔÚѧÉúʵÑéÊÒ£¬ÏñQQÓÎÏ·Ö®ÀàµÄÍøÂçÓ¦ÓÃÒ²ÊDz»ÔÊÐíѧÉúʹÓõģ¬¿ÉÒÔ²ÉÓÃͬÑùµÄÔ­ÀíÀ´½ûÖ¹¸Ã·þÎñ¡£Ê×ÏÈÐèÒª²éÕÒµ½ÒòÌØ¶ûÍøÉÏÌṩQQÓÎÏ·µÄ·þÎñÆ÷µÄIPµØÖ·£¬È»ºó²ÉÓÃACLÃüÁîÀ´½ûֹѧÉúʵÑéÊÒÍø¶Î192.168.3.0ºÍÕâЩIPµØÖ·µÄ·þÎñÆ÷Ö®¼äµÄÍøÂçÁ¬½Ó¡£

3.3½ûֹij̨Ö÷»úµÄͨÐÅ

¾ÖÓòÍøÊܲ¡¶¾¹¥»÷ÊDz»¿É±ÜÃâµÄ£¬Ò»µ©¾ÖÓòÍøÄÚÓÐһ̨¼ÆËã»ú¸ÐȾ²¡¶¾£¬¾ÍÓпÉÄÜÓ°ÏìÕû¸öÍâ¾ÖÓòÍøÄÚµÄͨÐÅ£¬ÑÏÖØÊ±¿ÉÄܵ¼ÖÂÍøÂç̱»¾¡£ËäÈ»²»Äܽ«²¡¶¾¾ÜÖ®ÃÅ£¬µ«ÊÇ¿ÉÒÔÔÚ¾¡Á¿·À¶¾µÄ»ù´¡ÉÏ£¬¼°Ê±¼ì²â²¡¶¾²¢¶ÔÓж¾Ö÷»ú²ÉÈ¡¸ôÀë´ëÊ©ÒÔ±£»¤ÍøÂç¡£

¼ÙÉèѧÉúʵÑéÊҵļÆËã»ú4£¨IPµØÖ·Îª192.168.3.12£©Ö÷»ú¸ÐȾÁ˲¡¶¾£¬ÕýÔÚÏò¾ÖÓòÍøÄ򵀮äËûÖ÷»ú·è¿ñ·¢Êý¾Ý°ü£¬ÄÇô¿ÉÒÔ²ÉȡһÏÂACL²ßÂÔÏÞÖÆ¸ÃÖ÷»úµÄÊý¾Ý´«Ê䣬´Ó¶ø×è¶Ï²¡¶¾ÏòÆäËûÍø¶Î´«²¥£¬½«²¡¶¾¶ÔÍøÂçµÄÓ°Ïì½µµ½×îС£º

Router(config)#access-list 2 deny 192.168.3.12 0.0.0.255 Router(config)#access-list 2 permit any Router(config)#int E2

Router(config)#ip access-group 2 in

3.4±£»¤ÖØÒª¶Ë¿ÚÃâÊܲ¡¶¾¹¥»÷

²Ù×÷ϵͳ¿ª·ÅÁËһЩ¶Ë¿Ú£¬ÀýÈç135£¬136£¬137£¬138£¬139£¬445µÈ¡£²¡¶¾¹¥»÷Ô­Àí¾ÍÊÇÏòÕâЩ¿ª·Å¶Ë¿Ú·¢ËÍ´óÁ¿Êý¾ÝʹËùÒÔ²Ù×÷ϵͳ×ÊÔ´ºÍÍøÂç×ÊÔ´ºÄ¾¡£¬×îÖÕÊ¹ÍøÂçÎÞ·¨ÏòºÏ·¨Óû§ÌṩÕý³£µÄ·þÎñ¡£Ê¹ÓÃACL·À·¶²¡¶¾¹¥»÷µÄ²ßÂÔÈçÏ£º

Router(config)#access-list 103 deny tcp any any eq 135 Router(config)#access-list 103 deny udp any any eq 135 Router(config)#access-list 103 deny ip any any eq 135 Router(config)#int S0

Router(config)#ip access-group 103 in

ÒÔÉϲßÂÔÊÇÒÔ135¶Ë¿ÚΪÀý£¬ÆäËû¶Ë¿ÚÅäÖòßÂÔÏàͬ¡£ÔÚ·ÓÉÆ÷ÉÏÏÞÖÆÁË135¶Ë¿Ú»ùÓÚTCP¡¢UDPºÍIPЭÒéµÄ·ÃÎÊ£¬´Ó¶ø½ûÖ¹²¡¶¾´Ó135¶Ë¿Ú¹¥»÷ÄÚÍø¡£µ±È»£¬¸Ã²ßÂÔÒ²½ûÖ¹ÁË135¶Ë¿ÚµÄÆäËûÕý³£¹¦ÄÜ¡£

3.5С½á

ͨ¹ý¶Ô·ÓÉÆ÷ÅäÖÃÒÔÉϲßÂÔ£¬¶ÔÄÚ²¿ÍøÂç¹¹½¨ÁË»ù±¾µÄÍøÂ簲ȫÌåϵ£¬ÔÚÒ»¶¨³Ì¶ÈÉÏ¿ÉÒÔÌá¸ßÍøÂçµÄ°²È«ÐÔ¡£µ«ÊÇACLÊÇÓðü¹ýÂ˼¼ÊõÀ´ÊµÏֵ쬹ýÂ˵ÄÒÀ¾Ý½ö½öÊǵÚ3²ãºÍ

- 14 -