¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
ACLµÄ½éÉÜ£¬Ö÷Òª°üÀ¨ÒÔϼ¸µã£º £¨1£© ACLʹÓðü¹ýÂ˼¼Êõ£¬ÔÚ·ÓÉÆ÷É϶ÁÈ¡µÚÈý²ã¼°µÚËIJã°üÍ·ÖеÄÐÅÏ¢ÈçÔ´µØÖ·¡¢Ä¿µÄµØÖ·¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿ÚµÈ£¬¸ù¾ÝԤѡ¶¨ÒåºÃµÄ¹æÔò¶Ô°ü½øÐйýÂË£¬´Ó¶ø´ïµ½·ÃÎÊ¿ØÖÆÄ¿µÄ¡£ £¨2£© ACLµÄÖ÷Òª¹¦ÄܾÍÊÇÒ»·½Ãæ±£»¤×ÊÔ´½Úµã£¬×éÖ¯·Ç·¨Óû§¶Ô×ÊÔ´½ÚµãµÄ·ÃÎÊ£¬ÁíÒ»·½ÃæÏÞÖÆÌØ¶¨µÄÓû§½ÚµãËùÄܾ߱¸µÄ·ÃÎÊȨÏÞ¡£ £¨3£© ÔÚʵʩACLµÄ¹ý³ÌÖУ¬Ó¦µ±×ñÑÈçÏÂÁ½¸ö»ù±¾ÔÔò¡£ ¡ð1 ×îÐ¡ÌØÈ¨ÔÔò£ºÖ»¸øÊܿضÔÏóÍê³ÉÈÎÎñ±ØÐëµÄ×îСȨÏÞ¡£ ¡ð2 ×î¿¿½üÊܿضÔÏóÔÔò£ºËùÓеÄÍøÂç²ã·ÃÎÊȨÏÞ¿ØÖƾ¡¿ÉÄÜÀëÊܿضÔÏó×î½ü¡£ £¨4£© ACL¹ýÂ˵ÄÒÀ¾ÝÊǵÚÈý²ãºÍµÚËIJã°üÍ·ÖеIJ¿·ÖÐÅÏ¢£¬ÕâÖÖ¼¼Êõ¾ßÓÐһЩ¹ÌÓеľÖÏÞÐÔ£¬ÈçÎÞ·¨Ê¶±ðµ½¾ßÌåµÄÈË£¬ÎÞ·¨Ê¶±ðµ½Ó¦ÓÃÄÚ²¿µÄȨÏÞ¼¶±ðµÈ¡£Òò´Ë£¬Òª´ïµ½end to end µÄȨÏÞ¿ØÖÆÄ¿µÄ£¬ÐèÒªºÍϵͳ¼¶¼°Ó¦Óü¶µÄ·ÃÎÊ¿ØÖÆÈ¨ÏÞ½áºÏʹÓᣠÑо¿µÄÖ÷ÒªÄÚÈÝ ±¾Ñ¡Ìâ»ùÓÚACLΪÖ÷£¬Í¬Ê±´îÅäNATºÍÐéÄâ¾ÖÓòÍø¼¼Êõ£¬ÆäÖвÉÓÃÐéÄâ¾ÖÓòÍø¼¼ÊõºÍ½¨Á¢ACLÁÐ±í¿ØÖÆ±£ÕÏÕû¸öÐ£Ô°ÍøÂçµÄ°²È«ÔËÐУ¬NATÔÚºÏÀí¼õÉٺϷ¨µØÖ·ÐèÇóµÄͬʱ»¹¿ÉÒÔÒþ²ØÄÚ²¿ÕæÊµµÄÍøÂçµØÖ·£¬¼õµÍºÚ¿ÍÈëÇֵijɹ¦ÂÊ,Ê¹Ð£Ô°ÍøÔË×÷ÔÚÒ»¸ö°²È«Îȶ¨µÄ»·¾³Ï¡£ ±¾Ñ¡ÌâÑо¿ÄÚÈÝÈçÏ£º (1) ACLµÄ·¢Õ¹£¬ÏÖ×´ºÍ½«À´£¬½éÉÜACLµÄ¸ÅÄÔÀí£¬¹¤×÷Á÷³Ì£¬·ÖÀàºÍ¾ÖÏÞÐÔ¡£ (2) Ïêϸ˵Ã÷ACLµÄÆ¥Åä˳Ðò£¬´´½¨³öÒ»¸ö¿ØÖÆ·ÃÎÊÁбíµÄ¼òµ¥Ê¾Àý£¬²¢Ïêϸ˵Ã÷¿ØÖÆ·ÃÎÊÁбíµÄÅäÖÃÈÎÎñºÍ·ÅÖÿØÖÆ·ÃÎÊÁбíµÄÕýȷλÖᣠ£¨3£©ÅäÖø÷ÖÖÀàÐ͵ÄACL£¬±ÈÈç»ù±¾·ÃÎÊ¿ØÖÆÁÐ±í£¬¸ß¼¶·ÃÎÊ¿ØÖÆÁÐ±í£¬»ùÓڽӿڵķÃÎÊ¿ØÖÆÁÐ±í£¬»ùÓÚÒÔÌ«ÍøMACµØÖ·µÄ·ÃÎÊ¿ØÖÆÁбí??²¢Íê³Éɾ³ý¿ØÖÆÁбíµÄ²Ù×÷¡£ £¨4£©Íê³Éʱ¼ä¶ÎµÄ¿ØÖÆ·ÃÎÊÁбíÅäÖ㬷ÃÎÊ¿ØÖÆÁбíµÄÏÔʾºÍµ÷ÊÔ¡£ £¨5£©¼òÊöÐ£Ô°ÍøµÄÌØµã¼°ÆäËùÃæÁٵݲȫÎÊÌâ¼°½â¾ö°ì·¨¡£ £¨6£©´î½¨ÅäÖÃÐ£Ô°ÍøµÄ»·¾³£¬ÅäÖÃÐ£Ô°ÍøµÄ¿ØÖÆ·ÃÎÊÁбíʵÀý¡£ £¨7£©¶ÔÅäÖúÿØÖÆ·ÃÎÊÁбíµÄÐ£Ô°ÍøµÄ°²È«ÐÔÄܽøÐвâÊÔ¡£ - 2 -
¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
²ÉÓõÄÑо¿·½·¨ a£©²éÕÒ²¢ÔĶÁÏà¹Ø×ÊÁÏ£¬Á˽â»ù±¾µÄÄÚÈÝ,ÀûÓÃÐèÇó·ÖÎöÎĵµ£¬¶ÔÕû¸ö¿ØÖÆ·ÃÎʲßÂÔÓиö»ù±¾µÄ¼Ü¹¹¡£ b£©ËÑѰʵÑéÓõÄÎļþÎĵµ¼¯ºÍÑо¿¹ý³ÌÖÐÓõ½µÄ¸÷ÖÖ¹¤¾ßÈí¼þ¡£ c£©¸ù¾ÝÒÑÓеÄ×ÊÁϲ¢ËÑѰµ½µÄ¸÷ÖÖÈí¼þ¹¤¾ß½øÐзÖÎö¡¢Éè¼Æ¡£ d£©²ÉÓÃDynamipsGUI¡¢gns3¡¢Cisco Packet Tracer 5.3µÈ¹¤¾ßÍê³ÉÕû¸ö²ßÂԵıàдÓë²âÊÔ¡£ ¹¤×÷µÄ½ø¶È°²ÅÅ 2011Äê10ÔÂ25ºÅ£10ÔÂ30ºÅ ËѼ¯×ÊÁÏ£¬²éÔÄÎÄÏ×£¬Íê³É¿ªÌⱨ¸æ¡£ ? 2011Äê11ÔÂ1ºÅ£2011Äê11ÔÂ5ÈÕ Íê³ÉÎÄÏ××ÛÊö 2011Äê11ÔÂ6ºÅ¡ª11ÔÂ10ºÅ ¶¨³ö»ùÓÚACL¼¼ÊõµÄÐ£Ô°ÍøÂ簲ȫµÄÐèÇó·ÖÎöÎĵµ 2011Äê11ÔÂ11ºÅ¡ª11ÔÂ15ºÅ ÕûÀíÏà¹Ø×ÊÁϲ¢Íê³É¸ÅÒªºÍÏêϸÉè¼Æ 2011Äê11ÔÂ16ºÅ¡ª11ÔÂ20ºÅ ½øÐÐУ԰¾ÖÓòÍøµÄÏà¹ØÅäÖúͱØÒªÐÔ²âÊÔ ? 2011Äê11ÔÂ21ºÅ¡ª11ÔÂ25ºÅ ×ܽá±ÏÒµÉè¼ÆµÄÕû¸ö¹ý³Ì£¬Íê³É±ÏÒµÉè¼ÆÂÛÎijõ¸å 2011Äê12ÔÂ1ºÅ¡ª12ÔÂ25ºÅ Ð޸ıÏÒµÂÛÎ͍¸å£¬´òÓ¡×°¶© Ö¸µ¼½ÌʦÒâ¼û Ö¸µ¼½ÌʦǩÃû£º Äê Ô ÈÕ - 3 -
¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
Ŀ ¼
ÕªÒª.........................................................................2 ¹Ø¼ü×Ö.......................................................................2 ǰÑÔ.........................................................................2 1 ACLµÄ¸ÅÊö..................................................................2
1.1»ù±¾ÔÀí.............................................................2 1.2¹¦ÄÜ.................................................................3 1.3ÅäÖûù±¾ÔÔò.........................................................3 1.4¾ÖÏÞÐÔ...............................................................4 1.5ACLµÄ×÷ÓÃ............................................................4 1.6ACLµÄ·ÖÀà............................................................4 1.7ACLµÄÖ´ÐÐ˳Ðò........................................................4 2 ACLµÄ´´½¨ºÍÅäÖÃ...........................................................5
2.1 ACLµÄ´´½¨...........................................................5 2.2 ACLµÄ´´½¨Î»ÖÃ.......................................................7 2.3 ACLµÄÅäÖÃ...........................................................7
2.3.1 ÅäÖñê×¼µÄACL.................................................7 2.3.2 ÅäÖÃÀ©Õ¹µÄACL.................................................8 2.3.3 ÅäÖÃÃüÃûACL...................................................8 2.3.4 ɾ³ýACL......................................................10 2.4 »ùÓÚʱ¼äµÄACL......................................................10 2.5 ACLµÄÏÔʾºÍµ÷ÊÔ....................................................11 3 ACLÔÚÐ£Ô°ÍøÖеÄÓ¦ÓÃʵÀý..................................................12
3.1ʵÏÖÍøÂç·ÃÎʵĵ¥Ïò¿ØÖÆ..............................................12 3.2½ûÖ¹»òÔÊÐí²¿·ÖÍøÂç·þÎñ..............................................13 3.3½ûֹij̨Ö÷»úµÄͨÐÅ..................................................14 3.4±£»¤ÖØÒª¶Ë¿ÚÃâÊܲ¡¶¾¹¥»÷............................................14 3.5С½á................................................................14
- 1 -
¹ðÁÖµç×ӿƼ¼´óѧְҵ¼¼ÊõѧԺ±ÏÒµÉè¼Æ£¨ÂÛÎÄ£©
ÕªÒª
Ëæ×ÅÍøÂçµÄ¸ßËÙ·¢Õ¹£¬ÍøÂçµÄÆÕ¼°Ò²Ô½À´Ô½Æ½Ãñ»¯£¬ÔÚÈËÃǵÄѧϰºÍÉú»îµÄ·½·½ÃæÃæ£¬ÍøÂçÎ޿ײ»È룬¸øÈËÃǵÄѧϰºÍÉú»î´øÀ´Á˼«´óµÄ±ãÀû£¬µ«ËæÖ®¶øÀ´µÄÍøÂ簲ȫÎÊÌâÒ²Ô½À´Ô½ÒýÆðÈËÃǵÄÖØÊÓ¡£¸ßÐ£Ð£Ô°ÍøµÄ°²È«ÊÇÒ»¸öÅÓ´óµÄϵͳ¹¤³Ì£¬ÐèҪȫ·½Î»µÄ·À·¶¡£·À·¶²»½öÊDZ»¶¯µÄ£¬¸üÒªÖ÷¶¯½øÐС£±¾ÎÄ»ùÓÚACLΪÖ÷£¬½¨Á¢ACLÁÐ±í¿ØÖÆºÍ±£ÕÏÕû¸öÐ£Ô°ÍøµÄ°²È«ÔËÐУ¬Ê¹Ð£Ô°ÍøÔË×÷ÔÚÒ»¸ö°²È«Îȶ¨µÄ»·¾³Ï¡£
[¹Ø¼ü´Ê]ACL£»Ð£Ô°Íø£»ÍøÂ簲ȫ²ßÂÔ£»·ÃÎÊ¿ØÖÆÁбí
ǰÑÔ
×Ô´Ó²úÉúÁËÍøÂç£¬ËæÖ®¶øÀ´µÄ¾ÍÊÇÍøÂçµÄ°²È«ÎÊÌâ¡£ÈκÎÁ¬½ÓÉÏÍøÂçµÄÆóÒµ¡¢µ¥Î»¡¢¸öÈ˶¼ÒªÊ±¿Ì×¢Òâ×Ô¼ºµÄÍøÂ簲ȫÎÊÌâ¡£¼ÈÒª·Àֹδ¾ÊÚȨµÄ·Ç·¨Êý¾Ý´ÓÍⲿÇÖÈëÄÚ²¿Intranet£¬Ò²Òª·ÀÖ¹ÄÚ²¿¸÷Ö÷»úÖ®¼äµÄÏ໥¹¥»÷,Ò»µ©ÍøÂç̱»¾»òÕßÐÅÏ¢±»ÇÔÈ¡£¬½«»á´øÀ´¾Þ´óµÄËðʧ¡£Â·ÓÉÆ÷×÷ΪIntranetºÍInternetµÄÍø¼ä»¥Á¬É豸£¬ÊDZ£Ö¤ÍøÂ簲ȫµÄµÚÒ»¹Ø,¶øÔÚ·ÓÉÆ÷ÉÏÉèÖÿØÖÆ·ÃÎÊÁÐ±í£¨ACL£©¿ÉÒԺܺõĽâ¾öÕâÐ©ÍøÂ簲ȫÎÊÌâ¡£·ÃÎÊ¿ØÖÆÁбíÊÊÓÃÓÚËùÓеÄ·ÓÉÐÒ飬ͨ¹ýÁé»îµØÔö¼Ó·ÃÎÊ¿ØÖÆÁÐ±í£¬ACL¿ÉÒÔµ±×÷Ò»ÖÖÍøÂç¿ØÖÆµÄÓÐÁ¦¹¤¾ß¡£Ò»¸öÉè¼ÆÁ¼ºÃµÄ·ÃÎÊ¿ØÖÆÁÐ±í²»½ö¿ÉÒÔÆðµ½¿ØÖÆÍøÂçÁ÷Á¿¡¢Á÷Á¿µÄ×÷Ó㬻¹¿ÉÒÔÔÚ²»Ôö¼ÓÍøÂçϵͳÈí¡¢Ó²¼þͶ×ʵÄÇé¿öÏÂÍê³ÉÒ»°ãÈí¡¢Ó²¼þ·À»ðǽ²úÆ·µÄ¹¦ÄÜ¡£
1¡¢ACLµÄ¸ÅÊö
ACLÈ«³Æ·ÃÎÊ¿ØÖÆÁÐ±í£ºAccess Control List ,ÍùÀï×ß³£ËµµÄACL ÊÇCisco IOS ËùÌṩµÄÒ»ÖÖ·ÃÎÊ¿ØÖƼ¼Êõ¡£³õÆÚ½öÔÚ·ÓÉÆ÷ÉÏÖ§³Ö£¬½üЩÄêÀ´ÒѾÀ©Õ¹µ½Èý²ã½»»»»ú£¬²¿·Ö×îеĶþ²ã½»»»»úÈç2950Ö®ÀàÒ²¿ªÊ¼ÌṩACLµÄÖ§³Ö¡£Ö»²»¹ýÖ§³ÖµÄÌØÐÔ²»ÊÇÄÇôµÄÍêÉÆ¶øÒÑ¡£ÔÚÆäËû³§É̵Ä·ÓÉÆ÷»òÕß¶à²ã½»»»»úÉÏÒ²ÌṩÀàËÆµÄ¼¼Êõ£¬²»¹ýÃû³ÆºÍÅäÖ÷½Ê½¶¼¿ÉÄÜÓÐÂèÉÔ΢µÄ²î±ð¡£
1.1»ù±¾ÔÀí
ACLʹÓðü¹ýÂ˼¼Êõ£¬ÔÚ·ÓÉÆ÷É϶ÁÈ¡µÚÈý´Î¼°ËIJã°üÍ·ÖеÄÐÅÏ¢ÈçÔ´µØÖ·¡¢Ä¿µÄµØÖ·¡¢Ô´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿ÚµÈ£¬¸ù¾ÝÔ¤Ïȶ¨ÒåºÃµÄ¹æÔò¡¢¶Ô°ü½øÐйýÂË¡£´Ó¶ø´ïµ½·ÃÎÊ¿ØÖƵÄ
- 2 -