½ð²Ê»ã

µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹â×êÑл㱨¡· £¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¢¼´ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨°ä²¼
date
Ô¤Ô¼Ö±²¥
½ð²Ê»ã - Ê×Ò³
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¹æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¹æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷ͬ°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/˵»°
½ð²Ê»ã - Ê×Ò³

ACLÊÇʲô £¬ÈôºÎÅäÖã¿

icon-time°ä²¼¹¦·ò£º2023-03-24
icon-seeµã»÷Á¿£º3516

 ACLÖ°ÄܽéÉÜ

ACL£¨Access Control List £¬½Ó¼û½ÚÔìÁÐ±í£©Ò²³ÆÎª½Ó¼ûÁбí £¬ÓеÄÎĵµÖл¹³ÆÖ®Îª°ü¹ýÂË¡£ACLͨ¹ý½ç˵һϵÁÐÔ̺¬ÔÊÐí»ò»Ø¾øµÄ¹æ¶¨Óï¾ä £¬²¢½«ÕâЩ¹æ¶¨ÀûÓõ½É豸½Ó¿ÚÉÏ £¬¶Ô½ø³ö½Ó¿ÚµÄÊý¾Ý°ü½øÐнÚÔì £¬´Ó¶øÌáÉýÍøÂçÉ豸µÄ°²È«ÐÔ¡£

ÅäÖÃACL¿ÉÄܱ£ÏÕÍøÂ簲ȫ¡¢¿¿µÃסºÍ²»±ä £¬ÀýÈ磺

l  Ô¤·À±¨ÎĹ¥»÷£ºÕë¶ÔIP¡¢TCP»òÕßICMP±¨ÎĵĹ¥»÷ £¬¶ÔÕâЩ¹¥»÷±¨ÎÄ×ö“»Ø¾ø”´¦Öá£

l  ÍøÂç½Ó¼û½ÚÔ죺ÏÞ¶Å×û§½Ó¼û·þÎñ £¬ÀýÈçÖ»ÔÊÐí½Ó¼ûWWWºÍµç×ÓÓʼþ·þÎñ £¬ÆäËû·þÎñÈçTelnetÔò²»ÈÝ¡£»òÕßÖ»ÔÊÐíÔÚ¸ø¶¨µÄ¹¦·ò¶ÎÄÚ½Ó¼û £¬»òÕßÖ»ÔÊÐíÌØ¶¨Ö÷»ú½Ó¼ûÍøÂçµÈ¡£

l  ÍøÂçÁ÷Á¿½ÚÔ죺½áºÏQoS¿ÉÒÔΪ³ÁÒªµÄÊý¾ÝÁ÷½øÐÐÓÅÏÈ·þÎñ±£ÕÏ¡£¹ØÓÚQoSµÄÅäÖÃÇë°Ý¼û“QoS”¡£

¹¤×÷µÀÀí

1.    ¸ù»ù¸ÅÏë

l  ½Ó¼ûÁбí

½Ó¼ûÁбíÓУº¸ù»ù½Ó¼ûÁбíºÍ¶¯Ì¬½Ó¼ûÁбí¡£

Óû§Äܹ»Æ¾¾Ý±ØÒªÑ¡Ôñ¸ù»ù½Ó¼ûÁбí»ò¶¯Ì¬½Ó¼ûÁбí¡£Í¨³£Çé¿öÏ £¬Ê¹Óøù»ù½Ó¼ûÁбíÒѾ­¿ÉÄÜÂú×㰲ȫ±ØÒª¡£µ«¹¥»÷Õß¿ÉÄÜͨ¹ýÈí¼þ¼ÙðԴµØÖ·ºýŪÉ豸 £¬´Ó¶ø½Ó¼ûÍøÂç¡£¶ø¶¯Ì¬½Ó¼ûÁбíÔÚÓû§½Ó¼ûÍøÂçÒÔǰ £¬ÒªÇóͨ¹ýÉí·ÝÈÏÖ¤ £¬Ê¹¹¥»÷ÕßÄÑÒÔ½Ó¼ûÍøÂç¡£ÔÚÃô¸ÐÇøÓòÄܹ»Ê¹Óö¯Ì¬½Ó¼ûÁÐ±í±£ÕÏÍøÂ簲ȫ¡£

*     ×¢Ã÷

ͨ¹ý¼ÙðԴµØÖ·ºýŪÉ豸¼´µç×ÓºýŪÊÇËùÓнӼûÁбí¹ÌÓеÄÎÊÌâ £¬Ê¹Óö¯Ì¬ÁбíÒ²»áÔâ·êµç×ÓºýŪÎÊÌ⣺¹¥»÷Õß¿ÉÄÜÔÚÓû§Í¨¹ýÉí·ÝÈÏÖ¤µÄÓÐЧ½Ó¼ûÆÚ¼ä £¬¼ÙðÓû§µÄµØÖ·½Ó¼ûÍøÂç¡£½â¾ö¸ÃÎÊÌâµÄ²½ÖèÓÐÁ½ÖÖ £¬Ò»ÖÖÊǾ¡Á¿ÉèÖøü¶ÌµÄÓû§½Ó¼û¿ÕÏй¦·ò£»ÁíÒ»ÖÖÊÇʹÓÃIPsec¼ÓÃܺÍ̸¶ÔÍøÂçÊý¾Ý½øÐмÓÃÜ £¬È·±£½øÈëÉ豸ʱ £¬ËùÓеÄÊý¾Ý¶¼ÊǼÓÃܵÄ¡£

 

½Ó¼ûÁбíͨ³£ÅäÖÃÔÚÒÔϵØÎ»µÄÍøÂçÉ豸ÉÏ£º

¡ð         ÄÚ²¿ÍøºÍ±í²¿Íø£¨ÈçInternet£©Ö®¼äµÄÉ豸

¡ð         Á½¸öÍøÂç½ÓÈÀ²¿ÃŵÄÉ豸

¡ð         ½ÓÈë½ÚÔì¶Ë¿ÚµÄÉ豸

l  ACE

ACE£¨Access Control Entry £¬½Ó¼û½ÚÔìÌõ¿î£©ÊÇÔ̺¬“ÔÊÐí£¨Permit£©”»ò“»Ø¾ø£¨Deny£©”Á½ÖÖ×÷Ϊ £¬ÒÔ¼°¹ýÂ˹涨µÄÒ»ÌõÓï¾ä¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ £¬¸ÃÐòºÅ¿ÉÓÉÉ豸×Ô¶¯·ÖÅä»òÕßÊÖ¶¯ÅäÖá£Ò»ÌõACLÖÐÔ̺¬Ò»¸ö»òÕß¶à¸öACE¡£ACLͨ¹ýACE¶ÔÊý¾Ý°ü½øÐбêʶ¹ýÂË¡£

ACLÖÐACEµÄ°¤´Î¾ö¶¨Á˸ÃACEÔÚ½Ó¼ûÁбíÖÐµÄÆ¥ÅäÓÅÏȼ¶¡£ÍøÂçÉ豸ÔÚ´¦Öñ¨ÎÄʱ £¬°´ACEµÄÐòºÅ´ÓÓ×µ½ÃͽøÐй涨ƥÅä £¬µ¹ØÒµ½Æ¥ÅäµÄACEºóÔòÖÕ³¡²é³­ºóÐøµÄACE¡£

ÀýÈç´´½¨Ò»ÌõÐòºÅΪ10µÄACE £¬Ëü»Ø¾øËùÓеÄÊý¾ÝÁ÷ͨ¹ý¡£

10 deny ip any any

20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any

ÓÉÓÚÐòºÅΪ10µÄACE»Ø¾øÁËËùÓеÄIP±¨ÎÄ £¬¼´±ã192.168.12.0/24ÍøÂçµÄÖ÷»úTelnet±¨ÎÄ £¬Äܹ»±»ÐòºÅΪ20µÄACEÆ¥Åä £¬¸Ã±¨ÎÄÒ²½«±»»Ø¾ø¡£ÓÉÓÚÉ豸Ôڲ鳭µ½±¨ÎĺÍÐòºÅΪ10µÄACEÆ¥Åäºó £¬±ãÖÕ³¡²é³­ºóÃæÐòºÅΪ20µÄACE¡£

ÓÖÀýÈç´´½¨Ò»Ìõ±àºÅΪ10µÄACE £¬ËüÔÊÐíËùÓеÄIPv6Êý¾ÝÁ÷ͨ¹ý¡£

10 permit ipv6 any any

20 deny ipv6 host 200::1 any

ÓÉÓÚÐòºÅΪ10µÄACEÔÊÐíËùÓеÄIPv6±¨ÎÄͨ¹ý £¬Ö÷»ú200::1·¢³öµÄIPv6±¨ÎÄ £¬¼´±ãÆ¥ÅäÐòºÅΪ20µÄACE £¬¸Ã±¨ÎÄÒ²½«±»ÔÊÐíͨ¹ý¡£ÓÉÓÚÉ豸Ôڲ鳭µ½±¨Îĺ͵ÚÒ»ÌõACEÆ¥Åä £¬±ãÖÕ³¡²é³­ºóÃæÐòºÅΪ20µÄACE¡£

l  ²½³¤

µ±É豸ΪACE×Ô¶¯·ÖÅäÐòºÅʱ £¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ £¬³ÆÎª²½³¤¡£ÀýÈç £¬ÈôÊǽ«²½³¤É趨Ϊ5 £¬ÔòÉ豸ÒÀÕÕ5¡¢10¡¢15…ÕâÑùµÄµÝÔö°¤´Î×Ô¶¯ÎªACE·ÖÅäÐòºÅ¡£ÈçÏÂËùʾ¡£

5 deny ip any any

10 permit tcp 192.168.12.0 0.0.0.255 eq telnet any

µ±²½³¤Å¤×ªºó £¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤Öµ³ÁзÖÅä¡£ÀýÈç £¬µ±°Ñ²½³¤¸ÄΪ10ºó £¬Ô­À´ACEÐòºÅ´Ó5¡¢10¡¢15Ôì³É5¡¢15¡¢25¡£

ͨ¹ýŤת²½³¤Äܹ»ÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£ÀýÈç´´½¨ÁË4¸öACE £¬²¢Í¨¹ýÊÖ¶¯ÅäÖÃACEÐòºÅ±ðÀëΪ1¡¢2¡¢3ºÍ4¡£ÈôÊǵ«Ô¸ÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE £¬ÔòÄܹ»ÏȽ«²½³¤Åú¸ÄΪ2 £¬´ËʱԭÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7 £¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÅäÖõÄÐòºÅΪ2µÄACE¡£

l  ¹ýÂËÓòÄ£°å

¹ýÂËÓòÖ¸µÄÊÇÌìÉúÒ»ÌõACEʱ £¬Æ¾¾Ý±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎĽøÐмø±ð¡¢·ÖÀà¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£ACEƾ¾ÝÒÔÌ«Íø±¨ÎĵÄijЩ×Ö¶ÎÀ´±êʶÒÔÌ«Íø±¨ÎÄ £¬ÕâЩ×Ö¶ÎÔ̺¬£º

¶þ²ã×ֶΣ¨Layer 2 Fields£©£º

¡ð         48λµÄÔ´MACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩

¡ð         48λµÄÖ÷ÕÅMACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩

¡ð         16λµÄ¶þ²ãÀàÐÍ×Ö¶Î

Èý²ã×ֶΣ¨Layer 3 Fields£©£º

¡ð         Ô´IPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÔ´IPµØÖ·Öµ £¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©

¡ð         Ö÷ÕÅIPµØÖ·×ֶΣ¨Äܹ»ÉêÃ÷È«ÊýÖ÷ÕÅIPµØÖ·Öµ £¬»òʹÓÃ×ÓÍøÀ´½ç˵һÀàÁ÷£©

¡ð         ºÍ̸ÀàÐÍ×Ö¶Î

ËIJã×ֶΣ¨Layer 4 Fields£©£º

¡ð         Äܹ»ÉêÃ÷Ò»¸öTCPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷ £¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£

¡ð         Äܹ»ÉêÃ÷Ò»¸öUDPµÄÔ´¶Ë¿Ú¡¢Ö÷ÕŶ˿ڻòÕß¶¼ÉêÃ÷ £¬»¹Äܹ»ÉêÃ÷Ô´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄÁìÓò¡£

ÀýÈç £¬ÔÚ´´½¨Ò»ÌõACEʱ±ØÒªÆ¾¾Ý±¨ÎĵÄÖ÷ÕÅIP×Ö¶Î £¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£¶øÔÚ´´½¨ÁíÒ»ÌõACEʱ £¬±ØÒªÆ¾¾Ý±¨ÎĵÄÔ´IPµØÖ·×ֶκÍUDPµÄÔ´¶Ë¿Ú×Ö¶Î £¬¶Ô±¨ÎĽøÐмø±ðºÍ·ÖÀà¡£ÕâÁ½ÌõACE¾ÍʹÓÃÁË·ÖÆçµÄ¹ýÂËÓòÄ£°å¡£

l  ¹æ¶¨

¹æ¶¨£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£ÀýÈç £¬Ò»ÌõACEµÄÄÚÈÝÈçÏ£º

10 permit tcp host 192.168.12.2 any eq telnet

ÔÚÕâÌõACEÖÐ £¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεļ¯ÖУºÔ´IPµØÖ·×ֶΡ¢Ö÷ÕÅIPµØÖ·×ֶΡ¢IPºÍ̸×ֶΡ¢TCPÖ÷ÕŶ˿Ú×ֶΡ£¶ÔÓ¦µÄÖµ£¨¼´¹æ¶¨£©±ðÀëΪ£ºÔ´IPµØÖ·ÎªHost 192.168.12.2¡¢Ö÷ÕÅIPµØÖ·ÎªAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPºÍ̸ΪTCP¡¢TCPÖ÷ÕŶ˿ÚΪTelnet¡£Èçͼ1-1Ëùʾ¡£

ͼ1-1     ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄ·ÖÎö

image011

µäÐÍÅäÖþÙÀý

 IP³ß¶ÈACLÅäÖþÙÀý

1.    ×éÍøÐèÒª

ͨ¹ýÅäÖÃIP³ß¶ÈACL £¬²»ÈݲÆÕþ²¿ÒÔ±íµÄ²¿ÃŽӼû²ÆÕþÊý¾Ý·þÎñÆ÷¡£

2.    ×éÍøÍ¼

ͼ1-3     IP³ß¶ÈACLÀûÓó¡¾°×éÍøÍ¼

image015

 

3.    ÅäÖÃÖØµã

l  Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

l  Device A½«IP³ß¶ÈACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£

4.    ÅäÖò½Öè

(1)   ÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

# Device AÅäÖÃIP³ß¶ÈACL²¢Ôö³¤½Ó¼û¹æ¶¨¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# ip access-list standard 1

DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255

DeviceA(config-std-nacl)# deny 11.1.1.1 0.0.0.255

DeviceA(config-std-nacl)# exit

(2)   ½«IP³ß¶ÈACLÀûÓõ½½Ó¿ÚÉÏ¡£

# Device A½«ACLÀûÓÃÔÚÏνӲÆÕþÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£

DeviceA(config)# interface gigabitethernet 0/3

DeviceA(config-if-GigabitEthernet 0/3)# ip access-group 1 out

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

²é³­Device AÉ豸ACLÅäÖúÅÁîÊÇ·ñÕýÈ·¡£

DeviceA# show access-lists

 

ip access-list standard 1

10 permit 10.1.1.0 0.0.0.255

20 deny 11.1.1.0 0.0.0.255

 

DeviceA# show access-group

ip access-group 1 out

Applied On interface GigabitEthernet 0/3

´Ó¿ª·¢²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷ £¬È·ÈÏping²»Í¨¡£

´Ó²ÆÕþ²¿µÄij̨PC»úÉÏping²ÆÕþÊý¾Ý·þÎñÆ÷ £¬È·ÈÏÄÜpingͨ¡£

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

ip access-list standard 1

 10 permit 10.1.1.0 0.0.0.255

 20 deny 11.1.1.0 0.0.0.255

!

interface GigabitEthernet 0/1

 no switchport

 ip address 10.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

 no switchport

 ip address 11.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

 no switchport

 ip access-group 1 out

 ip address 12.1.1.1 255.255.255.0

!

¸ü¶à°¸Àý

IPÀ©´óACLÅäÖþÙÀý

MACÀ©´óACLÅäÖþÙÀý

ר¼Ò¼¶À©´óACLÅäÖþÙÀý

IPv6 ACLÅäÖþÙÀý

ACL80ÅäÖþÙÀý

»ùÓÚ¹¦·ò¶ÎµÄACL¹æ¶¨ÅäÖþÙÀý

SVI Router ACLÅäÖþÙÀý

CL±¨ÎļÆÊýͳ¼ÆÅäÖþÙÀý

 

½ð²Ê»ã - Ê×Ò³

·µ»Ø¶¥²¿

ÊÕÆð
½ð²Ê»ã - Ê×Ò³ ÎĵµAI¸±ÊÖ
½ð²Ê»ã - Ê×Ò³ ÎĵµÆÀ¼Û
ev-close ev-close-m
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
ev-close ev-close-m
Äú¶Ôµ±Ç°Ò³ÃæµÄÖÐÒâ¶ÈÈôºÎ£¿
²»Õ¦µÎ
¼«¶ÈºÃ
dark-star dark-star dark-star dark-star dark-star
ev-close ev-close-m
ÄúÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
Äú¶ÔÎĵµÊÇ·ñ»¹ÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿
Ϊ¾¡¿ì½â¾öÎÊÌâ £¬ÇëÄúÁôÏÂÁªÏµ·½Ê½Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
ev-bg
¸Ð¼¤ÄúµÄ·´À¡£¡
½ð²Ê»ã - Ê×Ò³
½ð²Ê»ã - Ê×Ò³
½ð²Ê»ã - Ê×Ò³
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø¹ØÕ÷ѯҳ
ÊÛǰÕ÷ѯ ÊÛǰÕ÷ѯ
ÊÛǰÕ÷ѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
¶¨¼û·´À¡ ¶¨¼û·´À¡
¶¨¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿