資源描述:
《CCNA教材.ppt》由會員上傳分享,免費在線閱讀,更多相關內容在教育資源-天天文庫。
1、?2004CiscoSystems,Inc.Allrightsreserved.ICNDv2.2—4-1ManagingIPTrafficwithACLsIntroducingACLsOutlineOverviewACLOverviewACL概述ACLApplicationsACL應用TypesofACLsACL的類型ACLOperationsACL操作ACLStatementProcessingACL狀態(tài)WildcardMaskingProcess通配符匹配流程SummaryManageIPtrafficasnetworka
2、ccessgrows控制數(shù)據(jù)流量Filterpacketsastheypassthroughtherouter篩選通過路由器的數(shù)據(jù)包WhyUseACLs?Permitordenypacketsmovingthroughtherouter.允許或拒絕通過路由器的數(shù)據(jù)包Permitordenyvtyaccesstoorfromtherouter.允許或拒絕到路由器的vty訪問WithoutACLs,allpacketscouldbetransmittedontoallpartsofyournetwork.如果不使用ACL,數(shù)據(jù)包可
3、以到達網(wǎng)絡上的任何部分ACLApplicationsSpecialhandlingfortrafficbasedonpackettests某些控制流量的功能通過測試包來實現(xiàn)OtherACLUsesStandardCheckssourceaddress檢查源地址Generallypermitsordeniesentireprotocolsuite允許或拒絕整個協(xié)議棧ExtendedCheckssourceanddestinationaddress檢查源和目標地址Generallypermitsordeniesspecificpr
4、otocols允許或拒絕指定的協(xié)議TypesofACLsHowtoIdentifyACLsStandardIPlists(1-99)testconditionsofallIPpacketsfromsourceaddresses.標準IPlist檢查所有包的源地址ExtendedIPlists(100-199)testconditionsofsourceanddestinationaddresses,specificTCP/IPprotocols,anddestinationports.擴展的IPlist檢查源和目標地址,指定
5、的協(xié)議和目標端口StandardIPlists(1300-1999)(expandedrange).ExtendedIPlists(2000-2699)(expandedrange).OtherACLnumberrangestestconditionsforothernetworkingprotocols.NamedACLsidentifyIPstandardandextendedACLswithanalphanumericstring(name).可以用命名ACL來使用標準或擴展ACLTestingPacketswithS
6、tandardACLsIPDatagramHeaderTCPHeaderTestingPacketswithExtendedACLsOutboundACLOperationIfnoACLstatementmatches,thendiscardthepacket.如果沒有ACL匹配,那么數(shù)據(jù)包將被丟棄AListofTests:DenyorPermit0meanscheckvalueofcorrespondingaddressbit.0意味著檢測相應的bit1meansignorevalueofcorrespondingaddr
7、essbit.1意味著忽略相應的bitWildcardBits:HowtoChecktheCorrespondingAddressBits172.30.16.290.0.0.0checksalltheaddressbits.AbbreviatethiswildcardmaskusingtheIPaddressprecededbythekeywordhost(host172.30.16.29).Checkalltheaddressbits(matchall).檢測所有的地址位VerifyanIPhostaddress,forex
8、ample:指定一個主機地址,如下:WildcardBitstoMatchaSpecificIPHostAddress通配符匹配指定主機Testconditions:Ignorealltheaddressbits(matchany).忽略所有地址位Anyhostaddress