資源描述:
《基于Cisco的動態(tài)ACL、自反ACL配置.doc》由會員上傳分享,免費在線閱讀,更多相關(guān)內(nèi)容在教育資源-天天文庫。
1、動態(tài)ACL---lockandkey主機C1關(guān)聯(lián)到物理機的回環(huán)網(wǎng)卡。其他網(wǎng)卡禁用,避免ping外網(wǎng)時IP地址或網(wǎng)關(guān)相互沖突!步驟:1.設(shè)置連通性:在R2上配置缺省路由,檢查全網(wǎng)連通性,C1能ping通R1、R2;2.在R1上配置動態(tài)ACL:usernamexusecretxupa55access-list101permittcpanyhost192.168.1.1eqtelnetaccess-list101dynamictestlisttimeout15permitip192.168.1.00.0.0.25510.0.0.00.0.0.255line
2、vty04loginlocalautocommandaccess-enablehosttimeout53.驗證配置結(jié)果C1在telnet到R1之前,C1不能ping通R1、R2;在C1在telnet到R1,通過驗證后,telnet連接斷開,ACL自動添加一條新的規(guī)則。此時,再次嘗試C1應該能ping通R1、R2;(證明通過驗證后能訪問內(nèi)網(wǎng)了。)反復對比R1#showaccess-lists101這條命令的執(zhí)行結(jié)果,查看變化。R1#showaccess-lists101ExtendedIPaccesslist10110permittcpanyhost1
3、92.168.1.1eqtelnet(93matches)20Dynamictestlistpermitip192.168.1.00.0.0.25510.0.0.00.0.0.255permitip192.168.1.2000.0.0.25510.0.0.00.0.0.255自反ACL主機C1關(guān)聯(lián)到物理機的回環(huán)網(wǎng)卡。其他網(wǎng)卡禁用,避免ping外網(wǎng)時IP地址或網(wǎng)關(guān)相互沖突!步驟:1.設(shè)置連通性:在R2上配置缺省路由,檢查全網(wǎng)連通性,C1能ping通R1、R2;2.在R2上配置web服務:usernamexuaprivilege15secretxuapa
4、55iphttpserveriphttpauthenticationlocal3.在R1上配置自反ACL:interfaceFastEthernet0/1ipaddress10.0.0.2255.255.255.0ipaccess-groupexternal_ACLinipaccess-groupinternal_ACLout!ipaccess-listextendedexternal_ACLevaluateweb-only-reflect-ACLdenyipanyanyipaccess-listextendedinternal_ACLpermitt
5、cpanyanyeqwwwreflectweb-only-reflect-ACLdenyipanyany4.驗證結(jié)果(內(nèi)部主機ping不通外部web服務器,但是可以用瀏覽器發(fā)起訪問;外部ping不通內(nèi)部,不允許外部發(fā)起的訪問)R1#shaccess-listsinternal_ACLExtendedIPaccesslistinternal_ACL10permittcpanyanyeqwwwreflectweb-only-reflect-ACL20denyipanyany(3matches)R1#shaccess-listsexternal_ACLEx
6、tendedIPaccesslistexternal_ACL10evaluateweb-only-reflect-ACL20denyipanyanyR1#shaccess-listsinternal_ACLExtendedIPaccesslistinternal_ACL10permittcpanyanyeqwwwreflectweb-only-reflect-ACL20denyipanyany(6matches)R1#shaccess-listsexternal_ACLExtendedIPaccesslistexternal_ACL10evaluat
7、eweb-only-reflect-ACL20denyipanyanyR1#shaccess-listsexternal_ACLExtendedIPaccesslistexternal_ACL10evaluateweb-only-reflect-ACL20denyipanyany(12matches)R1#shaccess-listsinternal_ACLExtendedIPaccesslistinternal_ACL10permittcpanyanyeqwwwreflectweb-only-reflect-ACL(41matches)20deny
8、ipanyany(6matches)R1#shaccess-listsexternal_ACLExtende