Cisco access-list实验

来源:互联网 发布:网站80端口可以攻击吗 编辑:程序博客网 时间:2024/05/21 22:40

目的:禁止r5访问r4

Top图

第一步

路由配置完成后

R5#ping 192.168.110.4

 

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 192.168.110.4, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 4/9/16 ms

R5#

 

 

第二步:在R3上(关键)

R3(config)#access-list 1 deny 192.168.110.4

R3#show access-lists

Standard IP access list 1

deny 192.168.110.4 //看到已经deny了

 

R3(config)#interface e1/1        

R3(config-if)#ip access-group 1 out    //绑定到e1/1上

 

第三步

R5#ping 192.168.110.4

 

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 192.168.110.4, timeout is 2 seconds:

U.U.U

Success rate is 0 percent (0/5)

原创粉丝点击