0
点赞
收藏
分享

微信扫一扫

访问控制列表

访问控制列表_ci

核心

华为路由器访问控制列表默认的过滤模式是( )。

A.拒绝B.允许C.必须配置D.空

思科路由器访问控制列表默认的过滤模式是()

A.拒绝B.允许C.必须配置D.空

命令解析

acl number 2000  

rule 5 permit source 20.1.1.1 0  

rule 10 deny  

特别注意:

需要将允许的全部的写在前面,最后追加一条禁止所有,这样操作合理

配置

R1:

[r1]display current-configuration  

[V200R003C00]

#

sysname r1

#

snmp-agent local-engineid 800007DB03000000000000

snmp-agent  

#

clock timezone China-Standard-Time minus 08:00:00

#

portal local-server load portalpage.zip

#

drop illegal-mac alarm

#

set cpu-usage threshold 80 restore 75

#

acl number 2000  

rule 5 permit source 20.1.1.1 0  

rule 10 deny  

#

aaa  

authentication-scheme default

authorization-scheme default

accounting-scheme default

domain default  

domain default_admin  

local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$

local-user admin service-type http

#

firewall zone Local

priority 15

#

interface GigabitEthernet0/0/0

ip address 30.1.1.1 255.255.255.0  

#

interface GigabitEthernet0/0/1

ip address 12.1.1.1 255.255.255.0  

#

interface GigabitEthernet0/0/2

#

interface NULL0

#

interface LoopBack0

ip address 1.1.1.1 255.255.255.255  

#

ospf 100 router-id 1.1.1.1  

filter-policy 2000 import

area 0.0.0.0  

 network 1.1.1.1 0.0.0.0  

 network 12.1.1.0 0.0.0.255  

 network 30.1.1.0 0.0.0.255  

#

user-interface con 0

authentication-mode password

user-interface vty 0 4

user-interface vty 16 20

#

wlan ac

#

return

[r1]

R2:

<r2>display current-configuration  

[V200R003C00]

#

sysname r2

#

snmp-agent local-engineid 800007DB03000000000000

snmp-agent  

#

clock timezone China-Standard-Time minus 08:00:00

#

portal local-server load portalpage.zip

#

drop illegal-mac alarm

#

set cpu-usage threshold 80 restore 75

#

aaa  

authentication-scheme default

authorization-scheme default

accounting-scheme default

domain default  

domain default_admin  

local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$

local-user admin service-type http

#

firewall zone Local

priority 15

#

interface GigabitEthernet0/0/0

ip address 12.1.1.2 255.255.255.0  

#

interface GigabitEthernet0/0/1

#

interface GigabitEthernet0/0/2

#

interface NULL0

#

interface LoopBack0

ip address 2.2.2.2 255.255.255.255  

#

interface LoopBack1

ip address 10.1.1.1 255.255.255.255  

#

interface LoopBack2

ip address 20.1.1.1 255.255.255.255  

#

ospf 100 router-id 2.2.2.2  

area 0.0.0.0  

 network 2.2.2.2 0.0.0.0  

 network 10.1.1.1 0.0.0.0  

 network 12.1.1.0 0.0.0.255  

 network 20.1.1.1 0.0.0.0  

#

user-interface con 0

authentication-mode password

user-interface vty 0 4

user-interface vty 16 20

#

wlan ac

#

return

<r2>

举报

相关推荐

0 条评论