当前位置:网站首页>交换机和路由器技术-32-命名ACL
交换机和路由器技术-32-命名ACL
2022-08-11 04:44:00 【w辣条小王子】
命名ACL:
没有表号,使用名字作为表号,直接使用standard标识标准ACL、和extended标识扩展
删除访问控制列表
1.在删除访问控制列表前,需要先从应用的接口上取消
2.不管是标准ACL还是扩展ACL 不管no哪一条ACL,删除都是全部删除,不能单独删除
而且添加ACL是自动往后排,不能插在中间

![]()
![]()
![]()
命名ACL好处:
可以在某一个表内删除单条ACL或者在任意位置插入ACL
具体配置
Router(config)#ip access-list ?
extended Extended Access List
standard Standard Access List
Router(config)#ip access-list extended wn //扩展ACL命名为wn
Router(config-ext-nacl)#deny ?
ahp Authentication Header Protocol
eigrp Cisco's EIGRP routing protocol
esp Encapsulation Security Payload
gre Cisco's GRE tunneling
icmp Internet Control Message Protocol
ip Any Internet Protocol
ospf OSPF routing protocol
tcp Transmission Control Protocol
udp User Datagram Protocol
Router(config-ext-nacl)#deny icmp ?
A.B.C.D Source address
any Any source host
host A single source host
Router(config-ext-nacl)#deny icmp host 192.168.10.2 ?
A.B.C.D Destination address
any Any destination host
host A single destination host
Router(config-ext-nacl)#deny icmp host 192.168.10.2 host 192.168.30.2
Router(config-ext-nacl)#deny icmp host 192.168.20.2 host 192.168.30.2
Router(config-ext-nacl)#deny udp host 192.168.20.2 host 192.168.30.2 eq 53
Router(config-ext-nacl)#deny tcp host 192.168.10.2 host 192.168.30.2 eq 80
Router(config-ext-nacl)#permit ip any any
Router(config-ext-nacl)#exit
Router(config)#int g0/1
Router(config-if)#
Router(config-if)#ip access-group wn in
Router(config-if)#exit
Router(config)#
Router(config)#int g0/1 //应用到接口
Router(config-if)#ip access-group wn out
Router(config-if)#删除ACL
第一步:查看ACL编号
Show access-lists

假设删除编号为20的acl
进入扩展ACL;然后直接no
Router(config)#ip access-list extended wn
Router(config-ext-nacl)#no 20

指定ACL序号
Router(config-ext-nacl)#?
<1-2147483647> Sequence Number
Router(config-ext-nacl)#12 deny icmp 192.168.20.2 0.0.0.0 192.168.30.2 0.0.0.0
deny icmp 192.168.20.2 0.0.0.0 192.168.30.2 0.0.0.0等同于deny icmp 192.168.20.2 92.168.30.2
此处的0.0.0.0是是255.255.255.255的反掩码,原因acl需要反掩码,标识一个IP我们用的子网掩码是四个255
边栏推荐
- 我的LaTeX入门
- 【服务器安装Redis】Centos7离线安装redis
- Pinduoduo store business license related issues
- shell监视gpu使用情况
- 0 Basic software test for career change, self-study for 3 months, 12k*13 salary offer
- Get Qt installation information: including installation directory and various macro addresses
- Licking - frog jumping steps
- Do you understand how the Selenium automated testing framework works?
- Self-research capability was recognized again, and Tencent Cloud Database was included in the Forrester Translytical report
- 洛谷P7441 Erinnerung
猜你喜欢

无线电射频能量的收集

To break the bottleneck of transactional work, the gentleman signs the electronic contract to release the "source power" of HR!

北湖区燕泉街道开展“戴头盔·保安全”送头盔活动

What is machine learning?Explain machine learning concepts in detail

"239 Sliding Window Maximum Value" on the 16th day of LeetCode brushing

Harvesting of radio frequency energy

Do you understand how the Selenium automated testing framework works?

"104 Maximum Depth of Binary Trees" in LeetCode's Day 12 Binary Tree Series

Use jackson to parse json data in detail

嵌入式分享合集33
随机推荐
redis按照正则批量删除key
一种基于共识机制的数字集群终端防失控方案研究
【FPGA教程案例50】控制案例2——基于FPGA的PD控制器verilog实现
洛谷P7441 Erinnerung
"104 Maximum Depth of Binary Trees" in LeetCode's Day 12 Binary Tree Series
【FPGA教程案例49】控制案例1——基于FPGA的PID控制器verilog实现
Map中的getOrDefualt方法
使用百度EasyDL实现施工人员安全装备检测
FPGA工程师面试试题集锦111~120
findViewById返回null的问题
增加PRODUCT_BOOT_JARS及类 提供jar包给应用
直播软件搭建,流式布局,支持单选、多选等
ALSA音频架构
Licking - frog jumping steps
MySQL database storage engine and database creation, modification and deletion
Use jackson to parse json data in detail
洛谷P4847 银河英雄传说V2
shell monitors gpu usage
视觉任务种常用的类别文件之一json文件
Dry goods: The principle and practice of server network card group technology