前言
作者:神的孩子都在歌唱
企业网络中的设备进行通信时,需要保障数据传输的安全可靠和网络的性能稳定,网络安全很重要。
访问控制列表ACL(Access Control List) 可以定义一系列不同的规则,设备根据这些规则对数据包进行分类,并针对不同类型的报文进行不同的处理,从而可以实现网络访问行为的控制、限制网络流量、提高网络性能、防止网络攻击等。
R1
<Huawei>undo terminal monitor
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.10.1 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]q
[Huawei]int LoopBack 0
[Huawei-LoopBack0]ip address 8.1.1.1 32
R2
<Huawei>undo terminal monitor
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.9.1 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int LoopBack 0
[Huawei-LoopBack0]q
R3
<Huawei>undo terminal monitor
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.10.2 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.9.2 24
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 192.168.8.1 24
[Huawei-GigabitEthernet0/0/2]q
[Huawei]int LoopBack 0
[Huawei-LoopBack0]ip address 8.3.3.3 32
R4
<Huawei>undo terminal monitor
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.8.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int LoopBack 0
[Huawei-LoopBack0]ip address 8.4.4.4 32
R1
[Huawei]ospf 1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.9.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 8.1.1.1 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]dis ospf interface
R2
[Huawei]ospf 1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.9.0 0.0.0.255
R3
[Huawei-ospf-1-area-0.0.0.0]network 192.168.8.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 192.168.8.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 8.3.3.3 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]dis ospf in
[Huawei-ospf-1-area-0.0.0.0]dis ospf interface
R4
[Huawei]ospf 1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.8.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 8.4.4.4 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]dis ip routing-table protocol ospf
R4
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]authentication-mode password
Please configure the login password (maximum length 16):2018060808
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 5 permit source 8.1.1.1 0
[Huawei-acl-basic-2000]rule 10 deny source any
[Huawei-acl-basic-2000]q
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]acl 2000 inbound
分别配置名字
[Huawei]sysname R1
[Huawei]sysname R2
[Huawei]sysname R3
[Huawei]sysname R4
使R3也能通
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 8 permit source 8.3.3.3 0
查看
dis acl 2000
作者:神的孩子都在歌唱 本人博客:https://blog.csdn.net/weixin_46654114 转载说明:务必注明来源,附带本人博客连接