config terminal
access-list 表号 permit/deny 源IP或源网段 反子网掩码
config terminal access-list 1 permit/deny 协议 源IP或源网段 反子网掩码 目标IP或目标网段 反子网掩码 [eq 端口号]
config terminal no access-list 表号 //删除ACL表 //查看ACL表信息 show ip access-list //将ACL应用到接口 interface f0/x ip access-group 表号 in/out exit
config terminal ip access-list standard/extended 自定义表名 开始从deny或permit编写ACL条目 exit //删除某一条 ip access-list standard/extended 自定义表名 no 条目ID exit //插入某一条 ip access-list standard/extended 自定义表名 条目ID 动作 条件 exit
Router(config)#hostname r1 r1(config)#interface f0/0 r1(config-if)#ip address 10.1.1.254 255.255.255.0 r1(config-if)#no shutdown r1(config-if)#exit r1(config)#interface f0/1 r1(config-if)#ip address 20.1.1.1 255.255.255.0 r1(config-if)#no shutdown r1(config-if)#exit r1(config)#ip route 30.1.1.0 255.255.255.0 20.1.1.2 r1(config)#ip route 40.1.1.0 255.255.255.0 20.1.1.2 r1(config)#ip route 50.1.1.0 255.255.255.0 20.1.1.2
Router(config)#hostname count count(config)#interface f0/0 count(config-if)#ip address 20.1.1.2 255.255.255.0 count(config-if)#no shutdown count(config-if)#exit count(config)#interface f0/1 count(config-if)#ip address 30.1.1.1 255.255.255.0 count(config-if)#no shutdown count(config-if)#exit count(config)#interface f1/0 count(config-if)#ip address 50.1.1.254 255.255.255.0 count(config-if)#no shutdown count(config-if)#exit count(config)#ip route 40.1.1.0 255.255.255.0 30.1.1.2 count(config)#ip route 10.1.1.0 255.255.255.0 20.1.1.1 count(config)#access-list 1 deny host 40.1.1.1 count(config)#access-list 1 deny 10.1.1.0 0.255.255.255 count(config)#access-list 1 permit any count(config)#interface f1/0 count(config-if)#ip access-group 1 out count(config-if)#exit count(config)#do show access-list Standard IP access list 1 10 deny host 40.1.1.1 20 deny 10.0.0.0 0.255.255.255 30 permit any
r3(config)#hostname r2 r2(config)#interface f0/0 r2(config-if)#ip address 30.1.1.2 255.255.255.0 r2(config-if)#no shutdown r2(config-if)#exit r2(config)#interface f0/1 r2(config-if)#ip address 40.1.1.254 255.255.255.0 r2(config-if)#no shutdown r2(config-if)#exit r2(config)#ip route 10.1.1.0 255.255.255.0 30.1.1.1 r2(config)#ip route 20.1.1.0 255.255.255.0 30.1.1.1 r2(config)#ip route 50.1.1.0 255.255.255.0 30.1.1.1 r2(config)#access-list 2 deny host 10.1.1.1 r2(config)#access-list 2 permit any r2(config)#interface f0/0 r2(config-if)#ip access-group 2 in r2(config-if)#exit r2(config)#do show ip access-list Standard IP access list 2 10 deny host 10.1.1.1 20 permit any
//修改设备名 count(config)#hostname count //配置trunk count(config)#interface range f0/1 - 2 count(config-if-range)#switchport trunk encapsulation dot1q count(config-if-range)#switchport mode trunk //配置vtp count(config-if-range)#vtp domain stain Domain name already set to stain. //配置vlan count(config)#vlan 10 count(config-vlan)#exit count(config)#vlan 20 count(config-vlan)#exit count(config)#vlan 30 count(config-vlan)#exit count(config)#vlan 40 count(config-vlan)#exit //起三层、网关 count(config)#ip routing count(config)#interface vlan 10 count(config-if)#ip address 10.1.1.254 255.255.255.0 count(config-if)#no shutdown count(config-if)#exit count(config)#interface vlan 20 count(config-if)#ip address 20.1.1.254 255.255.255.0 count(config-if)#no shutdown count(config-if)#exit count(config)#interface vlan 30 count(config-if)#ip address 30.1.1.254 255.255.255.0 count(config-if)#no shutdown count(config-if)#exit count(config)#interface vlan 40 count(config-if)#ip address 40.1.1.254 255.255.255.0 count(config-if)#no shutdown count(config-if)#exit //升级三层端口 count(config)#interface f0/3 count(config-if)#no switchport count(config-if)#ip address 172.16.1.1 255.255.255.0 count(config-if)#no shutdown //配置路由 count(config)#ip route 200.1.1.0 255.255.255.0 172.16.1.2 //配置命令ACL,禁止10.1.1.0网段连接外网,不影响其vlan间通信 count(config)#ip access-list extended xx count(config-ext-nacl)#permit ip 10.1.1.0 0.0.0.255 20.1.1.0 0.0.0.255 count(config-ext-nacl)#permit ip 10.1.1.0 0.0.0.255 30.1.1.0 0.0.0.255 count(config-ext-nacl)#permit ip 10.1.1.0 0.0.0.255 40.1.1.0 0.0.0.255 count(config-ext-nacl)#deny ip 10.1.1.0 0.0.0.255 any count(config-ext-nacl)#permit ip any any count(config-ext-nacl)#exit count(config)#interface vlan 10 count(config-if)#ip access-group xx in count(config-if)#exit //配置命令ACL,任何部门均不能访问财务部,但不能影响财务部上网! count(config)#ip access-list standard cw count(config-std-nacl)#deny 10.1.1.0 0.0.0.255 count(config-std-nacl)#deny 20.1.1.0 0.0.0.255 count(config-std-nacl)#deny 40.1.1.0 0.0.0.255 count(config-std-nacl)#permit any count(config-std-nacl)#exit count(config)#interface vlan 30 count(config-if)#ip access-group cw out count(config-if)#exit
r1(config)#interface f0/0 r1(config-if)#ip address 172.16.1.2 255.255.255.0 r1(config-if)#no shutdown r1(config-if)#exit r1(config)#interface f0/1 r1(config-if)#ip address 100.1.1.1 255.255.255.0 r1(config-if)#no shutdown r1(config-if)#exit r1(config)#ip route 200.1.1.0 255.255.255.0 100.1.1.2 r1(config)#ip route 0.0.0.0 0.0.0.0 172.16.1.1
r2(config)#interface f0/0 r2(config-if)#ip address 100.1.1.2 255.255.255.0 r2(config-if)#no shutdown r2(config-if)#exit r2(config)#interface f0/1 r2(config-if)#ip address 200.1.1.254 255.255.255.0 r2(config-if)#no shutdown r2(config-if)#exit r2(config)#ip route 0.0.0.0 0.0.0.0 100.1.1.1
原文:https://www.cnblogs.com/xmtxh/p/14703567.html