ACL£¨Access Control List£¬·ÃÎÊ¿ØÖÆÁÐ±í£©Ò²³ÆÎª·ÃÎÊÁÐ±í£¬ÓеÄÎĵµÖл¹³ÆÖ®Îª°ü¹ýÂË¡£ACLͨ¹ý¶¨ÒåһϵÁаüº¬“ÔÊÐí”»ò“¾Ü¾ø”µÄ¹æÔòÓï¾ä£¬²¢½«ÕâЩ¹æÔòÓ¦Óõ½É豸½Ó¿ÚÉÏ£¬¶Ô½ø³ö½Ó¿ÚµÄÊý¾Ý°ü½øÐпØÖÆ£¬´Ó¶øÌáÉýÍøÂçÉ豸µÄ°²È«ÐÔ¡£
ÅäÖÃACLÄܹ»±£ÕÏÍøÂ簲ȫ¡¢¿É¿¿ºÍÎȶ¨£¬ÀýÈ磺
l ·ÀÖ¹±¨ÎĹ¥»÷£ºÕë¶ÔIP¡¢TCP»òÕßICMP±¨ÎĵĹ¥»÷£¬¶ÔÕâЩ¹¥»÷±¨ÎÄ×ö“¾Ü¾ø”´¦Àí¡£
l ÍøÂç·ÃÎÊ¿ØÖÆ£ºÏÞÖÆÓû§·ÃÎÊ·þÎñ£¬ÀýÈçÖ»ÔÊÐí·ÃÎÊWWWºÍµç×ÓÓʼþ·þÎñ£¬ÆäËû·þÎñÈçTelnetÔò½ûÖ¹¡£»òÕßÖ»ÔÊÐíÔÚ¸ø¶¨µÄʱ¼ä¶ÎÄÚ·ÃÎÊ£¬»òÕßÖ»ÔÊÐíÌØ¶¨Ö÷»ú·ÃÎÊÍøÂçµÈ¡£
l ÍøÂçÁ÷Á¿¿ØÖÆ£º½áºÏQoS¿ÉÒÔÎªÖØÒªµÄÊý¾ÝÁ÷½øÐÐÓÅÏÈ·þÎñ±£Ö¤¡£¹ØÓÚQoSµÄÅäÖÃÇë²Î¼û“QoS”¡£
l ·ÃÎÊÁбí
·ÃÎÊÁбíÓУº»ù±¾·ÃÎÊÁбíºÍ¶¯Ì¬·ÃÎÊÁÐ±í¡£
Óû§¿ÉÒÔ¸ù¾ÝÐèҪѡÔñ»ù±¾·ÃÎÊÁбí»ò¶¯Ì¬·ÃÎÊÁÐ±í¡£Ò»°ãÇé¿öÏ£¬Ê¹Óûù±¾·ÃÎÊÁбíÒѾÄܹ»Âú×㰲ȫÐèÒª¡£µ«¹¥»÷Õß¿ÉÄÜͨ¹ýÈí¼þ¼ÙðԴµØÖ·ÆÛÆÉ豸£¬´Ó¶ø·ÃÎÊÍøÂç¡£¶ø¶¯Ì¬·ÃÎÊÁбíÔÚÓû§·ÃÎÊÍøÂçÒÔǰ£¬ÒªÇóͨ¹ýÉí·ÝÈÏÖ¤£¬Ê¹¹¥»÷ÕßÄÑÒÔ·ÃÎÊÍøÂç¡£ÔÚÃô¸ÐÇøÓò¿ÉÒÔʹÓö¯Ì¬·ÃÎÊÁÐ±í±£Ö¤ÍøÂ簲ȫ¡£
˵Ã÷
ͨ¹ý¼ÙðԴµØÖ·ÆÛÆÉ豸¼´µç×ÓÆÛÆÊÇËùÓзÃÎÊÁбí¹ÌÓеÄÎÊÌ⣬ʹÓö¯Ì¬ÁбíÒ²»áÔâÓöµç×ÓÆÛÆÎÊÌ⣺¹¥»÷Õß¿ÉÄÜÔÚÓû§Í¨¹ýÉí·ÝÈÏÖ¤µÄÓÐЧ·ÃÎÊÆÚ¼ä£¬¼ÙðÓû§µÄµØÖ··ÃÎÊÍøÂç¡£½â¾ö¸ÃÎÊÌâµÄ·½·¨ÓÐÁ½ÖÖ£¬Ò»ÖÖÊǾ¡Á¿ÉèÖøü¶ÌµÄÓû§·ÃÎÊ¿ÕÏÐʱ¼ä£»ÁíÒ»ÖÖÊÇʹÓÃIPsec¼ÓÃÜÐÒé¶ÔÍøÂçÊý¾Ý½øÐмÓÃÜ£¬È·±£½øÈëÉ豸ʱ£¬ËùÓеÄÊý¾Ý¶¼ÊǼÓÃܵġ£
·ÃÎÊÁбíÒ»°ãÅäÖÃÔÚÒÔÏÂλÖõÄÍøÂçÉ豸ÉÏ£º
¡ð ÄÚ²¿ÍøºÍÍâ²¿Íø£¨ÈçInternet£©Ö®¼äµÄÉ豸
¡ð Á½¸öÍøÂç½»½ç²¿·ÖµÄÉ豸
¡ð ½ÓÈë¿ØÖÆ¶Ë¿ÚµÄÉ豸
ACE£¨Access Control Entry£¬·ÃÎÊ¿ØÖÆÌõÄ¿£©Êǰüº¬“ÔÊÐí£¨Permit£©”»ò“¾Ü¾ø£¨Deny£©”Á½ÖÖ¶¯×÷£¬ÒÔ¼°¹ýÂ˹æÔòµÄÒ»ÌõÓï¾ä¡£Ã¿¸öACE¶¼ÓÐÒ»¸öÐòºÅ£¬¸ÃÐòºÅ¿ÉÓÉÉ豸×Ô¶¯·ÖÅä»òÕßÊÖ¶¯ÅäÖá£Ò»ÌõACLÖаüº¬Ò»¸ö»òÕß¶à¸öACE¡£ACLͨ¹ýACE¶ÔÊý¾Ý°ü½øÐбêʶ¹ýÂË¡£
ACLÖÐACEµÄ˳Ðò¾ö¶¨Á˸ÃACEÔÚ·ÃÎÊÁбíÖÐµÄÆ¥ÅäÓÅÏȼ¶¡£ÍøÂçÉ豸ÔÚ´¦Àí±¨ÎÄʱ£¬°´ACEµÄÐòºÅ´ÓСµ½´ó½øÐйæÔòÆ¥Å䣬µ±ÕÒµ½Æ¥ÅäµÄACEºóÔòÍ£Ö¹¼ì²éºóÐøµÄACE¡£
ÀýÈç´´½¨Ò»ÌõÐòºÅΪ10µÄACE£¬Ëü¾Ü¾øËùÓеÄÊý¾ÝÁ÷ͨ¹ý¡£
10 deny ip any any
20 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
ÓÉÓÚÐòºÅΪ10µÄACE¾Ü¾øÁËËùÓеÄIP±¨ÎÄ£¬¼´Ê¹192.168.12.0/24ÍøÂçµÄÖ÷»úTelnet±¨ÎÄ£¬¿ÉÒÔ±»ÐòºÅΪ20µÄACEÆ¥Å䣬¸Ã±¨ÎÄÒ²½«±»¾Ü¾ø¡£ÒòΪÉ豸ÔÚ¼ì²éµ½±¨ÎĺÍÐòºÅΪ10µÄACEÆ¥Åäºó£¬±ãÍ£Ö¹¼ì²éºóÃæÐòºÅΪ20µÄACE¡£
ÓÖÀýÈç´´½¨Ò»Ìõ±àºÅΪ10µÄACE£¬ËüÔÊÐíËùÓеÄIPv6Êý¾ÝÁ÷ͨ¹ý¡£
10 permit ipv6 any any
20 deny ipv6 host 200::1 any
ÓÉÓÚÐòºÅΪ10µÄACEÔÊÐíËùÓеÄIPv6±¨ÎÄͨ¹ý£¬Ö÷»ú200::1·¢³öµÄIPv6±¨ÎÄ£¬¼´Ê¹Æ¥ÅäÐòºÅΪ20µÄACE£¬¸Ã±¨ÎÄÒ²½«±»ÔÊÐíͨ¹ý¡£ÒòΪÉ豸ÔÚ¼ì²éµ½±¨Îĺ͵ÚÒ»ÌõACEÆ¥Å䣬±ãÍ£Ö¹¼ì²éºóÃæÐòºÅΪ20µÄACE¡£
l ²½³¤
µ±É豸ΪACE×Ô¶¯·ÖÅäÐòºÅʱ£¬Á½¸öÏàÁÚACEÐòºÅÖ®¼äµÄ²îÖµ£¬³ÆÎª²½³¤¡£ÀýÈ磬Èç¹û½«²½³¤É趨Ϊ5£¬ÔòÉ豸°´ÕÕ5¡¢10¡¢15…ÕâÑùµÄµÝÔö˳Ðò×Ô¶¯ÎªACE·ÖÅäÐòºÅ¡£ÈçÏÂËùʾ¡£
5 deny ip any any
10 permit tcp 192.168.12.0 0.0.0.255 eq telnet any
µ±²½³¤¸Ä±äºó£¬ACEÐòºÅ»á×Ô¶¯°´Ð²½³¤ÖµÖØÐ·ÖÅä¡£ÀýÈ磬µ±°Ñ²½³¤¸ÄΪ10ºó£¬ÔÀ´ACEÐòºÅ´Ó5¡¢10¡¢15±ä³É5¡¢15¡¢25¡£
ͨ¹ý¸Ä±ä²½³¤¿ÉÒÔÔÚÁ½¸öACEÖ®¼ä²åÈëеÄACE¡£ÀýÈç´´½¨ÁË4¸öACE£¬²¢Í¨¹ýÊÖ¶¯ÅäÖÃACEÐòºÅ·Ö±ðΪ1¡¢2¡¢3ºÍ4¡£Èç¹ûÏ£ÍûÄÜÔÚÐòºÅ1ºóÃæ²åÈëÒ»ÌõеÄACE£¬Ôò¿ÉÒÔÏȽ«²½³¤ÐÞ¸ÄΪ2£¬´ËʱÔÏÈ4¸öACEµÄÐòºÅ×Ô¶¯±äΪ1¡¢3¡¢5ºÍ7£¬ÔÙ²åÈëÒ»ÌõÊÖ¶¯ÅäÖõÄÐòºÅΪ2µÄACE¡£
l ¹ýÂËÓòÄ£°å
¹ýÂËÓòÖ¸µÄÊÇÉú³ÉÒ»ÌõACEʱ£¬¸ù¾Ý±¨ÎÄÖеÄÄÄЩ×ֶζԱ¨ÎĽøÐÐʶ±ð¡¢·ÖÀà¡£¹ýÂËÓòÄ£°å¾ÍÊÇÕâЩ×ֶεÄ×éºÏ¡£ACE¸ù¾ÝÒÔÌ«Íø±¨ÎĵÄijЩ×Ö¶ÎÀ´±êʶÒÔÌ«Íø±¨ÎÄ£¬ÕâЩ×ֶΰüÀ¨£º
¶þ²ã×ֶΣ¨Layer 2 Fields£©£º
¡ð 48λµÄÔ´MACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩
¡ð 48λµÄÄ¿µÄMACµØÖ·£¨±ØÐëÉêÃ÷ËùÓÐ48룩
¡ð 16λµÄ¶þ²ãÀàÐÍ×Ö¶Î
Èý²ã×ֶΣ¨Layer 3 Fields£©£º
¡ð Ô´IPµØÖ·×ֶΣ¨¿ÉÒÔÉêÃ÷È«²¿Ô´IPµØÖ·Öµ£¬»òʹÓÃ×ÓÍøÀ´¶¨ÒåÒ»ÀàÁ÷£©
¡ð Ä¿µÄIPµØÖ·×ֶΣ¨¿ÉÒÔÉêÃ÷È«²¿Ä¿µÄIPµØÖ·Öµ£¬»òʹÓÃ×ÓÍøÀ´¶¨ÒåÒ»ÀàÁ÷£©
¡ð ÐÒéÀàÐÍ×Ö¶Î
ËIJã×ֶΣ¨Layer 4 Fields£©£º
¡ð ¿ÉÒÔÉêÃ÷Ò»¸öTCPµÄÔ´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú»òÕß¶¼ÉêÃ÷£¬»¹¿ÉÒÔÉêÃ÷Ô´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚµÄ·¶Î§¡£
¡ð ¿ÉÒÔÉêÃ÷Ò»¸öUDPµÄÔ´¶Ë¿Ú¡¢Ä¿µÄ¶Ë¿Ú»òÕß¶¼ÉêÃ÷£¬»¹¿ÉÒÔÉêÃ÷Ô´¶Ë¿Ú»òÄ¿µÄ¶Ë¿ÚµÄ·¶Î§¡£
ÀýÈ磬ÔÚ´´½¨Ò»ÌõACEʱÐèÒª¸ù¾Ý±¨ÎĵÄÄ¿µÄIP×ֶΣ¬¶Ô±¨ÎĽøÐÐʶ±ðºÍ·ÖÀà¡£¶øÔÚ´´½¨ÁíÒ»ÌõACEʱ£¬ÐèÒª¸ù¾Ý±¨ÎĵÄÔ´IPµØÖ·×ֶκÍUDPµÄÔ´¶Ë¿Ú×ֶΣ¬¶Ô±¨ÎĽøÐÐʶ±ðºÍ·ÖÀà¡£ÕâÁ½ÌõACE¾ÍʹÓÃÁ˲»Í¬µÄ¹ýÂËÓòÄ£°å¡£
l ¹æÔò
¹æÔò£¨Rules£©Ö¸µÄÊÇACE¹ýÂËÓòÄ£°å¶ÔÓ¦µÄÖµ¡£ÀýÈ磬һÌõACEµÄÄÚÈÝÈçÏ£º
10 permit tcp host 192.168.12.2 any eq telnet
ÔÚÕâÌõACEÖУ¬¹ýÂËÓòÄ£°åΪÒÔÏÂ×ֶεļ¯ºÏ£ºÔ´IPµØÖ·×ֶΡ¢Ä¿µÄIPµØÖ·×ֶΡ¢IPÐÒé×ֶΡ¢TCPÄ¿µÄ¶Ë¿Ú×ֶΡ£¶ÔÓ¦µÄÖµ£¨¼´¹æÔò£©·Ö±ðΪ£ºÔ´IPµØÖ·ÎªHost 192.168.12.2¡¢Ä¿µÄIPµØÖ·ÎªAny£¨¼´ËùÓÐÖ÷»ú£©¡¢IPÐÒéΪTCP¡¢TCPÄ¿µÄ¶Ë¿ÚΪTelnet¡£Èçͼ1-1Ëùʾ¡£
ͼ1-1 ¶ÔACE£ºpermit tcp host 192.168.12.2 any eq telnetµÄ·ÖÎö
ͨ¹ýÅäÖÃIP±ê×¼ACL£¬½ûÖ¹²ÆÎñ²¿ÒÔÍâµÄ²¿ÃÅ·ÃÎʲÆÎñÊý¾Ý·þÎñÆ÷¡£
ͼ1-3 IP±ê×¼ACLÓ¦Óó¡¾°×éÍøÍ¼

l Device AÅäÖÃIP±ê×¼ACL²¢Ìí¼Ó·ÃÎʹæÔò¡£
l Device A½«IP±ê×¼ACLÓ¦ÓÃÔÚÁ¬½Ó²ÆÎñÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£
(1) ÅäÖÃIP±ê×¼ACL²¢Ìí¼Ó·ÃÎʹæÔò¡£
# Device AÅäÖÃIP±ê×¼ACL²¢Ìí¼Ó·ÃÎʹæÔò¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# ip access-list standard 1
DeviceA(config-std-nacl)# permit 10.1.1.0 0.0.0.255
DeviceA(config-std-nacl)# deny 11.1.1.1 0.0.0.255
DeviceA(config-std-nacl)# exit
(2) ½«IP±ê×¼ACLÓ¦Óõ½½Ó¿ÚÉÏ¡£
# Device A½«ACLÓ¦ÓÃÔÚÁ¬½Ó²ÆÎñÊý¾Ý·þÎñÆ÷½Ó¿ÚµÄ³ö·½ÏòÉÏ¡£
DeviceA(config)# interface gigabitethernet 0/3
DeviceA(config-if-GigabitEthernet 0/3)# ip access-group 1 out
# ¼ì²éDevice AÉ豸ACLÅäÖÃÃüÁîÊÇ·ñÕýÈ·¡£
DeviceA# show access-lists
ip access-list standard 1
10 permit 10.1.1.0 0.0.0.255
20 deny 11.1.1.0 0.0.0.255
DeviceA# show access-group
ip access-group 1 out
Applied On interface GigabitEthernet 0/3
# ´Ó¿ª·¢²¿µÄij̨PC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬È·ÈÏping²»Í¨¡£
# ´Ó²ÆÎñ²¿µÄij̨PC»úÉÏping²ÆÎñÊý¾Ý·þÎñÆ÷£¬È·ÈÏÄÜpingͨ¡£
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
ip access-list standard 1
10 permit 10.1.1.0 0.0.0.255
20 deny 11.1.1.0 0.0.0.255
!
interface GigabitEthernet 0/1
no switchport
ip address 10.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
no switchport
ip address 11.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
no switchport
ip access-group 1 out
ip address 12.1.1.1 255.255.255.0
!