<!DOCTYPE html> <html> <head> </head> <body> <p>First you have to create an access list:</p> <p>router(config)#<strong>access-list 100 permit icmp any any unreachable</strong><br />router(config)#<strong>access-list 100 permit icmp any any echo-reply</strong><br />router(config)#<strong>access-list 100 permit icmp any any time-exceeded</strong><br />router(config)#<strong>access-list 100 permit icmp any any source-quench</strong><br />router(config)#<strong>access-list 100 deny icmp any any timestamp-request</strong><br />router(config)#<strong>access-list 100 deny icmp any any timestamp-reply</strong><br />router(config)#a<strong>ccess-list 100 permit ip any any</strong></p> <p>Then add id to IN or OUT to the interface:</p> <p>router(config)#<strong>interface GigabitEthernet0/2</strong><br />router(config)#<strong>ip access-group 100 in<br /><br />Modificare una access-list (Prima magari visualizzala e guarda i numeri di riga)<br />Visualizzare access-list: </strong>router#<strong>sh <strong>ip access-list 100</strong><br /><br /></strong>router(config)#<strong>ip access-list extended 100<br /></strong>router(config-ext-nacl)#<strong>67 deny tcp any any eq telnet<br /></strong>router(config-ext-nacl)#<strong>do sh ip access-list 100<br /></strong></p> <p><strong>NOTA: La sequenza è fondamentale per l'applicazione delle regole.<br /></strong></p> <p>Esempio:</p> <p>csco-gw02(config-ext-nacl)#do sh ip access-list 100 <br />Extended IP access list 100<br /> 10 permit icmp any any unreachable (2 matches)<br /> 20 permit icmp any any echo-reply<br /> 30 permit icmp any any time-exceeded<br /> 40 permit icmp any any source-quench<br /> 50 deny icmp any any timestamp-request (1 match)<br /> 60 deny icmp any any timestamp-reply<br /> 70 <span style="color: #ff6600;">permit ip any any (84562 matches)</span></p> <p> </p> </body> </html>
Subscribe
0 Comments
Oldest