下载此文档

CCNA 新版(英文)D20S06L02.pps


文档分类:外语学习 | 页数:约24页 举报非法文档有奖
1/24
下载提示
  • 1.该资料是网友上传的,本站提供全文预览,预览什么样,下载就什么样。
  • 2.下载该文档所得收入归上传者、原创者。
  • 3.下载的文档,不会出现我们的网址水印。
1/24 下载此文档
文档列表 文档介绍
© 2002, Cisco Systems, Inc. All rights reserved.
© 2002, Cisco Systems, Inc. All rights reserved.
2
Configuring IP Access Lists
Objectives
pleting this lesson, you will be able to:
Use Cisco mands to configure IP standard and extended access lists, given a functioning router
Use mands to identify anomalies in IP standard and extended access lists, given an operational router
Access List Configuration Guidelines
Access list numbers indicate which protocol is filtered.
One access list per interface, per protocol, per direction is allowed.
The order of access list statements controls testing.
Place the most restrictive statements at the top of list.
There is an implicit deny any statement as the last access list test. Every list needs at least one permit statement.
Create access lists before applying them to interfaces.
Access lists filter traffic going through the router; they do not apply to traffic originating from the router.
Step 1: Set parameters for this access list test statement (which can be one of several statements).
Step 2: Enable an interface to use the specified access list.
Router(config-if)#{protocol} access-group access-list-number {in | out}
Access mand Overview
Standard IP lists (1-99)
Extended IP lists (100-199)
Standard IP lists (1300-1999) (expanded range)
Extended IP lists (2000-2699) (expanded range)
Router(config)#access-list access-list-number {permit | deny} {test conditions}
Activates the list on an interface
Sets inbound or outbound testing
Default = outbound
no ip access-group access-list-number removes access list from the interface
Router(config-if)#ip access-group access-list-number {in | out}
Sets parameters for this list entry
IP standard access lists use 1 to 99
Default wildcard mask =
no access-list access-list-number removes entire access list
remark option lets you add a description for the access list
Router(config)#access-list access-list-number {permit | deny | remark} source [mask]
Standard

CCNA 新版(英文)D20S06L02 来自淘豆网m.daumloan.com转载请标明出处.

非法内容举报中心
文档信息
  • 页数24
  • 收藏数0 收藏
  • 顶次数0
  • 上传人12345
  • 文件大小0 KB
  • 时间2014-08-29