计算机网络/计算机科学与应用/系统/运维/开发

基本访问控制列表

Router>enable 

Router#

Router#

Router#

Router#conf t

Enter configuration commands, one per line.  End with CNTL/Z.

Router(config)#

Router(config)#

Router(config)#hostname R1

R1(config)#no ip doma

R1(config)#no ip domain-lo

R1(config)#no ip domain-lookup 

R1(config)#enable secret class

R1(config)#

R1(config)#line con 0

R1(config-line)#password cisco

R1(config-line)#exit

R1(config)#

R1(config)#inter

R1(config)#interface f

R1(config)#interface fastEthernet 0/0

R1(config-if)#ip addre

R1(config-if)#ip address 192.168.10.1 255.255.255.0

R1(config-if)#no shutdown

R1(config-if)#exit

R1(config)#inter

R1(config)#interface fa

R1(config)#interface fastEthernet 0/1

R1(config-if)#ip address 192.168.11.1 255.255.255.0

R1(config-if)#

R1(config-if)#no shutdown


R1(config-if)#

%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up


%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up


R1(config-if)#

R1(config-if)#

R1(config-if)#

R1(config-if)#ip address 192.168.10.1 255.255.255.0

R1(config-if)#no shutdown

R1(config-if)#

R1(config-if)#exit

R1(config)#

R1(config)#interface fastEthernet 0/0

R1(config-if)#ip address 192.168.10.1 255.255.255.0

% 192.168.10.0 overlaps with FastEthernet0/1

R1(config-if)#no shutdown

% 192.168.10.0 overlaps with FastEthernet0/1

FastEthernet0/0: incorrect IP address assignment

R1(config-if)#

R1(config-if)#

R1(config-if)#

R1(config-if)#exit

R1(config)#

R1(config)#

R1(config)#

R1(config)#interfa

R1(config)#interface fa

R1(config)#interface fastEthernet 0/0

R1(config-if)#ip address 192.168.10.1 255.255.255.0

% 192.168.10.0 overlaps with FastEthernet0/1

R1(config-if)#no shutdown

% 192.168.10.0 overlaps with FastEthernet0/1

FastEthernet0/0: incorrect IP address assignment

R1(config-if)#

R1(config-if)#

R1(config-if)#

R1(config-if)#exit

R1(config)#

R1(config)#interface fastEthernet 0/1

R1(config-if)#

R1(config-if)#ip address 192.168.11.1 255.255.255.0

R1(config-if)#

R1(config-if)#no shutdown

R1(config-if)#exit

R1(config)#

R1(config)#

R1(config)#inter

R1(config)#interface fa

R1(config)#interface fastEthernet 0/0

R1(config-if)#ip address 192.168.10.1 255.255.255.0

R1(config-if)#no shutdown


R1(config-if)#

%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up


%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up


R1(config-if)#no shutdown

R1(config-if)#exit

R1(config)#

R1(config)#

R1(config)#ip access-list extended extend-1

R1(config-ext-nacl)#

R1(config-ext-nacl)#deny ip 192.168.10.0 0.0.0.255 host 209.165.200.225

R1(config-ext-nacl)#permit ip any any

R1(config-ext-nacl)#exit

R1(config)#

R1(config)#

R1(config)#interfa

R1(config)#interface s

R1(config)#interface serial 0/0/0

R1(config-if)#clock rate 64000

R1(config-if)#ip acc

R1(config-if)#ip access-group extend-1 out

R1(config-if)#exit

R1(config)#show ip access-list

            ^

% Invalid input detected at '^' marker.

R1(config)#exit

R1#

%SYS-5-CONFIG_I: Configured from console by console


R1#show ip access-list

Extended IP access list extend-1

    10 deny ip 192.168.10.0 0.0.0.255 host 209.165.200.225

    20 permit ip any any

R1#

R1#

R1#

R1#

R1#conf t

Enter configuration commands, one per line.  End with CNTL/Z.

R1(config)#

R1(config)#

R1(config)#

R1(config)#ip access-list extended extend-1

R1(config-ext-nacl)#deny ip 192.168.10.0 0.0.0.255 host 209.165.200.225

R1(config-ext-nacl)#permit ip any any

R1(config-ext-nacl)#exit

R1(config)#

R1(config)#interface serial 0/0/0

R1(config-if)#ip access-group extend-1 out

R1(config-if)#

R1(config-if)#

R1(config-if)#

R1(config-if)#exit

R1(config)#

R1(config)#

R1(config)#inter

R1(config)#interface s

R1(config)#interface serial 0/0/0

R1(config-if)#ip address 10.1.1.1 255.255.255.252

R1(config-if)#no shutdown


%LINK-5-CHANGED: Interface Serial0/0/0, changed state to down

R1(config-if)#

R1(config-if)#

R1(config-if)#

R1(config-if)#

R1(config-if)#exit

R1(config)#exit

R1#

%SYS-5-CONFIG_I: Configured from console by console


R1#

R1#

R1#write

Building configuration...

[OK]

R1#


----------------------------

System Bootstrap, Version 12.3(8r)T8, RELEASE SOFTWARE (fc1)

Cisco 1841 (revision 5.0) with 114688K/16384K bytes of memory.


Readonly ROMMON initialized


Self decompressing the image :

######################### [OK]

              Restricted Rights Legend


Use, duplication, or disclosure by the Government is

subject to restrictions as set forth in subparagraph

(c) of the Commercial Computer Software - Restricted

Rights clause at FAR sec. 52.227-19 and subparagraph

(c) (1) (ii) of the Rights in Technical Data and Computer

Software clause at DFARS sec. 252.227-7013.


           cisco Systems, Inc.

           170 West Tasman Drive

           San Jose, California 95134-1706




Cisco IOS Software, 1841 Software (C1841-IPBASE-M), Version 12.3(14)T7, RELEASE SOFTWARE (fc2)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2006 by Cisco Systems, Inc.

Compiled Mon 15-May-06 14:54 by pt_team

Image text-base: 0x6007D180, data-base: 0x61400000


Port Statistics for unclassified packets is not turned on.

Cisco 1841 (revision 5.0) with 114688K/16384K bytes of memory.

Processor board ID FTX0947Z18E

M860 processor: part number 0, mask 49

2 FastEthernet/IEEE 802.3 interface(s)

4 Low-speed serial(sync/async) network interface(s)

191K bytes of NVRAM.

32768K bytes of ATA CompactFlash (Read/Write)

Cisco IOS Software, 1841 Software (C1841-IPBASE-M), Version 12.3(14)T7, RELEASE SOFTWARE (fc2)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2006 by Cisco Systems, Inc.

Compiled Mon 15-May-06 14:54 by pt_team


Press RETURN to get started!




Router>

Router>

Router>

Router>

Router>en

Router#

Router#

Router#conf t

Enter configuration commands, one per line.  End with CNTL/Z.

Router(config)#

Router(config)#

Router(config)#

Router(config)#hostname R2

R2(config)#

R2(config)#no ip do

R2(config)#no ip domain-lo

R2(config)#no ip domain-lookup 

R2(config)#ena

R2(config)#enable secret class

R2(config)#line con 0

R2(config-line)#password cisco

R2(config-line)#exit

R2(config)#

R2(config)#

R2(config)#

R2(config)#interfa

R2(config)#interface f

R2(config)#interface fastEthernet 0/0

R2(config-if)#ip address 192.168.20.1 255.255.255.0

R2(config-if)#no shutdown


R2(config-if)#

%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up


%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up


R2(config-if)#

R2(config-if)#exit

R2(config)#

R2(config)#inter

R2(config)#interface se

R2(config)#interface serial 0/0/0

R2(config-if)#ip address 10.1.1.2 255.255.255.252

R2(config-if)#no shutdown


R2(config-if)#

%LINK-5-CHANGED: Interface Serial0/0/0, changed state to up


R2(config-if)#

R2(config-if)#ex

%LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0/0, changed state to up

it

R2(config)#

R2(config)#exit

R2#

%SYS-5-CONFIG_I: Configured from console by console


R2#conf t

Enter configuration commands, one per line.  End with CNTL/Z.

R2(config)#

R2(config)#interfa

R2(config)#interface s

R2(config)#interface serial 0/0/1

R2(config-if)#ip address 10.2.2.1 255.255.255.252

R2(config-if)#no shutdown


%LINK-5-CHANGED: Interface Serial0/0/1, changed state to down

R2(config-if)#

R2(config-if)#

R2(config-if)#exit

R2(config)#

R2(config)#

R2(config)#interfa

R2(config)#interface s

R2(config)#interface serial 0/0/1

R2(config-if)#10.2.2.1 255.255.255.252

              ^

% Invalid input detected at '^' marker.

R2(config-if)#ip address 10.2.2.1 255.255.255.252

R2(config-if)#clock rate 64000

R2(config-if)#ip access-group extend-1 out

R2(config-if)#exit

R2(config)#

R2(config)#ip access-list standard Task-4

R2(config-std-nacl)#permit 10.2.2.0 0.0.0.3

R2(config-std-nacl)#permit 192.168.30.0 0.0.0.255

R2(config-std-nacl)#exit

R2(config)#

R2(config)#line vty 0 15

R2(config-line)#access-class Task-4 in

R2(config-line)#exit

R2(config)#


R2(config)#

R2(config)#

R2(config)#

R2(config)#

R2(config)#inter

R2(config)#interface lo

R2(config)#interface l

R2(config)#interface loopback 0/0

                              ^

% Invalid input detected at '^' marker.

R2(config)#interface loopback 0


R2(config-if)#

%LINK-5-CHANGED: Interface Loopback0, changed state to up


%LINEPROTO-5-UPDOWN: Line protocol on Interface Loopback0, changed state to up


R2(config-if)#exit

R2(config)#

R2(config)#int

R2(config)#interface Lo

R2(config)#interface Loopback 0

R2(config-if)#ip address 209.165.200.225 255.255.255.224

R2(config-if)#no shutdown

R2(config-if)#

R2(config-if)#


---------------------------

Router>en

Router#

Router#

Router#conf t

Enter configuration commands, one per line.  End with CNTL/Z.

Router(config)#

Router(config)#

Router(config)#

Router(config)#hostname R3

R3(config)#

R3(config)#

R3(config)#no ip domain-lo

R3(config)#no ip domain-lookup 

R3(config)#

R3(config)#enable secret class

R3(config)#

R3(config)#line con 0

R3(config-line)#password cisco

R3(config-line)#exit

R3(config)#

R3(config)#

R3(config)#

R3(config)#

R3(config)#inter

R3(config)#interface f

R3(config)#interface fastEthernet 0/0

R3(config-if)#ip ad

R3(config-if)#ip address 192.168.30.1 255.255.255.0

R3(config-if)#no shutdown


R3(config-if)#

%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up


%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up


R3(config-if)#exit

R3(config)#

R3(config)#int

R3(config)#interface s

R3(config)#interface serial 0/0/1

R3(config-if)#ip address 10.2.2.2 255.255.255.252

R3(config-if)#

R3(config-if)#no shutdown 


R3(config-if)#

%LINK-5-CHANGED: Interface Serial0/0/1, changed state to up


R3(config-if)#

R3(config-if)#

%LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0/1, changed state to up


R3(config-if)#

R3(config-if)#exit

R3(config)#

R3(config)#

R3(config)#ip access-list standard std-1

R3(config-std-nacl)#deny 192.168.11.0 0.0.0.255

R3(config-std-nacl)#permit any

R3(config-std-nacl)#exit

R3(config)#

R3(config)#interface serial 0/0/1

R3(config-if)#ip access-group std-1 in

R3(config-if)#

R3(config-if)#exit

R3(config)#exit

R3#

%SYS-5-CONFIG_I: Configured from console by console


R3#

R3#write

Building configuration...

[OK]

R3#

R3#

R3#



----------------------

S1

Switch>ena

Switch>enable 

Switch#

Switch#

Switch#conf t

Switch(config)#hostname S1

Switch(config)#int vlan 1

Switch(config-if)#ip ad

Switch(config-if)#ip address 192.168.10.2 255.255.255.0

Switch(config-if)#

Switch(config-if)#no shutdown 

----------------------

S2

Switch>ena

Switch>enable 

Switch#conf t

Enter configuration commands, one per line.  End with CNTL/Z.

Switch(config)#

Switch(config)#

Switch(config)#

Switch(config)#hostname S2

S2(config)#

S2(config)#int vlan 1

S2(config-if)#

S2(config-if)#ip address 192.168.11.2

% Incomplete command.

S2(config-if)#ip address 192.168.11.2 255.255.255.0

S2(config-if)#

S2(config-if)#no shutdown


S2(config-if)#

%LINK-5-CHANGED: Interface Vlan1, changed state to up


%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to up

no shutdown

S2(config-if)#

S2(config-if)#no shutdown

S2(config-if)#exit

S2(config)#exit

S2#

%SYS-5-CONFIG_I: Configured from console by console


S2#write

Building configuration...

[OK]

-------------

S3

Switch>ena

Switch>enable 

Switch#conf t

Enter configuration commands, one per line.  End with CNTL/Z.

Switch(config)#conf 

Switch(config)#conf t

Switch(config)#conf t

                ^

% Invalid input detected at '^' marker.

Switch(config)#

Switch(config)#

Switch(config)#hostname S3

S3(config)#

S3(config)#ip address 192.168.30.2 255.255.255.0

               ^

% Invalid input detected at '^' marker.

S3(config)#int vlan 1

S3(config-if)#

S3(config-if)#ip address 192.168.30.2 255.255.255.0

S3(config-if)#no shutdown


S3(config-if)#

%LINK-5-CHANGED: Interface Vlan1, changed state to up


%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to up


S3(config-if)#no shutdown

S3(config-if)#exit

S3(config)#

S3(config)#exit

S3#

%SYS-5-CONFIG_I: Configured from console by console


S3#write

Building configuration...

[OK]

S3#


整理参考:

https://blog.csdn.net/xtggbmdk/article/details/89212891

https://blog.csdn.net/weixin_44122062/article/details/109000078

https://www.cnblogs.com/fyy-hhzzj/p/8305683.html

https://tiku.baidu.com/web/view/906cb86cb94ae45c3b3567ec102de2bd9605de2f




知识是抵御一切灾祸的盾牌

评论

^