Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Cisco Press CCNA ICND 2004 - Cisco Press.pdf
Скачиваний:
120
Добавлен:
24.05.2014
Размер:
13.19 Mб
Скачать

442 Chapter 12: IP Access Control List Security

ACL 101 looks a lot like ACL 101 from Example 12-6, but this time, the ACL does not bother checking for the criteria to match Larry’s traffic, because Larry’s traffic will never enter R3’s Ethernet 0 interface. Because the ACL has been placed on R3, near Bob, it watches for packets Bob sends that enter its Ethernet0 interface. Because of the ACL, Bob’s FTP traffic to 172.16.1.0/24 is denied, with all other traffic entering R3’s E0 interface making it into the network. Example 12-7 does not show any logic for stopping Larry’s traffic.

Extended IP Access Lists: Example 2

Example 12-8, based on the network shown in Figure 12-6, shows another example of how to use extended IP access lists. This example uses the same criteria and network topology as the second standard IP ACL example, as repeated here:

Sam is not allowed access to Bugs or Daffy.

Hosts on the Seville Ethernet are not allowed access to hosts on the Yosemite Ethernet.

All other combinations are allowed.

Figure 12-6 Network Diagram for Extended Access List Example 2

Bugs Daffy

10.1.1.110.1.1.2

Subnet 10.1.1.0

 

E0

 

 

Albuquerque

s0

s1

 

 

 

.128

.0

 

 

.1

 

 

10

 

 

Subnet

 

 

 

 

 

 

 

s0

Subnet

10

. 1 .

130

. 0

s0

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Subnet 10.1.129.0

 

 

 

 

 

 

 

 

 

 

 

 

Yosemite

 

 

 

 

 

s1

s1

 

 

Seville

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

E0

E0

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Subnet 10.1.2.0

 

 

 

 

 

Subnet 10.1.3.0

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Sam

Emma

Elmer

Red

10.1.2.1

10.1.2.2

10.1.3.1

10.1.3.2