ãã 1 ã€èšãå¿ããŠããã®ã¯ãACL ã¯èš±å¯/æåŠããŒã¹ã§ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããã ãã§ãªããããã«å€ãã®æ©èœãå®è¡ããããšã§ãã ããšãã°ãACL 㯠VPN ãã©ãã£ãã¯ã®æå·åã«äœ¿çšãããŸãããCCNA è©Šéšã«åæ Œããã«ã¯ãACL ããã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ã«ã©ã®ããã«äœ¿çšãããããç¥ãã ãã§æžã¿ãŸãã åé¡ XNUMX ã«æ»ããŸãããã
次㮠ACL ãªã¹ãã䜿çšãããšãçµçéšéãšå¶æ¥éšéã®ãã©ãã£ãã¯ã R2 åºåã€ã³ã¿ãŒãã§ã€ã¹ã§ãããã¯ã§ããããšãããããŸããã
ãã®ãªã¹ãã®åœ¢åŒã«ã€ããŠã¯å¿é
ããå¿
èŠã¯ãããŸãããããã¯ãACL ãäœã§ããããç解ããã®ã«åœ¹ç«ã€äŸãšããŠæäŸãããŠããã ãã§ãã Packet Tracer ã䜿ãå§ãããšãæ£ãã圢åŒãåŸãããŸãã
ã¿ã¹ã¯ 2 ã¯æ¬¡ã®ããã«ãªããŸãããµãŒã㌠ã«ãŒã ã¯ã管çéšéã®ãã¹ããé€ããã¹ãŠã®ãã¹ããšéä¿¡ã§ããŸãã ã€ãŸãããµãŒã㌠ã«ãŒã ã®ã³ã³ãã¥ãŒã¿ã¯ã販売éšéãšçµçéšéã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ã«ã¢ã¯ã»ã¹ã§ããŸããã管çéšéã®ã³ã³ãã¥ãŒã¿ã«ã¯ã¢ã¯ã»ã¹ã§ããŸããã ããã¯ããµãŒã㌠ã«ãŒã ã® IT ã¹ã¿ããã管çéšéã®è²¬ä»»è
ã®ã³ã³ãã¥ãŒã¿ã«ãªã¢ãŒã ã¢ã¯ã»ã¹ã§ããªãããã«ããåé¡ãçºçããå Žåã«ã¯ç®¡çéšéã®è²¬ä»»è
ã®ãªãã£ã¹ã«æ¥ãŠããã®å Žã§åé¡ã解決ããããšãæå³ããŸãã ãµãŒã㌠ã«ãŒã ããããã¯ãŒã¯ãä»ããŠç®¡çéšéãšéä¿¡ã§ããªãçç±ãããããªãããããã®ã¿ã¹ã¯ã¯çŸå®çã§ã¯ãªãããšã«æ³šæããŠãã ããããã®å Žåããã¥ãŒããªã¢ã«ã®äŸãèŠãŠããã ãã§ãã
ãã®åé¡ã解決ããã«ã¯ããŸããã©ãã£ã㯠ãã¹ã決å®ããå¿ èŠããããŸãã ãµãŒããŒã«ãŒã ããã®ããŒã¿ã¯ã«ãŒã¿R0ã®å ¥åã€ã³ã¿ãŒãã§ãŒã¹G1/1ã«å°çããåºåã€ã³ã¿ãŒãã§ãŒã¹G0/0ãä»ããŠç®¡çéšéã«éä¿¡ãããŸãã
Deny 192.168.1.192/27 æ¡ä»¶ãå
¥åã€ã³ã¿ãŒãã§ã€ã¹ G0/1 ã«é©çšãããšããåç¥ã®ãšãããæšæº ACL ããã©ãã£ã㯠ãœãŒã¹ã®è¿ãã«é
眮ãããå¶æ¥éšéãäŒèšéšéãžã®ãã©ãã£ãã¯ãå«ããã¹ãŠã®ãã©ãã£ãã¯ããããã¯ãããŸãã
管çéšéå®ãŠã®ãã©ãã£ãã¯ã®ã¿ããããã¯ããããããåºåã€ã³ã¿ãŒãã§ã€ã¹ G0/0 ã« ACL ãé©çšããå¿
èŠããããŸãã ãã®åé¡ã¯ãACL ãå®å
ã®è¿ãã«é
眮ããããšã«ãã£ãŠã®ã¿è§£æ±ºã§ããŸãã åæã«ãçµçéšéãšå¶æ¥éšéã®ãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ã¯ç®¡çéšéã«èªç±ã«å°éããå¿
èŠãããããããªã¹ãã®æåŸã®è¡ã¯ãPermit anyãã³ãã³ãã«ãªããåã®æ¡ä»¶ã§æå®ããããã©ãã£ãã¯ãé€ããã¹ãŠã®ãã©ãã£ãã¯ãèš±å¯ããŸãã
ã¿ã¹ã¯ 3 ã«é²ã¿ãŸããããå¶æ¥éšéã® Laptop 3 ã©ãããããã¯ãå¶æ¥éšéã®ããŒã«ã« ãããã¯ãŒã¯äžã«ããããã€ã¹ä»¥å€ã®ããã€ã¹ã«ã¢ã¯ã»ã¹ã§ããŸããã ç ä¿®çããã®ã³ã³ãã¥ãŒã¿ã§äœæ¥ããŠãããLAN ãè¶
ããŠã¯ãããªããšä»®å®ããŸãããã
ãã®å Žåãã«ãŒã¿ R0 ã®å
¥åã€ã³ã¿ãŒãã§ã€ã¹ G1/2 ã« ACL ãé©çšããå¿
èŠããããŸãã ãã®ã³ã³ãã¥ãŒã¿ã« IP ã¢ãã¬ã¹ 192.168.1.3/25 ãå²ãåœãŠãå Žåã192.168.1.3/25 ã®æåŠæ¡ä»¶ãæºããããå¿
èŠããããä»ã® IP ã¢ãã¬ã¹ããã®ãã©ãã£ãã¯ããããã¯ãããŠã¯ãããªãããããªã¹ãã®æåŸã®è¡ã¯èš±å¯ã«ãªããŸããã©ãã§ãã
ãã ãããã©ãã£ãã¯ããããã¯ããŠã Laptop2 ã«ã¯åœ±é¿ããããŸããã
次ã®ã¿ã¹ã¯ã¯ã¿ã¹ã¯ No. 4 ã§ãã財åéšéã®ã³ã³ãã¥ãŒã¿ PC0 ã®ã¿ããµãŒã㌠ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããŸããã管çéšéã¯ã¢ã¯ã»ã¹ã§ããŸããã
èŠããŠãããšæããŸãããã¿ã¹ã¯ #1 ã® ACL ã¯ã«ãŒã¿ãŒ R0 ã® S1/0/2 ã€ã³ã¿ãŒãã§ã€ã¹äžã®ãã¹ãŠã®éä¿¡ãã©ãã£ãã¯ããããã¯ããŸãããã¿ã¹ã¯ #4 ã§ã¯ PC0 ãã©ãã£ãã¯ã®ã¿ãééããããã«ããå¿
èŠããããããäŸå€ãäœæããå¿
èŠããããšè¿°ã¹ãŠããŸãã
çŸåšè§£æ±ºããŠãããã¹ãŠã®ã¿ã¹ã¯ã¯ãå®éã®ç¶æ³ã§ãªãã£ã¹ ãããã¯ãŒã¯ã« ACL ãèšå®ããéã«åœ¹ç«ã€ã¯ãã§ãã 䟿å®äžãå€å
žçãªã¿ã€ãã®ãšã³ããªã䜿çšããŸãããããã¹ãŠã®è¡ãçŽã«ææžããããããšã³ããªãä¿®æ£ã§ããããã«ã³ã³ãã¥ãŒã¿ã«å
¥åããããšããå§ãããŸãã ä»åã®å Žåãã¿ã¹ã¯ No. 1 ã®æ¡ä»¶ã«åŸã£ãŠãã¯ã©ã·ã㯠ACL ãªã¹ããäœæãããŸããã Permit ã¿ã€ãã® PC0 ã«äŸå€ãè¿œå ãããå Žåã®å Žåããã®è¡ã¯ãªã¹ãã® 0 çªç®ãPermit Any è¡ã®åŸã«ã®ã¿é
眮ã§ããŸãã ãã ãããã®ã³ã³ãã¥ãŒã¿ã®ã¢ãã¬ã¹ã¯æåŠæ¡ä»¶ 192.168.1.128/26 ããã§ãã¯ããããã®ã¢ãã¬ã¹ç¯å²ã«å«ãŸããŠããããããã®æ¡ä»¶ãæºããããçŽåŸã«ãã®ãã©ãã£ãã¯ã¯ãããã¯ãããã«ãŒã¿ã¯ XNUMX è¡ç®ã®ãã§ãã¯ã«å°éããªãã ãã§ããã® IP ã¢ãã¬ã¹ããã®ãã©ãã£ãã¯ã
ãããã£ãŠãã¿ã¹ã¯ No. 1 ã® ACL ãªã¹ããå®å
šã«ããçŽãå¿
èŠããããŸããæåã®è¡ãåé€ããŠãPC192.168.1.130 ããã®ãã©ãã£ãã¯ãèš±å¯ããè¡ Permit 26/0 ã«çœ®ãæããŠããããã¹ãŠã®ãã©ãã£ãã¯ãçŠæ¢ããè¡ãå床å
¥åããå¿
èŠããããŸããçµçéšéãšå¶æ¥éšéããã
ãããã£ãŠãæåã®è¡ã«ã¯ç¹å®ã®ã¢ãã¬ã¹ã«å¯Ÿããã³ãã³ããããã192.168.1.130 è¡ç®ã«ã¯ãã®ã¢ãã¬ã¹ãååšãããããã¯ãŒã¯å
šäœã«å¯Ÿããäžè¬çãªã³ãã³ãããããŸãã ææ°ã®ã¿ã€ãã® ACL ã䜿çšããŠããå Žåã¯ãæåã®ã³ãã³ããšããŠè¡ Permit 26/XNUMX ãé
眮ããããšã§ãACL ãç°¡åã«å€æŽã§ããŸãã ã¯ã©ã·ã㯠ACL ãããå Žåã¯ããããå®å
šã«åé€ããŠãããæ£ããé åºã§ã³ãã³ããåå
¥åããå¿
èŠããããŸãã
åé¡ 4 ã®è§£æ±ºçã¯ãåé¡ 192.168.1.130 ã® ACL ã®å é ã«è¡ Permit 26/1 ãé 眮ããããšã§ãããã®å Žåã«éããPC0 ããã®ãã©ãã£ãã¯ãã«ãŒã¿ R2 ã®åºåã€ã³ã¿ãŒãã§ã€ã¹ããèªç±ã«åºåãããããã§ãã PC1 ã® IP ã¢ãã¬ã¹ã¯ãªã¹ãã® XNUMX è¡ç®ã«å«ãŸããçŠæ¢ã®å¯Ÿè±¡ãšãªããããPCXNUMX ã®ãã©ãã£ãã¯ã¯å®å šã«ãããã¯ãããŸãã
次ã«ãPacket Tracer ã«é²ã¿ãå¿ èŠãªèšå®ãè¡ããŸãã åã®ç°¡ç¥åãããå³ã¯å°ããããã«ããã£ãã®ã§ããã¹ãŠã®ããã€ã¹ã® IP ã¢ãã¬ã¹ããã§ã«æ§æããŸããã ããã«ã4 å°ã®ã«ãŒã¿ãŒéã« RIP ãèšå®ããŸããã æå®ããããããã¯ãŒã¯ ããããžã§ã¯ãXNUMX ã€ã®ãµããããã®ãã¹ãŠã®ããã€ã¹éã®éä¿¡ãå¶éãªãå¯èœã§ãã ãã ããACL ãé©çšãããšããã«ããã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ãéå§ãããŸãã
ãŸãã¯è²¡åéšéã® PC1 ããå§ããŠããµãŒã㌠ã«ãŒã ã«ãã Server192.168.1.194 ã«å±ãã IP ã¢ãã¬ã¹ 0 ã« ping ãå®è¡ããŠã¿ãŸãã ã芧ã®ãšãããping ã¯åé¡ãªãæåããŸãã 管çéšéãã Laptop0 ãžã® ping ãæåããŸããã æåã®ãã±ãã㯠ARP ã«ããç Žæ£ãããæ®ãã® 3 ã€ã¯èªç±ã« ping ãããŸãã
ãã©ãã£ã㯠ãã£ã«ã¿ãªã³ã°ãæŽçããããã«ãR2 ã«ãŒã¿ãŒã®èšå®ã«ç§»åããã°ããŒãã« ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ ã¢ãŒããã¢ã¯ãã£ãã«ããŠãææ°ã® ACL ãªã¹ããäœæããŸãã ã¯ã©ã·ãã¯ãªå€èŠ³ã® ACL 10 ããããŸãã æåã®ãªã¹ããäœæããã«ã¯ãçŽã«æžãçããã®ãšåããªã¹ãåãæå®ããå¿
èŠãããã³ãã³ããip access-list standard ACL Secure_Ma_And_Seããå
¥åããŸãã ãã®åŸãã·ã¹ãã ã¯å¯èœãªãã©ã¡ãŒã¿ã®å
¥åãæ±ããŸããæåŠãçµäºãããããèš±å¯ããŸãã¯ã³ã¡ã³ããéžæãã1 ïœ 2147483647 ã®ã·ãŒã±ã³ã¹çªå·ãå
¥åããããšãã§ããŸãããããè¡ããªããšãã·ã¹ãã ãèªåçã«å²ãåœãŠãŸãã
ãããã£ãŠããã®èš±å¯ã¯ç¹å®ã® PC192.168.1.130 ããã€ã¹ã«å¯ŸããŠæå¹ã§ããããããã®çªå·ãå
¥åããã«ãããã«èš±å¯ãã¹ã 0 ã³ãã³ãã«é²ã¿ãŸãã éã®ã¯ã€ã«ãã«ãŒã ãã¹ã¯ã䜿çšããããšãã§ããŸãããã®æ¹æ³ã次ã«ç€ºããŸãã
次ã«ãã³ãã³ããdeny 192.168.1.128ããå ¥åããŸãã /26 ãããã®ã§ãéãã¹ã¯ã䜿çšããŠã³ãã³ããè£è¶³ããŸã:deny 192.168.1.128 0.0.0.63ã ãããã£ãŠããããã¯ãŒã¯ 192.168.1.128/26 ãžã®ãã©ãã£ãã¯ãæåŠããŸãã
åæ§ã«ããããã¯ãŒã¯ãdeny 192.168.1.0 0.0.0.127ãããã®ãã©ãã£ãã¯ããããã¯ããŸãã ä»ã®ãã©ãã£ãã¯ã¯ãã¹ãŠèš±å¯ãããã®ã§ãã³ãã³ããpermit anyããå ¥åããŸãã 次ã«ããã®ãªã¹ããã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšããå¿ èŠããããããã³ãã³ã int s0/1/0 ã䜿çšããŸãã 次ã«ããip access-group Secure_Ma_And_Seããšå ¥åãããšãã·ã¹ãã ã¯ã€ã³ã¿ãŒãã§ãŒã¹ (åä¿¡ãã±ããã®å Žå㯠inãéä¿¡ãã±ããã®å Žå㯠out) ãéžæããããã«æ±ããŸãã ACL ãåºåã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšããå¿ èŠããããããip access-group Secure_Ma_And_Se out ã³ãã³ãã䜿çšããŸãã
PC0 ã³ãã³ã ã©ã€ã³ã«ç§»åããServer192.168.1.194 ãµãŒããŒã«å±ãã IP ã¢ãã¬ã¹ 0 ã« ping ãå®è¡ããŠã¿ãŸãããã PC0 ãã©ãã£ãã¯ã«ç¹å¥ãª ACL æ¡ä»¶ã䜿çšãããããping ã¯æåããŸãã PC1 ããåãããšãè¡ããšãäŒèšéšéã®æ®ãã® IP ã¢ãã¬ã¹ããã®ãã©ãã£ãã¯ããµãŒã㌠ã«ãŒã ãžã®ã¢ã¯ã»ã¹ããããã¯ããããããã·ã¹ãã ã¯ãå®å ãã¹ããå©çšã§ããŸããããšãããšã©ãŒãçæããŸãã
R2 ã«ãŒã¿ã® CLI ã«ãã°ã€ã³ããshow ip address-lists ã³ãã³ããå ¥åãããšã財åéšéã®ãããã¯ãŒã¯ ãã©ãã£ãã¯ãã©ã®ããã«ã«ãŒãã£ã³ã°ããããã確èªã§ããŸããèš±å¯ã«åŸã£ãŠ ping ãééããåæ°ãšããã®åæ°ã衚瀺ãããŸããçŠæ¢äºé ã«åŸããããã¯ãããŠããã ããŸãã
ãã€ã§ãã«ãŒã¿ãŒèšå®ã«ã¢ã¯ã»ã¹ããŠãã¢ã¯ã»ã¹ ãªã¹ãã確èªã§ããŸãã ãããã£ãŠãã¿ã¹ã¯No.1ãšã¿ã¹ã¯No.4ã®æ¡ä»¶ãæºããããŸãã ããäžã€ãèŠãããŸãããã äœããä¿®æ£ãããå Žåã¯ãR2 èšå®ã®ã°ããŒãã« ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ ã¢ãŒãã«ç§»åããã³ãã³ã ip access-list standard Secure_Ma_And_Se ãå
¥åããŠãããã³ãã³ããhost 192.168.1.130 is not allowedãïŒãã¹ã 192.168.1.130 ãèš±å¯ããŸããïŒãå
¥åããŸãã
ã¢ã¯ã»ã¹ ãªã¹ããããäžåºŠèŠããšã10 è¡ç®ãæ¶ããŠããã20,30ã40ãXNUMX è¡ã ããæ®ã£ãŠããããšãããããŸãããããã£ãŠãã«ãŒã¿ã®èšå®ã§ ACL ã¢ã¯ã»ã¹ ãªã¹ããç·šéã§ããŸããããããã³ã³ãã€ã«ãããŠããªãå Žåã«éããŸããå€å
žçãªåœ¢ã§ã
ãã㧠2 çªç®ã® ACL ã«é²ã¿ãŸãããããã㯠R3 ã«ãŒã¿ãŒã«ãé¢ä¿ããããã§ãã Laptop2 ããã®ãã©ãã£ãã¯ã¯å¶æ¥éšéã®ãããã¯ãŒã¯ããåºãŠã¯ãããªããšèšèŒãããŠããŸãã ãã®å ŽåãLaptop192.168.1.130 ã¯è²¡åéšéã®ã³ã³ãã¥ãŒã¿ãšåé¡ãªãéä¿¡ã§ããã¯ãã§ãã ããããã¹ãããããã«ããã®ã©ããããããã IP ã¢ãã¬ã¹ XNUMX ã« ping ãå®è¡ãããã¹ãŠãæ©èœããããšã確èªããŸãã
ããã§ãLaptop3 ã®ã³ãã³ã ã©ã€ã³ã«ç§»åããã¢ãã¬ã¹ 192.168.1.130 ã« ping ãéä¿¡ããŸãã ping ã¯æåããŸãããã¿ã¹ã¯ã®æ¡ä»¶ã«åŸã£ãŠãLaptop3 ã¯åãå¶æ¥éšéã®ãããã¯ãŒã¯å ã«ãã Laptop2 ãšã®ã¿éä¿¡ã§ãããããping ã¯å¿ èŠãããŸããã ãããè¡ãã«ã¯ãåŸæ¥ã®æ¹æ³ã䜿çšããŠå¥ã® ACL ãäœæããå¿ èŠããããŸãã
R2 èšå®ã«æ»ããpermit host 10 ã³ãã³ãã䜿çšããŠãåé€ããããšã³ã㪠192.168.1.130 ã埩å ããŠã¿ãŸãã ãã®ãšã³ããªããªã¹ãã®æåŸã50 çªã«è¡šç€ºãããŠããããšãããããŸãããã ããç¹å®ã®ãã¹ããèš±å¯ããè¡ããªã¹ãã®æåŸã«ããããã¹ãŠã®ãããã¯ãŒã¯ ãã©ãã£ãã¯ãçŠæ¢ããè¡ãäžçªäžã«ãããããã¢ã¯ã»ã¹ã¯ãŸã æ©èœããŸããããªã¹ãã®ã PC0 ãã管çéšéã® Laptop0 ã« ping ãå®è¡ããããšãããšãACL ã® 50 çªã«èš±å¯ãšã³ããªãããã«ããããããããå®å ãã¹ãã«ã¢ã¯ã»ã¹ã§ããŸããããšããã¡ãã»ãŒãžã衚瀺ãããŸãã
ãããã£ãŠãæ¢åã® ACL ãç·šéããå Žåã¯ãR2 ã¢ãŒã (config-std-nacl) ã§ã³ãã³ã nopermit host 192.168.1.130 ãå ¥åããè¡ 50 ããªã¹ãããæ¶ããŠããããšã確èªããŠãã³ãã³ã 10permit ãå ¥åããå¿ èŠããããŸãããã¹ã 192.168.1.130ã ãªã¹ããå ã®åœ¢åŒã«æ»ãããã®ãšã³ããªã XNUMX äœã«ãªã£ãŠããããšãããããŸãã ã·ãŒã±ã³ã¹çªå·ã¯ã©ã®ãããªåœ¢åŒã§ããªã¹ãã®ç·šéã«åœ¹ç«ã€ãããææ°åœ¢åŒã® ACL ã¯åŸæ¥ã®åœ¢åŒãããã¯ããã«äŸ¿å©ã§ãã
次ã«ãACL 10 ãªã¹ãã®å€å
žçãªåœ¢åŒãã©ã®ããã«æ©èœãããã瀺ããŸããå€å
žçãªãªã¹ãã䜿çšããã«ã¯ãã³ãã³ã accessâlist 10? ãå
¥åããããã³ããã«ç¶ããŠãç®çã®ã¢ã¯ã·ã§ã³ (æåŠãèš±å¯ããŸãã¯ã³ã¡ã³ã) ãéžæããå¿
èŠããããŸãã 次ã«ããaccess-list 10deny hostããšããè¡ãå
¥åãããã®åŸã³ãã³ããaccess-list 10deny 192.168.1.3ããå
¥åããŠãéãã¹ã¯ãè¿œå ããŸãã ãã¹ããããã®ã§ãé æ¹åã®ãµãããã ãã¹ã¯ã¯ 255.255.255.255ãéæ¹åã®ãµãããã ãã¹ã¯ã¯ 0.0.0.0 ã§ãã ãã®çµæããã¹ã ãã©ãã£ãã¯ãæåŠããã«ã¯ãã³ãã³ã accessâlist 10deny 192.168.1.3 0.0.0.0 ãå
¥åããå¿
èŠããããŸãã ãã®åŸãã¢ã¯ã»ã¹èš±å¯ãæå®ããå¿
èŠããããŸãããã®ããã«ã¯ãã³ãã³ã accessâlist 10permit any ãå
¥åããŸãã ãã®ãªã¹ãã¯ã«ãŒã¿ R0 ã® G1/2 ã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšããå¿
èŠããããããg0/1ãip access-group 10 ã«ã³ãã³ããé çªã«å
¥åããŸãã ã¯ã©ã·ãã¯ãŸãã¯ã¢ãã³ã®ã©ã¡ãã®ãªã¹ãã䜿çšããããã«é¢ä¿ãªããåãã³ãã³ãã䜿çšããŠãã®ãªã¹ããã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšããŸãã
èšå®ãæ£ãããã©ããã確èªããããã«ãLaptop3 ã³ãã³ã ã©ã€ã³ ã¿ãŒããã«ã«ç§»åããIP ã¢ãã¬ã¹ 192.168.1.130 ã« ping ãå®è¡ããŠã¿ãŸããã芧ã®ãšãããã·ã¹ãã ã¯å®å ãã¹ãã«å°éã§ããªããšå ±åããŸãã
ãªã¹ãã確èªããã«ã¯ãshow ip access-lists ã³ãã³ããš show access-lists ã³ãã³ãã®äž¡æ¹ã䜿çšã§ããããšãæãåºããŠãã ããã R1 ã«ãŒã¿ãŒã«é¢é£ãããã 192.168.1.192 ã€ã®åé¡ã解決ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããã®ã«ãŒã¿ã® CLI ã«ç§»åããã°ããŒãã« ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ ã¢ãŒãã«ç§»åããŠãã³ãã³ã ip access-list standard Secure_Ma_From_Se ãå ¥åããŸãã ãããã¯ãŒã¯ 27/255.255.255.224 ãããããããã®ãµãããã ãã¹ã¯ã¯ 0.0.0.31 ã«ãªããŸããã€ãŸãããªããŒã¹ ãã¹ã¯ã¯ 192.168.1.192 ãšãªããdeny 0.0.0.31 XNUMX ã³ãã³ããå ¥åããå¿ èŠããããŸãã ä»ã®ãã©ãã£ãã¯ã¯ãã¹ãŠèš±å¯ãããããããªã¹ãã¯ã³ãã³ãpermit anyã§çµãããŸãã ACL ãã«ãŒã¿ã®åºåã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšããã«ã¯ãip access-group Secure_Ma_From_Se out ã³ãã³ãã䜿çšããŸãã
ããã§ãServer0 ã®ã³ãã³ã ã©ã€ã³ ã¿ãŒããã«ã«ç§»åããIP ã¢ãã¬ã¹ 0 ã§ç®¡çéšéã® Laptop192.168.1.226 ã« ping ãå®è¡ããŠã¿ãŸãã è©Šã¿ã¯å€±æããŸããããã¢ãã¬ã¹ 192.168.1.130 ã« ping ãå®è¡ãããšãåé¡ãªãæ¥ç¶ã確ç«ãããŸãããã€ãŸãããµãŒã㌠ã³ã³ãã¥ãŒã¿ãŒãšç®¡çéšéãšã®éä¿¡ã¯çŠæ¢ãããŠããŸããããä»éšéã®ä»ã®ãã¹ãŠã®ããã€ã¹ãšã®éä¿¡ã¯èš±å¯ãããŠããŸããã ãããã£ãŠã4 ã€ã®åé¡ãã¹ãŠã解決ããããšãã§ããŸããã
ä»ã®ãã®ããèŠãããŸãããã R2 ã«ãŒã¿ãŒã®èšå®ã«å ¥ããŸããããã«ã¯ãã¯ã©ã·ãã¯ãšã¢ãã³ã® 2 çš®é¡ã® ACL ããããŸãã ACL 10ãæšæº IP ã¢ã¯ã»ã¹ ãªã¹ã 10 ãç·šéããããšããŸããããã¯ãåŸæ¥ã®åœ¢åŒã§ã¯ 10 ã€ã®ãšã³ã㪠20 ãš 4 ã§æ§æãããŸãã do show run ã³ãã³ãã䜿çšãããšãæåã« 10 ã€ã®ææ°ã®ã¢ã¯ã»ã¹ ãªã¹ããããããšãããããŸããäžè¬èŠåºã Secure_Ma_And_Se ã®äžã«çªå·ã®ãªããšã³ããªãããããã®äžã«ã¯ãåãã¢ã¯ã»ã¹ ãªã¹ã 10 ã®ååãç¹°ãè¿ãå€å žçãªåœ¢åŒã® XNUMX ã€ã® ACL XNUMX ãšã³ããªããããŸãã
æåŠãã¹ã 192.168.1.3 ãšã³ããªãåé€ããå¥ã®ãããã¯ãŒã¯äžã®ããã€ã¹ã®ãšã³ããªãå°å
¥ãããªã©ãããã€ãã®å€æŽãå ãããå Žåã¯ããã®ãšã³ããªã«å¯ŸããŠã®ã¿ delete ã³ãã³ãã䜿çšããå¿
èŠããããŸãã no access-list 10deny host 192.168.1.3 .10ã ãããããã®ã³ãã³ããå
¥åãããšããã«ããã¹ãŠã® ACL XNUMX ãšã³ããªãå®å
šã«æ¶ããŠããŸããããACL ã®ã¯ã©ã·ã㯠ãã¥ãŒã§ã¯ç·šéãéåžžã«äžäŸ¿ã§ãã ææ°ã®é²é³æ¹æ³ã¯èªç±ã«ç·šéã§ãããããéåžžã«äœ¿ãããããªã£ãŠããŸãã
ãã®ãã㪠ã¬ãã¹ã³ã®å 容ãåŠã¶ããã«ãããäžåºŠãããªãèŠãŠããã³ããªãã§è°è«ãããåé¡ãèªåã§è§£æ±ºããŠã¿ãããšããå§ãããŸãã ACL 㯠CCNA ã³ãŒã¹ã®éèŠãªãããã¯ã§ãããå€ãã®äººããããšãã°éã¯ã€ã«ãã«ãŒã ãã¹ã¯ã®äœææé ãªã©ã«æ··ä¹±ããŠããŸãã ãã¹ã¯å€æã®æŠå¿µãç解ããã ãã§ããã¹ãŠãã¯ããã«ç°¡åã«ãªãããšãä¿èšŒããŸãã CCNA ã³ãŒã¹ã®ãããã¯ãç解ããäžã§æãéèŠãªããšã¯å®è·µçãªãã¬ãŒãã³ã°ã§ããããšãå¿ããªãã§ãã ãããã·ã¹ã³ã®ããŸããŸãªæŠå¿µãç解ããã«ã¯ãå®è·µã®ã¿ã圹ç«ã€ããã§ãã ç·Žç¿ãšã¯ãç§ã®ããŒã ãã³ããŒïŒããŒã¹ãããããšã§ã¯ãªããèªåãªãã®æ¹æ³ã§åé¡ã解決ããããšã§ãã ããããããããžã®ãã©ãã£ãã¯ã®æµãããããã¯ããã«ã¯äœãããå¿ èŠãããããæ¡ä»¶ãã©ãã«é©çšããããªã©ãèªåèªèº«ã«è³ªåããŠãããã«çããŠã¿ãŠãã ããã
ãã€ãã宿æ³ããã ãããããšãããããŸãã ç§ãã¡ã®èšäºãæ°ã«å ¥ã£ãŠããŸãã? ãã£ãšèå³æ·±ãã³ã³ãã³ããèŠããã§ãã? 泚æããããå人ã«å§ãããããŠç§ãã¡ããµããŒãããŠãã ããã Habr ãŠãŒã¶ãŒã¯ãåœç€Ÿãããªãã®ããã«çºæããããšã³ããªãŒã¬ãã«ã®ãµãŒããŒã«äŒŒããŠããŒã¯ãªè£œåã 30% å²åŒã§ãå©çšããã ããŸãã
Dell R730xdã¯2åå®ãïŒ ããã ã
åºæïŒ habr.com