IPv4
Cisco / , 2016. .
Cisco. 1 11
. IPv4
IP-
1.
.
.
2.
IP-.
.
.
OSPF R1, ISP R3.
.
3. ACL
ACL-
, ACL-.
, ACL-.
4. ACL-
ACL-.
ACL-.
Cisco / , 2016. .
Cisco. 2 11
. IPv4
/
IP-
.
.
,
R1 R3.
LAN, R1 R3,
. ISP, R1 R3, ACL-
. ISP,
.
. CCNA
Cisco 1941 (ISR) Cisco IOS 15.2(4) M3 (
universalk9). Cisco Catalyst 2960 Cisco IOS
15.0(2) ( lanbasek9). ,
Cisco IOS. Cisco IOS
, .
.
.
. ,
. , .
3 (Cisco 1941 Cisco IOS 15.2(4)M3
( ) ).
2 (Cisco 2960 Cisco IOS 15.0(2) ( lanbasek9)
).
2 (Windows 7, Vista XP , , Tera Term).
Cisco IOS .
Ethernet .
1:
.
1: .
2: .
2:
,
. .
2: .
a. .
Cisco / , 2016. .
Cisco. 3 11
. IPv4
b.
.
no ip domain-lookup
hostname R1
service password-encryption
enable secret class
banner motd #
Unauthorized access is strictly prohibited. #
Line con 0
password cisco
login
logging synchronous
line vty 0 4
password cisco
login
c. .
d. loopback .
e. IP- .
f. 128000 DCE.
g. Telnet.
h. .
3: ().
a. .
b.
.
no ip domain-lookup
service password-encryption
enable secret class
banner motd #
Unauthorized access is strictly prohibited. #
Line con 0
password cisco
login
logging synchronous
line vty 0 15
password cisco
login
exit
c. .
d. IP-
.
e. .
Cisco / , 2016. .
Cisco. 4 11
. IPv4
f. Telnet.
g. .
5: .
. !
.
a. PC-A - PC-C loopback R3.
-? yes
_______
b. R1 - PC-C loopback-
R3. -? _______
yes
c. PC- - PC- loopback R1.
-? _______
yes
d. R3 - PC- loopback R1.
-? _______
yes
3: ACL-
ACL-
1: ACL-.
ACL- , .
ACL-
. ACL-,
192.168.10.0/24 192.168.20.0/24
192.168.30.0/24. ACL-
deny any (ACE),
ACL-.
Cisco / , 2016. .
Cisco. 5 11
. IPv4
, 192.168.10.0/24
192.168.30.0/24?
______________________________________________________________________________
0.0.0.255
Cisco, ACL-?
___________
R3
? ?
_______________________________________________________________________________________
s0/1.fififififififififi fifififi fifi R1 fifififififififififi fi 192.168.40.0/24
a. ACL- R3. 1.
R3(config)# access-list 1 remark Allow R1 LANs Access
R3(config)# access-list 1 permit 192.168.10.0 0.0.0.255
R3(config)# access-list 1 permit 192.168.20.0 0.0.0.255
R3(config)# access-list 1 deny any
b. ACL- .
R3(config)# interface g0/1
R3(config-if)# ip access-group 1 out
c. ACL-.
show ACL
.
1
ACE?
____________________________________________________________________________________
R3# show access-lists 1 or R3# show access-lists
, ,
?
____________________________________________________________________________________
R3# show ip interface g0/1 or R3# show ip interface
1) R3 show access-lists 1.
R3# show access-list 1
Standard IP access list 1
10 permit 192.168.10.0, wildcard bits 0.0.0.255
20 permit 192.168.20.0, wildcard bits 0.0.0.255
30 deny any
2) R3 show ip interface g0/1.
R3# show ip interface g0/1
GigabitEthernet0/1 is up, line protocol is up
Internet address is 192.168.30.1/24
Broadcast address is 255.255.255.255
Address determined by non-volatile memory
MTU is 1500 bytes
Helper address is not set
Directed broadcast forwarding is disabled
Multicast reserved groups joined: 224.0.0.10
Outgoing access list is 1
Inbound access list is not set
Cisco / , 2016. .
Cisco. 6 11
. IPv4
2: ACL-.
ACL-, :
192.168.40.0/24
192.168.10.0/24. , 192.168.10.0/24 PC-
C. BRANCH-OFFICE-POLICY.
Cisco, ACL-?
___________
R1
? ?
_______________________________________________________________________________________
G0/1,acl fifififififi fifififififififififi fififi.
Cisco / , 2016. .
Cisco. 7 11
. IPv4
Cisco / , 2016. .
Cisco. 8 11
. IPv4
G0/1 R3 . - IP-
PC-A. ? _______
NO
5) , ACL- 192.168.40.0/24 192.168.10.0/24.
- loopback- 0
R3 . - IP- PC-A.
? _______
YES
4: ACL-
. ACL-
. 4
.
, 209.165.200.224/27
192.168.10.0/24. , ACL-
. ACL-
ACE deny any. ACL- BRANCH-OFFICE-POLICY.
ACL .
:
1: no access-list standard BRANCH-OFFICE-POLICY
. ACL- . IOS
, : ,
; , ip access-group
G0/1 , . , ACL-
, ACL-
.
2: ACL- , , ACL-
. , ACL- .
ACL- .
ACL .
. 2.
Step 2: ACL-.
a. R1 EXEC show access-lists.
R1# show access-lists
Standard IP access list BRANCH-OFFICE-POLICY
10 permit 192.168.30.3 (8 matches)
20 permit 192.168.40.0, wildcard bits 0.0.0.255 (5 matches)
b. ACL-.
ACL- BRANCH-OFFICE-POLICY.
R1#(config)# ip access-list standard BRANCH-OFFICE-POLICY
R1(config-std-nacl)# 30 permit 209.165.200.224 0.0.0.31
R1(config-std-nacl)# 40 deny any
R1(config-std-nacl)# end
c. ACL-.
1) R1 show access-lists.
R1# show access-lists
Standard IP access list BRANCH-OFFICE-POLICY
Cisco / , 2016. .
Cisco. 9 11
. IPv4
1. , ACL- .
ACL?
_______________________________________________________________________________________
fififififififififififi fifififififi fififififififififififi fifififififififi fififififi fifififififi fififififi fifififififi fififififififififi fifi
fififififififififi fififififififi.
_______________________________________________________________________________________
fififi fififififififififi fifi fififififififi(fififififififififi fi fififififififi).fififififififififififi fifififififi fifififififififififi
fifififififififi.
_______________________________________________________________________________________
_______________________________________________________________________________________
2. ACL-
, ACL-.
ACL-, ?
_______________________________________________________________________________________
fi fififififififi fifififififi fifififififififififi fifififififififi fifififififififififi fififififi fi acl ,fififi fififififififififififififififi fifififi
fififififi.
_______________________________________________________________________________________
_______________________________________________________________________________________
_______________________________________________________________________________________
Cisco / , 2016. .
Cisco. 10 11
. IPv4
Ethernet 1 Ethernet 2 1 2
1800 Fast Ethernet 0/0 Fast Ethernet 0/1 Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
(F0/0) (F0/1)
1900 Gigabit Ethernet Gigabit Ethernet Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
0/0 (G0/0) 0/1 (G0/1)
2801 Fast Ethernet 0/0 Fast Ethernet 0/1 Serial 0/1/0 (S0/1/0) Serial 0/1/1 (S0/1/1)
(F0/0) (F0/1)
2811 Fast Ethernet 0/0 Fast Ethernet 0/1 Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
(F0/0) (F0/1)
2900 Gigabit Ethernet Gigabit Ethernet Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
0/0 (G0/0) 0/1 (G0/1)
. ,
.
.
Ethernet .
,
. ISDN BRI.
, Cisco IOS
.
Cisco / , 2016. .
Cisco. 11 11