ã¯ããã«
ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒã¯ãäœããèš±å¯ãŸãã¯çŠæ¢ããããã¹ãåŒã®ã»ããã§ãã éåžžãACLã¯IPãã±ãããèš±å¯ãŸãã¯æåŠããŸããããšããããIPãã±ããã®å éšã調ã¹ããã±ããã¿ã€ããTCPããã³UDPããŒãã衚瀺ã§ããŸãã ACLã¯ãããŸããŸãªãããã¯ãŒã¯ãããã³ã«ïŒIPãIPXãAppleTalkãªã©ïŒã«ãååšããŸãã åºæ¬çã«ãã¢ã¯ã»ã¹ãªã¹ãã®äœ¿çšã¯ãã±ãããã£ã«ã¿ãªã³ã°ã®èŠ³ç¹ããèæ ®ãããŸããã€ãŸããã€ã³ã¿ãŒããããšãã©ã€ããŒããããã¯ãŒã¯ã®å¢çã«æ©åšããããäžèŠãªãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããå¿ èŠãããç¶æ³ã§ã¯ããã±ãããã£ã«ã¿ãªã³ã°ãå¿ èŠã§ãã
ACLãçä¿¡æ¹åã«é 眮ããåé·ã¿ã€ãã®ãã©ãã£ãã¯ããããã¯ããŸãã
çè«
ACLã®æ©èœã¯ãã©ãã£ãã¯ãåé¡ããããšã§ããACLãé©çšããå Žæã«å¿ããŠãæåã«ãã©ãã£ãã¯ããã§ãã¯ããããããäœããè¡ãå¿ èŠããããŸãã ACLã¯ã©ãã«ã§ãé©çšãããŸããäŸïŒ
- ã€ã³ã¿ãŒãã§ã€ã¹ïŒ ããããã£ã«ã¿ãªã³ã°
- Telnetåç·ïŒ ã«ãŒã¿ãŒã¢ã¯ã»ã¹å¶é
- VPNïŒ æå·åããå¿ èŠããããã©ãã£ãã¯
- QoSïŒ ã©ã®ãã©ãã£ãã¯ã«åªå é äœãä»ããå¿ èŠãããã
- NATïŒ å€æããã¢ãã¬ã¹
ããããã¹ãŠã®ã³ã³ããŒãã³ãã«ACLã䜿çšããã«ã¯ããããã®æ©èœãç解ããå¿ èŠããããŸãã ãããŠãäž»ã«ããããã£ã«ã¿ãªã³ã°ãæ±ããŸãã ãã±ãããã£ã«ã¿ãªã³ã°ã«é¢é£ããŠãACLã¯ã€ã³ã¿ãŒãã§ã€ã¹ã«é 眮ãããç¬ç«ããŠäœæãããŠãããã€ã³ã¿ãŒãã§ã€ã¹ã«ãã蟌ãŸããŸãã ã€ã³ã¿ãŒãã§ãŒã¹ã«åºå®ãããšããã«ãã«ãŒã¿ãŒã¯ãã©ãã£ãã¯ã®è¡šç€ºãéå§ããŸãã ã«ãŒã¿ãŒã¯ããã©ãã£ãã¯ãçä¿¡ããã³çºä¿¡ãšèŠãªããŸãã ã«ãŒã¿ãŒã«å ¥ããã©ãã£ãã¯ã¯ã€ã³ããŠã³ããšåŒã°ããã«ãŒã¿ãŒããåºããã©ãã£ãã¯ã¯ã¢ãŠãããŠã³ãã§ãã ãããã£ãŠãACLã¯çä¿¡æ¹åãŸãã¯çºä¿¡æ¹åã«é 眮ãããŸãã

ãã±ããããã©ã€ããŒããããã¯ãŒã¯ããã«ãŒã¿ãŒfa0 / 1ã®ã€ã³ã¿ãŒãã§ã€ã¹ã«å°çãããšãã«ãŒã¿ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã«ACLããããã©ããããã§ãã¯ããACLãããå Žåã¯ãã¢ã¯ã»ã¹ãªã¹ãã®ã«ãŒã«ã«åŸã£ãŠãåŒãèšè¿°ãããŠããæ£ç¢ºãªé åºã§åŠçãå®è¡ãããŸãïŒã¢ã¯ã»ã¹ãªã¹ããèš±å¯ããå ŽåïŒãã±ããããã®å Žåãã«ãŒã¿ãŒã¯fa0 / 0ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠãããã€ããŒã«ãã±ãããéä¿¡ããŸããã¢ã¯ã»ã¹ãªã¹ãããã±ããã®ééãèš±å¯ããªãå Žåããã±ããã¯ç Žæ£ãããŸãã ã¢ã¯ã»ã¹ãªã¹ãããªãå Žåããã±ããã¯å¶éãªãã§é£è¡ããŸãã ãã±ããããããã€ããŒã«éä¿¡ããåã«ãã«ãŒã¿ãŒã¯çºä¿¡ACLã®fa0 / 0ã€ã³ã¿ãŒãã§ã€ã¹ããã§ãã¯ããŸãã å®éã«ã¯ãACLã¯ã€ã³ããŠã³ããŸãã¯ã¢ãŠãããŠã³ããšããŠã€ã³ã¿ãŒãã§ãŒã¹ã«æ¥ç¶ã§ããŸãã ããšãã°ãã€ã³ã¿ãŒãããäžã®ãã¹ãŠã®ããŒãããããã¯ãŒã¯ã«ãã±ãããéä¿¡ããããšãçŠæ¢ããã«ãŒã«ãæã€ACLããããŸãã
ããã§ã¯ããã®ACLãã©ã®ã€ã³ã¿ãŒãã§ãŒã¹ã«ã¢ã¿ããããŸããïŒ ACLãçºä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ãšããŠfa0 / 1ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ã¿ãããããšãACLã¯æ©èœããŸãããããã¯å®å šã«çå®ã§ã¯ãããŸããã ãšã³ãŒèŠæ±ããã©ã€ããŒããããã¯ãŒã¯äžã®äžéšã®ãã¹ãã®ã«ãŒã¿ãŒã«å±ããfa0 / 0ã€ã³ã¿ãŒãã§ã€ã¹ã«ACLãååšãããã©ããã確èªããååšããªãå Žåãfa0 / 1ã€ã³ã¿ãŒãã§ã€ã¹ã確èªãããã®ã€ã³ã¿ãŒãã§ã€ã¹ã«ACLããããçºä¿¡ãšããŠèšå®ããããã¹ãŠãæ£ãããããã¯ãŒã¯ã«äŸµå ¥ããŸããããã«ãŒã¿ãŒã«ãã£ãŠç Žå£ãããŸãã ãã ããACLãçä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ãšããŠfa0 / 0ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ã¿ãããããšããã±ããã¯ã«ãŒã¿ãŒã«å°çãããšããã«ç Žæ£ãããŸãã ã«ãŒã¿ãŒã®ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ã®è² è·ãå°ãªããããåŸè ã®ãœãªã¥ãŒã·ã§ã³ã¯æ£ããã§ãã æ¡åŒµACLã¯ãœãŒã¹ã®ã§ããã ãè¿ãã«é 眮ããå¿ èŠããããŸãããæšæºã®ACLã¯ã§ããã ãã¬ã·ãŒãã®è¿ãã«é 眮ããå¿ èŠããããŸã ã ããã¯ããããã¯ãŒã¯ãä»ããŠãã±ãããç¡é§ã«ããªãããã«å¿ èŠã§ãã
ACLèªäœã¯ã èš±å¯ ïŒ deny ïŒãŸãã¯æåŠ ïŒdenyïŒãèšè¿°ãããããã¹ãåŒã®ã»ããã§ãããåŠçã¯åŒãæå®ãããé åºã§å³å¯ã«å®è¡ãããŸãã ãããã£ãŠããã±ãããã€ã³ã¿ãŒãã§ã€ã¹ã«å°çãããšãæåã®æ¡ä»¶ããã§ãã¯ãããæåã®æ¡ä»¶ããã±ããã«äžèŽããå Žåããã®åŠçã¯çµäºããŸãã ããã±ãŒãžã¯ç¶è¡ãããããç Žæ£ãããŸãã
ããã§ãã ãã±ãããæ¡ä»¶ã«äžèŽããå ŽåãåŠçãããŸãã ã æåã®æ¡ä»¶ãäžèŽããªãå Žåã2çªç®ã®æ¡ä»¶ãåŠçãããäžèŽããå ŽåãåŠçã¯åæ¢ããããã§ãªãå Žåã3çªç®ã®æ¡ä»¶ãåŠçããããã¹ãŠã®æ¡ä»¶ããã§ãã¯ããããŸã§ç¶ããŸãã äžèŽããæ¡ä»¶ããªãå Žåãããã±ãŒãžã¯åã«ç Žæ£ãããŸãã ãªã¹ãã®äž¡ç«¯ã«ã¯ãæé»ã®æåŠïŒãã¹ãŠã®ãã©ãã£ãã¯ãæåŠïŒããããŸãã æ§æãšã©ãŒãé »ç¹ã«çºçããããããããã®ã«ãŒã«ã«ã¯éåžžã«æ³šæããŠãã ããã
ACLã¯2ã€ã®ã¿ã€ãã«åããããŸãã
- æšæºïŒ éä¿¡å ã¢ãã¬ã¹ã®ã¿ããã§ãã¯ã§ããŸã
- æ¡åŒµïŒ éä¿¡å ã¢ãã¬ã¹ãšåä¿¡è ã¢ãã¬ã¹ããã§ãã¯ã§ããŸããIPã®å Žåããããã³ã«ã¿ã€ããšTCP / UDPããŒãã
ã¢ã¯ã»ã¹ãªã¹ãã¯ãçªå·ãŸãã¯èšå·åã§ç€ºãããŸãã ACLã¯ãããŸããŸãªãããã¯ãŒã¯ãããã³ã«ã«ã䜿çšãããŸãã 次ã«ãIPã䜿çšããŸãã ãããã¯ãã¢ã¯ã»ã¹ãªã¹ãã«çªå·ãä»ããŠæ¬¡ã®ããã«æå®ãããŸãã
- æšæºïŒ 1ãã99
- æ¡åŒµïŒ 100ãã199
æåACLãæšæºãšæ¡åŒµã«åãããŠããŸãã æšæºã®ãã®ãããã¯ããã«å€ããã§ãã¯ã§ããããšãæãåºããŠãã ããããã ãããœãŒã¹ã¢ãã¬ã¹ãã£ãŒã«ãã®ã¿ãèŠãæšæºã®ãã®ãšã¯ç°ãªããããã±ãŒãžå ãèŠãå¿ èŠããããããåäœãé ããªããŸãã ACLãäœæãããšããåã¢ã¯ã»ã¹ãªã¹ããšã³ããªã¯ãããã©ã«ãã§ã¯10ïŒ10ã20ã30ãªã©ïŒä»¥å ã®ã·ãªã¢ã«çªå·ã§èå¥ãããŸãã ãã®ãããç¹å®ã®ãšã³ããªãåé€ããŠå¥ã®ãšã³ããªããã®å Žæã«æ¿å ¥ã§ããŸããããã®æ©èœã¯Cisco IOS 12.3ã«ç»å Žããããã12.3ããåã«ACLãåé€ããŠããå®å šã«åäœæããå¿ èŠããããŸããã ã€ã³ã¿ãŒãã§ã€ã¹ããããã³ã«ãæ¹åããšã«è€æ°ã®ã¢ã¯ã»ã¹ãªã¹ããé 眮ããããšã¯ã§ããŸãã ã 説æããŸãïŒã«ãŒã¿ãŒããããã€ã³ã¿ãŒãã§ãŒã¹ãããå ŽåãIPãããã³ã«ã®ã¢ã¯ã»ã¹ãªã¹ãã¯ãããšãã°10çªäžã«1ã€ã ãé 眮ã§ããŸããã«ãŒã¿ãŒèªäœã«é¢ããå¥ã®ã«ãŒã«ã¯ã ACLãã«ãŒã¿ãŒèªäœã«ãã£ãŠçæããããã©ãã£ãã¯ã«åœ±é¿ããŸããã ã
ACLã®ã¢ãã¬ã¹ããã£ã«ã¿ãªã³ã°ããã«ã¯ãWildCardãã¹ã¯ã䜿çšãããŸãã ããã¯éãã¹ã¯ã§ãã ãã³ãã¬ãŒãåŒïŒ255.255.255.255ãååŸãããã³ãã¬ãŒãããéåžžã®ãã¹ã¯ãæžç®ããŸãã
255.255.255.255-255.255.255.0ããã¹ã¯0.0.0.255ãååŸããŸããããã¯éåžžã®ãã¹ã¯255.255.255.0ã§ãã¯ã€ã«ãã«ãŒããã¹ã¯ã¯0.0.0.255ã®ã¿ã§ãã
ACLã®çš®é¡
åçïŒåçACLïŒ
ããšãã°ããããµãŒããŒã«æ¥ç¶ãããŠããã«ãŒã¿ãŒããããå€éšããã®ã¢ã¯ã»ã¹ããããã¯ããå¿ èŠãããå Žåã次ã®ããšãã§ããŸãããåæã«ãµãŒããŒã«æ¥ç¶ã§ãã人ãæ°äººããŸãã
åçã¢ã¯ã»ã¹ãªã¹ããèšå®ããçä¿¡æ¹åã«ã¢ã¿ããããŠãããæ¥ç¶ããå¿ èŠããã人ã ãTelnetãä»ããŠãã®ããã€ã¹ã«æ¥ç¶ããŸãããã®çµæãåçACLã¯ãµãŒããŒãžã®éè·¯ãéãããã§ã«HTTPãªã©ã§ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããŸãã ããã©ã«ãã§ã¯ã10ååŸã«ãã®ããã»ãŒãžãéãããããŠãŒã¶ãŒã¯ããã€ã¹ã«æ¥ç¶ããããã«å床Telnetãå®è¡ããããã«åŒ·å¶ãããŸãã
ååž°ACL
ããã§ç¶æ³ã¯ãããã«ç°ãªããŸããããŒã«ã«ãããã¯ãŒã¯äžã®ããŒããTCPèŠæ±ãã€ã³ã¿ãŒãããã«éä¿¡ãããšããTCPå¿çãæ¥ç¶ã確ç«ããããã«éããéè·¯ãå¿ èŠã§ãã ééããªãå Žåãæ¥ç¶ã確ç«ã§ãããæ»æè ã¯ãã®ééãå©çšããŠãããšãã°ãããã¯ãŒã¯ã«äŸµå ¥ããããšãã§ããŸãã ãªãã¬ã¯ãã£ãACLã¯ãã®ããã«æ©èœããã¢ã¯ã»ã¹ãå®å šã«ãããã¯ããŸãããããŒã«ã«ãããã¯ãŒã¯ããçæããããŠãŒã¶ãŒã»ãã·ã§ã³ã®ãã©ã¡ãŒã¿ãŒãèªã¿åããããããæåŠããããã®éè·¯ãéãããšãã§ããå¥ã®ç¹å¥ãªACLã圢æãããŸããã€ãŸããã€ã³ã¿ãŒãããããã€ã³ã¹ããŒã«ã§ããŸãããæ¥ç¶ã ãŸããããŒã«ã«ãããã¯ãŒã¯ããçæãããã»ãã·ã§ã³ã¯åçãåãåããŸãã
æéããŒã¹ã®ACL
éåžžã®ACLã§ãããæéå¶éããããããã¢ã¯ã»ã¹ãªã¹ãã®ç¹å®ã®ãšã³ããªãã¢ã¯ãã£ãã«ããç¹å¥ãªã¹ã±ãžã¥ãŒã«ãå ¥åã§ããŸãã ãããŠããã®ãããªããªãã¯ãè¡ãã«ã¯ãããšãã°ãå¶æ¥æ¥äžã«HTTPã¢ã¯ã»ã¹ãçŠæ¢ããã«ãŒã¿ãŒã€ã³ã¿ãŒãã§ã€ã¹ã«ãã³ã°ã¢ããããã¢ã¯ã»ã¹ãªã¹ããäœæããŸãã ã
å¿ èŠã«å¿ããŠãã€ã³ã¿ãŒãããããµãŒãã£ã³ããŠãã ããã
ã«ã¹ã¿ãã€ãº
ACLèªäœã¯åå¥ã«äœæãããŸããã€ãŸããã°ããŒãã«æ§æã§äœæããããªã¹ãã«éãããã€ã³ã¿ãŒãã§ã€ã¹ã«å²ãåœãŠãããŠããåããŠæ©èœããŸãã ã¢ã¯ã»ã¹ãªã¹ããæ£ããèšå®ããã«ã¯ãããã€ãã®ç¹ãèŠããŠããå¿ èŠããããŸãã
- åŠçã¯ãæ¡ä»¶ãèšé²ãããé åºã§å³å¯ã«å®è¡ãããŸãã
- ãã±ãããæ¡ä»¶ã«äžèŽããå ŽåãåŠçãããŸãã
- åã¢ã¯ã»ã¹ãªã¹ãã®æåŸã«ã¯ãæé»ã®æåŠïŒãã¹ãŠæåŠïŒããããŸãã
- æ¡åŒµACLã¯ãœãŒã¹ã®ã§ããã ãè¿ãã«é 眮ããå¿ èŠããããŸãããæšæºACLã¯ã§ããã ãã¬ã·ãŒãã®è¿ãã«é 眮ããå¿ èŠããããŸãã
- ã€ã³ã¿ãŒãã§ã€ã¹ããããã³ã«ãæ¹åããšã«è€æ°ã®ã¢ã¯ã»ã¹ãªã¹ããé 眮ããããšã¯ã§ããŸããã
- ACLã¯ãã«ãŒã¿ãŒèªäœã«ãã£ãŠçæããããã©ãã£ãã¯ã«ã¯åœ±é¿ããŸãã
- WildCardãã¹ã¯ã¯ãã¢ãã¬ã¹ã®ãã£ã«ã¿ãªã³ã°ã«äœ¿çšãããŸãã
æšæºã¢ã¯ã»ã¹ãªã¹ã
Router(config)# access-list < 1 99> {permit | deny | remark} {address | any | host} [source-wildcard] [log]
- èš±å¯ïŒ èš±å¯ãã
- æåŠïŒ çŠæ¢
- åèïŒ ã¢ã¯ã»ã¹ãªã¹ããžã®ã³ã¡ã³ã
- ã¢ãã¬ã¹ïŒ ãããã¯ãŒã¯ãç¡å¹ãŸãã¯èš±å¯ãã
- anyïŒ ãã¹ãŠãèš±å¯ãŸãã¯æåŠ
- ãã¹ãïŒãã¹ããèš±å¯ãŸãã¯æåŠããŸã
- source-wildcardïŒã¯ã€ã«ãã«ãŒããããã¯ãŒã¯ãã¹ã¯
- logïŒ ãã®ACLãééãããã±ããã®ãã®ã³ã°ãæå¹ã«ããŸã
æ¡åŒµã¢ã¯ã»ã¹ãªã¹ã
Router(config)# access-list < 100 199> {permit | deny | remark} protocol source [source-wildcard] [ operator operand] [ port < > [established]
- ãããã³ã«ãœãŒã¹ïŒ ã©ã®ãããã³ã«ãèš±å¯ãŸãã¯éãããïŒICMPãTCPãUDPãIPãOSPFãªã©ïŒ
- æåŠïŒ çŠæ¢
- æŒç®åïŒ
ABCD-åä¿¡è ã¢ãã¬ã¹
any-ä»»æã®ãšã³ããã¹ã
eq-ãã®ããŒãäžã®ãã±ããã®ã¿
gt-ããŒãçªå·ã倧ãããã±ããã®ã¿
host-å¯äžã®ãšã³ããã¹ã
lt-å°ããããŒãçªå·ã®ãã±ããã®ã¿
neq-ãã®ããŒãçªå·ã«ãªããã±ããã®ã¿
ç¯å²-ããŒãç¯å² - portïŒããŒãçªå·ïŒTCPãŸãã¯UDPïŒãååãæå®ã§ããŸã
- 確ç«æžã¿ïŒ æ¢ã«äœæãããTCPã»ãã·ã§ã³ã®äžéšã§ããTCPã»ã°ã¡ã³ãã®ééãèš±å¯ããŸã
ã€ã³ã¿ãŒãã§ãŒã¹ã«æ¥ç¶ãã
Router(config-if)# ip access-group < ACL> {in | out}
- inïŒ çä¿¡æ¹å
- outïŒ çºä¿¡æ¹å
ååä»ãã¢ã¯ã»ã¹ãªã¹ã
Router(config)# ip access-list {standard | extended} {< ACL> | < ACL>}
Router(config-ext-nacl)# {default | deny | exit | no | permit | remark}
- æšæºïŒ æšæºACL
- æ¡åŒµïŒ æ¡åŒµACL
- ããã©ã«ãïŒ ã³ãã³ããããã©ã«ãã«èšå®ããŸã
ã«ãŒã¿ãŒã¢ã¯ã»ã¹å¶é
R(config)# line vty 0 4
ä»®æ³åç·æ§æã¢ãŒãã«ç§»åããŸãã
R(config-line)# password <>
R(config-line)# login
R(config-line)# access-class 21 in
R(config-line)# password <>
R(config-line)# login
R(config-line)# access-class 21 in
in-ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããèšå®ããèš±å¯ãããIPã¢ãã¬ã¹ã§ã¢ã¯ã»ã¹ãªã¹ããä¿®æ£ããŸãã
ãã€ãããã¯ã¢ã¯ã»ã¹ãªã¹ã

R3(config)# username Student password 0 cisco
-Telnetçµç±ã§æ¥ç¶ãããŠãŒã¶ãŒãäœæããŸãã
R3(config)# access-list 101 permit tcp any host 10.2.2.2 eq telnet
R3(config)# access-list 101 dynamic testlist timeout 15 permit ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
ãã¹ãŠã®ããŒããTelnetçµç±ã§ãµãŒããŒã«æ¥ç¶ã§ããããã«ããŸãã
R3(config)#interface serial 0/0/1
R3(config-if)# ip access-group 101 in
R3(config)#interface serial 0/0/1
R3(config-if)# ip access-group 101 in
101 in-çä¿¡æ¹åã®ã€ã³ã¿ãŒãã§ã€ã¹ã«101 ACLãå²ãåœãŠãŸãã
R3(config)# line vty 0 4
R3(config-line)# login local
R3(config-line)# autocommand access-enable host timeout 5
R3(config)# line vty 0 4
R3(config-line)# login local
R3(config-line)# autocommand access-enable host timeout 5
ãŠãŒã¶ãŒãèªèšŒããããšããã«ããããã¯ãŒã¯192.168.30.0ãå©çšå¯èœã«ãªããéã¢ã¯ãã£ããªç¶æ ã5åéç¶ããšã»ãã·ã§ã³ãéããããŸãã
åå°åã¢ã¯ã»ã¹ãªã¹ã

R2(config)# ip access-list extended OUTBOUNDFILTERS
R2(config-ext-nacl)# permit tcp 192.168.0.0 0.0.255.255 any reflect TCPTRAFFIC
R2(config-ext-nacl)# permit icmp 192.168.0.0 0.0.255.255 any reflect ICMPTRAFFIC
R2(config)# ip access-list extended OUTBOUNDFILTERS
R2(config-ext-nacl)# permit tcp 192.168.0.0 0.0.255.255 any reflect TCPTRAFFIC
R2(config-ext-nacl)# permit icmp 192.168.0.0 0.0.255.255 any reflect ICMPTRAFFIC
-å éšããéå§ããããã©ãã£ãã¯ãã«ãŒã¿ãŒã«ç£èŠãããŸãã
R2(config)# ip access-list extended INBOUNDFILTERS
R2(config-ext-nacl)# evaluate TCPTRAFFIC
R2(config-ext-nacl)# evaluate ICMPTRAFFIC
R2(config)# ip access-list extended INBOUNDFILTERS
R2(config-ext-nacl)# evaluate TCPTRAFFIC
R2(config-ext-nacl)# evaluate ICMPTRAFFIC
-çä¿¡ãã©ãã£ãã¯ããã§ãã¯ããŠå éšããéå§ããããã©ããã確èªããTCPTRAFFICãINBOUNDFILTERSã«ãã€ã³ãããããã«ã«ãŒã¿ãŒã«èŠæ±ããåä¿¡ããªã·ãŒãäœæããŸãã
R2(config)# interface serial 0/1/0
R2(config-if)# ip access-group INBOUNDFILTERS in
R2(config-if)# ip access-group OUTBOUNDFILTERS out
R2(config)# interface serial 0/1/0
R2(config-if)# ip access-group INBOUNDFILTERS in
R2(config-if)# ip access-group OUTBOUNDFILTERS out
ã€ã³ã¿ãŒãã§ã€ã¹ã§çä¿¡ããã³çºä¿¡ACLã䜿çšããŸãã
å¶éæé

R1(config)# time-range EVERYOTHERDAY
R1(config-time-range)# periodic Monday Wednesday Friday 8:00 to 17:00
R1(config)# time-range EVERYOTHERDAY
R1(config-time-range)# periodic Monday Wednesday Friday 8:00 to 17:00
ææ¥ãšæå»ãè¿œå ããæéãªã¹ããäœæããŸãã
R1(config)# access-list 101 permit tcp 192.168.10.0 0.0.0.255 any eq telnet time-range EVERYOTHERDAY
-ACLã«æéç¯å²ãé©çšããŸãã
R1(config)#interface s0/0/0
R1(config-if)# ip access-group 101 out
R1(config)#interface s0/0/0
R1(config-if)# ip access-group 101 out
-ACLãã€ã³ã¿ãŒãã§ã€ã¹ã«ä¿®æ£ããŸãã
ãã©ãã«ã·ã¥ãŒãã£ã³ã°
RïŒ show access-lists {ACLçªå·| åå}-ã¢ã¯ã»ã¹ãªã¹ãæ å ±ã確èªããŸãã
RïŒ show access-lists-ã«ãŒã¿ãŒäžã®ãã¹ãŠã®ã¢ã¯ã»ã¹ãªã¹ãã衚瀺ããŸãã
äŸ
Router# show access-lists
Extended IP access list nick
permit ip host 172.168.1.1 host 10.0.0.5
deny ip any any (16 match(es))
Standard IP access list nick5
permit 172.16.0.0 0.0.255.255
nickããã³nick5ãšããååã®2ã€ã®ACLïŒæšæºããã³è©³çŽ°ïŒãããããšãããããŸãã æåã®ãªã¹ãã¯ããã¹ã172.16.1.1ãIPçµç±ã§ã¢ã¯ã»ã¹ã§ããããã«ããŸãïŒããã¯ãIPãä»ããŠå®è¡ããããã¹ãŠã®ãããã³ã«ãèš±å¯ãããããšãæå³ããŸãïŒã ä»ã®ãã¹ãŠã®ãã©ãã£ãã¯ã¯ãdeny ip any anyã³ãã³ãã«ãã£ãŠæåŠãããŸãã ãã®æ¡ä»¶ã®é£ã«ããã®äŸã§ã¯ãïŒ16 matchïŒesïŒïŒãšæžã蟌ã¿ãŸãã ããã¯ã16åã®ãã±ããããã®æ¡ä»¶ã«è©²åœããããšã瀺ããŠããŸãã
2çªç®ã®ACLã¯ã172.16.0.0 / 16ãããã¯ãŒã¯äžã®ä»»æã®ãœãŒã¹ããã®ãã©ãã£ãã¯ã®ééãèš±å¯ããŸãã
ç·Žç¿ãã
CCNA 4 ACLã³ãŒã¹ã®ç¬¬5ç« ããPacket Tracerã®ã©ãäœæ¥ãåéããŸããã å®éã«ç¥èãçµ±åãããå Žåã¯ã -link ãmirror- FTPãã芧ãã ããã ãµã€ãº-865.14 KBã
æåŠ
CCNA調æ»ïŒWANãžã®ã¢ã¯ã»ã¹ïŒ5ç« ïŒ