ãã®èšäºã§ã¯ãCisco IOSã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒã®æ©èœã«ã€ããŠèª¬æããŸãã ãã®ãããã¯ã¯å€ãã®äººã«éŠŽæã¿ãããã¯ããªã®ã§ãããŸããŸãªçš®é¡ã®ACLã«é¢ããæ å ±ãèŠçŽããŸãã åºæ¬ã«ã€ããŠç°¡åã«èª¬æããåŸãæéããŒã¹ïŒæéããŒã¹ïŒãåå°ïŒåå°ïŒãåçïŒåçïŒã®ç¹å¥ãªã¿ã€ãã®ACLã«ã€ããŠèª¬æããŸãã ããã§ã¯å§ããŸããã...
åºæ¬ïŒãã¹ãŠãèŠãã...
åºæ¬çãªæŠå¿µãšæ§æã«ã€ããŠã¯ããã«èª¬æããã®ã§ãåŸã§ããèå³æ·±ãããšãç°¡åã«é²ããããšãã§ããŸãã Ciscoã«ãŒã¿ãŒã®ACLã䜿çšãããšã2ã€ã®ã°ã«ãŒãã®åé¡ã解決ã§ããŸãã
- ãã©ãã£ãã¯ãã£ã«ã¿ãªã³ã°;
- ãã©ãã£ãã¯åé¡ã
ãã®èšäºã¯ãäž»ã«ãã£ã«ã¿ãªã³ã°ãã€ãŸã ãã¡ã€ã¢ãŠã©ãŒã«ãšããŠACLã䜿çšããŸãã åé¡ã«ãããããã«åŠçããããã±ãŒãžãéžæã§ããŸãã ããšãã°ãVPNã®äœææã«ç¹å®ã®ãã©ãã£ãã¯ã®ã¿ãæå·åãããµãŒãã¹å質ããªã·ãŒãé©çšããç¹å®ã®ã¢ãã¬ã¹ã®ã¿ããããŒããã£ã¹ãããŸãã
ACLã¯ããã±ãããã£ã«ã¿ãªã³ã°ãã¡ã€ã¢ãŠã©ãŒã«ã«èµ·å ããŸãã ã€ãŸã 次ã®5ã€ã®ãã©ã¡ãŒã¿ãŒã§ãã±ããããã£ã«ã¿ãŒã§ããŸãã
- éä¿¡å IPã¢ãã¬ã¹
- å®å IP
- IPã«ãã»ã«åãããã³ã«
- éä¿¡å ããŒã
- å®å ããŒã
ACLã¯2ã€ã®ã¿ã€ãã«åããããŸãã
- æšæº
- 延é·
æšæºACLã䜿çšãããšãåäžã®åºæºïŒãœãŒã¹IPã¢ãã¬ã¹ïŒã§ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ã§ããŸãã é«åºŠãªACLã¯ããªã¹ããããŠãã5ã€ã®ãã©ã¡ãŒã¿ãŒãã¹ãŠããã£ã«ã¿ãŒããŸãã
ACLã¯äžé£ã®ã«ãŒã«ã§æ§æãããŸãã åã«ãŒã«ã§ã¯ããã£ã«ã¿ãªã³ã°ãã©ã¡ãŒã¿ãŒïŒã¢ãã¬ã¹ãããŒããªã©ïŒãšããã±ãããã«ãŒã«ã®ãã¹ãŠã®åºæºãæºãããŠããå Žåã«å®è¡ããã¢ã¯ã·ã§ã³ãå®çŸ©ããŸãã 2ã€ã®ã¢ã¯ã·ã§ã³ïŒèš±å¯ïŒèš±å¯ïŒããã³æåŠïŒæåŠïŒã æå¹ãªå Žåããã±ããã¯ããã«åŠçãããç¡å¹ãªå Žåã¯ç Žæ£ãããŸãã ãã±ããã察å¿ããã«ãŒã«ãèŠã€ãããŸã§ãã«ãŒã«ã¯é çªã«ãã§ãã¯ãããŸãã ããã±ãŒãžã«å¯ŸããŠã¢ã¯ã·ã§ã³ïŒèš±å¯/æåŠïŒãå®è¡ãããã«ãŒã«ã®ãããªãæ€èšŒãçµäºããŸãã ACLã®æåŸã«ã¯ããã¹ãŠã®ãã©ãã£ãã¯ãçŠæ¢ããæé»ã®ã«ãŒã«ããããŸãã ã€ãŸã å¶éä»ãã¢ã¯ã»ã¹å¶åŸ¡ã䜿çšãããŸããæ瀺çã«èš±å¯ãããŠããªããã®ã¯ãã¹ãŠçŠæ¢ãããŸãã
æ§æ
ACLãäœæãã2ã€ã®æ¹æ³ïŒ
- ãå€ããæ§æã çªå·ã¯ãACLãèå¥ããããã«äœ¿çšãããŸãã æšæºACLã«ã¯1ã99ããã³1300ã1999ã®çªå·ãå²ãåœãŠãããæ¡åŒµACLã«ã¯100ã199ããã³2000ã2699ãå²ãåœãŠãããŸãã
- ååä»ãACLã®æ§æã 管çè ãéžæããååã¯ãèå¥ã«äœ¿çšãããŸãã
2çªç®ã®æ¹æ³ã¯ãã䟿å©ã§ãã ãŸããACLãèå¥ããã«ã¯ãçªå·ã§ã¯ãªãååã䜿çšããŸãã ååã«ãã£ãŠãACLã®äœ¿çšç®çãç解ã§ããŸãã 次ã«ãååä»ãã·ãŒãã¯ç¬èªã®æ§æã¢ãŒãã䜿çšãããããACLãããç°¡åã«ç·šéã§ããŸãã
æšæºACLã®äŸã次ã«ç€ºããŸãã
access-list 1 permit 192.168.1.0 0.0.0.255 ! access-list 2 permit any ! access-list 3 permit host 10.1.1.1 ! access-list 4 permit 10.1.1.0 0.0.0.15 access-list 4 permit 192.168.0.0 0.0.31.255
æåã®ACLïŒ1ïŒã¯ã192.168.1.0 / 24ãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ãèš±å¯ããŸãã 2çªç®ã®ïŒ2ïŒACLã¯ãã¹ãŠã®ãã©ãã£ãã¯ãèš±å¯ããŸãã 3çªç®ïŒ3ïŒã¯ããã¹ã10.1.1.1ããã®ãã©ãã£ãã¯ãèš±å¯ããŸãã æåŸã®4çªç®ã¯ãæåã®è¡ã§ãã¹ã10.1.1.0-10.1.1.15ããã®ãã©ãã£ãã¯ãèš±å¯ãã2çªç®ã®è¡ã§ã¯ãããã¯ãŒã¯192.168.0.0-192.168.31.0ããã®ãã©ãã£ãã¯ãèš±å¯ããŸãã 以äžã¯4ã€ã®ç°ãªãACLã®äŸã§ããã1ã€ã®ACLã®5ã€ã®ã«ãŒã«ã§ã¯ãªãããšã«æ³šæããŠãã ããã
ãããŠãããã€ãã®æ¡åŒµACLïŒ
access-list 100 permit tcp 10.1.1.0 0.0.0.255 any eq 80 access-list 101 permit udp host 1.1.1.1 eq 500 host 2.2.2.2 eq 555 access-list 102 permit icmp any any echo access-list 103 permit ip any any
ACL 100ã¯ã10.1.1.0 / 24ãããã¯ãŒã¯ããä»»æã®ãããã¯ãŒã¯ãå®å ããŒã80ãžã®TCPãã©ãã£ãã¯ãèš±å¯ããŸããã€ãŸãã ããŒã«ã«ãããã¯ãŒã¯ããã®WebãµãŒãã£ã³ãèš±å¯ããŸãã ACL 101ã¯ããã¹ã1.1.1.1ãããŒã500ãããã¹ã2.2.2.2ãããŒã555ãžã®UDPãã©ãã£ãã¯ãèš±å¯ããŸããACL102ã¯ãã©ãããã§ããã©ãããã§ãpingãèš±å¯ããŸãã æåŸã«ãæåŸã®ACL 103ã¯ãã¹ãŠã®ãã©ãã£ãã¯ãèš±å¯ããŸãã
åæ§ã®æšæºããã³æ¡åŒµACLããã ãæ°ããæ§æã䜿çšïŒ
ip access-list standard LIST1 permit 192.168.1.0 0.0.0.255 ! ip access-list standard LIST2 permit any ! ip access-list standard LIST3 permit host 10.1.1.1 ! ip access-list standard LIST1 permit 10.1.1.0 0.0.0.15 permit 192.168.0.0 0.0.31.255 ! ip access-list extended LIST100 permit tcp 10.1.1.0 0.0.0.255 any eq 80 ! ip access-list extended LIST101 permit udp host 1.1.1.1 eq 500 host 2.2.2.2 eq 555 ! ip access-list extended LIST102 permit icmp any any echo ! ip access-list extended LIST103 permit ip any any
iOS 12.3以éãACLã®ç·šéã¯éåžžã«äŸ¿å©ã«ãªããŸããã ã³ãã³ããäžããå ŽåïŒ
show access-list
ACLãšãã®å 容ã®ãªã¹ãã衚瀺ãããŸãã
R0(config-ext-nacl)#do sh access-li Standard IP access list LIST1 <b> 10</b> permit 192.168.1.0, wildcard bits 0.0.0.255 <b> 20</b> permit 10.1.1.0, wildcard bits 0.0.0.15 <b> 30</b> permit 192.168.0.0, wildcard bits 0.0.31.255 Standard IP access list LIST2 10 permit any Standard IP access list LIST3 10 permit 10.1.1.1 Extended IP access list LIST100 10 permit tcp 10.1.1.0 0.0.0.255 any eq www Extended IP access list LIST101 10 permit udp host 1.1.1.1 eq isakmp host 2.2.2.2 eq 555 Extended IP access list LIST102 10 permit icmp any any echo Extended IP access list LIST103 10 permit ip any any
ACLè¡ã«ã¯çªå·ãä»ããããŠããããšã«æ³šæããŠãã ããã ç¹å®ã®äœçœ®ã«æ°ããè¡ãè¿œå ããã«ã¯ãç®çã®ACLã®ç·šéã¢ãŒãã«å ¥ããæ°ããã«ãŒã«ãå ¥åããåã«è¡çªå·ãæå®ããŸãã
ip access-list standard LIST1 25 permit âŠ
ãŸããACLã®äœææ¹æ³ã¯éèŠã§ã¯ãããŸãããå€ãæ§æã䜿çšããããæ°ããæ¹æ³ã§ãACLåã§ã¯ãªãACLçªå·ãæå®ããã ãã§ãã è¡ã®è¿œå ãšåé€ã¯ãŸã£ããåãã§ãã
è¡ãåé€ããã«ã¯ãè¡çªå·ãæå®ããŠnoã³ãã³ãã䜿çšããŸãã
ip access-list standard LIST103 no 25
è¡ã®çªå·ãå€æŽã§ããŸãïŒ
ip access-list resequence LIST103 10 50
äžèšã®äŸã§ã¯ãååãLIST103ã®ACLã®å Žåãçªå·ã®ä»ãçŽããå®è¡ãããæåã®è¡ã®çªå·ã¯10ã«ãªããåŸç¶ã®è¡ã«ã¯50ã®å¢åã§çªå·ãä»ããããŸãã 10ã60ã110ã160 ...
æåŸã«ãACLãäœæããåŸãç®æšãšç®çã«å¿ããŠACLãé©çšããå¿ èŠããããŸãã ãã£ã«ã¿ãªã³ã°ã«é¢ããŠã¯ãACLã¯ã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšãããŸãã é©çšæã«ã¯ããã£ã«ã¿ãªã³ã°ã®æ¹åã瀺ãå¿ èŠããããŸããinïŒå ¥åïŒ-ãã©ãã£ãã¯ã¯ã¯ã€ã€ããã«ãŒã¿ã€ã³ã¿ãŒãã§ã€ã¹ã«å°éããoutïŒåºåïŒ-ã€ã³ã¿ãŒãã§ã€ã¹ããã®ãã©ãã£ãã¯ã¯ã¯ã€ã€ã«å°éããŸãã ãã®äŸã§ã¯ãACLã䜿çšããŠçä¿¡ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããŸãã
interface fa0/0 ip access-group LIST103 in
ãã®ãã¹ãŠããããç¥ãããŠããããšãé¡ã£ãŠããŸãã 質åãããã°ãå°ããŠãã ãããç§ã¯çããããšããŸãã 質åãå€ãå Žåã¯ãå¥ã®æçš¿ãäœæã§ããŸãã 次ã«ãACLãCiscoã«ãŒã¿ãŒã«æã£ãŠããè¿œå æ©èœãèŠãŠã¿ãŸãããã
æéããŒã¹ã®ACL
ACLããå§ããŸãããããã®ACLã§ã¯ããã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ãŸãã¯åé¡ããè¿œå ã®åºæºãšããŠæéã䜿çšã§ããŸãã ããšãã°ãå°±æ¥æéäžã¯WebãµãŒãã£ã³ã¯çŠæ¢ãããŠããŸããæŒé£æããã³ä»äºã®åŸã¯ããé¡ãããŸãã æéããŒã¹ã®ACLãäœæããã«ã¯äœãå¿ èŠã§ããïŒ ãã¹ãŠãéåžžã«ç°¡åã§ãïŒ
- 1ã€ä»¥äžã®ãã«ã¬ã³ããŒã-æéç¯å²ãäœæããŸãã
- æ¡åŒµACLã«ãŒã«ã§ãããã®ã«ã¬ã³ããŒã䜿çšããŸãã
ãã«ã¬ã³ããŒããäœæããã«ã¯ã time-rangeã³ãã³ãã䜿çšããŸãããã®ã³ãã³ãã¯ãã«ã¬ã³ããŒã«å²ãåœãŠãããä»»æã®ååãæå®ããŸãã ãã®åŸãACLã®ã«ãŒã«ã§ãã®ååãåç §ããŸãã ãã®äŸã§ã¯ãWORK_DAYSãšããååã®ãã«ã¬ã³ããŒããäœæããŸãã
time-range WORK_DAYS absolute start 00:00 01 January 2012 end 23:59 31 December 2012 periodic weekdays 9:00 to 18:00 periodic ? Friday Friday Monday Monday Saturday Saturday Sunday Sunday Thursday Thursday Tuesday Tuesday Wednesday Wednesday daily Every day of the week weekdays Monday thru Friday weekend Saturday and Sunday
ãã«ã¬ã³ããŒãã®èšå®ã¢ãŒãã§ãæéç¯å²ãå®çŸ©ããŸãã 2çš®é¡ã®ç¯å²ïŒ
- 絶察ïŒç¹å®ã®æ¥ä»ãšæå»ã瀺ãããŠããŸãïŒã
- å®æçïŒææ¥ãå°±æ¥æ¥ããŸãã¯é±æ«ã瀺ãããŸãããç¹å®ã®æ¥ä»ãžã®åç §ã¯ãããŸããïŒã
äžèšã®äŸã§ã¯ã2ã€ã®æéééãäœæãããŸãã絶察ïŒ2012幎1æ1æ¥00:00ãã2012幎12æ31æ¥23:59ãŸã§ã®æéãå®çŸ©ïŒãšçžå¯ŸïŒæææ¥ããéææ¥ã®9:00ãã18:00ãŸã§ã®æ¥ã決å®ããŸãïŒã å®æçãªééã«ã€ããŠã¯ãã芧ã®ãšãããææ¥ãæ¯æ¥-æ¯æ¥ãå¹³æ¥-皌åæ¥ãé±æ«-é±æ«ã®ååã䜿çšã§ããŸãã
äœæããããã«ã¬ã³ããŒãã衚瀺ããã«ã¯ã show time-tangeã³ãã³ããå®è¡ããŸã ã
R0#sh time-range time-range entry: WORK_DAYS <b>(active)</b> absolute start 00:00 01 January 2012 end 23:59 31 December 2012
ãã«ã¬ã³ããŒãã®ååã®æšªã«ããã¢ã¯ãã£ããšããèªã¯ããããã¢ã¯ãã£ãã§ããããšã瀺ããŸãã ãã«ã¬ã³ããŒãæéã¯ãã«ãŒã¿ãŒã®çŸåšã®æéã«å¯Ÿå¿ããããã«ãªããŸããã
次ã«ãACLã«ãŒã«ã§ãã«ã¬ã³ããŒãã䜿çšããŸãã
ip access-list extended TIME_BASED_ACL permit tcp 10.0.0.0 0.255.255.255 any eq www <b>time-range WORK_DAYS</b> permit tcp 10.0.0.0 0.255.255.255 any eq ftp-data <b>time-range ANOTHER_RANGE</b>
ã芧ã®ãšããã1ã€ã®ACLã®ç°ãªãã«ãŒã«ã«ç°ãªããã«ã¬ã³ããŒãã䜿çšã§ããŸãã é«åºŠãªACLã§ã®ã¿äœ¿çšã§ããã«ã¬ã³ããŒã
åå°acl
åå°åãŸãã¯ãã©ãŒåãããACLã䜿çšãããšããã£ã«ã¿ãªã³ã°æ©èœãæ¡åŒµã§ããŸãã åºæ¬çã«ãACLã¯ãã±ãããã£ã«ã¿ãªã³ã°ããã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã«å€ãããŸãã ã€ãŸã ããã§ãã«ãŒã¿ãŒã¯äŒç€Ÿã®å éšãããã¯ãŒã¯ããéå§ãããã»ãã·ã§ã³ã®ã¹ããŒã¿ã¹ãç£èŠããé©åãªãªã¿ãŒã³ã«ãŒã«ãäœæããŸãã

å žåçãªç¶æ³ã§èª¬æãããŠãã ããã å éšãããã¯ãŒã¯192.168.1.0/24ããããŸãã ãã®ãããã¯ãŒã¯ããã€ã³ã¿ãŒãããïŒhttpïŒ-ãã°ãªãŒã³ãACLãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸãã ã€ãŸã ãã®ACLã䜿çšããŠãå éšãããã¯ãŒã¯ãå€éšãããã¯ãŒã¯ã«æ®ãããã®ããªã·ãŒãå®çŸ©ããŸãã 2çªç®ã®ãèµ€ãACLã䜿çšããŠãå€éšããã®äŸµå ¥è ããå éšãããã¯ãŒã¯ãä¿è·ããŸãã ãã ããå éšãããã¯ãŒã¯ããéå§ãããã»ãã·ã§ã³ãžã®å¿çãèš±å¯ããå¿ èŠãããããããªã¿ãŒã³ãã©ãã£ãã¯ãèš±å¯ãããŸãã ãã¹ãŠãè«ççãªããã§ããèš±å¯ãããèŠæ±ãèš±å¯ãããåçã ãããããã®æ§æã§ã¯ãå éšãããã¯ãŒã¯ã倧ããéããŸãã ããŒã80ããã®TCPãã±ããã¯ãå éšãããã¯ãŒã¯ã«èªç±ã«å ¥ããŸãã SYN Floodæ»æãªã©ãžããããã ãã®åé¡ã¯ãã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ïŒCBACãŸãã¯IOSãã¡ã€ã¢ãŠã©ãŒã«ïŒã䜿çšããŠç°¡åã«è§£æ±ºã§ããŸãããIOSãšãã£ã·ã§ã³ããã®æ©èœããµããŒãããŠããªãå Žåã¯ã©ããªããŸããïŒ ãã©ãŒåãããACLã圹ç«ã¡ãŸãã
ããã¯ã1ã€ã®ACLïŒéåžžã¯ãç·ã-å éšïŒããããã¹ãã«åæ Œãããã±ãããç¹å¥ãªäžæACLã®ã«ãŒã«ã«ãã©ãŒãªã³ã°ãŸãã¯åæ ãããå€éšïŒãèµ€ãïŒACLã«ãã£ãŠãã§ãã¯ããããšããèãæ¹ã§ãã

äŸãã芧ãã ããã ç·ã®ACLã®ç¹å®ã®ã«ãŒã«ã§ã¯ãreflectãã©ã¡ãŒã¿ãŒã䜿çšããŠãã«ãŒã«ãåæ ãããäžæACLã®ååïŒãã®äŸã§ã¯MIRRORïŒãæå®ããŸãã èµ€ãACLã§ãäžæçãªãã©ãŒåãããACLããã¹ãããŸãïŒevaluateã³ãã³ãã ãã®ã³ãã³ãã¯ãããACLãå¥ã®ACLå ã§ãã§ãã¯ããæ©äŒãšèŠãªãããšãã§ããŸãã ãã®ã³ãã³ãã¯ãäžæçãªACLã®äžé£ã®ã«ãŒã«ã«çœ®ãæããããŸãã
å éšãããã¯ãŒã¯ããã®ã»ãã·ã§ã³ãéããŸã§ããã©ãŒåãããACLã¯ç©ºã§ãããã«ãŒã«ã¯å«ãŸããŠããŸããã
Extended IP access list EXTERNAL 10 evaluate MIRROR 20 deny ip any any log Extended IP access list INTERNAL 10 permit ip any any reflect MIRROR (2 matches) Reflexive IP access list MIRROR
ãã ããã»ãã·ã§ã³ãéããšããã«ããã©ãŒåãããACLããã£ã±ãã«ãªãå§ããŸãã
R1#sh access-li Extended IP access list EXTERNAL 10 evaluate MIRROR 20 deny ip any any log (5 matches) Extended IP access list INTERNAL 10 permit ip any any reflect MIRROR (36 matches) Reflexive IP access list MIRROR permit icmp host 2.2.2.2 host 192.168.1.1 (19 matches) (time left 289) permit tcp host 192.168.2.1 eq telnet host 192.168.1.1 eq 62609 (30 matches) (time left 286) permit ospf host 224.0.0.5 host 192.168.1.1 (6 matches) (time left 297)
äŸã§ã¯ãã¢ãã¬ã¹192.168.1.1ããã®å éšãããã¯ãŒã¯ãããã¢ãã¬ã¹2.2.2.2ãžã®pingãéå§ããã次ã«ãå éšã¢ãã¬ã¹192.168.1.1ããå€éšã¢ãã¬ã¹192.168.2.1ãžã®telnetæ¥ç¶ãéãããŸããã telnetæ¥ç¶ã®äŸã¯ãå®äºããäžé£ã®ã¢ã¯ã·ã§ã³ã瀺ããŠããŸãã
- å éšãã¹ãã¯ãã¢ãã¬ã¹192.168.1.1ããã³ã©ã³ãã ã«éžæãããããŒã62609ããå€éšãã¹ã192.168.2.1ãããŒã23ïŒtelnetïŒã®ã¢ãã¬ã¹ãžã®æ¥ç¶ãéå§ããŸãã
- ãã±ããã¯å éšACLã«ãã£ãŠãã§ãã¯ããã次ã®è¡ã§èš±å¯ãããŸãïŒ 10 permit ip any any reflect MIRROR
- MIRROR ACLã«åæ ïŒ èš±å¯tcpãã¹ã192.168.2.1 eq telnetãã¹ã192.168.1.1 eq 62609
- å€éšå¿çã¯ãMIRROR ACLãžã®åç §ãå«ãEXTERNAL ACLã«ãã£ãŠãã§ãã¯ãããŸãïŒ MIRRORãè©äŸ¡ããŸãã
ãªã¿ãŒã³ãã©ãã£ãã¯ãæçµçã«èš±å¯ãããŸãã å€éšããå éšãããã¯ãŒã¯ãžã®æ¥ç¶ãéãããšãããšãçŠæ¢ãããŸããipany any logãæåŠããŸã ã
å šäœãšããŠãæéŠã軜ãåããã ãã§ãACLã¯ã»ãŒã¹ããŒããã«ãªæ€æ»ãã¡ã€ã¢ãŠã©ãŒã«ã«å€ãããŸããã
ãã€ãããã¯ïŒããã¯ã¢ã³ãããŒïŒACL
ACLã®æ¬¡ã®ã«ããŽãªã¯åçã§ãã åºæ¬çã«ããããã®ACLã¯äŒç€Ÿã®ãããã¯ãŒã¯ãžã®ãªã¢ãŒãæ¥ç¶ã«äœ¿çšãããŸãããããŸããŸãªãªãœãŒã¹ãžã®æ¥ç¶ã«äºåèªèšŒãå¿ èŠãªå Žåã«äœ¿çšã§ããŸãã 管çè ã¯äŒç€Ÿã®ãããã¯ãŒã¯ã«åžžææ¥ç¶ããå¿ èŠãããããç°ãªãå Žæãããç°ãªãIPã¢ãã¬ã¹ããæ¥ç¶ããããšãæ³åããŠãã ããã ãã€ãããã¯ACLã®èãæ¹ã¯ã人ãæåã«èªèšŒããå¿ èŠããããæåããå Žåã«ã®ã¿ãããã¯ãŒã¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããACLãé©çšããããšããããšã§ãã ã¢ã«ãŽãªãºã ã¯æ¬¡ã®ãšããã§ãã
() . . , ACL. .
åçACLãæ§æããããã«å¿ èŠãªãã®ïŒ
- ã«ãŒã¿ãŒãžã®telnetãŸãã¯SSHæ¥ç¶ãèš±å¯ããæ¡åŒµACLãäœæããŸãã ãããã®ãããã³ã«ã¯ãã«ãŒã¿ãŒãžã®æ¥ç¶ã«äœ¿çšãããŸãã
- èªèšŒãã©ã¡ãŒã¿ãŒãå®çŸ©ããŸãã VTYããŒãã§ã®ããŒã«ã«èªèšŒãAAAããã¹ã¯ãŒãããµããŒããããŠããŸãã
- åçãªACLèšå®ãæ§æããŸãã
次ã®äŸãèŠãŠã¿ãŸãããã

ãŠãŒã¶ãŒã¯ãå éšãããã¯ãŒã¯ã®ããŒã80ã§ãµãŒããŒ192.168.1.1ã«æ¥ç¶ããå¿ èŠããããŸãã æ¥ç¶ãè¡ãããã¢ãã¬ã¹ã¯ãç§ãã¡ã«ã¯ç¥ãããŠããŸããã ãŸããã«ãŒã¿ãŒïŒã¢ãã¬ã¹1.1.1.1ïŒãžã®telnetæ¥ç¶ãèš±å¯ããåçACLãšã³ããªãŒãå«ãæ¡åŒµACLãäœæããŠãããç®çã®ã€ã³ã¿ãŒãã§ãŒã¹ã«é©çšããŸãã
ip access-list extended TELNET-IN permit tcp any host 1.1.1.1 eq telnet (1) dynamic DYNAMIC-ACL-NAME permit tcp any host 192.168.1.1 eq www (4) deny ip any any ! int s0/0 description CONNECTED TO EXTERNAL NETWORK ip address 1.1.1.1 255.255.255.0 ip access-group TELNET-IN in
次ã®ã¹ãããã¯ãèªèšŒãæ§æããããšã§ãã ããŒã«ã«èªèšŒã䜿çšããã®ã§ãrootãŠãŒã¶ãŒãäœæããvtyããŒãã§ããŒã«ã«èªèšŒãæå¹ã«ããŸãã
username root secret USERS_PASSWORD (2) ! line vty 0 4 login local (2) autocommand access-enable host timeout 10 (3)
autocommand access-enableã³ãã³ãã¯ãèªèšŒãæå¹ã«ãããã€ãããã¯ACLãšã³ããªãæå¹ã«ããŸãã ãã¹ããã©ã¡ãŒã¿ã¯ãªãã·ã§ã³ã§ãã 䜿çšãããšããã€ãããã¯ACLã®ãœãŒã¹IPã¢ãã¬ã¹ãšããŠã®anyã¯ããŠãŒã¶ãŒãæ¥ç¶ããŠããã¢ãã¬ã¹ã«çœ®ãæããããŸãã ã¿ã€ã ã¢ãŠããã©ã¡ãŒã¿ã¯ããã®ã»ãã·ã§ã³ã®éã¢ã¯ãã£ãæéãååäœã§æ±ºå®ããŸããããã©ã«ãã§ã¯ç¡å¶éã§ãã
ç¹å®ã®äŸã§ã¢ã¯ã»ã¹ãååŸããããã»ã¹ã¯ã©ã®ããã«ãªããŸããïŒ
- ãŠãŒã¶ãŒã¯ã1.1.1.1ã§ã«ãŒã¿ãŒãžã®telnetæ¥ç¶ãéããŸãã æ¡åŒµACLã«ãŒã«ã«ãã£ãŠèš±å¯ãããŸãïŒ1ïŒã
- ããŒã«ã«èªèšŒãã§ãŒãºïŒ2ïŒã
- èªèšŒã«æåãããšãaccess-enableïŒ3ïŒã³ãã³ããèªåçã«å®è¡ãããåçACLïŒ4ïŒã«ãŒã«ãæå¹ã«ãªããŸãã Telnetæ¥ç¶ãéããŸãã
- ãŠãŒã¶ãŒã«ã¯ãåçACLã®ã«ãŒã«ã«åŸã£ãŠã¢ã¯ã»ã¹ãèš±å¯ãããŸãã
ãããã«
ã芧ã®ãšãããCisco IOS ACLã¯éåžžã«èå³æ·±ãæ©èœãåããŠããŸããããã¯ããããäºå®äžãã¹ãŠã®IOSã®åºæ¬æ©èœã§ããããšãèæ ®ãããã®ã§ãã ãã¡ãããACLãšQoSãã¬ãŒãå¶éãªã©ãå€ãã®ããšãèå°è£ã«æ®ã£ãŠããŸãã ããã«ãCBACããŸãŒã³ããŒã¹ã®ãã¡ã€ã¢ãŠã©ãŒã«ãªã©ã®ããã㯠èªãã§ãããŠããããšãã