1.ãã¬ãã£ãã¯ã¹ãªã¹ãã®æŠèŠ
é åžãªã¹ãããã¬ãã£ãã¯ã¹ãªã¹ããªã©ãã«ãŒãã£ã³ã°ã¢ããããŒãã«ããŸããŸãªãã£ã«ã¿ãªã³ã°æ¹æ³ã䜿çšããŠãCisco IOSã§ã«ãŒãã£ã³ã°æ å ±ã®äº€æãåä¿¡ãéä¿¡ããŸãã¯åé åžã管çã§ããŸãã
é åžãªã¹ãã®äœ¿çšã«ã¯ã次ã®ãããªç¹å®ã®æ¬ ç¹ããããŸãã
- é åžãªã¹ãã§äœ¿çšãããACLïŒAccess-ListïŒã¯ãå ã ãã«ãŒãããã£ã«ã¿ãŒããã®ã§ã¯ãªãããã±ããããã£ã«ã¿ãŒããããã«èšèšãããŸãã
- æšæºACLã䜿çšããŠãããšãã«ã«ãŒããã¹ã¯ãäžèŽãããããšãã§ããªã
- æ¡åŒµACLã䜿çšãããšãèšå®ãé¢åã«ãªãå ŽåããããŸã
- ACLã¯ã«ãŒãã£ã³ã°æŽæ°ã®åãšã³ããªã«é çªã«é©çšããããããéåžžã«äœéã§ãã
ãã¬ãã£ãã¯ã¹ã®ãªã¹ãã¯ãACLã䜿çšãã代ããã«éçºããããã®ã§ãã«ãŒãããã£ã«ã¿ãªã³ã°ããããã«èšèšãããå€ãã®ã³ãã³ãã§äœ¿çšã§ããŸãã
ãã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšããäž»ãªå©ç¹ã¯æ¬¡ã®ãšããã§ãã
- ACLããã³ã¬ã³ãŒãã®å€§ããªãªã¹ãã®è¡šç€ºãšæ¯èŒããŠãããã©ãŒãã³ã¹ãå€§å¹ ã«åäžããŸãã ã«ãŒã¿ã¯ãã¬ãã£ãã¯ã¹ã®ãªã¹ããããªãŒæ§é ã«å€æããŸããããªãŒæ§é ã§ã¯ãããªãŒã®åãã©ã³ããç¹å®ã®æ¡ä»¶ãè¡šããŸããããã«ãããCisco IOSã¯å¿ èŠãªã¢ã¯ã·ã§ã³ãèš±å¯ãŸãã¯çŠæ¢ãããè¿ éã«æ±ºå®ã§ããŸã
- å¢åå€æŽããµããŒãããŸãã æšæºã®çªå·ä»ãACLã¯ç·šéããµããŒãããŠããŸãã;ãããã§ã¯ã1ã€ã®noã³ãã³ããACLå šäœãåé€ããŸãã ãã¬ãã£ãã¯ã¹ã®ãªã¹ãã¯å€æŽã§ããŸãã ãã¬ãã£ãã¯ã¹ãªã¹ãã®åè¡ã«ã·ãªã¢ã«çªå·ãå²ãåœãŠãããšãã§ããã«ãŒã¿ãŒã¯ãããã®ã·ãªã¢ã«çªå·ã䜿çšããŠãšã³ããªããœãŒãããŸãã äžå®ã®ããŒãžã³ïŒ10ã20ã30ïŒã§é£ç¶ããçªå·ãå²ãåœãŠããšãåŸã§æ¢åã®ãšã³ããªã®éã«æ°ãããšã³ããªãè¿œå ã§ããŸãã çªå·ã§åã ã®ãšã³ããªãåé€ããããšãã§ããŸã
泚 ïŒååä»ãACLã¯å¢åå€æŽããµããŒãããŸãã
- ããæè»æ§ã ããšãã°ãã«ãŒã¿ãŒã¯ãã¢ãã¬ã¹ã®å¿ èŠãªãããæ°ïŒãã¹ã¯ã®é·ãã§æ±ºå®ïŒã§ãã¬ãã£ãã¯ã¹ã®ãªã¹ããšäžèŽãããããã¯ãŒã¯ã®æ°ããã§ãã¯ããŸãã ãã¹ã¯ã¯ãæšæºããŒãžã§ã³ãšç¯å²ã䜿çšããŠå®çŸ©ã§ããŸã
ãã¬ãã£ãã¯ã¹ãªã¹ãã«ã¯ãACLãšã®ç¹å®ã®é¡äŒŒç¹ããããŸãã ãã¬ãã£ãã¯ã¹ãªã¹ãã«ã¯ä»»æã®æ°ã®ãšã³ããªãå«ããããšãã§ããåãšã³ããªã«ã¯æ¡ä»¶ãšã¢ã¯ã·ã§ã³ãå«ãŸããŸãã ã«ãŒã¿ãŒããã¬ãã£ãã¯ã¹ã®ãªã¹ãã䜿çšããŠã«ãŒãã®ã³ã³ãã©ã€ã¢ã³ã¹ããã§ãã¯ããå Žåãæ¡ä»¶ãšæåã«äžèŽããããšã«ãããã«ãŒãã«é©çšãããã¢ã¯ã·ã§ã³ïŒèš±å¯ãŸãã¯çŠæ¢ïŒã決å®ãããŸãã ã«ãŒããã©ã®ãšã³ããªãšãäžèŽããªãå Žåãæé»ã®ããã©ã«ãããªã·ãŒdeny anyãé©çšãããŸãã
2.ãã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšããŠã«ãŒãããã£ã«ã¿ãªã³ã°ããããã®äžè¬çãªã«ãŒã«
ã«ãŒãã¯ã次ã®ã«ãŒã«ã«åºã¥ããŠèš±å¯ãŸãã¯æåŠãããŸãã
- 空ã®ãªã¹ãã¯ãã¹ãŠã®ãã¬ãã£ãã¯ã¹ãèš±å¯ããŸãã
- ãã¬ãã£ãã¯ã¹ãæå¹ãªå Žåãã«ãŒãã䜿çšãããããã§ãªãå Žåã¯äœ¿çšãããŸãã
- ãã¬ãã£ãã¯ã¹ãªã¹ãã«ã¯çªå·ä»ãã®ãšã³ããªãå«ãŸããã«ãŒã¿ãŒã¯ãªã¹ãã®å é ããã³ã³ãã©ã€ã¢ã³ã¹ã®ãã§ãã¯ãéå§ããæå°çªå·ã®ãšã³ããªã䜿çšããŸãã
- äžèŽãèŠã€ãã£ãå Žåããã¬ãã£ãã¯ã¹ã®ãªã¹ãã¯åæ¢ããŸãã å¹çãäžããã«ã¯ãäžèŽãã確çãæãé«ãã¬ã³ãŒãããããäœãã·ãŒã±ã³ã¹çªå·ã®ãªã¹ãã®äžçªäžã«é 眮ããŸã
- äžèŽãçºçããªãã£ãå Žåãæé»ã®ããã©ã«ãããªã·ãŒãé©çšããã æåŠãããŸã
3.ãã¬ãã£ãã¯ã¹ãªã¹ãã®èšå®
ãã¬ãã£ãã¯ã¹ã®ãªã¹ããäœæããã«ã¯ã ip prefix-list { list-name | ãªã¹ãçªå· } [ seq seq-value ] { æåŠ | permit } network / length [ ge ge-value ] [ le le-value ]ã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãã ãã®ã³ãã³ãã®ãã©ã¡ãŒã¿ãŒã«ã€ããŠã¯ãè¡š1ã§èª¬æããŠããŸãã
è¡š1. ip prefix-listã³ãã³ãã®ãã©ã¡ãŒã¿ãŒã®èª¬æ
ãã©ã¡ãŒã¿ | 説æ |
ãªã¹ãå | äœæããããã¬ãã£ãã¯ã¹ãªã¹ãã®ååã¯å€§æåãšå°æåãåºå¥ãããŸã |
ãªã¹ãçªå· | äœæãããã¬ãã£ãã¯ã¹ãªã¹ãã®çªå· |
seq seq-value | ãã¬ãã£ãã¯ã¹ãªã¹ãå ã®ãšã³ããªã®32ãããæ°ããã£ã«ã¿ãªã³ã°äžã®ã³ã³ãã©ã€ã¢ã³ã¹ãã§ãã¯ã®é åºã決å®ããããã«äœ¿çšãããŸãã ããã©ã«ãã¯5å¢å |
æåŠãã | èš±å¯ãã | ãããã³ã°ã¢ã¯ã·ã§ã³ |
ãããã¯ãŒã¯ / é·ã | èšé²æ¡ä»¶ã¯ããã¬ãã£ãã¯ã¹ïŒãããã¯ãŒã¯çªå·ïŒãšãã®ãã¹ã¯ã®é·ãã§ãã ãããã¯ãŒã¯çªå·ã¯IPã¢ãã¬ã¹ãšããŠæå®ããããã¹ã¯ã®é·ãã¯ãã®äžã®ãŠããããããæ°ãšããŠæå®ãããŸã |
ge ge-value | network / lengthãã©ã¡ãŒã¿ãŒã§æå®ããããããé·ããã¹ã¯ãæã€ãããã¯ãŒã¯ã®ãã¹ã¯é·äžèŽç¯å²ã geãã©ã¡ãŒã¿ãŒã®ã¿ã䜿çšããå Žåãç¯å²ã¯ge-valueãã32ãšèŠãªãããŸã |
le le-value | network / lengthãã©ã¡ãŒã¿ãŒã§æå®ããããããé·ããã¹ã¯ãæã€ãããã¯ãŒã¯ã®ãã¹ã¯é·äžèŽç¯å²ã leãã©ã¡ãŒã¿ãŒã®ã¿ã䜿çšããå Žåãç¯å²ã¯é·ãããge-valueãŸã§ãšèŠãªãããŸã |
ãã©ã¡ãŒã¿geããã³leã¯ãªãã·ã§ã³ã§ãããã«ãŒããã¹ã¯ã®é·ãã®ç¯å²ã決å®ããããã«äœ¿çšã§ããŸãããã®ç¯å²å ã§ãã«ãŒãããã¬ãã£ãã¯ã¹ã®ãªã¹ããäœæããæ¡ä»¶ãæºãããŠãããšèŠãªãããŸãã length ã ge-valueãããã³le-valueãã©ã¡ãŒã¿ãŒã®å€ã¯ã é· ã < ge-value < le-value <= 32ã®ã«ãŒã«ãæºããå¿ èŠããããŸãã
ãã¬ãã£ãã¯ã¹ãªã¹ããåé€ããã«ã¯ãã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãã®no ip prefix-list list-nameã³ãã³ãã䜿çšããŸãã
[ no ] ip prefix-list list-name description textã³ãã³ãã¯ãããã¹ãã³ã¡ã³ãããã¬ãã£ãã¯ã¹ãªã¹ãã«è¿œå ãŸãã¯åé€ããããã«äœ¿çšãããŸãã
geããã³leãã©ã¡ãŒã¿ãŒãæå®ãããŠããªãå Žåãèšé²æ¡ä»¶ãæºããããã«å®å šã«äžèŽããå¿ èŠããããŸãã
geãªãã·ã§ã³ãšleãªãã·ã§ã³ã䜿çšãããšãæ··ä¹±ãæããç解ãã¥ãããªãå ŽåããããŸãã 以äžã«ããã€ãã®å®éã®å®éšã瀺ããŸãããã®åæã«ããããããã®ãã©ã¡ãŒã¿ãŒã䜿çšããå¯èœæ§ãç解ãããããªããŸãã
å³1ã¯ã geããã³leãã©ã¡ãŒã¿ãŒã®æäœã瀺ãããã«äœ¿çšãããããããžãŒã瀺ããŠããŸãã
å³1. ip prefix-listã³ãã³ãã®geããã³leãã©ã¡ãŒã¿ãŒã®åäœã瀺ãããã«äœ¿çšããããããã¯ãŒã¯
åæç¶æ ã§ã¯ããã¬ãã£ãã¯ã¹ãªã¹ãã¯äœ¿çšããããã«ãŒã¿ãŒAã¯æ¬¡ã®ãããã¯ãŒã¯ãžã®ã«ãŒãã§ã«ãŒã¿ãŒBããæ å ±ãåä¿¡ããŸããã
172.16.0.0ãµããããåïŒ 172.16.10.0/24 172.16.11.0/24
ãã®äŸã§ã¯ãããã€ãã®BGPã³ãã³ãã䜿çšããŸããã ip prefix-listã³ãã³ããã©ã¡ãŒã¿ãŒã®äŸãç解ããããã«ããããã®ã³ãã³ãã®åäœã«é¢ãã詳现æ å ±ã¯å¿ èŠãããŸããã éèŠãªæ å ±ã¯æ¬¡ã®ãšããã§ããå ã / 24ãã¹ã¯ã®2ã€ã®ã«ãŒãããã£ãã«ãŒã¿ãŒBã¯ããããã1ã€ã®ãšã³ããª172.16.0.0/16ã«ãŸãšãããããIPã¢ãã¬ã¹10.1.1.1ã®é£æ¥ã«ãŒã¿ãŒCãžã®éä¿¡ã«äœ¿çšã§ãã3ã€ã®ã«ãŒãããããŸãã å®éã«éä¿¡ãããã«ãŒãã¯ããã¬ãã£ãã¯ã¹ã®ãªã¹ãã®äœ¿çšæ¹æ³ã«ãã£ãŠç°ãªããŸãã
5ã€ã®æ§æã·ããªãªãæ³å®ã§ããŸãã
æåã®ã·ããªãªã§ã¯ãã«ãŒã¿ãŒBã®æ§æã¯æ¬¡ã®ãšããã§ãã
ã«ãŒã¿ãŒbgp 65000 éçŽã¢ãã¬ã¹172.16.0.0 255.255.0.0 ãã€ããŒ10.1.1.1ãã¬ãã£ãã¯ã¹ãªã¹ãtest1åºå ip prefix-list test1 permit 172.16.10.0/8 le 24
show running-configã³ãã³ãã䜿çšããŠã«ãŒã¿ã®çŸåšã®èšå®ã衚瀺ãããšãæåŸã®è¡ã次ã®è¡ã«èªåçã«çœ®ãæããããããšãããããŸãã
ip prefix-list test permit 172.0.0.0/8 le 24
ããã¯ãIPã¢ãã¬ã¹ã®æåã®8ãããã®ã¿ã/ 8ãã¹ã¯ã§éèŠãšèŠãªãããããã§ãã ãã®å Žåã3ã€ã®ãããã¯ãŒã¯ãã¹ãŠãžã®ã«ãŒãã¯ãé£æ¥ããã«ãŒã¿ãŒ172.16.0.0/16ã172.16.10.0/24ããã³172.16.11.0/24ã«éä¿¡ãããŸãã ãããã®ãã¹ãŠã®ã«ãŒãã¯ãåãé©åãªæåã®8ããããæã¡ã8ã24ã®ç¯å²ã®é·ãã«ã€ãªãããã¹ã¯ãæã£ãŠããŸãã
2çªç®ã®ã·ããªãªã§ã¯ãã«ãŒã¿ãŒBã®æ§æã¯æ¬¡ã®ãšããã§ãã
ã«ãŒã¿ãŒbgp 65000 éçŽã¢ãã¬ã¹172.16.0.0 255.255.0.0 ãã€ããŒ10.1.1.1ãã¬ãã£ãã¯ã¹ãªã¹ãtest2åºå ip prefix-list test2 permit 172.16.10.0/8 le 16
ãã®å Žåã1ã€ã®ã«ãŒãã®ã¿ãé£æ¥ã«ãŒã¿ãŒã«éä¿¡ããããããã¯ãŒã¯ãžã®ã«ãŒãã¯172.16.0.0/16ã§ãã 圌ã ããé©åãªæåã®8ããããšã8ã16ã®é·ãã®ç¯å²ã«ã€ãªãããã¹ã¯ãæã£ãŠããŸãã
3çªç®ã®ã·ããªãªã§ã¯ãã«ãŒã¿ãŒBã®æ§æã¯æ¬¡ã®ãšããã§ãã
ã«ãŒã¿ãŒbgp 65000 éçŽã¢ãã¬ã¹172.16.0.0 255.255.0.0 ãã€ããŒ10.1.1.1ãã¬ãã£ãã¯ã¹ãªã¹ãtest3åºå ip prefix-list test3 permit 172.16.10.0/8 ge 17
ãã®å Žåããããã¯ãŒã¯ãžã®ã«ãŒãã¯é£æ¥ããã«ãŒã¿ãŒ172.16.10.0/24ããã³172.16.11.0/24ã«éä¿¡ãããŸãã ãã®å Žåããã¹ã¯ãã©ã¡ãŒã¿ãŒ/ 8ã¯ãIPã¢ãã¬ã¹ã®ãã§ãã¯ããããããã匷調ããããã ãã«äœ¿çšããããã¹ã¯ã®é·ãã®ãã§ãã¯ã§ã¯ç¡èŠãããŸããã€ãŸããgeãã¹ã¯ç¯å²ge 17 le 32-from / 17 to / 32ã«å¯ŸããŠãã§ãã¯ãè¡ãããŸãã
4çªç®ã®ã·ããªãªã§ã¯ãã«ãŒã¿ãŒBã®æ§æã¯æ¬¡ã®ãšããã§ãã
ã«ãŒã¿ãŒbgp 65000 éçŽã¢ãã¬ã¹172.16.0.0 255.255.0.0 ãã€ããŒ10.1.1.1ãã¬ãã£ãã¯ã¹ãªã¹ãtest4åºå ip prefix-list test4 permit 172.16.10.0/8 ge 16 le 24
ãã®å Žåããã¹ãŠã®ãããã¯ãŒã¯ãžã®ã«ãŒãã¯ãé£æ¥ããã«ãŒã¿ãŒ172.16.0.0/16ã172.16.10.0/24ããã³172.16.11.0/24ã«éä¿¡ãããŸãã ãã®å Žåããã¹ã¯ãã©ã¡ãŒã¿ãŒ/ 8ã¯ãIPã¢ãã¬ã¹ã®ãã§ãã¯æžã¿ãããã匷調衚瀺ããããã«ã®ã¿äœ¿çšããããã¹ã¯ã®é·ãã®ãã§ãã¯ã§ã¯ç¡èŠãããŸããã€ãŸããge 16 le 24ãã¹ã¯ã®ç¯å²ã«å¯ŸããŠãã§ãã¯ãè¡ãããŸãã
5çªç®ã®ã·ããªãªã§ã¯ãã«ãŒã¿ãŒBã®æ§æã¯æ¬¡ã®ãšããã§ãã
ã«ãŒã¿ãŒbgp 65000 éçŽã¢ãã¬ã¹172.16.0.0 255.255.0.0 ãã€ããŒ10.1.1.1ãã¬ãã£ãã¯ã¹ãªã¹ãtest5åºå ip prefix-list test5 permit 172.16.10.0/8 ge 17 le 24
ãã®å Žåããããã¯ãŒã¯ãžã®ã«ãŒãã¯é£æ¥ããã«ãŒã¿ãŒ172.16.10.0/24ããã³172.16.11.0/24ã«éä¿¡ãããŸãã ãã®å Žåããã¹ã¯ãã©ã¡ãŒã¿ãŒ/ 8ã¯ãIPã¢ãã¬ã¹ã®ãã§ãã¯ããããããã匷調ããããã«ã®ã¿äœ¿çšããããã¹ã¯é·ã®ãã§ãã¯ã§ã¯ç¡èŠãããŸããã€ãŸããgeãã¹ã¯ç¯å²ge 17 le 24-from / 17 to / 24ã«å¯ŸããŠãã§ãã¯ãè¡ãããŸãã
4.ãã¬ãã£ãã¯ã¹ãªã¹ãã®ãšã³ããªã®çªå·ä»ã
ãã®æ©èœãç¡å¹ã«ããªãå Žåããã¬ãã£ãã¯ã¹ãªã¹ãã®ãšã³ããªã®çªå·ä»ãã¯èªåçã«è¡ãããŸãã èªåçªå·ä»ããç¡å¹ã«ããå Žåãåã¬ã³ãŒããäœæãããšãã«ã seq seq-valueãã©ã¡ãŒã¿ãŒã䜿çšããå¿ èŠããããŸãã
ãã¬ãã£ãã¯ã¹ãªã¹ãã¯ãœãŒãããããªã¹ãã§ãã ã«ãŒãããã¬ãã£ãã¯ã¹ãªã¹ãå ã®è€æ°ã®ãšã³ããªãšäžèŽã§ããå Žåãã¬ã³ãŒãçªå·ã¯éèŠãªãã©ã¡ãŒã¿ãŒã§ãããã®å Žåããã®ã«ãŒããäžèŽãããã¹ãŠã®çªå·ã®ãã¡æãå°ããçªå·ã§ã¬ã³ãŒãã«å®çŸ©ãããã¢ã¯ã·ã§ã³ãå®è¡ãããŸãã
ã³ã³ãã©ã€ã¢ã³ã¹ãã§ãã¯ã¯ãåžžã«æãå°ããçªå·ã®ã¬ã³ãŒãããéå§ãããäžèŽãèŠã€ãããŸã§çªå·ã®æé ã§ãªã¹ããäžã£ãŠãããŸãã äžèŽãããã®ãèŠã€ãã£ãå Žåãã«ãŒãã¯èš±å¯ãŸãã¯æåŠãããŸããããã¯ããã¬ãã£ãã¯ã¹ãªã¹ãã®å¯Ÿå¿ãããšã³ããªã§æå®ãããŠããã¢ã¯ã·ã§ã³ã«å¿ããŠã èš±å¯ãŸãã¯æåŠã«ãªããŸãã
ãšã³ããªã®ããã©ã«ãã®çªå·ä»ãã䜿çšãããã©ããã«é¢ä¿ãªããç¹å®ã®æ§æã¢ã€ãã ãåé€ããããã«çªå·ãæå®ããå¿ èŠã¯ãããŸããã
ããã©ã«ãã§ã¯ããã¬ãã£ãã¯ã¹ãªã¹ãã¢ã€ãã ã«ã¯ã5ã10ã15ãªã©ã®çªå·ãä»ããããŸãã ã·ãŒã±ã³ã¹çªå·ã®ãããããååšããªãå Žåãæ°ããã¬ã³ãŒãã¯æ¬ èœããŠããçªå·ãåä¿¡ãããçªå·ã¯æ倧å€ãã5倧ãããªããŸãã ãããã£ãŠãæåŸã®ã¬ã³ãŒãã®çªå·ã23ã§ããå Žåã次ã®çªå·ã¯28ã33ã38ãªã©ãåãåããŸãã
åºåã®show ip prefix-listã³ãã³ãã¯ããã¹ãŠã®ãšã³ããªã®ã·ãŒã±ã³ã¹çªå·ã衚瀺ããŸãã
ãã¬ãã£ãã¯ã¹ãªã¹ããšã³ããªã®èªåçªå·ä»ãããªãã«ããã«ã¯ãã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãã®no ip prefix-list sequence-numberã³ãã³ãã䜿çšããŸãã å床æå¹ã«ããã«ã¯ã ip prefix-list sequence-numberã³ãã³ãã䜿çšããŸãã
5.ãã¬ãã£ãã¯ã¹ãªã¹ãã®äœ¿çšäŸ
ip prefix-list filter1 permit 192.168.0.0/16 prefix listãæ€èšããŠãã ããã ãã®ãšã³ããªã«å¯Ÿå¿ããã«ãŒãã¯ã©ãã§ããïŒãããã¯ãŒã¯192.168.0.0/16ãžã®ã«ãŒãããããã¯ãŒã¯192.168.0.0/20ãžã®ã«ãŒãããããã¯ãŒã¯192.168.2.0/24ãžã®ã«ãŒãïŒ
ãããã¯ãŒã¯192.168.0.0/16ãžã®ã«ãŒãã®ã¿ããã®ãšã³ããªã«å¯Ÿå¿ããŸããããã¯ãã¢ãã¬ã¹ãšãã¹ã¯ãç §åããããã®æ¡ä»¶ãæ£åžžã«æºãããããšããã«çºçããããã§ãã
ããã«2ã€ã®ãã¬ãã£ãã¯ã¹ãªã¹ããæ€èšããŸãã
- ip prefix-list filter2 permit 192.168.0.0/16 le 20
- ip prefix-list filter3 permit 192.168.0.0/16 ge 18
æåã®ã±ãŒã¹ã§ã¯ããããã¯ãŒã¯ãžã®ã«ãŒãã¯ã³ã³ãã©ã€ã¢ã³ã¹æ¡ä»¶ã«é©ããŠããŸãïŒ 192.168.0.0/16ããã³192.168.0.0/20 ããããã¯ãŒã¯192.168.2.0/24ãžã®ã«ãŒãã¯å¿ èŠä»¥äžã«é·ããã¹ã¯ãæã£ãŠããŸãã
2çªç®ã®å Žåããããã¯ãŒã¯ãžã®ã«ãŒãã¯ã³ã³ãã©ã€ã¢ã³ã¹æ¡ä»¶ã«é©ããŠããŸãïŒ 192.168.0.0/20ããã³192.168.2.0/24 ããããã¯ãŒã¯192.168.0.0/16ãžã®ã«ãŒãã®ãã¹ã¯ãçãããŸãã
å¥ã®äŸã¯ã ip prefix-list filter4 0.0.0.0/0 prefix listã§ãã æ¥é èŸããã¹ãŠãŒããã¯ãã¹ãŠã®ãããã¯ãŒã¯ã«å¯Ÿå¿ããŸããããã®å Žåããã©ã¡ãŒã¿ãŒgeããã³leã¯äœ¿çšãããªãããããŒããã¹ã¯/ 0ãäžèŽãããå¿ èŠããããŸãã ãã®ãã¬ãã£ãã¯ã¹ã®ãªã¹ãã«ã¯ ã ããã©ã«ãã«ãŒãã®ã¿ãé©ããŠããŸã ã
ãã¬ãã£ãã¯ã¹ãªã¹ãip prefix-list filter5 0.0.0.0/0 ge 32ã䜿çšããå Žåã/ 32ãã¹ã¯ãæã€ã«ãŒãã¯ãã¹ãŠããã«å¯Ÿå¿ããŸãã
ãŸãã¯ããã®ãããªãã¬ãã£ãã¯ã¹ã®ãªã¹ã ïŒ ip prefix-list filter6 0.0.0.0/0 le 32㯠ã ä»»æã®ã«ãŒã ãä»»æã®ãããã¯ãŒã¯ãããã³ä»»æã®ãã¹ã¯é·ã«å¯Ÿå¿ããŸã ã
/ 1ãã/ 24ãŸã§ã®ãã¹ã¯ãæã€ãã¹ãŠã®ã«ãŒããéžæããå Žåã次ã®ãã¬ãã£ãã¯ã¹ã®ãªã¹ãã䜿çšããå¿ èŠããããŸããip prefix-list filter7 0.0.0.0/1 le 24 ã
6.ãã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšããåé åžã®ç®¡ç
å³2ã«ç€ºããããã¯ãŒã¯ã«ã€ããŠèããŸãããããããã³ã«ããå¥ã®ãããã³ã«ãžã®ã«ãŒãã£ã³ã°æ å ±ã®åé åžãç¹å®ã®ãããã¯ãŒã¯ã®ã¿ã«å¶éããå¿ èŠããããšããŸãã
RIPv2ãããã³ã«ã®ã«ãŒãã£ã³ã°ãã¡ã€ã³ããOSPFv2ãããã³ã«ã®ã«ãŒãã£ã³ã°ãã¡ã€ã³ã«ããããã¯ãŒã¯ã«é¢ããæ å ±ã®ã¿ã転éããå¿ èŠããããŸãã
- 10.1.0.0
- 10.2.0.0
- 10.3.0.0
OSPFv2ãããã³ã«ã®ã«ãŒãã£ã³ã°ãã¡ã€ã³ããRIPv2ãããã³ã«ã®ã«ãŒãã£ã³ã°ãã¡ã€ã³ã«ããããã¯ãŒã¯ã«é¢ããæ å ±ã®ã¿ã転éããå¿ èŠããããŸãã
- 10.8.0.0
- 10.9.0.0
- 10.10.0.0
- 10.11.0.0
å³2.ãã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšããåé åžå¶åŸ¡ã瀺ãããã«äœ¿çšããããããã¯ãŒã¯
ã«ãŒã¿ãŒR2ã®æ§æã¯æ¬¡ã®ãšããã§ãã
ã«ãŒã¿ãŒospf 1 ãããã¯ãŒã¯10.0.0.8 0.0.0.0ãšãªã¢0 rip route-mapãOSPFãµããããã«åé åžããŸã ã«ãŒã¿ãŒãªããã³ã° ãããã¯ãŒã¯10.0.0.0 ããŒãžã§ã³2 ããã·ãã€ã³ã¿ãŒãã§ã€ã¹s0 / 0/0 OSPF 1ã«ãŒãããããRIPã¡ããªãã¯5ã«åé åžããŸã route-map intoOSPF permit 10 äžèŽããIPã¢ãã¬ã¹ã®ãã¬ãã£ãã¯ã¹ãªã¹ãPFX1 ã«ãŒããããintoRIPèš±å¯10 äžèŽããIPã¢ãã¬ã¹ã®ãã¬ãã£ãã¯ã¹ãªã¹ãPFX2 ip prefix-list PFX1 permit 10.0.0.0/14 ip prefix-list PFX2 permit 10.8.0.0/14
IntoOSPF Route Mapã¯ã PFX1ãã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšããŸã ã ãããã£ãŠã 10.0.0.0 / 14-10.0.0.0ãã10.3.0.0ã®ç¯å²å ã®ãã¹ãŠã®ãããã¯ãŒã¯ã¯ãRIPããOSPFã«åé åžã§ããŸããä»ã®ãããã¯ãŒã¯ã¯ããã®ãã¬ãã£ãã¯ã¹ã®ãªã¹ãã«ãã£ãŠçŠæ¢ãããåé åžãããŸããã
IntoRIP Route Mapã¯ã PFX2ãã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšããŸã ã ãããã£ãŠã 10.8.0.0 / 14-10.8.0.0ãã10.11.0.0ã®ç¯å²å ã®ãã¹ãŠã®ãããã¯ãŒã¯ã¯ã OSPFããRIPã«åé åžã§ããŸãããä»ã®ãããã¯ãŒã¯ã¯ãã®ãã¬ãã£ãã¯ã¹ã®ãªã¹ãã«ãã£ãŠçŠæ¢ãããåé åžãããŸããã
ç¹å®ã®ã«ãŒããåé åžãããã©ããã®æ±ºå®ã¯ã route-mapã³ãã³ãã®èš±å¯ãŸãã¯æåŠã¢ã¯ã·ã§ã³ã®ã¿ã«åºã¥ããŠããã ip prefix-listã³ãã³ãã®èš±å¯ãŸãã¯æåŠã¢ã¯ã·ã§ã³ã«ã¯åºã¥ããŠããªãããšã«æ³šæããŠãã ããã ip prefix-list ipã³ãã³ãã®èš±å¯ãŸãã¯æåŠã¢ã¯ã·ã§ã³ã¯ãã«ãŒããã«ãŒããããã®æ¡ä»¶ã«äžèŽãããã©ããã«ã®ã¿åœ±é¿ããŸãã
ããã¯ã¢ãããã¹ã®ãããããã¯ãŒã¯ã§ã¯ããã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšãããšãã«ãŒãã«ãŒãã®å¯èœæ§ããªããªããŸãã ãã ããé åžãªã¹ããšåæ§ã«ããã¬ãã£ãã¯ã¹ãªã¹ãã䜿çšãããšãã«ãŒãæŽæ°ããäžéšã®ã«ãŒããå®å šã«ãã£ã«ã¿ãªã³ã°ã§ããŸãã ãããã£ãŠããããã¯ãŒã¯äžã®äžéšã®ã«ãŒã¿ãŒã¯ãäžéšã®ãããã¯ãŒã¯ã«å°éããããã®ä»£æ¿æ¹æ³ãèªèããªãããããããã®æè¡ãããã¯ã¢ãããã¹ã®ãããããã¯ãŒã¯ã§äœ¿çšããå Žåã¯æ³šæãå¿ èŠã§ãã
7.ãã¬ãã£ãã¯ã¹ãªã¹ãã®ç¢ºèª
ãã¬ãã£ãã¯ã¹ãªã¹ãã®ç¢ºèªãšèšºæã«äœ¿çšãããäž»ãªã³ãã³ããè¡š2ã«ç€ºããŸããipprefix-list help ïŒ äœ¿çšå¯èœãªãã©ã¡ãŒã¿ãŒãšãã®ç®çã«é¢ããå®å šãªæ å ±ã
è¡š2ãã¬ãã£ãã¯ã¹ãªã¹ãã確èªããã³èšºæããããã®ã³ãã³ã
ãã©ã¡ãŒã¿ | 説æ |
show ip prefix-list [ 詳现 | æŠèŠ ] | ãã¹ãŠã®ãã¬ãã£ãã¯ã¹ãªã¹ãã«é¢ããæ å ±ã衚瀺ããŸãã detailãã©ã¡ãŒã¿ã䜿çšãããšããã¬ãã£ãã¯ã¹ãªã¹ãã®åãšã³ããªã®èª¬æãšã«ãŠã³ã¿ã衚瀺ãããŸãã |
show ip prefix-list [ 詳现 | èŠçŽ ] ãã¬ãã£ãã¯ã¹ãªã¹ãå | æå®ããããã¬ãã£ãã¯ã¹ãªã¹ãã®ãšã³ããªã衚瀺ããŸã |
show ip prefix-list prefix-listname [ ãããã¯ãŒã¯ / é·ã ] | æå®ããããããã¯ãŒã¯/ãã¹ã¯ãã¢ã®ãã¬ãã£ãã¯ã¹ã®ãã®ãªã¹ãã§å®çŸ©ãããããªã·ãŒã衚瀺ããŸã |
show ip prefix-list prefix-listname [ seq sequence-number ] | ãã®ãã¬ãã£ãã¯ã¹ã®ãªã¹ãã®æå®ãããæ°ã®ã¬ã³ãŒãã衚瀺ããŸã |
show ip prefix-list prefix-listname [ network / length ] é·ã | æå®ãããããã/ãã¹ã¯ã®ãã¢ãããé©åã§æ£ç¢ºãªãã¹ãŠã®ãã¬ãã£ãã¯ã¹ãªã¹ããšã³ããªã衚瀺ããŸã |
show ip prefix-list prefix-listname [ network / length ] firstmatch | æå®ããããããã¯ãŒã¯/ãã¹ã¯ãã¢ã®æåã«äžèŽãããã¬ãã£ãã¯ã¹ãªã¹ã/ãã¹ã¯ãã¢ã®è¡šç€º |
clear ip prefix-list prefix-listname [ ãããã¯ãŒã¯ / é·ã ] | æå®ããããã¬ãã£ãã¯ã¹ã®ãªã¹ãã®ãã¹ãŠã®ã«ãŠã³ã¿ãŒããªã»ããããŸã |
次ã«ã show ip prefix-list detailã³ãã³ãã®åºåã瀺ãäŸã瀺ããŸãã ãã¬ãã£ãã¯ã¹5ã®ãšã³ããªã1ã€æã€ãsuperonlyããšããååã®åäžã®ãã¬ãã£ãã¯ã¹ãªã¹ããã«ãŒã¿äžã«äœæãããŸãããå€ããããã«ãŠã³ãïŒ0ãã¯ããã®ãšã³ããªã«åäžã®äžèŽããªãã£ãããšãæå³ããŸãã
show ip prefix-list detailã³ãã³ãã®åºåã¯æ¬¡ã®ãšããã§ãã
ã«ãŒã¿ïŒshow ip prefix-list detail æåŸã®åé€/æ¿å ¥ã®ãã¬ãã£ãã¯ã¹ãªã¹ãïŒsuperonly ip prefix-list superonlyïŒ èª¬æïŒã¹ãŒããŒãããã®ã¿ãèš±å¯ ã«ãŠã³ãïŒ1ãç¯å²ãšã³ããªïŒ0ãã·ãŒã±ã³ã¹ïŒ5-5ãåç §ã«ãŠã³ãïŒ1 ã·ãŒã±ã³ã¹5èš±å¯172.0.0.0/8ïŒãããã«ãŠã³ãïŒ0ãåç §ã«ãŠã³ãïŒ1ïŒ