Ò»¡¢access-list ÓÃÓÚ´´½¨·ÃÎʹæÔò¡£ £¨1£©´´½¨±ê×¼·ÃÎÊÁбí
access-list [ normal | special ] listnumber1 { permit | deny } source-addr [ source-mask ] £¨2£©´´½¨À©Õ¹·ÃÎÊÁбí
access-list [ normal | special ] listnumber2 { permit | deny } protocol source-addr
source-mask [ operator port1 [ port2 ] ] dest-addr dest-mask [ operator port1 [ port2 ] | icmp-type [ icmp-code ] ] [ log ] £¨3£©É¾³ý·ÃÎÊÁбí
no access-list { normal | special } { all | listnumber [ subitem ] } ¡¾²ÎÊý˵Ã÷¡¿
normal Ö¸¶¨¹æÔò¼ÓÈëÆÕͨʱ¼ä¶Î¡£ special Ö¸¶¨¹æÔò¼ÓÈëÌØÊâʱ¼ä¶Î¡£
listnumber1 ÊÇ1µ½99Ö®¼äµÄÒ»¸öÊýÖµ£¬±íʾ¹æÔòÊDZê×¼·ÃÎÊÁбí¹æÔò¡£ listnumber2 ÊÇ100µ½199Ö®¼äµÄÒ»¸öÊýÖµ£¬±íʾ¹æÔòÊÇÀ©Õ¹·ÃÎÊÁбí¹æÔò¡£
permit ±íÃ÷ÔÊÐíÂú×ãÌõ¼þµÄ±¨ÎÄͨ¹ý¡£ deny ±íÃ÷½ûÖ¹Âú×ãÌõ¼þµÄ±¨ÎÄͨ¹ý¡£
protocol ΪÐÒéÀàÐÍ£¬Ö§³ÖICMP¡¢TCP¡¢UDPµÈ£¬ÆäËüµÄÐÒéÒ²Ö§³Ö£¬´ËʱûÓж˿ڱȽϵÄ
¸ÅÄΪIPʱÓÐÌØÊ⺬Ò壬´ú±íËùÓеÄIPÐÒé¡£ source-addr ΪԴµØÖ·¡£
source-mask ΪԴµØַͨÅä룬ÔÚ±ê×¼·ÃÎÊÁбíÖÐÊÇ¿ÉÑ¡Ï²»ÊäÈëÔò´ú±íͨÅäλΪ
0.0.0.0¡£
dest-addr ΪĿµÄµØÖ·¡£ dest-mask ΪĿµÄµØַͨÅäλ¡£
operator[¿ÉÑ¡] ¶Ë¿Ú²Ù×÷·û£¬ÔÚÐÒéÀàÐÍΪTCP»òUDPʱ֧³Ö¶Ë¿Ú±È½Ï£¬Ö§³ÖµÄ±È½Ï²Ù×÷
ÓУºµÈÓÚ£¨eq£©¡¢´óÓÚ£¨gt£©¡¢Ð¡ÓÚ£¨lt£©¡¢²»µÈÓÚ£¨neq£©»ò½éÓÚ£¨range£©£»Èç¹û²Ù×÷·ûΪrange£¬ÔòºóÃæÐèÒª¸úÁ½¸ö¶Ë¿Ú¡£
port1 ÔÚÐÒéÀàÐÍΪTCP»òUDPʱ³öÏÖ£¬¿ÉÒÔΪ¹Ø¼ü×ÖËùÉ趨µÄÔ¤ÉèÖµ£¨Èçtelnet£©»ò0~65535
Ö®¼äµÄÒ»¸öÊýÖµ¡£
port2 ÔÚÐÒéÀàÐÍΪTCP»òUDPÇÒ²Ù×÷ÀàÐÍΪrangeʱ³öÏÖ£»¿ÉÒÔΪ¹Ø¼ü×ÖËùÉ趨µÄÔ¤ÉèÖµ
£¨Èçtelnet£©»ò0~65535Ö®¼äµÄÒ»¸öÊýÖµ¡£
icmp-type[¿ÉÑ¡] ÔÚÐÒéΪICMPʱ³öÏÖ£¬´ú±íICMP±¨ÎÄÀàÐÍ£»¿ÉÒÔÊǹؼü×ÖËùÉ趨µÄÔ¤Éè
Öµ£¨Èçecho-reply£©»òÕßÊÇ0~255Ö®¼äµÄÒ»¸öÊýÖµ¡£
icmp-codeÔÚÐÒéΪICMPÇÒûÓÐÑ¡ÔñËùÉ趨µÄÔ¤Éèֵʱ³öÏÖ£»´ú±íICMPÂ룬ÊÇ0~255Ö®¼ä
µÄÒ»¸öÊýÖµ¡£
log [¿ÉÑ¡] ±íʾÈç¹û±¨ÎÄ·ûºÏÌõ¼þ£¬ÐèÒª×öÈÕÖ¾¡£ listnumber Ϊɾ³ýµÄ¹æÔòÐòºÅ£¬ÊÇ1~199Ö®¼äµÄÒ»¸öÊýÖµ¡£
subitem[¿ÉÑ¡] Ö¸¶¨É¾³ýÐòºÅΪlistnumberµÄ·ÃÎÊÁбíÖйæÔòµÄÐòºÅ¡£ ¡¾È±Ê¡Çé¿ö¡¿
ϵͳȱʡ²»ÅäÖÃÈκηÃÎʹæÔò¡£ ¡¾ÃüÁîģʽ¡¿ È«¾ÖÅäÖÃģʽ ¡¾Ê¹ÓÃÖ¸ÄÏ¡¿
ͬһ¸öÐòºÅµÄ¹æÔò¿ÉÒÔ¿´×÷Ò»Àà¹æÔò£»Ëù¶¨ÒåµÄ¹æÔò²»½ö¿ÉÒÔÓÃÀ´ÔÚ½Ó¿ÚÉϹýÂ˱¨ÎÄ£¬Ò²¿É
ÒÔ±»ÈçDDRµÈÓÃÀ´ÅжÏÒ»¸ö±¨ÎÄÊÇ·ñÊǸÐÐËȤµÄ±¨ÎÄ£¬´Ëʱ£¬permitÓëdeny±íʾÊǸÐÐËȤµÄ»¹ÊDz»¸ÐÐËȤµÄ¡£
ʹÓÃÐÒéÓòΪIPµÄÀ©Õ¹·ÃÎÊÁбíÀ´±íʾËùÓеÄIPÐÒé¡£
ͬһ¸öÐòºÅÖ®¼äµÄ¹æÔò°´ÕÕÒ»¶¨µÄÔÔò½øÐÐÅÅÁкÍÑ¡Ôñ£¬Õâ¸ö˳Ðò¿ÉÒÔͨ¹ý show
access-list ÃüÁî¿´µ½¡£ ¡¾¾ÙÀý¡¿
ÔÊÐíÔ´µØַΪ10.1.1.0 ÍøÂ硢ĿµÄµØַΪ10.1.2.0ÍøÂçµÄWWW·ÃÎÊ£¬µ«²»ÔÊÐíʹÓÃFTP¡£ Quidway(config)#access-list 100 permit tcp 10.1.1.0 0.0.0.255 10.1.2.0 0.0.0.255
eq www
Quidway(config)#access-list 100 deny tcp 10.1.1.0 0.0.0.255 10.1.2.0 0.0.0.255 eq
ftp
¶þ¡¢clear access-list counters Çå³ý·ÃÎÊÁбí¹æÔòµÄͳ¼ÆÐÅÏ¢¡£ clear access-list counters [ listnumber ] ¡¾²ÎÊý˵Ã÷¡¿
listnumber [¿ÉÑ¡] ÒªÇå³ýͳ¼ÆÐÅÏ¢µÄ¹æÔòµÄÐòºÅ£¬Èç²»Ö¸¶¨£¬ÔòÇå³ýËùÓеĹæÔòµÄͳ¼ÆÐÅÏ¢¡£
¡¾È±Ê¡Çé¿ö¡¿
ÈκÎʱºò¶¼²»Çå³ýͳ¼ÆÐÅÏ¢¡£ ¡¾ÃüÁîģʽ¡¿ ÌØȨÓû§Ä£Ê½ ¡¾Ê¹ÓÃÖ¸ÄÏ¡¿
ʹÓôËÃüÁîÀ´Çå³ýµ±Ç°ËùÓùæÔòµÄͳ¼ÆÐÅÏ¢£¬²»Ö¸¶¨¹æÔò±àºÅÔòÇå³ýËùÓйæÔòµÄͳ¼ÆÐÅÏ¢¡£ ¡¾¾ÙÀý¡¿
Àý1£ºÇå³ýµ±Ç°ËùʹÓõÄÐòºÅΪ100µÄ¹æÔòµÄͳ¼ÆÐÅÏ¢¡£ Quidway#clear access-list counters 100 Àý2£ºÇå³ýµ±Ç°ËùʹÓõÄËùÓйæÔòµÄͳ¼ÆÐÅÏ¢¡£ Quidway#clear access-list counters Èý¡¢firewall ÆôÓûò½ûÖ¹·À»ðǽ¡£ firewall { enable | disable } ¡¾²ÎÊý˵Ã÷¡¿
enable ±íʾÆôÓ÷À»ðǽ¡£ disable ±íʾ½ûÖ¹·À»ðǽ¡£ ¡¾È±Ê¡Çé¿ö¡¿
ϵͳȱʡΪ½ûÖ¹·À»ðǽ¡£
¡¾ÃüÁîģʽ¡¿ È«¾ÖÅäÖÃģʽ ¡¾Ê¹ÓÃÖ¸ÄÏ¡¿
ʹÓôËÃüÁîÀ´ÆôÓûò½ûÖ¹·À»ðǽ£¬¿ÉÒÔͨ¹ýshow firewallÃüÁî¿´µ½ÏàÓ¦½á¹û¡£Èç¹û²ÉÓÃÁË
ʱ¼ä¶Î°ü¹ýÂË£¬ÔòÔÚ·À»ðǽ±»¹Ø±ÕʱҲ½«±»¹Ø±Õ£»¸ÃÃüÁî¿ØÖÆ·À»ðǽµÄ×Ü¿ª¹Ø¡£ÔÚʹÓà firewall disable ÃüÁî¹Ø±Õ·À»ðǽʱ£¬·À»ðǽ±¾ÉíµÄͳ¼ÆÐÅÏ¢Ò²½«±»Çå³ý¡£ ¡¾¾ÙÀý¡¿ ÆôÓ÷À»ðǽ¡£
Quidway(config)#firewall enable
ËÄ¡¢firewall default ÅäÖ÷À»ðǽÔÚûÓÐÏàÓ¦µÄ·ÃÎʹæÔòÆ¥Åäʱ£¬È±Ê¡µÄ¹ýÂË·½Ê½¡£ firewall default { permit | deny } ¡¾²ÎÊý˵Ã÷¡¿
permit ±íʾȱʡ¹ýÂËÊôÐÔÉèÖÃΪ¡°ÔÊÐí¡±¡£ deny ±íʾȱʡ¹ýÂËÊôÐÔÉèÖÃΪ¡°½ûÖ¹¡±¡£ ¡¾È±Ê¡Çé¿ö¡¿
ÔÚ·À»ðǽ¿ªÆôµÄÇé¿öÏ£¬±¨Îı»È±Ê¡ÔÊÐíͨ¹ý¡£ ¡¾ÃüÁîģʽ¡¿ È«¾ÖÅäÖÃģʽ ¡¾Ê¹ÓÃÖ¸ÄÏ¡¿
µ±ÔÚ½Ó¿ÚÓ¦ÓõĹæÔòûÓÐÒ»¸öÄܹ»ÅжÏÒ»¸ö±¨ÎÄÊÇ·ñÓ¦¸Ã±»ÔÊÐí»¹Êǽûֹʱ£¬È±Ê¡µÄ¹ýÂËÊô
ÐÔ½«Æð×÷Óã»Èç¹ûȱʡ¹ýÂËÊôÐÔÊÇ¡°ÔÊÐí¡±£¬Ôò±¨ÎÄ¿ÉÒÔͨ¹ý£¬·ñÔò±¨Îı»¶ªÆú¡£