【Cisco】ラボ#11 ルータの確認
FORSE 9
手順8確認する
・VLANを確認
・インターフェースとIPアドレスを確認
・スタティックルートを確認
RT-1#show vlan-switch
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gi1, Gi2, Gi3, Gi4, Gi5, Gi6
Gi7
10 VLAN0010 active Gi0
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
RT-1#show ip interface brief
Interface IP-Address OK? Method Status Protocol
Async3 unassigned YES unset down down
BRI0 unassigned YES unset administratively down down
BRI0:1 unassigned YES unset administratively down down
BRI0:2 unassigned YES unset administratively down down
FastEthernet0 192.168.201.1 YES manual up up
GigabitEthernet0 unassigned YES unset up up
GigabitEthernet1 unassigned YES unset down down
GigabitEthernet2 unassigned YES unset down down
GigabitEthernet3 unassigned YES unset down down
GigabitEthernet4 unassigned YES unset down down
GigabitEthernet5 unassigned YES unset down down
GigabitEthernet6 unassigned YES unset down down
GigabitEthernet7 unassigned YES unset down down
GigabitEthernet8 172.16.10.1 YES manual up up
Vlan1 unassigned YES unset down down
Vlan10 192.168.10.1 YES manual up up
RT-1#show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
a - application route
+ - replicated route, % - next hop override, p - overrides from PfR
Gateway of last resort is not set
172.16.0.0/16 is variably subnetted, 2 subnets, 2 masks
C 172.16.10.0/30 is directly connected, GigabitEthernet8
L 172.16.10.1/32 is directly connected, GigabitEthernet8
192.168.10.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.10.0/24 is directly connected, Vlan10
L 192.168.10.1/32 is directly connected, Vlan10
S 192.168.20.0/24 [1/0] via 172.16.10.2
S 192.168.202.0/24 [1/0] via 172.16.10.2
【Cisco】ラボ#11 拡張ACLの設定
FORSE 14
手順13【RT-3】
手順13 【RT-4】
要件
2.サーバがお互いに通信出来ないように通信拒否
3.PC1→Server2のhttp通信、PC2→Server1へのhttp通信を拒否
手順13 【RT-1】拡張ACLを作成し、インターフェースに適用する
手順13 【RT-2】
RT-1(config)#ip access-list extended Server-Filter
RT-1(config-ext-nacl)#deny ip host 192.168.201.100 host
192.168.202.100
RT-1(config-ext-nacl)#permit ip any any
RT-1(config-ext-nacl)#exit
RT-1(config)#ip access-list extended PC-Filter
RT-1(config-ext-nacl)#deny tcp host 192.168.10.10 host
192.168.202.100 eq 80
RT-1(config-ext-nacl)#permit ip any any
RT-1(config-ext-nacl)#exit
RT-2(config)#ip access-list extended Server-Filter
RT-2(config-ext-nacl)#deny ip host 192.168.202.100 host
192.168.201.100
RT-2(config-ext-nacl)#permit ip any any
RT-2(config-ext-nacl)#exit
RT-2(config)#ip access-list extended PC-Filter
RT-2(config-ext-nacl)#deny tcp host 192.168.20.10 host
192.168.201.100 eq 80
RT-2(config-ext-nacl)#permit ip any any
RT-2(config-ext-nacl)#exit
RT-4(config)#ip access-list extended Server-Filter
RT-4(config-ext-nacl)#deny ip host 192.168.204.100 host
192.168.203.100
RT-4(config-ext-nacl)#permit ip any any
RT-4(config-ext-nacl)#exit
RT-4(config)#ip access-list extended PC-Filter
RT-4(config-ext-nacl)#deny tcp host 192.168.40.10 host
192.168.203.100 eq 80
RT-4(config-ext-nacl)#permit ip any any
RT-4(config-ext-nacl)#exit
RT-3(config)#ip access-list extended Server-Filter
RT-3(config-ext-nacl)#deny ip host 192.168.203.100 host
192.168.204.100
RT-3(config-ext-nacl)#permit ip any any
RT-3(config-ext-nacl)#exit
RT-3(config)#ip access-list extended PC-Filter
RT-3(config-ext-nacl)#deny tcp host 192.168.30.10 host
192.168.204.100 eq 80
RT-3(config-ext-nacl)#permit ip any any
RT-3(config-ext-nacl)#exit
15.
【Cisco】ラボ#11 拡張ACLの設定・確認
SE 15
FOR
手順【全員共通】インターフェースに適用する
手順 確認する
RT-1#show access-list
Standard IP access list 1
10 deny 192.168.10.0, wildcard bits 0.0.0.255 (16 matches)
20 deny 192.168.20.0, wildcard bits 0.0.0.255 (10 matches)
30 permit any
Extended IP access list PC-Filter
10 deny tcp host 192.168.10.10 host 192.168.202.100 eq www
20 permit ip any any
Extended IP access list Server-Filter
10 deny ip host 192.168.201.100 host 192.168.202.100
20 permit ip any any (8 matches)
RT-1#show ip interface fastEthernet 0 | include access list
Outgoing access list is not set
Inbound access list is Server-Filter
RT-1(config)#interface fastEthernet 0
RT-1(config-if)#ip access-group Server-Filter in
RT-1(config-if)#exit
RT-1(config)#interface gigabitEthernet 0
RT-1(config-if)#ip access-group PC-Filter in
RT-1(config-if)#end
RT-1#show run | section interface FastEthernet0
interface FastEthernet0
ip address 192.168.201.1 255.255.255.0
ip access-group Server-Filter in
duplex auto
speed auto
RT-1#show run | section interface GigabitEthernet0
interface GigabitEthernet0
switchport access vlan 10
no ip address
ip access-group PC-Filter in
RT-1#