Anda di halaman 1dari 1

Access Control Lists

====================
Example 1: Only ITAdmin is permitted to telnet to Router
-------------------------------------------------------Router(config)#ip access-list standard RST-TELNET
Router(config-std-nacl)#permit host 172.16.4.2
Router(config-std-nacl)#exit
Router(config)#line vty 0 4
Router(config-line)#access-class RST-TELNET in
Router(config-line)#exit
Example 2: Student is not permitted to access faculty PC
-------------------------------------------------------Router(config)#ip access-list extended 100
Router(config-ext-nacl)#deny ip 172.16.2.0 0.0.0.255 172.16.3.0 0.0.0.63
Router(config-ext-nacl)#permit ip any any
Router(config-ext-nacl)#exit
Router(config)#int f0/0.20
Router(config-subif)#ip access-group 100 in
Router(config-subif)#exit
Example 3: Student is not permitted to browse grade server
---------------------------------------------------------Router(config)#int f0/0.20
Router(config-subif)#no ip access-group 100 in
Router(config-subif)#exit
Router(config)#ip access-list extended 101
Router(config-ext-nacl)#remark deny student vlan to faculty vlan
Router(config-ext-nacl)#deny ip 172.16.2.0 0.0.0.255 172.16.3.0 0.0.0.63
Router(config-ext-nacl)#remark deny student vlan to browse grade server
Router(config-ext-nacl)#deny tcp 172.16.2.0 0.0.0.255 host 172.16.1.10 eq www
Router(config-ext-nacl)#permit ip any any
Router(config-ext-nacl)#exit
Router(config)#int f0/0.20
Router(config-subif)#ip access-group 101 in
Router(config-subif)#exit

Anda mungkin juga menyukai