Acls Comandos

Páginas: 6 (1489 palabras) Publicado: 14 de julio de 2012
ACL estándar y extendidas
numerada
access-list 101 deny tcp 172.16.16.0 0.0.0.255 host 172.17.17.252 eq www
access-list 101 permit ip any any
asignar ACL a la interface
interface FastEthernet0/0
ip address 172.16.16.1 255.255.255.0
ip access-group 101 in
Con nombre
ip access-list extended noweb1
deny tcp 172.16.16.0 0.0.0.255 host 172.17.17.252 eq www
permit ip any any
asignar ACLa la interface
interface FastEthernet0/0
ip address 172.16.16.1 255.255.255.0
ip access-group noweb1 in

ACL dinámica
Router(config)#username prueba password cisco
Router(config)#access-list 101 permit tcp any host 10.2.2.2 eq telnet
Router(config)#access-list 101 dynamic testlist timeout 15
permit ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
Router(config)#inteface serial 0/0/1Router(config-if)# ip access-group 101 in
Router(config)#line vty 0 4
Router(config-line)# login local
Router(config-line)# autocommand access-enable host timeout 5
Permite conexión por 15 minutos y la cierra después de 5 de inactividad

ACLs REFLEXIVAS
Router(config)#ip access-list extended OUTBOUNDFILTERS
Router(config-ext-nacl)#permit tcp 192.168.0.0 0.0.255.255 any reflect TCPTRAFFICRouter(config-ext-nacl)#permit tcp 192.168.0.0 0.0.255.255 any reflect ICMPTRAFFIC

Router(config)#ip access-list extended INBOUNDFILTERS
Router(config-ext-nacl)#evaluate TCPTRAFFIC
Router(config-ext-nacl)#evaluate ICMPTRAFFIC

Router(config)#interface serial 0/0/1
Router(config-if)#ip access-group INBOUNDFILTERS in
Router(config-if)#ip access-group OUTBOUNDFILTERS out

ACLs basadasen tiempo
Router(config)#time range EVERYOTHERDAY
Router(config-time-range)#periodic Monday Wednesday Friday 8:00 to 17:00
Router(config)#access-list 101 permit tcp 192.168.0.0 0.0.255.255 any eq telnet time-range EVERYOTHERDAY
Router(config)#interface serial 0/0/1
Router(config-if)#ip access-group 101 out

ACL para el telnet
Router(config)#access-list 10 permit 172.16.16.0 0.0.0.255asignar ACL al VTY
Router(config)#line vty 0 15
Router(config-line)#password cisco
Router(config-line)#login
Router(config-line)#access-class 10 in
Frame relay point to point
R0
interface Serial0/0/0
no ip address
encapsulation frame-relay
interface Serial0/0/0.100 point-to-point
ip address 10.0.0.1 255.255.255.252
frame-relay interface-dlci 100
frame-relay lmi-type (ansi , cisco, q933a), cisco es el default
R1
interface Serial0/0/0
no ip address
encapsulation frame-relay
interface Serial0/0/0.301 point-to-point
ip address 10.0.0.2 255.255.255.252
frame-relay interface-dlci 301
Configuracion nube Frame Relay, Frame Relay Switch
Conf terminal
frame-relay switching
interface s0/0
description PVC_R0_R1
encapsulation frame-relay
frame-relayintf-type dce
frame-relay route 102 interface Serial0/1 201
frame-relay route 103 interface Serial0/2 301
clock rate 64000
no shutdown

interface s0/1
description PVC_R1_R0
encapsulation frame-relay
frame-relay intf-type dce
frame-relay route 201 interface Serial0/0 102
Frame relay mapeo estático
R0
interface Serial0/0/0
encapsulation frame-relay
encapsulation frame-relay ?
ietfUse RFC1490/RFC2427 encapsulation o bien la default que es cisco
ip address 10.0.0.1 255.255.255.252
NO FRAME-RELAY inverse-ARP
frame-relay map ip 10.0.0.2 100 broadcast
R1
interface Serial0/0/0
encapsulation frame-relay
ip address 10.0.0.2 255.255.255.252
NO FRAME-RELAY inverse-ARP
frame-relay map ip 10.0.0.2 100 broadcast
Configuracion nube Frame Relay, Frame Relay Switchframe-relay switching
interface s0/0
description PVC_R0_R1
encapsulation frame-relay
frame-relay intf-type dce
frame-relay route 100 interface Serial0/1 301
interface s0/1
description PVC_R1_R0
encapsulation frame-relay
frame-relay intf-type dce
frame-relay route 301 interface Serial0/0 100
Comandos de verificación
Router#show frame-relay map
Serial0/0/0.201 (up): point-to-point...
Leer documento completo

Regístrate para leer el documento completo.

Estos documentos también te pueden resultar útiles

  • acls
  • Acls
  • Acls
  • acls
  • acls
  • Texto Acls
  • comandos
  • Comandos

Conviértase en miembro formal de Buenas Tareas

INSCRÍBETE - ES GRATIS