【文章內(nèi)容簡(jiǎn)介】
1 1 Octet bit position and address value for bit ignore last 6 address bits check all address bits (match all) ignore last 4 address bits check last 2 address bits Examples Wildcard Bits: How to Check the Corresponding Address Bits 169。 2022, Cisco Systems, Inc. ICND —1028 ? Example checks all the address bits ? Abbreviate this wildcard mask using the IP address preceded by the keyword host (host ) Test conditions: Check all the address bits (match all) (checks all bits) An IP host address, for example: Wildcard mask: Wildcard Bits to Match a Specific IP Host Address 169。 2022, Cisco Systems, Inc. ICND —1029 ? Accept any address: ? Abbreviate the expression using the keyword any Test conditions: Ignore all the address bits (match any) (ignore all) Any IP address Wildcard mask:Wildcard Bits to Match Any IP Address 169。 2022, Cisco Systems, Inc. ICND —1030 Check for IP subs Network .host 0 0 0 1 0 0 0 0 Wildcard mask: 0 0 0 0 1 1 1 1 | match | don’t care | 0 0 0 1 0 0 0 0 = 16 0 0 0 1 0 0 0 1 = 17 0 0 0 1 0 0 1 0 = 18 : : 0 0 0 1 1 1 1 1 = 31 Address and wildcard mask: Wildcard Bits to Match IP Subs 169。 1999, Cisco Systems, Inc. 1031 Configuring Standard IP Access Lists 169。 2022, Cisco Systems, Inc. ICND —1032 Standard IP Access List Configuration accesslist accesslistnumber {permit|deny} source [mask] Router(config) ? Sets parameters for this list entry ? IP standard access lists use 1 to 99 ? Default wildcard mask = ? “no accesslist accesslistnumber” removes entire accesslist 169。 2022, Cisco Systems, Inc. ICND —1033 accesslist accesslistnumber {permit|deny} source [mask] Router(config) ? Activates the list on an interface ? Sets inbound or outbound testing ? Default = Outbound ? “no ip accessgroup accesslistnumber” removes accesslist from the interface Router(configif) ip accessgroup accesslistnumber { in | out } ? Sets parameters for this list entry ? IP standard access lists use 1 to 99 ? Default wildcard mask = ? “no accesslist accesslistnumber” removes entire accesslist Standard IP Access List Configuration 169。 2022, Cisco Systems, Inc. ICND —1034 E0 S0 E1 Non Standard IP Access List Example 1 accesslist 1 permit (implicit deny all not visible in the list) (accesslist 1 deny ) 169。 2022, Cisco Systems, Inc. ICND —1035 ? Permit my work only accesslist 1 permit (implicit deny all not visible in the list) (accesslist 1 deny ) interface ether 0 ip accessgroup 1 out interface ether 1 ip accessgroup 1 out Standard IP Access List Example 1 E0 S0 E1 Non 169。 2022, Cisco Systems, Inc. ICND —1036 Deny a specific host Standard IP Access List Example 2 E0 S0 E1 Non accesslist 1 deny 169。 2022, Cisco Systems, Inc. ICND —1037 Standard IP Access List Example 2 E0 S0 E1 Non Deny a specific host accesslist 1 deny accesslist 1 permit (implicit deny all) (accesslist 1 deny ) 169。 2022, Cisco Systems, Inc. ICND —1038 accesslist 1 deny accesslist 1 permit (implicit deny all) (accesslist 1 deny ) interface ether 0 ip accessgroup 1 out Standard IP Access List Example 2 E0 S0 E1 Non ? Deny a specific host 169。 2022, Cisco Systems, Inc. ICND —1039 Deny a specific sub Standard IP Access List Example 3 E0 S0 E1 Non accesslist 1 deny accesslist 1 permit any (implicit deny all) (accesslist 1 deny ) 169。 2022, Cisco Systems, Inc. ICND —1040 accesslist 1 deny accesslist 1 permit any (implicit deny all) (accesslist 1 deny ) interface ether 0 ip accessgroup 1 out Standard IP Access List Example 3 E0 S0 E1 Non ? Deny a specific sub 169。 1999, Cisco Systems, Inc. 1041 Control vty Access With Access Class 169。 2022, Cisco Systems, Inc. ICND —