【正文】
Router (configif) ip summaryaddress eigrp asnumber address mask ? 允許在一個(gè)指定的接口進(jìn)行總結(jié)廣播 ? 關(guān)閉自動(dòng)總結(jié) ip address router eigrp 1 work work no autosummary router eigrp 1 work int s0 ip summaryaddress eigrp 1 S0 World 路由總結(jié)實(shí)例 Router (config) ip route work [ mask ] address [ distance ] Router (config) ip route work [ mask ] interface [ distance ] 靜態(tài)路由配置 ? 定義一條到 IP目的網(wǎng)絡(luò)或子網(wǎng)的路徑 – 缺省的管理距離 1 ? 需要重新分配 ? 定義一條到 IP目的網(wǎng)絡(luò)或子網(wǎng)的路徑 ? 缺省的管理距離 0 (意思是直接相連 ) ? 自動(dòng)重新分配 D E 靜態(tài)路由的重新分配 D E ip route ip route ! router eigrp 1 work defaultmetric 10000 100 255 1 1500 redistribute static distributelist 3 out static ! accesslist 3 permit passiveinterface s0 S0 B A C show ip protocols Router 校驗(yàn)增強(qiáng) IGRP 運(yùn)作 ? 顯示當(dāng)前激活的路由協(xié)議進(jìn)程的參數(shù)和當(dāng)前狀態(tài) show ip route eigrp Router ? 顯示路由表中當(dāng)前的 IGRP入口 show ip eigrp neighbors Router 校驗(yàn)增強(qiáng) IGRP 運(yùn)作 (續(xù) .) ? 顯示 IP 增強(qiáng) IGRP發(fā)現(xiàn)的鄰居 show ip eigrp topology Router ? 顯示 IP增強(qiáng) IGRP 拓?fù)浔? show ip eigrp traffic Router ? 顯示 IP 增強(qiáng) IGRP發(fā)送和接收到的包 Basic Traffic Management with Access Lists Module 9 Copyright ?1998, Cisco Systems, Inc. Managing IP ? Configure IP standard access lists ? Limit virtual terminal access ? Configure IP extended access lists ? Verify access list configuration ? Configure an alternative to using access lists ? Configure an IP helper address to manage broadcasts 目標(biāo) 在完成本章學(xué)習(xí)基礎(chǔ)上 , 你應(yīng)該能執(zhí)行以下任務(wù) Access List 應(yīng)用 ? 訪問列表可以控制通過網(wǎng)絡(luò)的包轉(zhuǎn)發(fā) 虛擬終端訪問 (IP) 在一個(gè)端口上傳遞一個(gè)包 Queue List Priority and custom queuing 其他訪問列表使用 ? 訪問列表是多用途的 Dialondemand routing Route filtering Routing Table 配置 IP 標(biāo)準(zhǔn) 訪問列表 Copyright ?1998, Cisco Systems, Inc. Managing IP IP Standard Access Lists Overview ? Use source address only ? Access list range: 1 to 99 Destination Address Source Address X For Standard IP Access Lists Route to interface Ining packet Access list? Next entry in list Does source address match? More entries? Apply condition Deny Permit Yes No Yes No ICMP Message Forward Packet Yes No Inbound Access List Processing Forward Packet For Standard IP Access Lists ICMP Message Ining packet Does source address match? More entries? Permit Yes No Yes No Route to interface Yes No Next entry in list Apply condition Access list? Deny Outbound Access List Processing Class B subs Class C subs HighOrder Bits First Octet Class Standard Mask 0 10 110 1126 128191 192223 A B C 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 0 1 2 3 4 5 6 7 IP Addressing Review exactly host Address Mask Matches any address work only sub * local broadcast * Assuming sub mask of ? 0 bit = must match bits in addresses ? 1 bit = unconditional match for bits in addresses Access Lists Use Wildcard Mask ? To create an access list, perform the following tasks: – Define an access list Apply the list to an interface Access List Configuration Tasks Router (config) accesslist accesslistnumber { permit | deny } { source [ sourcewildcard ] | any } Standard Access List Commands ? Defines a standard access list (numbered 199) Router (configif) ip accessgroup accesslistnumber { in | out } ? Applies an access list to a specific interface correct mon errors accesslist 1 permit ! accesslist 1 permit accesslist 1 permit accesslist 1 deny any accesslist 1 deny For Standard IP Access Lists not needed Implicit Masks ? Omitted mask assumed to be ? Last two lines unnecessary (implicit deny any) Configuration Principles ? Topdown processing – Place more specific references first ? Implicit deny any – Unless access list ends with explicit permit any ? New lines added to the end – Cannot selectively add/remove lines ? Undefined access list = permit any – Need to create access list lines for implicit deny any Standard Access List Example Router (config) accesslist 2 permit Router (config) accesslist 2 deny Router (config) accesslist 2 permit Router (config) !(Note: all other access implicitly denied) Router (config) interface ether 0 Router (configif) ip accessgroup 2 in E0 Inter A B C D ? Who can connect to A? accesslist 3 deny accesslist 3 permit any B A E0 E0 E0 E0 E1 E1 E1 E1 C D W A V X Y Z B C D Location of Standard Access Lists ? On which router should the access list be configured to deny host Z access to host V? ? How does location of a standard access list change the policy implemented? E0 E1 E0 E1 E2 S0 W X Z A B Outside World Written Exercise: IP Standard Access Lists