
代码
R1 [Huawei]acl 3000 [Huawei-acl-adv-3000]rule deny ip source
192.168.1.1 0.0.0.0 destination 12.0.0. 2 0.0.0.0 [Huawei-acl-adv-3000]rule deny tcp source 192.168.1.2 0.0.0.0 des
[Huawei-acl-adv-3000]rule deny tcp source 192.168.1.2 0.0.0.0
destination 12.0.0 .2 0.0.0.0 destination-port eq telnet
[Huawei-GigabitEthernet0/0/0]traffic-filter inbound acl 3000
R2
[Huawei]user-interface vty 0 4 [Huawei-ui-vty0-4]authentication-mode
aaa [Huawei-ui-vty0-4]q [Huawei]aaa [Huawei-aaa]local-user huawei
password cipher 123456 Info: Add a new user.
R3
[Huawei]ip route-static 0.0.0.0 0 192.168.1.254
R4
[Huawei]ip route-static 0.0.0.0 0 192.168.1.254
结果
PC1.
ping 12.0.0.2 PING 12.0.0.2: 56 data bytes, press CTRL_C to
break
Request time out
Request time out
Request time out
Request time out
Request time out— 12.0.0.2 ping statistics —
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
PC2:
ping 12.0.0.2 PING 12.0.0.2: 56 data bytes, press CTRL_C to
break
Reply from 12.0.0.2: bytes=56 Sequence=1 ttl=254 time=80 ms
Reply from 12.0.0.2: bytes=56 Sequence=2 ttl=254 time=40 ms
Reply from 12.0.0.2: bytes=56 Sequence=3 ttl=254 time=50 ms
Reply from 12.0.0.2: bytes=56 Sequence=4 ttl=254 time=40 ms
Reply from 12.0.0.2: bytes=56 Sequence=5 ttl=254 time=40 ms— 12.0.0.2 ping statistics —
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 40/50/80 ms telnet 12.0.0.2 Press CTRL_] to quit telnet mode Trying 12.0.0.2 … Error: Can’t
connect to the remote host
文章描述了华为路由器的访问控制列表(ACL)配置,禁止了特定IP地址对12.0.0.2的TCP和ICMP通信。同时,PC1无法连接到12.0.0.2,可能由于ACL限制,而PC2能成功ping通但无法telnet到目标地址,可能是端口过滤导致。
1307

被折叠的 条评论
为什么被折叠?



