ip access-list extended Block_Telnet
R1(config-ext-nacl)#
no 10
R1(config-ext-nacl)#
10 deny tcp host 10.1.1.10 host 172.16.20.254 eq 80
Verify that your list is working.
R1#
telnet 172.16.20.254
Trying 172.16.20.254 ...
% Destination unreachable; gateway or host down
Step 8: Display the ACL again and observe the updated hit counters with each line, and
also verify that the interface is set with the ACL.
R1#
sh access-list
Extended IP access list Block_Telnet
10 deny tcp host 10.1.1.10 host 172.16.20.254 eq telnet (58 matches)
20 permit ip any any (86 matches)
R1#
sh ip int f0/0
FastEthernet0/0 is up, line protocol is up
Internet address is 10.10.10.1/24
Broadcast address is 255.255.255.255
Address determined by non-volatile memory
MTU is 1500 bytes
Helper address is not set
Directed broadcast forwarding is disabled
Multicast reserved groups joined: 224.0.0.10
Outgoing access list is not set
Do'stlaringiz bilan baham: |