分类: 系统运维
2009-05-19 14:04:06
环境:两台路由器由串口相连。
要求:只允许R1的loop 1能ping 通R2的loop 0;并且在R2上做telnet访问控制,只允许R1的loop 0能够远程登录,不能使用deny语句。
步骤一、连通性配置
r1的配置:
r1(config)#interface loopback 0
r1(config-if)#ip address
r1(config-if)#interface loopback 1
r1(config-if)#ip adress
r1(config-if)#interface s0
r1(config-if)#ip address 30.1.1.1 255.255.255.0
r1(config-if)#no shutdown
r1(config)#ip route
r2的配置:
r2(config)#interface loopback 0
r2(config-if)#ip address
r2(config-if)#interface s1
r2(config-if)#ip address 30.1.1.2 255.255.255.0
r2(config-if)#clock rate 64000
r2(config-if)#no shutdown
r2(config)#ip route
做ping测试:
r1#ping
Protocol [ip]:
Target IP address:
Extended commands [n]: y
Source address or interface:
!!!!!
步骤二、配置VTY
r2(config)#line vty 0 4
r2(config-line)#login local à使用本地用户数据库
测试:
r1#telnet 30.1.1.2 /source-interface loopback 0 à使用回环接口做为源
Trying 30.1.1.2 ... Open
User Access Verification
Password:
r2>
r1#telnet 30.1.1.2 /source-interface loopback
Trying 30.1.1.2 ... Open
User Access Verification
Username: cisco à 输入用户名
Password: à输入密码,登录r2
r2>
步骤三、配置访问列表
r2(config)#access-list 102 permit icmp host
r2(config)#access-list 102 permit tcp any any eq telnet à创建扩展访问列表102
r2(config)#interface s1
r2(config-if)#ip access-group
r2(config-if)#
ping测试:
r1#ping
Protocol [ip]:
Target IP address:
Extended commands [n]: y
Source address or interface:
!!!!!
r1#ping
Protocol [ip]:
Target IP address:
Extended commands [n]: y
Source address or interface:
…..
步骤四、创建telnet访问列表
r2(config)#access-list 10 permit host
r2(config)#line vty 0 4
r2(config-line)#access-class
r2(config-line)#exit
r2(config)#
测试:
r1#telnet 30.1.1.2
Trying 30.1.1.2 ...
% Connection refused by remote host
r1#telnet 30.1.1.2 /source-interface loopback 0
Trying 30.1.1.2 ... Open
User Access Verification
Password:
r2>
步骤五、显示配置结果
访问列表配置:
r2#show access-lists à显示访问列表
Standard IP access list 10
permit
Extended IP access list 102
Permit icmp host
permit tcp any any eq telnet (162 matches)
r1当前配置:
r1#show running-config
hostname r1
no ip domain-lookup
!
interface Loopback0
ip address
!
interface Loopback1
ip address
!
interface Serial0
ip address 30.1.1.1 255.255.255.0
clockrate 64000
!
ip route
!
end
r2的当前配置:
r2#show running-config
!
hostname r2
!
no ip domain-lookup
!
interface Loopback0
ip address
!
interface Serial1
ip address 30.1.1.2 255.255.255.0
ip access-group
!
ip route
!
access-list 10 permit
access-list 102 permit icmp host
access-list 102 permit tcp any any eq telnet
!
line vty 0 4
access-class
password cisco
login
!
end