1、Basic Traffic Management with Access Lists Module 9Copyright 1998, Cisco Systems, Inc. Managing IPManaging IPCopyright 1998, Cisco Systems, Inc. Configure IP standard access lists Limit virtual terminal access Configure IP extended access lists Verify access list configuration Configure an alternati
2、ve to using access lists Configure an IP helper address to manage broadcastsObjectivesUpon completion of this module, you will be able to perform the following tasks:Managing IPCopyright 1998, Cisco Systems, Inc.Managing IP Traffic Overview Limit traffic and restrict network useEnable directed forwa
3、rding of broadcastsXBroadcastFTP XManaging IPCopyright 1998, Cisco Systems, Inc.Access List Applications Access lists control packet movement through a networkVirtual terminal line access (IP)Transmission of packets on an interfaceManaging IPCopyright 1998, Cisco Systems, Inc.QueueListPriority and c
4、ustom queuingOther Access List Uses Access lists are multipurposeDial-on-demand routingRoute filteringRoutingTableConfiguring IP Standard Access ListsCopyright 1998, Cisco Systems, Inc. Managing IPManaging IPCopyright 1998, Cisco Systems, Inc.172.16.5.0IP Standard Access Lists Overview Use source ad
5、dress only Access list range: 1 to 9910.0.0.3Destination Address Source Address172.16.5.17XManaging IPCopyright 1998, Cisco Systems, Inc.For Standard IP Access ListsRoute to interfaceIncoming packet Access list?Next entry in list Does sourceaddress match?More entries?Apply conditionDeny PermitYes No
6、 YesNoICMP Message Forward PacketYesNoInbound Access List ProcessingManaging IPCopyright 1998, Cisco Systems, Inc.Forward PacketFor Standard IP Access ListsICMP MessageIncoming packetDoes sourceaddress match?More entries?PermitYes No YesNoRoute to interfaceYesNoNext entry in listApply conditionAcces
7、s list?DenyOutbound Access List ProcessingManaging IPCopyright 1998, Cisco Systems, Inc.Class B subnetsClass CsubnetsHigh-Order Bits First Octet Class Standard Mask0101101-126128-191192-223ABC255.0.0.0255.255.0.0255.255.255.00123456789101112131415255.255.0.0255.255.128.0255.255.192.0255.255.224.0255.255.240.0255.255.248.0255.255.252.0255.255.254.0255.255.255.0255.255.255.128255.255.255.192255.255.255.224255.255.255.240255.255.255.248255.255.255.252255.255.255.25401234567IP Addressing Review