interface serial 0 ! 定義接口 description To The Internet ! 目的描述 ip address 161.71.73.33 255.255.255.248 ! 設(shè)置IP地址 ip access-list 101 in ! 定義入站過(guò)濾器 ip access-list 102 out ! 定義出站過(guò)濾器 access-list 101 permit tcp any any established Note 1 ! 答應(yīng)所有tcp業(yè)務(wù)流入,會(huì)話始于園區(qū)網(wǎng)內(nèi)
access-list 101 permit tcp any host 144.254.1.3 eq FTP ! 答應(yīng) ftp 到不潔網(wǎng) !(dirty net )中的ftp服務(wù)器 access-lsit 101 permit tcp any host 144.254.1.3 eq ! 答應(yīng) ftp 數(shù)據(jù)到不潔網(wǎng)中的ftp服務(wù)器 ftp-date
access-list 101 deny ip 127.0.0.0 0.255.255.255 any ! 阻止來(lái)自Internet并以RFC access-list 101 deny ip 10.0.0.0 0.255.255.255 any !保留地址為源的數(shù)據(jù)包入站 access-list 101 deny ip 172.16.0.0 0.240.255.255 any access-list 101 deny ip 192.168.0.0 0.0.255.255 any access-list 101 deny icmp any any echo-reply ! 拒絕任何應(yīng)答 access-list 101 deny icmp any any host-unreachable ! 拒絕任何無(wú)法接通的主機(jī) access-list 101 deny udp any any eq snmp ! 拒絕引入的SNMP access-list 101 deny udp any eq 2000 ! 拒絕引入的openwindows access-list 101 deny udp any any gt 6000 ! 拒絕引入的X-windows access-list 101 deny tcp any any eq 2000 ! 拒絕引入的openwindows access-list 101 deny tcp any any gt 6000 ! 拒絕引入的X-windows access-list 101 deny udp any any eq 69 ! 拒絕引入的tftpd access-list 101 deny udp any any eq 111 ! 拒絕引入的SunRPC access-list 101 deny udp any any eq 2049 ! 拒絕引入的NFS access-list 101 deny tcp any any eq 111 ! 拒絕引入的SunRPC access-list 101 deny tcp any any eq 2049 ! 拒絕引入的 NFS access-list 101 deny tcp any any eq 87 ! 拒絕引入的連接 access-list 101 deny tcp any any eq 512 ! 拒絕引入的 BSD UNIX “r”指令 access-list 101 deny tcp any any eq 513 ! 拒絕引入的 BSD UNIX “r”指令 access-list 101 deny tcp any any eq 514 ! 拒絕引入的 BSD UNIX “r”指令 access-list 101 deny tcp any any eq 515 ! 拒絕引入的 lpd access-list 101 deny tcp any any eq 540 ! 拒絕引入的 uUCpd
access-list 101 permit ip any any ! 其它均答應(yīng)
access-list 102 permit ip 144.254.0.0 0.0.255.255 any ! 只答應(yīng)有源的包 access-list 102 deny ip any any ! 園區(qū)網(wǎng)到Internet的地址