ACL Inspector – Konfiguracje

ACL Inspector – Konfiguracje

Sieć: ACL Inspector – Konfiguracje.

Projekt sieci składającej się z 3 routerów przedstawiającej działanie list kontroli dostępu jak i inspectora.

Konfiguracje routerów:

Current configuration : 1199 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R2
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
!
no aaa new-model
dot11 syslog
ip source-route
!
!
!
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
voice-card 0
!
!
!
!
!
archive
log config
hidekeys
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0/1/0
ip address 10.1.1.2 255.255.255.252
!
interface Serial0/1/1
ip address 10.2.2.2 255.255.255.252
clock rate 125000
!
interface Serial0/2/0
no ip address
shutdown
clock rate 125000
!
interface Serial0/2/1
no ip address
shutdown
clock rate 125000
!
router eigrp 5
network 10.1.1.0 0.0.0.3
network 10.2.2.0 0.0.0.3
no auto-summary
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
!
!
!
!
!
!
!
!
!
control-plane
!
!
!
ccm-manager fax protocol cisco
!
mgcp fax t38 ecm
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
login
!
scheduler allocate 20000 1000
end

Current configuration : 1810 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R3
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
!
no aaa new-model
dot11 syslog
ip source-route
!
!
!
!
ip cef
ip inspect name myinspect smtp
ip inspect name myinspect tcp
ip inspect name myinspect icmp
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
voice-card 0
!
!
!
!
!
archive
log config
hidekeys
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet0/1
ip address 192.168.3.1 255.255.255.0
ip access-group 102 in
duplex auto
speed auto
!
interface Serial0/1/0
no ip address
shutdown
no fair-queue
clock rate 125000
!
interface Serial0/1/1
ip address 10.2.2.1 255.255.255.252
ip access-group 101 in
ip inspect myinspect in
!
router eigrp 5
passive-interface default
no passive-interface Serial0/1/1
network 10.2.2.0 0.0.0.3
network 192.168.3.0
no auto-summary
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
!
!
access-list 101 permit tcp any host 192.168.3.3 eq smtp
access-list 101 permit icmp any 192.168.3.0 0.0.0.255 echo
access-list 101 permit icmp any 192.168.3.0 0.0.0.255 echo-reply
access-list 101 permit icmp any 192.168.3.0 0.0.0.255 unreachable
access-list 101 permit icmp any 192.168.3.0 0.0.0.255 ttl-exceeded
access-list 101 permit eigrp any any
access-list 102 permit tcp 192.168.3.0 0.0.0.255 any
access-list 102 permit udp 192.168.3.0 0.0.0.255 any
access-list 102 permit icmp 192.168.3.0 0.0.0.255 any
!
!
!
!
!
!
!
control-plane
!
!
!
ccm-manager fax protocol cisco
!
mgcp fax t38 ecm
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
login
!
scheduler allocate 20000 1000
end