|
http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=498 [복사]
문제------------------------------------------------------------
you hav been tasked to create and apply a numberd access list to a single oubound interface in not more than three statements
1.Host c should be able to use a web brower (HTTP) to access the finance web server.
2.Other types of access from host C to the finance web server should be blocked.
3.All access from hosts in the core or local LAN to the finace web server should be blocked.
4.All hosts in the core and on local lan should be able to access the public web server.
you hav been tasked to create and apply a numberd access list to a single oubound interface in not more than three statements
All passwords have been temporarily set to “cisco”.
The Core connection uses an IP address of 198.18.196.65
The computers in the Hosts LAN have been assigned addresses of 192.168.33.1 ? 192.168.33.254
Host A 192.168.33.1
Host B 192.168.33.2
Host C 192.168.33.3
Host D 192.168.33.4
The servers in the Server LAN have been assigned addresses of 172.22.242.17 ~ 172.22.242.30
The Finance Web Server is assigned an IP address of 172.22.242.23.
----------------------------------------------------------------------------------------------------------------
이 문제에관한 답을 쓴 명령인데요
access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80 (여기에 생략되어있는게있다는데...)
access-list 100 deny ip any host 172.22.242.23
access-list 100 permit ip any any
!
interface fastether 0/1
ip access-group 100 out -> 이거는 그 라우터에서 나가는걸 막는다는 뜻인가요 ?
이명령들 해석을모르겠습니다.. |
Hit : 3838 Date : 2011/12/29 10:36
|