949, 1/48 회원가입  로그인  
   sayhung
   CCNA 덤프중 명령해석문의드립니다.

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=498 [복사]


문제------------------------------------------------------------
you hav been tasked to create and apply a numberd access list to a single oubound interface in not more than three statements

1.Host c should be able to use a web brower (HTTP) to access the finance web server.

2.Other types of access from host C to the finance web server should be blocked.

3.All access from hosts in the core or local LAN to the finace web server should be blocked.

4.All hosts in the core and on local lan should be able to access the public web server.

you hav been tasked to create and apply a numberd access list to a single oubound interface in not more than three statements

All passwords have been temporarily set to “cisco”.

The Core connection uses an IP address of 198.18.196.65

The computers in the Hosts LAN have been assigned addresses of 192.168.33.1 ? 192.168.33.254

Host A 192.168.33.1
Host B 192.168.33.2
Host C 192.168.33.3
Host D 192.168.33.4

The servers in the Server LAN have been assigned addresses of 172.22.242.17 ~ 172.22.242.30

The Finance Web Server is assigned an IP address of 172.22.242.23.
----------------------------------------------------------------------------------------------------------------
이 문제에관한 답을 쓴 명령인데요

access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80 (여기에 생략되어있는게있다는데...)
access-list 100 deny ip any host 172.22.242.23
access-list 100 permit ip any any
!
interface fastether 0/1            
ip access-group 100 out    -> 이거는 그 라우터에서 나가는걸 막는다는 뜻인가요 ?
이명령들 해석을모르겠습니다..

  Hit : 3838     Date : 2011/12/29 10:36



    
akrwosla 제가 배운지 좀되서 ..살짝 기억나는걸로는..저 적용내용을.. 0/1로 나갈때 적용시키는게 아니였나 하는데.. 확실한 답변못해드리겠네요..ㅠㅠ 2011/12/30  
akrwosla 책자 찾아보고 검색해본결과.. 이더넷으로 나가는거에서 막는다는 뜻이네요 ㅎ
2011/12/30  
gorani access-list 100 permit tcp host 192.168.33.3 host 172.22.242.23 eq 80 (여기에 생략되어있는게있다는데...)
access-list 100 deny ip any host 172.22.242.23
access-list 100 permit ip any any
!
interface fastether 0/1
ip access-group 100 out


;;; 막는다는 뜻이 아닙니다.

여기서 패킷이 들어오고 나간다는 개념이 상대적이라 처음에는 많이 헤깔려 하십니다.

외부에서 serial 포트로 패킷이 들어와서 fa쪽으로 나가는 것이므로

serial인터페이스로 들어와서 fa0/1 인터페이스로 나가는 패킷에

ACL 100번 설정을 적용하겠다는 뜻이네요.



host -> sever(가정) 으로 패킷을 보내는것이라고 생각하면

sever 입장에서는 라우터에서 패킷이 빠져나와서 자신에게 오는것이므로 out 이 맞습니다.

sever의 라우터 입장에서 serial 인터페이스에 ACL100을 적용한다면 in 으로 하는게 맞겠지요

외부에서 라우터로 패킷이 들어오는거니까요
2012/01/02  
sayhung 아 해석해주신분들 감사합니다ㅜㅜ 2012/01/04