코인데일리넷

가상화폐 / NFT / 경제

기타/1

[DAY 30] OSPF 복습 예제 & 네트워크 접근제어

코인데일리넷 매니저 2021. 11. 4. 12:12

---- do show ip route로 확인한 ospf 설정 해줘야 하는 부분 (빨간표시)   

1.0.0.0/8 is variably subnetted, 2 subnets, 2 masks

C 1.1.1.0/24 is directly connected, FastEthernet0/0

L 1.1.1.1/32 is directly connected, FastEthernet0/0

   203.230.7.0/24 is variably subnetted, 4 subnets, 2 masks

C 203.230.7.0/30 is directly connected, Serial0/2/0

L 203.230.7.1/32 is directly connected, Serial0/2/0

C 203.230.7.8/30 is directly connected, Serial0/2/1

L 203.230.7.10/32 is directly connected, Serial0/2/1

 

--OSPF 설정 명령어 ( R0 )---

Router(config)#router ospf 1

Router(config-router)#network 1.1.1.0 0.0.0.255 area 0

Router(config-router)#network 203.230.7.0 0.0.0.3 area 0

Router(config-router)#network 203.230.7.8 0.0.0.3 area 0

 

--OSPF 설정 명령어 ( R1 )---

Router(config)#router ospf 1

Router(config-router)#network 2.2.2.0 0.0.0.255 area 0

Router(config-router)#network 203.230.7.0 0.0.0.3 area 0

Router(config-router)#network 203.230.7.4 0.0.0.3 area 0

 

--OSPF 설정 명령어 ( R2 )---

Router(config)#router ospf 1

Router(config-router)#network 3.3.3.0 0.0.0.255 area 0

Router(config-router)#network 203.230.7.4 0.0.0.3 area 0

Router(config-router)#network 203.230.7.8 0.0.0.3 area 0

 

PC간 통신 (PING) 확인

------ 특정 pc 통신 못하게 하는 방법 (pc1은 허용 , pc0은 불가능하게 하는방법 ---------

Router(config)#access-list 1 ?

deny Specify packets to reject

permit Specify packets to forward

remark Access list entry comment

 

Router(config)#access-list 1 permit 1.1.1.3 0.0.0.0

Router(config)#access-list 1 deny any

 

Router(config)#do show access-list

Standard IP access list 1

10 permit host 1.1.1.3

20 deny any

 

Router(config)#int fa0/0

Router(config-if)#ip access-group 1 ?

in inbound packets

out outbound packets

 

Router(config-if)#ip access-group 1 in

pc2에서 통신을 해본 결과 

위 설정을 취소하고 싶으면 no access-list 1