资源描述:
《Route-map和acl的permit,any动作对路由过滤的影响.pdf》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、By神的幻觉Route-map和acl的permit,any动作对路由过滤的影响此实验讨论route-map中aclpermit和any动作对路由过滤影响。拓扑:LAB1:R1:access-list1permit1.1.1.00.0.0.255!route-mapapermit10matchipaddress1!routerospf1redistributeconnectedsubnetsroute-mapaR2:R2#shipro1.0.0.0/24issubnetted,1subnetsOE21.1.1.
2、0[110/20]via12.1.1.1,00:00:13,FastEthernet0/012.0.0.0/24issubnetted,1subnetsC12.1.1.0isdirectlyconnected,FastEthernet0/0Route-map仅仅重分发了1.1.1.0/24的路由,过滤了其他两条路由。Route-map末尾有一条隐含的denyany子句,这个子句拒绝了其他两条路由,并不是acl的隐含denyany拒绝掉的。By神的幻觉LAB2:R1:access-list1deny1.1.1.0
3、0.0.0.255access-list1permitany!route-mapapermit10matchipaddress1!routerospf1redistributeconnectedsubnetsroute-mapaR2:R2#shipro2.0.0.0/24issubnetted,1subnetsOE22.2.2.0[110/20]via12.1.1.1,00:00:01,FastEthernet0/03.0.0.0/24issubnetted,1subnetsOE23.3.3.0[110/20]
4、via12.1.1.1,00:00:01,FastEthernet0/012.0.0.0/24issubnetted,1subnetsC12.1.1.0isdirectlyconnected,FastEthernet0/0R1的acl由两条语句构成,实际上是由permit子句匹配了2.2.2.0/24和3.3.3.0/24两条路由。所以仅仅重分发aclpermit所匹配的路由。By神的幻觉LAB3:R1:access-list1deny1.1.1.00.0.0.255!route-mapapermit10
5、ro
6、ute-mapadeny10(两个得出的结果一样)matchipaddress1route-mapapermit20!routerospf1redistributeconnectedsubnetsroute-mapaR2#shipro1.0.0.0/24issubnetted,1subnetsOE21.1.1.0[110/20]via12.1.1.1,00:02:17,FastEthernet0/02.0.0.0/24issubnetted,1subnetsOE22.2.2.0[110/20]via12.1.1
7、.1,00:02:17,FastEthernet0/03.0.0.0/24issubnetted,1subnetsOE23.3.3.0[110/20]via12.1.1.1,00:02:17,FastEthernet0/012.0.0.0/24issubnetted,1subnetsC12.1.1.0isdirectlyconnected,FastEthernet0/0R1中的acl拒绝了1.1.1.0/24的路由,但是R2学习到了所有的路由,即没有路由被过滤。可见在route-map中acl的deny子句并没
8、有起到作用,匹配失败。也就是说在Route-map中acl的deny子句单独使用不起到匹配路由的作用。由LAB2可以看出和permitany子句一起使用时将可以起到作用。By神的幻觉LAB4:R1:access-list1deny1.1.1.00.0.0.255access-list1permit2.2.2.00.0.0.255!route-mapapermit10matchipaddress1route-mapapermit20!routerospf1redistributeconnectedsubnetsr
9、oute-mapaR2:R2#shipro1.0.0.0/24issubnetted,1subnetsOE21.1.1.0[110/20]via12.1.1.1,00:00:01,FastEthernet0/02.0.0.0/24issubnetted,1subnetsOE22.2.2.0[110/20]via12.1.1.1,00:00:33,FastEthernet0/03.0.0