ÍøÂ綪°üÊÇʲô£¿ÍøÂ綪°üÔõô°ì£¿
ÍøÂ綪°üÊÇÖ¸ÔÚÍøÂçÉÏ´«ÊäµÄÊý¾Ý°üÔÚ´«Êä¹ý³ÌÖжªÊ§»òË𻵵ÄÏÖÏó¡£ÕâÖÖÏÖÏó¿ÉÄܻᵼÖÂÍøÂçÁ¬½ÓÖжϡ¢Ó¦ÓóÌÐò±ÀÀ£»òÊý¾Ý¶ªÊ§µÈÎÊÌâ¡£
×ÜÌå˼·£º
1¡¢ ÏÈÈ·¶¨ÊÇ·ñ·¢Éú¶ª°üÒÔ¼°ÄÄЩÉ豸·ÃÎʵÄʱºò»á·¢Éú¶ª°ü£»ÔÙÕ¹¿ªËµ¾ÍÊǵ±·¢ÏÖÉ豸·ÃÎÊÄ³Ò»Íø¶ÎʱÓжª°ü£¬¿ÉÒÔÏÈÔÚ¶ą̀É豸ÉÏÈ¥ ping Ä¿µÄÍø¶ÎµÄÖÜΧµÄ¶à¸öÍø¶Î£¬ÓÃÓÚÈ·¶¨ÊǺÎÖÖÁ÷Á¿¶ª°ü»¹ÊÇËùÓÐÁ÷Á¿¶¼»á¶ª°ü£»
Èç¹ûÊǾßÌåÒ»ÖÖÁ÷Á¿¶ª°üµÄ»°¿ÉÒÔÈ·¶¨Îª×öÁË·ÓɲßÂÔ»òÕß²ßÂÔ·ÓÉ£»
Èç¹ûÊǶàÖÖÁ÷Á¿¶¼¶ª°ü£¬Ôì³ÉµÄÔÒò¾Í¿ÉÄܺܶ࣬ÎïÀí²ã¡¢Êý¾ÝÁ´Â·²ã¡¢ÍøÂç²ãÒÔ¼°²ßÂÔ·Óɶ¼ÓпÉÄÜ£»
2¡¢ Åж϶ª°üµÄλÖ㬼´¶¨Î»£»
·½·¨ÓÐÁ½ÖÖ£º
µÚÒ»ÖÖ£¬Ê¹Óà ping ºÍ tracert Ò»¶ÎÒ»¶Î²âÊÔ£¬ÏÈ ping Íø¹Ø£¬È»ºóÊÇÍø¹ØµÄÏÂÒ»Ìø£¬Ò»Ö±µ½Ä¿µÄµØÖ·£¬»òÕßÓà tracert ¸ú×Ù¿ÉÒÔÈ·¶¨¾ßÌåÔÚÄÄÒ»Ìø¶ª°ü£»ÕâÖÖ·½·¨¼òµ¥£¬µ«½ÏΪ´Ö²ÚһЩ£¬ÒòΪ¶ª°ü¿ÉÄÜÊǼäЪÐԵģ¬ÐèÒª¶à´Îping ºÍtracert£¬²âÊÔ¶à´Î¡£
µÚ¶þÖÖ£¬Ê¹ÓÃÁ÷Á¿Í³¼ÆµÄ·½·¨£¬Èçͼ£¬ÑØ×Å·¢Éú¶ª°üµÄÁ´Â·£¬ÔÚÉ豸µÄÈë½Ó¿ÚºÍ³ö½Ó¿ÚÉϲ¿ÊðÁ÷²ßÂÔ£¬·Ö±ðͳ¼ÆÈë½Ó¿ÚµÄ Inbound ·½ÏòºÍ³ö½Ó¿ÚµÄ Outbound ·½ÏòµÄÌØ¶¨±¨ÎÄ£¬ ÒÔÈ·ÈϸÃÀ౨ÎÄÊÇ·ñÔÚ±¾É豸±»¶ªÆú¡£
3¡¢ ÅŲé¾ßÌ嶪°üÔÒò
ÍøÂ綪°üµÄÔÒòÓкܶ࣬ÀýÈç:
1. Ïß·ÎÊÌ⣺Ïß·ÖÊÁ¿²»¼Ñ¡¢Ïß·ÀÏ»¯¡¢Ïß·˥¼õµÈ¶¼¿ÉÄܵ¼ÖÂÍøÂ綪°ü¡£
2. ·ÓÉÆ÷ÎÊÌ⣺·ÓÉÆ÷¹ÊÕÏ¡¢ÅäÖôíÎóµÈ¶¼¿ÉÄܵ¼ÖÂÍøÂ綪°ü¡£
3. ²¡¶¾ºÍ¶ñÒâÈí¼þ£º²¡¶¾ºÍ¶ñÒâÈí¼þ¹¥»÷ÍøÂçϵͳ£¬Õ¼ÓÃÍøÂç×ÊÔ´£¬µ¼ÖÂÍøÂ綪°ü¡£
4. ÍøÂç·ç±©£ºÍøÂç·ç±©»áµ¼ÖÂÍøÂç´ø¿í±»Õ¼Ó㬴Ӷøµ¼ÖÂÍøÂ綪°ü¡£
5. ÆäËûÒòËØ£ºÌìÆøÒòËØ¡¢µçÁ¦¹ÊÕϵȶ¼¿ÉÄܵ¼ÖÂÍøÂ綪°ü¡£
ΪÁ˽â¾öÕâ¸öÎÊÌ⣬76net±ØÓ®¹ÙÍøÊÖ»ú°æ¿ÉÒÔ²ÉÈ¡ÒÔÏ´ëÊ©:
¼ì²éÏß·£º¼ì²éÍøÂçÏß·µÄÖÊÁ¿ºÍÎȶ¨ÐÔ£¬È·±£Ïß·ûÓÐË¥½ß»òÕßË𻵡£
2. ¼ì²é·ÓÉÆ÷£º¼ì²é·ÓÉÆ÷µÄÅäÖúÍÐÔÄÜ£¬È·±£Â·ÓÉÆ÷ûÓгöÏÖ¹ÊÕÏ¡£
3. ɱ¶¾ºÍÓÅ»¯£º¶¨ÆÚʹÓÃɱ¶¾Èí¼þºÍϵͳÓÅ»¯¹¤¾ßɱ¶¾ºÍÓÅ»¯ÏµÍ³£¬È·±£ÍøÂçϵͳûÓв¡¶¾ºÍ¶ñÒâÈí¼þµÄ¹¥»÷¡£
4. ÓÅ»¯ÍøÂ磺ÓÅ»¯ÍøÂç´ø¿í¡¢ÑÓ³ÙºÍÍÌÍÂÁ¿µÈ²ÎÊý£¬È·±£ÍøÂçϵͳÔËÐÐÁ÷³©¡£
5. ÁªÏµÔËÓªÉÌ£ºÈç¹ûÒÔÉÏ´ëÊ©ÎÞ·¨½â¾öÎÊÌ⣬¿ÉÒÔÁªÏµÍøÂçÔËÓªÉÌ£¬ÈÃËûÃǼì²éÏß·ºÍÉ豸£¬²¢¼°Ê±´¦Àí¹ÊÕÏ¡£
¾ßÌå´¦Àí·½Ê½ÈçÏ£º
¶Ë¿Úa Èë·½ÏòºÍ¶Ë¿Úb ³ö·½Ïò£¬¶Ë¿Ú b ³ö·½ÏòºÍ¶Ë¿Úc Èë·½ÏòµÄÁ÷Á¿Í³¼ÆÇé¿ö¾Í²âÊÔ¸÷ÖÖÇé¿ö¡£
ÅÐ¶Ï¶Ë¿Ú a Èë·½ÏòºÍ¶Ë¿Úb ³ö·½Ïò Passed ¼ÆÊý´óÖÂÏàµÈ£¬ËµÃ÷´Ë´¦ÎÞ¶ª°ü¡£
ÅÐ¶Ï¶Ë¿Ú a Èë·½ÏòµÄ±¨ÎÄ Passed ¼ÆÊý¶àÓÚ¶Ë¿Ú b ³ö·½ÏòµÄ±¨ÎÄ Passed ¼ÆÊý£¬ËµÃ÷¶ª°ü·¢ÉúÔÚ Switch_3¡£
Åж϶˿Úb ³ö·½ÏòºÍ¶Ë¿Úc Èë·½ÏòPassed ¼ÆÊý´óÖÂÏàµÈ£¬ËµÃ÷´Ë´¦ÎÞ¶ª°ü¡£
Åж϶˿Úb ³ö·½ÏòµÄ±¨ÎÄPassed ¼ÆÊý¶àÓÚ¶Ë¿Úc Èë·½ÏòµÄ±¨ÎÄPassed ¼ÆÊý£¬ËµÃ÷¶ª°ü
·¢ÉúÔÚ Switch_3 ºÍ Switch_2 Ö®¼äµÄÎïÀíÁ´Â·ÉÏ£¬Çë²Î¿¼¼ì²éÉ豸֮¼äµÄÎïÀíÁ´Â·½øÐж¨Î»´¦Àí¡£
Á÷Á¿Í³¼ÆÅäÖ÷½·¨£º
a. ÅäÖà ACL ¹æÔò¡£
<Switch_3> system-view[Switch_3 acl number 3000[Switch_3-acl-adv-3000] rule permit icmp source 192.168.100.1 0destination 202.10.1.1 0[Switch_3-acl-adv-3000] quit
b. ÅäÖÃÁ÷·ÖÀà¡£
[Switch_3] traffic classifier 3000[Switch_3-classifier-3000] if-match acl 3000[Switch_3-classifier-3000] quit
c. ÅäÖÃÁ÷ÐÐΪ¡£
[Switch_3] traffic behavior 3000[Switch_3-behavior-3000] statistic enable[Switch_3-behavior-3000] quit
d. ÅäÖÃÁ÷²ßÂÔ¡£
[Switch_3] traffic policy 3000[Switch_3-trafficpolicy-3000] classifier 3000 behavior 3000[Switch_3-trafficpolicy-3000] quit
e. ÔÚ½Ó¿ÚÉÏÓ¦ÓÃÁ÷²ßÂÔ¡£
[Switch_3] interface gigabitethernet 1/0/2[Switch_3-GigabitEthernet1/0/2] traffic-policy 3000 inbound[Switch_3-GigabitEthernet1/0/2] quit