




已阅读5页,还剩1页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
不同于用于匹配流量的IP访问列表,IP前缀列表主要是用来指定具体的网络可达的。前缀列表用来匹配前缀(网段)和前缀长度(子网掩码)。前缀列表有两个参数很难理解。下面是普通的前缀列表的参数:ip prefix-list name permit | deny prefix/lenname为任意的名字或者数字,prefix是指定的路由前缀(网段),len是指定的前缀长度(子网掩码)。例子如下:ip prefix-list LIST permit 1.2.3.0/24上面的例子中指定匹配网段1.2.3.0,并且指定子网掩码为255.255.255.0,这个列表不匹配1.2.0.0/24,也不匹配1.2.3.4/32ip prefix-list LIST permit 0.0.0.0/0上面的例子指定匹配网段0.0.0.0和子网掩码0.0.0.0。这个列表用来匹配默认路由。通常情况下,在使用前缀列表的时候加上“GE”(大于或等于)和“LE”(小于或等于)时比较容易发生混淆。这是因为当使用“GE”和“LE”时,列表的长度(len)发生了改变。另外一种前缀列表的参数:ip prefix-list name permit | deny prefix/len ge min_length le max_lengthname为任意的名字或者数字,prefix是将要进行比较的路由前缀(网段),len是指从最左边开始的比特位,min_length为最小的子网掩码的值,max_length为最大的子网掩码的值使用GE和LE,必须满足下面的条件:len GE = LE上面的参数很容易混淆,简单的说就是一个匹配前缀或子网的地址的范围。看下面的例子:ip prefix-list LIST permit 1.2.3.0/24 le 32上面的例子表示前缀1.2.3.0前面的24位必须匹配。此外,子网掩码必须小于或等于32位ip prefix-list LIST permit 0.0.0.0/0 le 32上面的例子意味着0位需要匹配,此外子网掩码必须小于或等于32位。一位所有的网段的掩码都小于或等于32位,并且一位都不用匹配,所以这句话等于permit anyip prefix-list LIST permit 10.0.0.0/8 ge 21 le 29上面的例子说明网段10.0.0.0的前8位必须匹配,此外子网掩码必须在21位和29位之间。注意:使用前缀列表不能像访问列表那样匹配具体的应用流。前缀列表也不能用来具体匹配奇数或偶数的前缀,或什么可以被15整除的前缀在前缀列表中,比特位必须是连续的,并且从左边开始ip prefix-list fuck permit 0.0.0.0/0 ge 1 表示除了默认路由外的所有路由ip prefix-list test16 seq 5 permit 0.0.0.0/1 ge 8 le 8 配置A类地址ip prefix-list test16 seq 10 permit 128.0.0.0/2 ge 16 le 16 配置B类地址ip prefix-list test16 seq 15 permit 192.0.0.0/3 ge 24 le 24 配置C类地址-Exercises:1. Construct a prefix list that permits only the 192.168.1.0/24 network.ip prefix-list test1 seq 5 permit 192.168.1.0/242. Construct a prefix list that denies network 119.0.0.0, and permits all other prefixes (including all subnets of 119.0.0.0).ip prefix-list test2 seq 5 deny 119.0.0.0/8ip prefix-list test2 seq 10 permit 0.0.0.0/0 le 323. Construct a prefix list that permits only the default route.ip prefix-list test3 seq 5 permit 0.0.0.0/04. Construct a prefix list the permits everything except the default route.ip prefix-list test4 seq 5 deny 0.0.0.0/0ip prefix-list test4 seq 10 permit 0.0.0.0/0 le 325. Construct a prefix list that permits network 172.16.0.0 and any of its subnets, and denies all other prefixes.ip prefix-list test5 seq 5 permit 172.16.0.0/16 le 326. Construct a prefix list that permits only the following prefixes: 10.2.8.32/27 10.2.8.32/28 10.2.8.32/29 10.2.8.32/30ip prefix-list test6 seq 5 permit 10.2.8.32/27 le 307. Construct a prefix list that:Permits 197.25.94.128/25 Denies 197.25.94.192/26 Permits 197.25.94.224/27 Denies 197.25.94.240/28 Permits 197.25.94.248/29 Denies 197.25.94.252/30 Permits all other prefixes, except for 198.82.0.0/16ip prefix-list test7 seq 5 deny 197.25.94.192/26ip prefix-list test7 seq 10 deny 197.25.94.240/28ip prefix-list test7 seq 15 deny 197.25.94.252/30ip prefix-list test7 seq 20 deny 198.82.0.0/16ip prefix-list test7 seq 25 permit 0.0.0.0/0 le 328. Construct a prefix list that permits any prefix matching the first 20 bits of 175.29.64.0 which has a mask of at least /26 but not exceeding /29, and denies all other prefixes.ip prefix-list test8 seq 5 permit 175.29.64.0/20 ge 26 le 299. Construct a prefix list that denies any prefix matching the first 19 bits of 15.26.96.0 with any mask up to and including /32, and permits any other prefix.ip prefix-list test9 seq 5 deny 15.26.96.0/19 le 32ip prefix-list test9 seq 10 permit 0.0.0.0/0 le 3210. Construct a prefix list that denies the RFC 1918 private networks and any of their subnets, and permits everything else.ip prefix-list test10 seq 5 deny 10.0.0.0/8 le 32ip prefix-list test10 seq 10 deny 172.16.0.0/12 le 32ip prefix-list test10 seq 15 deny 192.168.0.0/16 le 32ip prefix-list test10 seq 20 permit 0.0.0.0/0 le 3211. Construct a prefix list that permits any subnet of network 15.0.0.0 (but not the network), and denies everything else. Your router lies within AS 65011. Place the prefix list in service in the inbound direction with BGP neighbor 1.2.3.4.ip prefix-list test11 seq 5 permit 15.0.0.0/8 ge 9To place it in service: router bgp 65011neighbor 1.2.3.4 prefix-list test11 in12. Construct a prefix list that denies 162.56.0.0/16 and all of its subnets (with the exception of 162.56.209.208/29, which is permitted), and permits all other prefixes. Your router lies within AS 65012. Place the prefix list in service in the outbound direction with its BGP neighbor having address 5.6.7.8.ip prefix-list test12 seq 5 permit 162.56.209.208/29ip prefix-list test12 seq 10 deny 162.56.0.0/16 le 32ip prefix-list test12 seq 15 permit 0.0.0.0/0 le 32To place it in service: router bgp 65012neighbor 5.6.7.8 prefix-list test12 out13. Construct a prefix list that permits the CIDR block containing the thirty-two class C networks beginning with 200.202.160.0/24, and denies everything else. Your router is within AS 65013. Place the prefix list in service in the inbound direction with BGP peer-group Lucky_13.ip prefix-list test13 seq 5 permit 200.202.160.0/19To place it in service: router bgp 65013neighbor Lucky_13 prefix-list test13 in14. Construct a prefix list that denies any prefix for which the most-significant four bits are 0110, and permits everything else.ip prefix-list test14 seq 5 deny 96.0.0.0/4 le 32ip prefix-list test14 seq 10 permit 0.0.0.0/0 le 3215. Construct a prefix list that permits the host address of CatSpace, and denies everything else.ip prefix-list test15 seq 5 permit 64.82.100.67/3216. Construct a prefix list that permits only classful networks, and denies everything else.ip prefix-list test16 seq 5 permit 0.0.0.0/1 ge 8 le 8ip prefix-list test16 seq 10 permit 128.0.0.0/2 ge 16 le 16ip prefix-list test16 seq 15 permit 192.0.0.0/3 ge 24 le 2417. Construct a prefix list that denies only supernets, and permits everything else.ip prefix-list test17 seq 5 deny 0.0.0.0/1 le 7ip prefix-list test17 seq 10 deny 128.0.0.0/2 le 15ip prefix-list test17 seq 15 deny 192.0.0.0/3 le 23ip prefix-list test17 seq 20 permit 0.0.0.0/0 le 3218. Construct a prefix list that permits only subnets, and denies everything else.ip prefix-list test18 seq 5 permit 0.0.0.0/1 ge 9ip prefix-list test18 seq 10 permit 128.0.0.0/2 ge 17ip
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2025新款广州市劳动合同范本
- 2025解除终止劳动合同确认书模板
- 饭馆供肉合同范本
- 2025影视剧本授权合同
- 单位保洁包年合同范本
- 汽车租赁折旧合同范本
- 雕像商铺租售合同范本
- 汽配仓库代管合同范本
- 球鞋广告合同范本
- 产品合同范本
- (2025年标准)委托他人要账协议书
- 2025-2030中国青少年无人机教育课程体系构建与创新能力培养研究
- 煤矿安全规程新旧版本对照表格版
- 2025山东“才聚齐鲁成就未来”水发集团高校毕业招聘241人笔试参考题库附带答案详解(10套)
- 中学2025年秋季第一学期开学工作方案
- 儿童急救流程
- GB 11122-2025柴油机油
- 私募薪酬管理办法
- 经营废钢管理办法
- 联通技能竞赛考试题及答案(5G核心网知识部分)
- #20kV设备交接和预防性试验规定
评论
0/150
提交评论