Acl Lab
Acl Lab
R1-
conf t
int f0/0
no sh
int lo 1
int lo 2
int lo 3
int lo 4
ip add 1.1.1.4 255.255.255.255
R2-
conf t
int f0/0
no sh
int f0/1
no sh
int f1/0
no sh
R3-
conf t
int f0/0
no sh
int lo 1
conf t
int f1/0
no sh
*** FOR THIS ACL CAN BE APPLIED ON R1 OR R2 ANYONE CAN PERFORM THE TASK.
R2-
int f0/1
ip access-group 1 in
R3-
do ping 10.11.11.1 so 2.2.2.2 ( IT SHOULD HAVE PINGGED BUT DUE TO IMPLICIT DENY THIS COULDN'T
WORK.)
R2-
R2-
int f0/1
no ip unreachables
R3-
R2-
R1-
line vty 0 4
pass akki
login
R3-
telnet 10.11.11.1
2.3. TO DENY THIS TELNET ACCESS ONLY, ACL NEEDS TO BE RUN ON R1 IN VTY
R1-
line vty 0 4
access-class 1 in
R3-
telnet 10.11.11.1
R1-
no access-class 1 in
ip http server
R3-
telnet 10.11.11.1 ( THIS WOULD WORK AND THIS SHOULDN'T BE THE CASE )
telnet 10.11.11.1 80 ( TO TELNET THROUGH HTTP SERVER- THIS WOULD ALSO WORK )
R1-
do sh ip access-list
int f0/0
ip access-group 101 in
R3-
telnet 10.11.11.1 80
R1-
21 deny icmp any any ( 21- TO PROVIDE PRIORITY, ICMP- THE PROTOCOL USED WHEN PINGGED.)
R3-
do ping 10.11.11.1
R1-
ip domain-name cns.com
line vty 0 4
R3-
( PRESS ENTER OR TYPE ADMIN AT THE PLACE OF PASSWORD IF PRESSING ENTER DOESN'T WORK )
R1-
R3-
R1-
no ip access-group 101 in
R3-
telnet 10.11.11.1
telnet 10.11.11.1 80
R1-
int f0/0
ip access-group cns-acl in
MOCK LAB-
R1-
int f0/0
ip access-group 102 in
do sh ip acces-1
ping 20.11.11.3.