EX1) 192.168.1.0/24 ~ 192.168.255.0/24중에 홀수 서브넷만 정의한다.
192.168.1.0/24
192.168.3.0/24
192.168.5.0/24
192.168.7.0/24
...
192.168.255.0/24
------------------
192.168.0000000 1.0
192.168.0000001 1.0
192.168.0000010 1.0
...
192.168.1111111 1.0
-----------------> 192.168.1.0 0.0.254.255
/24이지만 서브넷마스크는 255.255.0.0??
0.0.1111111 0.255 <- 0.0.254.255
EX2) 192.168.2.0/24 ~ 192.168.255.0/24중에 짝수서브넷만 정의
192.168.2.0/24
192.168.4.0/24
192.168.6.0/24
...
192.168.254.0/24
----------------
192.168.00000010.0
192.168.00000100.0
...
192.168.11111110.0
----------------> 192.168.0.0 0.0.254.255
0.0.1111111 0.255 <- 0.0.254.255
EX3) 192.168.112.32 ~ 192.168.112.63
192.168.112.001 00000
192.168.112.001 00001
...
192.168.112.001 11111
------------------->192.168.112.32 0.0.0.31
0.0.0.000 11111<- 0.0.0.31
(선수지식)
Ex1) 잘못된 예제
13.13.0.0 permit
13.13.30.0 deny
R1(config)#access-list 10 permit 13.13.0.0 0.0.255.255
R1(config)#access-list 10 deny 13.13.30.0 0.0.0.255
R1(config)#int s1/0
R1(config)# ip access-group 10 in
R1(config)#end
R1#show ip access-list
Standard IP access list 10
10 permit 13.13.0.0, wildcard bits 0.0.255.255
20 deny 13.13.30.0, wildcard bits 0.0.0.255
-> 차단하고 싶었지만 허용 범위가 더 커 허용됨.
-> 범위가 작은 것 부터 설정하면 해결
(해결 방법)
R1#conf t
R1(config)#no access-list 10
R1(config)#access-list 10 deny 13.13.30.0 0.0.0.255
R1(config)#access-list 10 permit 13.13.0.0 0.0.255.255
R1(config)#access-list 10 deny 13.13.30.0 0.0.0.255
R1(config)#end
R1#show ip access-list
Standard IP access list 10
10 deny 13.13.30.0, wildcard bits 0.0.0.255
(마지막에 'deny any' 처리 실시)
(해결 방법)
R1#conf t
R1(config)#access-list 10 permit any
R1#show ip access-list
Standard IP access list 10
10 deny 172.16.3.0, wildcard bits 0.0.0.255 (11 matches)
20 permit any
R1#conf t
R1(config)#access-list 10 deny 13.13.30.0 0.0.0.255
R1(config)#end
R1#show ip access-list
Standard IP access list 10
10 deny 172.16.3.0, wildcard bits 0.0.0.255 (11 matches)
20 permit any
30 deny 13.13.30.0, wildcard bits 0.0.0.255 <- 덮어쓰기되지않고 추가가 된다.
R1#conf t
R1(config)#no access-list 10 deny 13.13.30.0 0.0.0.255
R1(config)#end
R1#show ip access-list
R1# <- 전체 다 사라진다.
프로토콜 출발지IP 출발지 Port 목적지IP 목적지Port
--------------------------------------------