data:image/s3,"s3://crabby-images/9d1ba/9d1ba1c1df3107fed754d6991f7459e53a0f8643" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 229"
13-3
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 13 Identifying Traffic with Access Lists
Access List Overview
Access List Implicit Deny
Access lists have an implicit deny at the end of the list, so unless you explicitly permit it, traffic cannot
pass. For example, if you want to allow all users to access a network through the FWSM except for
particular addresses, then you need to deny the particular addresses and then permit all others.
IP Addresses Used for Access Lists When You Use NAT
When you use NAT, the IP addresses you specify for an access list depend on the interface to which the
access list is attached; you need to use addresses that are valid on the network connected to the interface.
This guideline applies for both inbound and outbound access groups: the direction does not determine
the address used, only the interface does.
For example, you want to apply an access list to the inbound direction of the inside interface. You
configure the FWSM to perform NAT on the inside source addresses when they access outside addresses.
Because the access list is applied to the inside interface, the source addresses are the original
untranslated addresses. Because the outside addresses are not translated, the destination address used in
the access list is the real address (see
Figure 13-1
).
Figure 13-1
IP Addresses in Access Lists: NAT Used for Source Addresses
See the following commands for this example:
hostname(config)#
access-list INSIDE extended permit ip 10.1.1.0 255.255.255.0 host
209.165.200.225
hostname(config)#
access-group INSIDE in interface inside
209.165.200.225
Inside
Outside
Inbound ACL
Permit from
10.1.1.0/24
to
209.165.200.225
10.1.1.0/24
PAT
209.165.201.4:port
10.1.1.0/24
104634
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......