扩展访问控制列表:
access-list <number> permit|deny icmp <SourceIP wild> <destinationIPwild>[type]
access-list <number> permit|deny tcp <SourceIP wild> <destinationIPwild>[port]
例1:
router(config)#access-list 101 deny icmp any 10.64.0.2 0.0.0.0 echo
router(config)#access-list 101 permit ip any any
router(config)#int s0/0
router(config-if)#ip access-group 101 in
例2:
router(config)#access-list 102 deny tcp any 10.65.0.2 0.0.0.0 eq 80
router(config)#access-list 102 permit ip any any
router(config)#interface s0/1router(config-if)#ip access-group 102 out
router(config)#no access-list 102
router(config-if)#no ip access-group 101 in 在路由器上设置 SNMP Community Strings
router(config) # snmp-server community read-community-string
rorouter(config) # snmp-server community write-community-string rw
在交换机上设置SNMP Community String
switch(config) # snmp-server community read-community-string ro
switch(config) # snmp-server community write-community-string rw