Проект системы безопасности корпоративной сети. Настройка VPN-туннелей для организации собственных и арендованных каналов связи, страница 6

access-list 152 deny tcp any any eq www

access-list 152 permit ip any any

int f0/0.2

ip access-group 152 in

ex

access-list 153 permit udp 10.0.13.0 0.0.0.255 host 10.0.15.2 eq domain

access-list 153 deny tcp any any eq www

access-list 153 permit ip any any

int f0/0.3

ip access-group 153 in

ex

access-list 154 deny udp any any eq domain

access-list 154 deny tcp any any eq www

access-list 154 permit ip any any

int f0/0.4

ip access-group 154 in

ex

conf t

access-list 161 permit tcp 10.0.10.0 0.0.0.255 host 10.0.50.2 eq www

access-list 161 deny udp any any eq domain

access-list 161 permit ip any any

int f0/1.1

ip access-group 161 in

ex

access-list 162 permit tcp 10.0.20.0 0.0.0.255 host 10.0.50.2 eq www

access-list 162 deny udp any any eq domain

access-list 162 permit ip any any

int f0/1.2

ip access-group 162 in

ex

access-list 163 permit tcp 10.0.30.0 0.0.0.255 host 10.0.50.2 eq www

access-list 163 permit udp 10.0.7.0 0.0.0.255 host 10.0.50.2 eq domain

access-list 163 permit ip any any

int f0/1.3

ip access-group 163 in

ex

access-list 164 deny udp any any eq domain

access-list 164 deny tcp any any eq www

access-list 164 permit ip any any

int f0/1.4

ip access-group 164 in

ex

ЦО

conf t

access-list 191 permit udp 10.0.21.0 0.0.0.255 host 10.0.25.2 eq domain

access-list 191 deny tcp any any eq www

access-list 191 permit ip any any

int f0/1.1

ip access-group 191 in

ex

access-list 192 deny udp any any eq domain

access-list 192 deny tcp any any eq www

access-list 192 permit ip any any

int f0/1.2

ip access-group 192 in

ex

access-list 193 deny udp any any eq domain

access-list 193 deny tcp any any eq www

access-list 193 permit ip any any

int f0/1.3

ip access-group 193 in

ex

access-list 194 permit tcp 10.0.24.0 0.0.0.255 host 10.0.25.2 eq www

access-list 194 deny udp any any eq domain 

access-list 194 permit ip any any

int f0/1.4

ip access-group 194 in

ex

3 филиал

conf t

access-list 181 deny tcp any any eq www

access-list 181 deny udp any any eq domain

access-list 181 permit ip any any

int f0/1.1

ip access-group 181 in

ex

access-list 182 permit tcp 10.0.32.0 0.0.0.255 host 10.0.35.2 eq www

access-list 182 permit udp 10.0.32.0 0.0.0.255 host 10.0.35.2 eq domain

access-list 182 permit ip any any

int f0/1.2

ip access-group 182 in

ex

access-list 183 permit tcp 10.0.33.0 0.0.0.255 host 10.0.35.2 eq www

access-list 183 deny udp any any eq domain

access-list 183 permit ip any any

int f0/1.3

ip access-group 183 in

ex

access-list 184 permit udp 10.0.34.0 0.0.0.255 host 10.0.35.2 eq domain

access-list 184 deny tcp any any eq www

access-list 184 permit ip any any

int f0/1.4

ip access-group 184 in

ex

оконечная настройка

1 филиал

Conf t

access-list 171 deny ospf any any

access-list 171 permit ip any any

access-list 172 deny eigrp any any

access-list 172 permit ip any any

interface F0/1

ip access-group 171 in

ip access-group 172 out

ex

interface F1/0

ip access-group 171 in

ip access-group 172 out

ex

2 филиал

Conf t

access-list 171 deny ospf any any

access-list 171 permit ip any any

access-list 172 deny eigrp any any

access-list 172 permit ip any any

interface F0/1

ip access-group 171 in

ip access-group 172 out

ex

interface F1/0

ip access-group 171 in

ip access-group 172 out

ex

interface F0/0

ip access-group 171 in

ip access-group 172 out

ex

ЦО

Conf t

access-list 171 deny ospf any any

access-list 171 permit ip any any

access-list 172 deny eigrp any any

access-list 172 permit ip any any

interface F0/0

ip access-group 171 in

ip access-group 172 out

ex

interface F1/0

ip access-group 171 in

ip access-group 172 out

ex

interface F0/1

ip access-group 171 in

ip access-group 172 out

ex

3 филиал

Conf t

access-list 171 deny ospf any any

access-list 171 permit ip any any

access-list 172 deny eigrp any any

access-list 172 permit ip any any

interface F0/1

ip access-group 171 in

ip access-group 172 out

ex

interface F1/0

ip access-group 171 in

ip access-group 172 out

ex