cess-list 110 deny ip any host 131.1.23.2 log 允许已经建立的TCP会话的信息包通过: access-list 110 permit tcp any 131.1.23.0 0.0.0.255 established 允许和FTP/HTTP服务器的FTP连接: access-list 110 permit tcp any host 131.1.23.3 eq ftp 允许和FTP/HTTP服务器的FTP数据连接: access-list 110 permit tcp any host 131.1.23.2 eq ftp-data 允许和FTP/HTTP服务器的HTTP连接: access-list 110 permit tcp any host 131.1.23.2 eq www 禁止和FTP/HTTP服务器的别的连接并记录到系统日志服务器任何企图连接FTP/HTTP的事件: access-list 110 deny ip any host 131.1.23.2 log 允许其他预页码:[1] [2] [3] [4] [5] [6] [7] 第4页、共7页 |