3.
【问题3】 为了便于管理,公司有生产部、销售部和财务部等部门,VLAN划分及IP地址规划,如图所示。为了安全起见,公司要求生产部不能够访问销售部的主机和财务服务器,销售部可以对公司网络自由访问。根据以上要求,网络管理员对SwitchA做了如下配置,请根据描述,将下面的配置代码补充完整。
设备基本配置及VLAN配置略
[SwitchA]acl 3001
[SwitchA-acl-adv-3001]rule permeit ip source 192.168. 30.0.0.0.0.255 destination 192.168.10.0.0.0.0. 255
[SwitchA-acl-adv-3001]rule permeit ip source 192.168. 30.0.0.0.0.255 destination 192.168.20.0.0.0.0.255
[SwitchA-acl-adv-3001]rule permeit ip source 192. 168. 30.0.0.0.0.255 destination ______ 0
[SwitchA]acl 3002
[SwitchA-acal-adv-3002]rule deny ip source 192. 168.10.0.0.0.0.255 destination 192.168.30.0.0.0.0.255
[SwitchA-acl-adv-3002]rule deny ip source 192.168.10.0.0.0.0.255 destination 172.16.1.2.0
[SwitchA]acl 3003
[SwitchA-acl-adv-3003]rule d eny ip source 192.168.20.0.0.0.0.255 destination 192.168.30.0.0.0.0.255
[SwitchA-acl-adv-3003]rule deny ip source 192.168.20.0.0.0.0.255 destination 172.16.1.2.0
[SwitchA-acl-adv-3003]quit
[SwitchA]traffic classifiler tc1// ______
[SwitchA-classifier-tc1]if-match acl ______ //将ACL与流分类关联
[SwitchA]traffic classifier tc2
[SwitchA-classifier-tc1]if-match acl 3002
[SwitchA-classifier-tc1] if-match acl 3003
[SwitchA-classifier-tc1]quit
[SwitchA]traffic behavior tb1 //______
[SwitchA-behavior-tb1]peimit //配置流行为动作为允许报文通过
[SwitchA]traffic behavior tb2
[SwitchA-behavior-tb1]deny //配置流行为动作为拒绝报文通过
[SwitchA-behavior-tb1]quit
[SwitchA]traffic policy tp1 //______
[SwitchA-traffic policy-tp1]classifier ______ behavior tbl
[SwitchA]traffic policy tp2 //创建流策略
[SwitchA-trafficpolicy-tp1] classifier ______ behavior tb2
[SwitchA-traf ficpolicy-tp1] quit
[SwitchA]interface ______
[SwitchA-GigabitEthernet1/0/1] traffic-policy tp1 inbound //流策略应用在接口入方向
[SwitchA-GigabitEthernet1/0/1] quit
[SwitchA]interface ______
[SwitchA-GigabitEthemet1/0/2]traffic-policy tp2 inbound //流策略应用在接口入方向
[SwitchA-GigabitEthemet1/0/2] quit
备选答案
A.172.16.1.2
B.3001
C.创建流策略
D.tc2
E.GigabitEthernet 01/0/23
F.GigabitEthernet 0/0/22
G.tc1
H.创建流行为
I.创建流分类
A.172.16.1.2
I.创建流分类
B:3001
H.创建流行为
C.创建流策略
G.tcl
D.tc2
F.GigabitEthernet0/0/22
E.GigabitEthernet0/0/23