R1(config)#access-list 1
R1(config)#Deny 20.1.1.1
R1(config)#Permit any
R1(config)# int s0/0
R1(config-if)#ip access-group 1 in
当我尝试 ping 10.1.1.1 时,它返回U.U.U
-----> 这意味着无法访问目标主机。
您唯一能做的就是添加no ip unreachables
到 Serial0/0。当数据包在串行接口上被拒绝时,这将使 ping 只是超时,而不是接收 ICMP 管理员禁止消息。
例子:
以下示例说明了发生的情况:
- 当ROUTER1 ping ROUTER2:Gi0/0,ROUTER2通过acl 166拒绝ROUTER1时;
ip unreachables
在 Gi0/0 上配置
- 当ROUTER1 ping ROUTER2:G0/0,ROUTER2通过acl 166拒绝ROUTER1时;
no ip unreachables
在 Gi0/0 上配置
With ip unreachables
(这是默认值)在界面上
在带有 ACL 的路由器上...
ROUTER2#sh runn | i access-list 166
access-list 166 deny ip host 192.0.2.111 any
access-list 166 permit ip any any
ROUTER2#sh runn int gi0/0
!
interface GigabitEthernet0/0
ip address 192.0.2.29 255.255.255.0
ip access-group 166 in
no ip redirects
no ip proxy-arp
并且在被阻止的主机上...
ROUTER1#debug ip icmp
ROUTER1#ping 192.0.2.29 source lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.0.2.29, timeout is 2 seconds:
Packet sent with a source address of 192.0.2.111
U.U.U
Success rate is 0 percent (0/5)
ROUTER1#sh log | i administrat
Jan 16 11:02:29.251 CST: ICMP: dst (192.0.2.111) administratively
prohibited unreachable rcv from 192.0.2.29
Jan 16 11:02:31.255 CST: ICMP: dst (192.0.2.111) administratively
prohibited unreachable rcv from 192.0.2.29
Jan 16 11:02:33.263 CST: ICMP: dst (192.0.2.111) administratively
prohibited unreachable rcv from 192.0.2.29
和 no ip unreachables
no ip unreachables
在 ROUTER2 上添加...
ROUTER2#conf t
ROUTER2(config)#int gi0/0
ROUTER2(config-if)#no ip unreach
现在 ping默默地失败了......
ROUTER1#ping 192.0.2.29 source lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.0.2.29, timeout is 2 seconds:
Packet sent with a source address of 192.0.2.111
.....
Success rate is 0 percent (0/5)
ROUTER1#