Tag Archives: access control list

Cara Configurasi Standard Access List (ACL)

Hi,

Bulan lalu saya sudah memposting tentang access control list (ACL) yang terdiri dari standard access list dan extended access list. Hari ini saya akan coba memberikan contoh penggunanaan standard access list menggunakan packet tracer. Ini yang perlu diingat dalam menerapkan konfigurasi standard access list “Standard IP access-lists are based upon the source host or network IP
address, and should be placed closest to the destination network”.

Di bawah ini akan saya lampirkan gambar konfigurasi standard acl :

 

 

 

 

Dari gambar diatas saya memberikan 2 contoh kasus konfigurasi standard access list yaitu :

  1. Block network192.168. 30.0  /24 dan network 192.168. 40.0  /24 untuk ping ke 192.168.50.0 /24 kecuali network 192.168. 60.0 /24 :
  • access-list 10 permit 192.168.60.0 0.0.0.255
  • access-list 10 deny 192.168.50.0 0.0.0.255
  • access-list 10 permit any
  • apply to router 0
  • se 0/0
  • ip access-list group in

2. Block network 192.168.50.0 /24 ke network 192.168.30.0 /24, sedangkan ping ke lain network berjalan lancar.

  • access-list 20 deny 192.168.30.0 0.0.0.255
  • access-list 20 permit any
  • apply to router 1
  • int f0/0
  • ip access-group 20 out

Detail configurasi ada di bawah ini :

Router1
========

Router>en
Router#
Router#
Router#
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int se0/0
Router(config-if)#no shut

Router(config-if)#
%LINK-5-CHANGED: Interface Serial0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0, changed state to up

Router>en
Router#
Router#
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int se0/0
Router(config-if)#ip address 192.168.20.2 255.255.255.252
Router(config-if)#no shut
Router(config-if)#
Router(config-if)#exit
Router(config)#
Router(config)#
Router(config)#exit
Router#

Router#
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int fa0/1
Router(config-if)#ip address 192.168.60.1 255.255.255.0
Router(config-if)#no shut

Router(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up

Router(config-if)#
Router(config-if)#exit
Router(config)#int fa0/0
Router(config-if)#ip address 192.168.50.1 255.255.255.0
Router(config-if)#no shut

Router(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up

Router(config-if)#
Router(config-if)#exit
Router(config)#exit
Router#
%SYS-5-CONFIG_I: Configured from console by console

Router#

Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#router rip
Router(config-router)#network 192.168.20.0
Router(config-router)#network 192.168.50.0
Router(config-router)#network 192.168.60.0
Router(config-router)#exit
Router(config)#
Router(config)#
Router(config)#exit
Router#

 

Router0
========
Router>en
Router#
Router#
Router#
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int se0/0
Router(config-if)#no shut

Router(config-if)#
%LINK-5-CHANGED: Interface Serial0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0, changed state to up

Router#
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int se0/0
Router(config-if)#ip address 192.168.20.1 255.255.255.252
Router(config-if)#no shut
Router(config-if)#
Router(config-if)#exit
Router(config)#
Router(config)#
Router(config)#exit
Router#
%SYS-5-CONFIG_I: Configured from console by console

Router#

Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#
Router(config)#int fa0/1
Router(config-if)#ip address 192.168.30.1 255.255.255.0
Router(config-if)#no shut

Router(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up

Router(config-if)#exit
Router(config)#int fa0/0
Router(config-if)#ip address 192.168.40.1 255.255.255.0
Router(config-if)#no shut

Router(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up

Router(config-if)#
Router(config-if)#exit
Router(config)#
Router(config)#
Router(config)#exit

Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#router rip
Router(config-router)#network 192.168.20.0
Router(config-router)#network 192.168.40.0
Router(config-router)#network 192.168.30.0
Router(config-router)#
Router(config-router)#exit
Router(config)#
Router(config)#
Router(config)#exit
Router#

Router#
Router#
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#
Router(config)#access-list 10 permit 192.168.60.0 0.0.0.255
Router(config)#access-list 10 deny 192.168.50.0 0.0.0.255
Router(config)#access-list 10 permit any
Router(config)#
Router(config)#
Router(config)#int se0/0
Router(config-if)#ip access-group 10 in
Router(config-if)#
Router(config-if)#exit
Router(config)#
Router(config)#
Router(config)#
Router(config)#
Router(config)#exit
Router#

Untuk script diatas saya memberikan contoh untuk kasus yang pertama, sedangkan untuk yang kasus yang kedua silahkan anda coba sendiri.

Bagi teman teman yang ingin lebih details tentang gambar yang saya lampirkan karena kurang jelas bisa konfirmasi ke saya, nanti akan saya kirimkan.

Semoga bermanfaat.

Terimakasih.

Advertisements

Access Control List

Hi,

Hari ini saya coba berbagi tentang access control list atau biasa disebut ACL.  Fasilitas ini biasa kita gunakan untuk sebagai filter atau firewall didalam cisco router.

Apa itu Access Control List :

  • statement yang berisikan daftar “permit” atau “deny” yang berurutan di dalam list
  • statement akan dibaca secara berurutan sampai dengan kondisi yang cocok atau sama
  • statement akan berhenti jika sudah sesuai dengan kondisi
  • jika statement tidak cocok dengan kondisi makan akan langsung “dropped”
  • statement harus di terapkan (apply) agar berjalan untuk menghasilkan effect yang diminta

Ada dua jenis ACL

  • Standard access control list (1-99) or (1300 – 1999)
    – acts only on the source Ip address for filtering
  • Extended acl (100 – 199) or (2000 – 2699 )
    – filter on:
    – source ip address
    – destination ip address
    – protocol type
    – port number

Aturan dalam penulisan / penerapan ACL

  • satu list per type, per interface, per direction ( in – out )
  • list nomor untuk type ACL
  • – standar : 1-99 0r 1300-1999
    – extended : 100-199 or 2000-2699

standard access list syntax
– access-list [1-99] [permit|deny] [wildcard bits]
extended access list syntax
– access-list [100-199] [permit | deny] [protocol] [wildcard mask] [destination address] [wildcard mask] [operator [port]] [log]

Untuk saat ini itu yang bisa saya sampaikan, untuk contoh standard dan extended list nanti akan saya berikan di post berikutnya.