Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| networking:cisco:std-acl [2026/02/04 13:27] – created ilyasa | networking:cisco:std-acl [2026/02/04 22:48] (current) – ilyasa | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| {{indexmenu_n> | {{indexmenu_n> | ||
| - | ====== Cisco : Standard Access Control List [U] ====== | + | ====== Cisco : Standard Access Control List ====== |
| - | Desciption | + | ACL Standard Cisco adalah sebuah daftar akses kontrol yang digunakan untuk menyaring lalu lintas jaringan berdasarkan Source IP Address. |
| ===== Syntax ===== | ===== Syntax ===== | ||
| - | ==== Some acction | + | ==== Membuat Standard ACL (number) |
| - | ^ Command ^ Description ^ | + | |
| - | | '' | + | <code js> |
| - | | '' | + | Router(config)# |
| + | </ | ||
| + | |||
| + | * ACL_NUMBER : 1-99 atau 1300-1999 | ||
| + | * permit: Mengizinkan lalu lintas dari alamat IP yang ditentukan. | ||
| + | * deny: Menolak lalu lintas dari alamat IP yang ditentukan. | ||
| + | * SOURCE_IP: source ip address yang ingin di filter. | ||
| + | * WILDCARD_MASK: | ||
| Contoh: | Contoh: | ||
| - | < | + | |
| - | vlan 10 | + | < |
| - | name VLAN-10 | + | Router(config)# |
| - | vlan 20 | + | </ |
| - | name VLAN-20 | + | |
| - | vlan 99 | + | ==== Membuat Standard ACL (Named) ==== |
| - | name VLAN-Management | + | |
| + | <code js> | ||
| + | Router(config)# | ||
| + | Router(config-std-nacl)# | ||
| + | Router(config-std-nacl)# | ||
| + | </ | ||
| + | |||
| + | contoh: | ||
| + | |||
| + | <code js> | ||
| + | Router(config)# | ||
| + | Router(config-std-nacl)# | ||
| + | Router(config-std-nacl)# | ||
| + | Router(config-std-nacl)# | ||
| + | </ | ||
| + | |||
| + | ==== Terapkan ACL ke interface ==== | ||
| + | |||
| + | <code js> | ||
| + | Router(config)# | ||
| + | Router(config-if)# | ||
| + | </ | ||
| + | |||
| + | * in: Menerapkan ACL pada paket yang kearah interface. | ||
| + | * out: Menerapkan ACL pada paket yang keluar dari interface. | ||
| + | |||
| + | Contoh: | ||
| + | |||
| + | <code js> | ||
| + | Router(config)# | ||
| + | Router(config-if)# | ||
| + | </ | ||
| + | |||
| + | <code js> | ||
| + | Router(config)# | ||
| + | Router(config-if)# ip access-group BLOCK_LAN1 in | ||
| + | </ | ||
| + | |||
| + | ==== Troubleshot ==== | ||
| + | |||
| + | <code js> | ||
| + | Router# show access-lists | ||
| </ | </ | ||
| ===== Topologi ===== | ===== Topologi ===== | ||
| - | Gambar topology | + | {{ : |
| - | Goals Topology | + | Tujuan: |
| + | - LAN 1 Dilarang mengakses Server-B | ||
| + | - LAN 2 Dilarang mengakses Server-C | ||
| + | |||
| + | <hidden preconfig> | ||
| + | * **R1 : Preconfig** | ||
| + | <code js> | ||
| + | hostname R1 | ||
| + | ! | ||
| + | ip dhcp excluded-address 192.168.1.1 | ||
| + | ip dhcp excluded-address 192.168.2.1 | ||
| + | ! | ||
| + | ip dhcp pool LAN1 | ||
| + | | ||
| + | | ||
| + | ! | ||
| + | ip dhcp pool LAN2 | ||
| + | | ||
| + | | ||
| + | interface FastEthernet0/ | ||
| + | ip address 192.168.1.1 255.255.255.0 | ||
| + | no shutdown | ||
| + | ! | ||
| + | interface FastEthernet0/ | ||
| + | ip address 192.168.2.1 255.255.255.0 | ||
| + | no shutdown | ||
| + | ! | ||
| + | interface FastEthernet1/ | ||
| + | ip address 172.16.1.1 255.255.255.25 | ||
| + | no shutdown | ||
| + | ! | ||
| + | router ospf 1 | ||
| + | | ||
| + | | ||
| + | | ||
| + | ! | ||
| + | </ | ||
| + | |||
| + | * **R2 : Preconfig** | ||
| + | |||
| + | <code js> | ||
| + | hostname R2 | ||
| + | ! | ||
| + | interface FastEthernet0/ | ||
| + | ip address 10.0.1.1 255.255.255.0 | ||
| + | no shutdown | ||
| + | ! | ||
| + | interface FastEthernet0/ | ||
| + | ip address 10.0.2.1 255.255.255.0 | ||
| + | no shutdown | ||
| + | ! | ||
| + | interface FastEthernet1/ | ||
| + | ip address 172.16.1.2 255.255.255.252 | ||
| + | no shutdown | ||
| + | ! | ||
| + | router ospf 1 | ||
| + | | ||
| + | | ||
| + | | ||
| + | </ | ||
| + | </ | ||
| ===== Konfigurasi ===== | ===== Konfigurasi ===== | ||
| - | * **Step 1 : Pembuatan VLANs** | + | <WRAP center round tip 90%> |
| - | <code> | + | Standar ACL umumnya |
| - | Switch(config)# | + | </ |
| - | Switch(config-vlan)#name BIRU | + | |
| - | Switch(config-vlan)#exit | + | |
| - | Switch(config)# | + | ==== Blocking LAN1 untuk berkomunikasi dengan Server B ==== |
| - | Switch(config-vlan)#name MAGENTA | + | |
| - | Switch(config-vlan)#exit | + | * Router terdekat dengan tujuan addlah R2, mari kita buat rulesnya |
| + | |||
| + | <code js> | ||
| + | R2(config)#access-list 10 deny 192.168.1.0 0.0.0.255 | ||
| + | R2(config)#access-list 10 permit any | ||
| </ | </ | ||
| - | * **Step 2 : Assign VLANs ke Ports** | ||
| - | < | ||
| - | Switch(config)# | ||
| - | Switch(config-if)# | ||
| - | Switch(config-if)# | ||
| - | Switch(config-if)# | ||
| - | Switch(config)# | + | * Terapkan pada interface menuju server B Fa0/1 |
| - | Switch(config-if)# | + | |
| - | Switch(config-if)# | + | <code js> |
| - | Switch(config-if)# | + | R2(config)# |
| + | R2(config-if)# | ||
| + | R2(config-if)# | ||
| + | </ | ||
| + | |||
| + | ==== Blocking LAN2 untuk berkomunikasi dengan Server A ==== | ||
| + | |||
| + | <code js> | ||
| + | R2(config)#access-list 20 deny 192.168.2.0 0.0.0.255 | ||
| + | R2(config)# | ||
| + | </ | ||
| + | |||
| + | * Terapkan pada interface menuju server A Fa1/1 | ||
| + | |||
| + | <code js> | ||
| + | R2(config)# | ||
| + | R2(config-if)# | ||
| + | R2(config-if)# | ||
| </ | </ | ||
| ===== Testing ===== | ===== Testing ===== | ||
| + | |||
| + | * **Tets ping LAN1 ke Server A & B** | ||
| + | <code js> | ||
| + | PC-A1> show ip | ||
| + | |||
| + | NAME : PC-A1[1] | ||
| + | IP/ | ||
| + | GATEWAY | ||
| + | DNS : | ||
| + | MAC : 00: | ||
| + | LPORT : 20000 | ||
| + | RHOST: | ||
| + | MTU : 1500 | ||
| + | |||
| + | PC-A1> ping 10.0.1.2 | ||
| + | |||
| + | 84 bytes from 10.0.1.2 icmp_seq=1 ttl=62 time=95.125 ms | ||
| + | 84 bytes from 10.0.1.2 icmp_seq=2 ttl=62 time=65.038 ms | ||
| + | 84 bytes from 10.0.1.2 icmp_seq=3 ttl=62 time=60.712 ms | ||
| + | 84 bytes from 10.0.1.2 icmp_seq=4 ttl=62 time=63.358 ms | ||
| + | 84 bytes from 10.0.1.2 icmp_seq=5 ttl=62 time=50.142 ms | ||
| + | |||
| + | PC-A1> ping 10.0.2.2 | ||
| + | |||
| + | *172.16.1.2 icmp_seq=1 ttl=254 time=45.899 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=2 ttl=254 time=32.774 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=3 ttl=254 time=45.168 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=4 ttl=254 time=34.268 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=5 ttl=254 time=42.260 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | </ | ||
| + | |||
| + | * **Tets ping LAN2 ke Server A & B** | ||
| + | |||
| + | <code js> | ||
| + | PC-B1> show ip | ||
| + | |||
| + | NAME : PC-B1[1] | ||
| + | IP/ | ||
| + | GATEWAY | ||
| + | DNS : | ||
| + | DHCP SERVER : 192.168.2.1 | ||
| + | DHCP LEASE : 67259, 86400/ | ||
| + | MAC : 00: | ||
| + | LPORT : 20000 | ||
| + | RHOST: | ||
| + | MTU : 1500 | ||
| + | |||
| + | PC-B1> ping 10.0.1.2 | ||
| + | |||
| + | *172.16.1.2 icmp_seq=1 ttl=254 time=46.086 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=2 ttl=254 time=47.608 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=3 ttl=254 time=47.629 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=4 ttl=254 time=46.073 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | *172.16.1.2 icmp_seq=5 ttl=254 time=46.126 ms (ICMP type:3, code:13, Communication administratively prohibited) | ||
| + | |||
| + | PC-B1> ping 10.0.2.2 | ||
| + | |||
| + | 84 bytes from 10.0.2.2 icmp_seq=1 ttl=62 time=83.063 ms | ||
| + | 84 bytes from 10.0.2.2 icmp_seq=2 ttl=62 time=67.256 ms | ||
| + | 84 bytes from 10.0.2.2 icmp_seq=3 ttl=62 time=61.611 ms | ||
| + | 84 bytes from 10.0.2.2 icmp_seq=4 ttl=62 time=61.236 ms | ||
| + | 84 bytes from 10.0.2.2 icmp_seq=5 ttl=62 time=62.238 ms | ||
| + | </ | ||