12 IP I P I P E s t a b l i s h e d I P I P l o c k - a n d - k e y V T Y 12.1 1) 2) D D R 3) 4) 5) 12.2 IP C i s c o 1) I P I P I P
402 CCIE 1 I P 0 0.0.0.0 1 3 150. 1. 1 1 ~ 255 150. 1. 1. 0 2) Inbound o u t b o u n d 12-1 151.1.1.1 A B A 150.1.1.0 12-1 A 150. 1. 1. 2 P C A 1 52. 1. 1. 2 A ( i n b o u n d ) o u t b o u n d p a c k e t 12.3
12 IP 403 a c c e s s - c l a s s a c c e s s - c l a s s C i s c o V T Y V T Y [ 1-99 ] V T Y i n o u t a c c e s s - e n a b l e I O S t e l n e t a c c e s s - l i s t [ 1-99 ] 1 ~ 99 I P I P I a c c e s s - l i s t [ 100-199 ] 100 ~ 199 d y n a m i c I P I P TO S a c c e s s - l i s t [ 100-199 ][ d y n m a i c ] 100 ~ 199 d y n a m i c access-template a u t o c o m m a n d
404 CCIE clear access-list counters clear access-template ip access-group [ 1-199 ] i n o u t ip telnet source-interface t e l n e t show access-lists I P username 12.4 IOS IOS 10.0 12.5 48 IP 12.5.1 1) C i s c o E t h e r n e t 2) P C 3) Cisco IOS 10.0 4) Cisco DTE/DCE 5) C i s c o 12.5.2 12-2 151.1.1.1 A B 150.1.1.0 12-2
12 IP 405 A 150. 1. 1. 0 A B D C E A I P 12-2 B I P 151. 1. 1. 1 A 150. 1. 1. 0 B p i n g ping A 195. 1. 1. 4 I P I P IP 12.5.3 1. A 2. B
406 CCIE 12.5.4 B p i n g ping A(195.1.1.4) p i n g A debug ip packet B I C M P A show access-list 1 1 5 0. 1. 1. 0 12.6 49 IP 12.6.1 1) C i s c o E t h e r n e t
12 IP 407 12.6.2 2) Cisco IOS 10.0 3) P C 4) Cisco DTE/DCE 5) C i s c o A P C C 1 50. 1. 1. 2 P C A 1 52. 1. 1. 2 P C C 1 50. 1. 1. P C B 1 52. 1. 1. 3 I P I P A B D E C A 12-3 I P A B I P 151.1.1.1 A B A B 12-3 IP A P C C 1 50. 1. 1. 2 P C A P C C P C B TFTP 12.6.3 1. A
408 CCIE 2. B
12 IP 409 12.6.4 p i n g I P (1) 150.1.1.2 ping 152.1.1.3 A debug ip packet I C M P show ip access list l o g L o g L o g g i n g i n f o r m a t i o n - l o g g i n g (2) B 150.1.1.2 ping 152.1.1.3 A debug ip packet show ip access-list ; 12.7 50: Established 12.7.1 1) C i s c o E t h e r n e t 2) Cisco IOS 10.0 3) P C 4) C i s c o 5) Cisco DTE/DCE 12.7.2 e s t a b l i s h e d e s t a b l i s h e d
410 CCIE 12-4 A P C A P C A I n t e r n e t A P C A 12-4 Established e s t a b l i s h e d T C P A C K R S T 1 1) PCA w w w. p u s h t e c. c o m H T T P 2) w w w. p u s h t e c. c o m 3) A A C K R S T w w w. p u s h t e c. c o m P C A S Y N T C P 12.7.3 e s t a b l i s h e d A A n o n - e s t a b l i s h e d I P A B D C E A I P 12-5 A A B A B 12-5 Established
12 IP 411 12.7.4 1. A 2. B
412 CCIE 12.7.5 A B t e l n e t A E t h e r n e t I P A IP telnet source-interface e0 1) debug ip packet detailed I P A 2) A 1 5 2. 1. 1. 1 Telnet B(150.1.1.1) A debug ip packet detailed 150. 1. 1. 1 1 52. 1. 1. 1 A C K R S T l o g l o g l o g g i n g 1 50. 1. 1. 1 100 3) show ip access-list 6 1
12 IP 413 4) t e l n e t B 1 50. 1. 1. 1 A ( 152. 1. 1. 1 ) B E t h e r n e t I P t e l n e t 5) debug ip packet detailed I P A S Y N A A C K R S T e s t a b l i s h e d S Y N T C P A C K R S T r e s e t 12.8 51 IP 12.8.1 1) C i s c o E t h e r n e t 2) Cisco IOS 11. 1 3) 4) Cisco DTE/DCE 5) C i s c o 12.8.2 t e l n e t Lock-and-key Security 12-6 A 2) A PCB 1) A PCB 4) 3) PCB PCA 12-6 Lock-and-key
414 CCIE 12.8.3 Lock-and-key 1) PCB A 2) A t e l n e t 3) PCB t e l n e t P C B P C A 4) P C B A 5) A 12.8.4 12-7 lock-and key A B A B 12-7 Lock and-key A B A 5 B 1 50. 1. 1. 1 A ( 152. 1. 1. 1 ) A B D C E A I P 12-7 A 12.8.5 1. A
2. B 12 IP 415
416 CCIE 12.8.6 B A ( 195. 1. 1. 4 ) P C B P C A t e l n e t A 100 A show ip access-list B 1 50. 1. 1. 1 152. 1. 1. 1 t e l n e t B E t h e r n e t I P t e l n e t A ip telnet source-interface e0 A l o g L o L o g l o 150. 1. 1. 1 t e l n e t 100 t e l n e t A show ip access-list
12 IP 417 B 1 50. 1. 1. 1 152. 1. 1. 1 P C B A t e l n e t 1 52. 1. 1. 1 12.9 52 VTY 12.9.1 1) C i s c o E t h e r n e t 2) Cisco IOS 10.0 3) 4) Cisco DTE/DCE 5) C i s c o 12.9.2 V T Y p r o d u c t i o n I P I P V T Y t e l n e t 12.9.3 V T Y A 150. 1. 1. 1 V T Y A A B B D C E A I P 12-8 A 12.9.4 A 12-8 VTY B B
418 CCIE 1. A 2. B
12 IP 419 12.9.5 B A 1 95. 1. 1. 4 t e l n e t B ip telnet source interface Ethernet 0 t e l n e t I P 150. 1. 1. 1 t e l n e t B t e l n e t B A 1 95. 1. 1. 1 t e l n e t A 12.10 IP Cisco IOS show access-list show ip access-list I P I P clear access list counters clear access list counters 0 debug ip packet
420 CCIE 12.11 Cisco IOS D D R