求思科交换机access-list命令的解释!!

ip access-list extended Smtp_Deny
permit tcp any host 210.77.176.58 eq smtp
deny tcp any any eq smtp
permit ip any any
ip access-list extended control
permit ip host 172.20.65.1 any
permit ip host 172.20.65.3 any
permit ip host 172.20.65.9 any
permit ip host 172.20.65.115 any
permit ip host 172.20.65.6 any
permit ip host 172.20.65.10 any
permit ip host 172.20.65.235 any
permit ip host 172.20.65.65 any
permit ip host 172.20.65.28 any
permit ip host 172.20.65.210 any
permit ip host 172.20.65.253 any
permit ip host 172.20.65.20 any
permit ip host 172.20.107.38 any
希望能逐句解释下。。

ip access-list extended Smtp_Deny 定义acl的标准控制列表名字为 Smtp_Deny
permit tcp any host 210.77.176.58 eq smtp 允许tcp协议源地址所有到目的主机210.77.这个ip的smtp端口
deny tcp any any eq smtp 拒绝tcp协议源地址和目的地址为所有的禁止访问smtp端口
permit ip any any 允许ip协议所有到所有
ip access-list extended control 定义acl标准控制列表名字为control
permit ip host 172.20.65.1 any 允许源地址为ip主机的172.20.65.1 到所有
permit ip host 172.20.65.3 any
permit ip host 172.20.65.9 any
permit ip host 172.20.65.115 any
permit ip host 172.20.65.6 any
permit ip host 172.20.65.10 any
permit ip host 172.20.65.235 any
permit ip host 172.20.65.65 any
permit ip host 172.20.65.28 any
permit ip host 172.20.65.210 any
permit ip host 172.20.65.253 any
permit ip host 172.20.65.20 any
permit ip host 172.20.107.38 any

permit 就是允许 deny就是拒绝
后面跟着的是协议 ip 或者tcp、udp等
之后是源地址any是所有 ip host 是单个主机
源地址后跟着的是目的地址
eq是等于此端口
smtp是协议,也是端口。
温馨提示:答案为网友推荐,仅供参考
第1个回答  2015-01-02
ip access-list extended Smtp_Deny 扩展访问列表名为 smtp_deny
permit tcp any host 210.77.176.58 eq smtp 允许所有地址访问210....的smtp端口
deny tcp any any eq smtp 禁止所有地址访问其他的smtp端口
permit ip any any 允许所有其他访问
ip access-list extended control 扩展访问列表名为 control
permit ip host 172.20.65.1 any 允许ip为172....的主机访问所有
permit ip host 172.20.65.3 any 允许ip为172....的主机访问所有

下面一样都是允许某个主机访问所有本回答被网友采纳