r1:
router rip
redistribute-list prefix 1 out s1/1
ip prefix-list 1 permit 44.1.1.0/24
ip prefix-list name permit 172.16.0.0/22 ge 24 le 24
/22前缀22bit相同
ge 24掩码范围最小24位.
当没有ge(172.16.0.0/22),掩码范围最小值跟前缀相同le 24(172.16.0.0/22le24)掩码范围大于24位,即22位到24位的掩码
如果没有写le2
1.当没有ge,le值前缀相同;
2.当有ge,没有指定le,le值=32
0.0.0.0/0 le32
r1:
ip prefix-list 1 deny 44.1.1.0/24
ip prefix-list 1 permit 44.1.2.0/24 le29
r4:
int lo1
ip add 44.1.2.1 255.255.255.240
router eigrp 90
network 44.1.2.1 0.0.0.0
int lo2
ip add 44.1.3.1 255.255.255.0
router eigrp 90
network 44.1.3.1 0.0.0.0
r1:
ip prefix-list 2 permit 44.1.1.0/22 ge 24 le 24
ip prefix-list 1 seq 1 permit 0.0.0.0/0 le 32
前缀列表举例说明
ip prefix-list 1 permit 172.16.1.0/24-网络号172.16.1.0,掩码24位
ip prefix-list 1 permit 172.16.1.0/24 le 32-网络号172.16.1.0,掩码为24到32之间的路由
ip prefix-list 1 permit 172.16.1.0/24 ge 25-网络号172.16.1.0,掩码为25到32位的路由(含25)
ip prefix-list 1 permit 172.16.1.0/24 ge 25 le 31-网络号172.16.1.0,掩码为25到31位的路由.
扩展access-list
step1:使用源地址部分匹配网络地址,方法跟标准access-list一样
172.16.00000000.0
172.16.00000001.0
172.16.00000010.0
172.16.00000011.0
172.16.00000000.0->172.16.0.0
0.0.00000011.0->0.0.3.0
setp2:使用目标地址部分匹配掩码
255.255.255.192---/26
255.255.255.192-->255.255.255.192
0.0.0.0->0.0.0.0
access-list 100 permit ip 172.16.0.0 0.0.3.0 255.255.255.192 0.0.0.0
172.16.0.0
172.16.1.0
172.16.2.0
172.16.3.0
step1:扩展访问控制列表的源匹配网络地址
172.16.00000000.0
172.16.00000001.0
172.16.00000010.0
172.16.00000011.0
172.16.00000000.0->172.16.0.0
0.0.00000011.0->0.0.3.0
255.255.255.0
255.255.255.128
255.255.255.192
step2:扩展访问控制列表的目标匹配掩码地址
255.255.255.00000000
255.255.255.10000000
255.255.255.11000000
255.255.255.00000000->255.255.255.0
0.0.0.11000000->0.0.0.192
access-list 100 permit ip 172.16.0.0 0.0.3.0 255.255.255.0 0.0.0.192
标签:24,0.0,list,ACL,255.255,Prefix,172.16,ip From: https://www.cnblogs.com/smoke520/p/18368034