华为路由器访问控制列表ACL配置实例 |
您所在的位置:网站首页 › 华为配置acl到vlan下 › 华为路由器访问控制列表ACL配置实例 |
ACL配置
实验拓扑实验准备配置4台主机配置ftp服务器
实验思路实验步骤实验验证
实验拓扑
二层交换机上的配置 [Huawei]sysname sw1 [sw1]vlan batch 10 20 //创建vlan Info: This operation may take a few seconds. Please wait for a moment...done. [sw1] [sw1]int e0/0/1 //将接口划入vlan [sw1-Ethernet0/0/1]p l a [sw1-Ethernet0/0/1]p d v 10 [sw1-Ethernet0/0/1] [sw1-Ethernet0/0/1]int e0/0/2 [sw1-Ethernet0/0/2]p la Error: Unknown host la. [sw1-Ethernet0/0/2]p l a [sw1-Ethernet0/0/2]p d v 20 [sw1-Ethernet0/0/2] [sw1-Ethernet0/0/2] [sw1-Ethernet0/0/2]int e0/0/3 [sw1-Ethernet0/0/3]p l a [sw1-Ethernet0/0/3]p d v 10 [sw1-Ethernet0/0/3] [sw1-Ethernet0/0/3] [sw1-Ethernet0/0/3]int e0/0/4 [sw1-Ethernet0/0/4]p l a [sw1-Ethernet0/0/4]p d v 20 [sw1-Ethernet0/0/4] [sw1-Ethernet0/0/4]int g0/0/1 //和路由器相连的接口配置trunk模式,因为路由器需要做单臂路由 [sw1-GigabitEthernet0/0/1]p l t [sw1-GigabitEthernet0/0/1]p t a v a单臂路由器R1的配置: interface GigabitEthernet0/0/0.1 //配置单臂路由,子接口为vlan的网关 dot1q termination vid 10 ip address 192.168.10.1 255.255.255.0 arp broadcast enable # interface GigabitEthernet0/0/0.2 dot1q termination vid 20 ip address 192.168.20.1 255.255.255.0 arp broadcast enable # interface GigabitEthernet0/0/1 ip address 12.1.1.1 255.255.255.0 # ip route-static 0.0.0.0 0.0.0.0 12.1.1.2 //配置一条出去的默认路由 [R1]acl 2000 [R1-acl-basic-2000]rule deny source 192.168.10.0 0.0.0.255 //配置普通acl策略 [R1-acl-basic-2000]rule permit source any [R1]int g0/0/0.2 [R1-GigabitEthernet0/0/0.2]traffic-filter outbound acl 2000 //应用策略出口路由器R2的配置: [Huawei]sys R2 [R2] [R2]int g0/0/0 [R2-GigabitEthernet0/0/0]ip add 12.1.1.2 24 [R2-GigabitEthernet0/0/0]undo shutdown Info: Interface GigabitEthernet0/0/0 is not shutdown. [R2-GigabitEthernet0/0/0]int g0/0/1 [R2-GigabitEthernet0/0/1]ip add 202.10.100.1 24 [R2-GigabitEthernet0/0/1]undo shutdown Info: Interface GigabitEthernet0/0/1 is not shutdown. [R2-GigabitEthernet0/0/1]q [R2]ip route-static 192.168.10.0 24 12.1.1.1 //R2上需要做2条静态路由到vlan10和vlan20网段 [R2]ip route-static 192.168.20.0 24 12.1.1.1 [R2]acl 3000 //配置阻止ftp访问的扩展acl策略 [R2-acl-adv-3000]rule deny tcp source 12.1.1.1 0.0.0.0 destination 202.10.100.10 0.0.0.0 destination-port eq 21 [R2-acl-adv-3000]rule deny tcp source 12.1.1.1 0.0.0.0 destination 202.10.100.10 0.0.0.0 destination-port eq 20 [R2-acl-adv-3000]rule permit ip source any destination any [R2]int g0/0/1 [R2-GigabitEthernet0/0/1]traffic-filter outbound acl 3000 //应用策略 实验验证没有配置acl策略之前,验证全网互通 |
今日新闻 |
推荐新闻 |
CopyRight 2018-2019 办公设备维修网 版权所有 豫ICP备15022753号-3 |