华为交换机报文过滤配置
1、 配置acl规则
acl 3001
rule 10 permit ip source 10.129.4.29 0 destination 10.3.143.128 0
rule 20 permit ip source 10.129.4.29 0 destination 10.3.143.127 0
rule 30 deny tcp source 10.129.4.29 0 destination 10.3.172.64 0 destination-port eq 3306
rule 40 permit ip source 10.129.4.29 0 destination 10.3.172.64 0
rule 50 permit tcp source 10.129.4.29 0 destination 10.3.172.64 0 destination-port range 0 65535
rule 60 deny ip source 10.129.4.29 0
rule 70 permit ip source any
2、 配置流分类
traffic classifier bug-scan
if-match acl 3001
3、配置流行为
traffic behavior b-s
permit
4、 配置流策略
traffic policy bug-scan
classifier bug-scan behavior b-s
5、将流策略应用在接口上
interface GE2/0/14
traffic-policy bug-scan inbound