转自:http://support.huawei.com/ecommunity/bbs/10248323.html?auther=1&buildingowner=10184221
通过traffic-filter调用
<Huawei>sys
[Huawei]acl 3000 //创建高级ACL(3000~3999)
[Huawei-acl-adv-3000]
[Huawei-acl-adv-3000]rule permit ip source192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 //配置允许192.168.1.0段去访问192.168.2.0段
[Huawei-acl-adv-3000]rule deny ip source192.168.1.0 0.0.0.255 destination 192.168.4.0 0.0.0.255 //配置拒绝192.168.1.0段去访问192.168.=4.0段
[Huawei-acl-adv-3000]dis thi //查看当前配置是否配置成功
#
acl number 3000
rule5 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule10 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
#
return
[Huawei-acl-adv-3000]q //退出ACL视图
[Huawei]int g0/0/1 //进入对应的接口
[Huawei-GigabitEthernet0/0/1]traffic-filterinbound acl 3000 //接口下调用ACL 3000
[Huawei-GigabitEthernet0/0/1]q //退出接口视图
[Huawei]