核心交换机 数通 S9303,WIFI网段的VLAN 172,需禁止其访问 192.168.0.0网段,用流策略将其隔离。
1)创建ACL
acl 2050
rule 10 deny source 192.168.0.0 0.0.255.255
quit
2)创建流分类,并匹配ACL
traffic classifier lan2wifi
if-match acl 2050
quit
3)创建流行为
traffic behavior nopass
deny
quit
4)创建流策略,并匹配流分类和流行为
traffic policy nolan2wifi
classifier lan2wifi behavior nopass
quit
5)在VLAN 172的出方向应用流策略
vlan 172
traffic-policy nolan2wifi outbound
quit
rule 10 deny source 192.168.0.0 0.0.255.255
quit
2)创建流分类,并匹配ACL
traffic classifier lan2wifi
if-match acl 2050
quit
3)创建流行为
traffic behavior nopass
deny
quit
4)创建流策略,并匹配流分类和流行为
traffic policy nolan2wifi
classifier lan2wifi behavior nopass
quit
5)在VLAN 172的出方向应用流策略
vlan 172
traffic-policy nolan2wifi outbound
quit