H3C S5100 屏蔽内网共享端口
允许到 1.18 ip 共享(共享打印机)
[S5100]
acl number 3100
rule 1 permit tcp destination 0.0.0.18 255.255.255.0 destination-port eq 445
rule 2 permit tcp destination 0.0.0.18 255.255.255.0 destination-port eq 135
rule 3 permit tcp destination 0.0.0.18 255.255.255.0 destination-port eq 139
(允许通过规则要在禁止规则之前!!!)
禁止其它所有 ip 共享
[S5100]
acl number 3100
rule 4 deny tcp destination-port eq 445
rule 5 deny tcp destination-port eq 135
rule 6 deny tcp destination-port eq 139
quit
应用一、把规则应用到VLAN
[S5100]
packet-filter vlan 1 inbound ip-group 3100
删除规则
undo packet-filter vlan 1 inbound ip-group 3100
应用二、把规则应用到接口
[S5100]
interface GigabitEthernet 1/0/1
packet-filter inbound ip-group 3100
quit