拓扑如下:
实验目的:只有192.168.3.0网段可以ping通server1 192.168.4.4
【1】PC1的配置:
PC2的配置:
server1 的配置:
【2】路由器AR1的配置:
<Huawei>sys
[Huawei]undo info-center enable
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.2.254 24
[Huawei-GigabitEthernet0/0/0]undo shut.
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 192.168.3.254 24
[Huawei-GigabitEthernet0/0/1]undo shut
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]ip add 192.168.4.254 24
[Huawei-GigabitEthernet0/0/2]undo shut
[Huawei-GigabitEthernet0/0/2]quit
[Huawei]int g4/0/0
[Huawei-GigabitEthernet4/0/0]ip add 100.1.1.1 24
[Huawei-GigabitEthernet4/0/0]undo shut
[Huawei-GigabitEthernet4/0/0]quit
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule 10 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.4.4 0.0.0.0
[Huawei-acl-adv-3000]rule 15 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.4 0.0.0.0
[Huawei-acl-adv-3000]rule 20 deny ip source any destination 192.168.4.4 0.0.0.0
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]traffic-filter outbound acl 3000
[Huawei-GigabitEthernet0/0/2]quit
【3】路由器AR2的配置:
<Huawei>sys
[Huawei]undo info-center enable
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 100.1.1.2 24
[Huawei-GigabitEthernet0/0/0]undo shut
[Huawei-GigabitEthernet0/0/0]quit
[Huawei]ip route-static 0.0.0.0 0.0.0.0 100.1.1.1
【4】实验结果:
PC1不能ping通192.168.4.4
PC2不能ping通192.168.4.4
AR2不能ping通192.168.4.4