实验要求
1.通过ACL 使PC1无法访问PC3
实验结构
实验步骤
1. LSW1 配置vlan ip
<Huawei>system-view
[Huawei]vlan batch 10 20 30
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]ip address 192.168.10.254 255.255.255.0
[Huawei-Vlanif10]q
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]ip address 192.168.20.254 255.255.255.0
[Huawei-Vlanif20]q
[Huawei]interface Vlanif 30
[Huawei-Vlanif30]ip address 192.168.30.254 255.255.255.0
[Huawei-Vlanif30]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan all
2. LSW2 配置vlan
<Huawei>system-view
[Huawei]vlan batch 10 20 30
[Huawei]interface g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 10
[Huawei-GigabitEthernet0/0/2]q
[Huawei]interface g0/0/3
[Huawei-GigabitEthernet0/0/3]
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 20
[Huawei-GigabitEthernet0/0/3]q
[Huawei]interface g0/0/4
[Huawei-GigabitEthernet0/0/4]port link-type access
[Huawei-GigabitEthernet0/0/4]port default vlan 30
[Huawei-GigabitEthernet0/0/4]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan all
3. 配置PC1 2 3 IP GW 测试三台PC之间都可以Ping通
4. LSW1 配置 ACL 应用ACL
[Huawei]acl name test advance
[Huawei-acl-adv-test]rule deny ip source 192.168.10.0 0.0.0.255 destination 192.
168.30.0 0.0.0.255
[Huawei-acl-adv-test]q
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]traffic-filter inbound acl name test
测试
实验目的
1. 学习ACL
相关指令
查看vlan
查看接口列表
...
dis acl all