system (进入配置模式)
acl number 3005 (定义高级访问列表3005)
rule deny ip source any des10.65.156.24 0(拒绝任何IP访问10.65.156.24)
rule permit ip source 10.65.156.191 0 des 10.65.156.240 (仅允许10.65.156.191访问10.65.156.24)
quit(退出acl number)
intgig1/0/1 (进入端口1,该端口直接连10.65.156.191)
packet-filter inbound ip-group3005 (让3005列表在端口1中激活生效)