IP课:端口安全、时间acl、二层acl实验

在这里插入图片描述

一、 端口安全
SW3:
[sw3]int e0/0/1
[sw3-Ethernet0/0/1]port-security enable
[sw3-Ethernet0/0/1]port-security mac-address sticky 5489-98D1-30ED vlan 2
Error: Sticky MAC is not enabled.
[sw3-Ethernet0/0/1]port-security protect-action protect
[sw3]int e0/0/2
[sw3-Ethernet0/0/2]port-security enable
[sw3-Ethernet0/0/2]port-security mac-address sticky 5489-98CC-5CE2 vlan 3
Error: Sticky MAC is not enabled.
[sw3-Ethernet0/0/2]port-security protect-action protect

SW4:
[sw4]int e0/0/1
[sw4-Ethernet0/0/1]port-security enable

[sw4-Ethernet0/0/1]port-security mac-address sticky 5489-982D-5DD8 vlan 3
Error: Sticky MAC is not enabled.
[sw4-Ethernet0/0/1]port-security protect-action protect
[sw4]int e0/0/2
[sw4-Ethernet0/0/2]port-security enable
[sw4-Ethernet0/0/2]port-security mac-address sticky 5489-985D-5D53 vlan 3
Error: Sticky MAC is not enabled.
[sw4-Ethernet0/0/2]port-security protect-action protect

SW5:
[sw5]int e0/0/1
[sw5-Ethernet0/0/1]port-security enable
[sw5-Ethernet0/0/1]port-security mac-address sticky 5489-9825-2989 vlan 2
Error: Sticky MAC is not enabled.
[sw5-Ethernet0/0/1]port-security protect-action protect
[sw5]int e0/0/2
[sw5-Ethernet0/0/2]port-security enable
[sw5-Ethernet0/0/2]port-security mac-address sticky 5489-9889-4986 vlan 2
Error: Sticky MAC is not enabled.
[sw5-Ethernet0/0/2]port-security protect-action protect

二、 二层acl PC3不通PC4
[sw4]acl 4000
[sw4-acl-L2-4000]rule 5 deny source-mac 5489-982D-5DD8 destination-mac 5489-985D-5D53
[sw4-acl-L2-4000]rule 10 permit source-mac ffff-ffff-ffff destination-mac ffff-ffff-ffff
[sw4]int e0/0/1
[sw4-Ethernet0/0/1]traffic-filter inbound acl 4000
在这里插入图片描述

三、time-range 控制PC1 PC4 访问外网时间。
[r1]time-range PC1 from 21:05 2020/8/11 to 00:00 2099/1/1
[r1]time-range PC1 09:00 to 12:00 daily
[r1]time-range PC1 13:00 to 16:00 daily
[r1-acl-adv-3000]rule 5 deny icmp source 12.1.1.254 0.0.0.0 destination any time-range PC1
[r1-acl-adv-3000]rule 10 deny icmp source 23.1.1.252 0.0.0.0 destination any time-range PC1
[r1-acl-adv-3000]rule 15 permit icmp source any destination any
[r1-acl-adv-3000]q
[r1]int g0/0/1
[r1-GigabitEthernet0/0/1]traffic-filter inbound acl 3000
[r1]int g0/0/2
[r1-GigabitEthernet0/0/2]traffic-filter inbound acl 3000

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 2
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值