一、 端口安全
SW3:
[sw3]int e0/0/1
[sw3-Ethernet0/0/1]port-security enable
[sw3-Ethernet0/0/1]port-security mac-address sticky 5489-98D1-30ED vlan 2
Error: Sticky MAC is not enabled.
[sw3-Ethernet0/0/1]port-security protect-action protect
[sw3]int e0/0/2
[sw3-Ethernet0/0/2]port-security enable
[sw3-Ethernet0/0/2]port-security mac-address sticky 5489-98CC-5CE2 vlan 3
Error: Sticky MAC is not enabled.
[sw3-Ethernet0/0/2]port-security protect-action protect
SW4:
[sw4]int e0/0/1
[sw4-Ethernet0/0/1]port-security enable
[sw4-Ethernet0/0/1]port-security mac-address sticky 5489-982D-5DD8 vlan 3
Error: Sticky MAC is not enabled.
[sw4-Ethernet0/0/1]port-security protect-action protect
[sw4]int e0/0/2
[sw4-Ethernet0/0/2]port-security enable
[sw4-Ethernet0/0/2]port-security mac-address sticky 5489-985D-5D53 vlan 3
Error: Sticky MAC is not enabled.
[sw4-Ethernet0/0/2]port-security protect-action protect
SW5:
[sw5]int e0/0/1
[sw5-Ethernet0/0/1]port-security enable
[sw5-Ethernet0/0/1]port-security mac-address sticky 5489-9825-2989 vlan 2
Error: Sticky MAC is not enabled.
[sw5-Ethernet0/0/1]port-security protect-action protect
[sw5]int e0/0/2
[sw5-Ethernet0/0/2]port-security enable
[sw5-Ethernet0/0/2]port-security mac-address sticky 5489-9889-4986 vlan 2
Error: Sticky MAC is not enabled.
[sw5-Ethernet0/0/2]port-security protect-action protect
二、 二层acl PC3不通PC4
[sw4]acl 4000
[sw4-acl-L2-4000]rule 5 deny source-mac 5489-982D-5DD8 destination-mac 5489-985D-5D53
[sw4-acl-L2-4000]rule 10 permit source-mac ffff-ffff-ffff destination-mac ffff-ffff-ffff
[sw4]int e0/0/1
[sw4-Ethernet0/0/1]traffic-filter inbound acl 4000
三、time-range 控制PC1 PC4 访问外网时间。
[r1]time-range PC1 from 21:05 2020/8/11 to 00:00 2099/1/1
[r1]time-range PC1 09:00 to 12:00 daily
[r1]time-range PC1 13:00 to 16:00 daily
[r1-acl-adv-3000]rule 5 deny icmp source 12.1.1.254 0.0.0.0 destination any time-range PC1
[r1-acl-adv-3000]rule 10 deny icmp source 23.1.1.252 0.0.0.0 destination any time-range PC1
[r1-acl-adv-3000]rule 15 permit icmp source any destination any
[r1-acl-adv-3000]q
[r1]int g0/0/1
[r1-GigabitEthernet0/0/1]traffic-filter inbound acl 3000
[r1]int g0/0/2
[r1-GigabitEthernet0/0/2]traffic-filter inbound acl 3000