一.acl
测试环境
配置pc机以及服务器
pc1:192.168.1.1 24
pc2:192.168.1.2 24
pc3:192.168.2.1 24
服务器:192.168.3.10 24
配置交换机
lsw1:
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan 10
[Huawei-vlan10]q
[Huawei]port-group group-member g0/0/1 to g 0/0/3
[Huawei-port-group]port link-type access
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-port-group]port default vlan 10
[Huawei-GigabitEthernet0/0/1]port default vlan 10
[Huawei-GigabitEthernet0/0/2]port default vlan 10
[Huawei-GigabitEthernet0/0/3]port default vlan 10
[Huawei-port-group]
lsw2:
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan 20
[Huawei-vlan20]q
[Huawei]port-group group-member g0/0/1 g0/0/2
[Huawei-port-group]port link-type access
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-port-group]port default vlan 20
[Huawei-GigabitEthernet0/0/1]port default vlan 20
[Huawei-GigabitEthernet0/0/2]port default vlan 20
[Huawei-port-group]
ar1:
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.12.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 192.168.0.0 16 192.168.12.2
[Huawei]
<Huawei>
ar2:
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.12.2 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.2.254 24
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 192.168.3.254 24
[Huawei-GigabitEthernet0/0/2]q
[Huawei]ip route-static 192.168.1.0 24 192.168.12.1
在ar2中配置acl:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 10 deny source 192.168.1.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]traffic-filter outbound acl 2000
[Huawei-GigabitEthernet0/0/2]
<Huawei>
实验结果:
192.168.1.0网段ping服务器不通
192.168.2.0网段ping服务区通
二.高级cal
测试环境
配置路由器:
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 192.168.1.254 24
[Huawei-GigabitEthernet0/0/2]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.12.1 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 0.0.0.0 0 192.168.12.2
[Huawei]
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule 10 permit tcp source 192.168.1.0 0.0.0.255 destination
192.168.3.10 0.0.0.0 des
[Huawei-acl-adv-3000]rule 10 permit tcp source 192.168.1.0 0.0.0.255 destination
192.168.3.10 0.0.0.0 destination-port eq 80
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]acl 3000
[Huawei-acl-adv-3000]rule 20 permit ip source 192.168.1.0 0.0.0.255 destination
192.168.2.0 0.0.0.255
[Huawei-acl-adv-3000]rule 30 deny ip source 192.168.1.0 0.0.0.255 destination an
y
[Huawei-acl-adv-3000]
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]traffic-filter inbound acl 3000
[Huawei-GigabitEthernet0/0/2]