ACL简单运用
SW1 : VLAN 10 IP:10.10.1.1/30 SW2 :VLAN10 IP :10.10.1.2/30
SW1 : VLAN 20 IP:10.10.2.1/30 SW2 :VLAN20 IP :10.10.2.2/30
SW1配置:
#
interface Vlanif10
ip address 10.10.1.1 255.255.255.252
#
interface Vlanif20
ip address 10.10.2.1 255.255.255.252
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20
#
#
acl number 3000
rule 5 permit icmp source 10.10.1.2 0 destination 10.10.1.1 0
acl number 3001
rule 5 permit ip
#
traffic classifier deny operator and
if-match acl 3000