公司AC访问控制
思科3750
AC在VLAN30
access-list 100 permit tcp 192.168.5.0 0.0.0.31 172.16.0.0 0.0.255.255 eq 443 允许5.30以前的地址访问
access-list 100 deny tcp any 172.16.0.0 0.0.255.255 eq 443 不允许其它地址访问443
access-list 100 permit ip any any 允许其它数据通过
interface vlan 30
ip access-group 100 out
telnet 访问控制 只允许部分管理用户登录
access-list 101 permit tcp 192.168.5.0 0.0.0.31 any eq 23 # telnet
access-list 101 permit tcp 192.168.5.0 0.0.0.31 any eq 22 #SSH登录
line vty 0 4
access-class 101 in
line vty 5 15
access-class 101 in
思科ASA5520 只允许部分管理用户登录
telnet 192.168.5.0 255.255.255.224 inside 只允许此段地址登录asa5520
no telnet 0.0.0.0 0.0.0.0 outside
ssh 192.168.5.0 255.255.255.224 inside
no ssh 0.0.0.0 0.0.0.0 inside
限制登录流控设备
access-list 100 permit tcp 192.168.5.0 255.255.255.224 host 1.1.1.1 eq 443
access-list 100 permit tcp 192.168.5.0 255.255.255.224 host 10.252.252.252 eq 443
access-list 100 deny tcp any host 1.1.1.1 eq 443
access-list 100 deny tcp any host 10.252.252.252 eq 443
access-list 100 permit ip any any
access-group 100 out interface outside