在MSR830上想让网段内的一部分电脑不能访问外网,照猫画虎的做了个策略,但不起作用。大神们看看,是那里不对了。
acl number 3000
description int
rule 1 permit ip source 192.168.100.1 0
rule 2 permit ip source 192.168.100.2 0
rule 3 permit ip source 192.168.100.3 0
......
rule 30 permit ip source 192.168.100.30 0
acl number 3001
description int
rule 0 deny ip
traffic classifier PER-A operator and
if-match acl 3000
traffic
classifier DEN-B operator and
if-match acl 3001
traffic behavior aclpermit
filter permit
traffic behavior acldeny
filter deny
qos policy PolicyLimitOut
classifier PER-A behavior aclpermit
classifier DEN-B behavior acldeny
interface GigabitEthernet0/0
port link-mode route
nat outbound
ip address 192.168.1.2 255.255.255.0
tcp mss 1024
qos apply policy PolicyLimitOut outbound
dns server 8.8.8.8
dns server 202.99.192.68
(0)
最佳答案
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论