各位大神请教个问题
目前核心交换机又5个Vlan
Vlan 10 172.16.201.1/24
Vlan 20 172.16.202.1/24
Vlan 30 172.16.203.1/24
Vlan 40 172.16.204.1/24
Vlan 50 172.16.205.1/24
怎么通过ACL策略实现
Vlan 10 禁止访问其他vlan,其他vlan也禁止访问vlan10
vlan20 ~50 互访
(0)
写ACL匹配源地址是VLAN10的地址,目的地址是VLAN20-50的地址。应用ACL到VLAN10的in方向就可以了
[Core-A]acl advanced name vlan10-in-out-block
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 200 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.202.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 201 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.203.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 202 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.204.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 203 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.205.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 204 permit ip
[Core-A-acl-ipv4-adv-vlan10-in-out-block]quit
[Core-A]save f
[Core-A]interface Vlan-interface 10
[Core-A-Vlan-interface10]packet-filter name vlan10-in-out-block inbound
[Core-A-Vlan-interface10]quit
[Core-A]save f
(0)
1、VLAN10进制访问其它VLAN
再vlan10的inbound放行套用packet-filter,源地址为vlan10地址,目的地址为其它vlan地址,动作拒绝
2、其它vlan进制访问vlan 10
再vlan10的outbound方向套用packet-filter,源地址为其它vlan,目的地址为vlan10的IP地址
(0)
是这么写吗?
[Core-A]acl advanced name vlan10-in-out-block
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 200 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.202.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 201 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.203.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 202 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.204.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]rule 203 deny ip source 172.16.201.0 0.0.0.255 destination 172.16.205.0 0.0.0.255
[Core-A-acl-ipv4-adv-vlan10-in-out-block]quit
[Core-A]save f
[Core-A]interface Vlan-interface 10
[Core-A-Vlan-interface10]packet-filter name vlan10-in-out-block inbound
[Core-A-Vlan-interface10]packet-filter name vlan10-in-out-block outbound
[Core-A-Vlan-interface10]quit
[Core-A]save f
(0)
看下我答案,改了一下您的命令。
写in就可以,out可以删了
acl规则最后加一个permit 的any
看下我答案,改了一下您的命令。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
那就不需要了