我来为您设计最精简的ACL规则,实现精确放行指定的IP范围和端口:
# 创建高级ACL
acl advanced 3000
rule 5 permit tcp source 10.202.0.11 0 destination 10.71.15.66 0 destination-port eq 111
rule 6 permit tcp source 10.202.0.11 0 destination 10.71.15.67 0 destination-port eq 111
rule 7 permit tcp source 10.202.0.11 0 destination 10.71.15.68 0 destination-port eq 111
rule 8 permit tcp source 10.202.0.11 0 destination 10.71.15.69 0 destination-port eq 111
rule 9 permit tcp source 10.202.0.11 0 destination 10.71.15.70 0 destination-port eq 111
rule 10 permit tcp source 10.202.0.12 0 destination 10.71.15.66 0 destination-port eq 111
rule 11 permit tcp source 10.202.0.12 0 destination 10.71.15.67 0 destination-port eq 111
rule 12 permit tcp source 10.202.0.12 0 destination 10.71.15.68 0 destination-port eq 111
rule 13 permit tcp source 10.202.0.12 0 destination 10.71.15.69 0 destination-port eq 111
rule 14 permit tcp source 10.202.0.12 0 destination 10.71.15.70 0 destination-port eq 111
rule 15 permit tcp source 10.202.0.13 0 destination 10.71.15.66 0 destination-port eq 111
rule 16 permit tcp source 10.202.0.13 0 destination 10.71.15.67 0 destination-port eq 111
rule 17 permit tcp source 10.202.0.13 0 destination 10.71.15.68 0 destination-port eq 111
rule 18 permit tcp source 10.202.0.13 0 destination 10.71.15.69 0 destination-port eq 111
rule 19 permit tcp source 10.202.0.13 0 destination 10.71.15.70 0 destination-port eq 111
rule 20 permit tcp source 10.202.0.14 0 destination 10.71.15.66 0 destination-port eq 111
rule 21 permit tcp source 10.202.0.14 0 destination 10.71.15.67 0 destination-port eq 111
rule 22 permit tcp source 10.202.0.14 0 destination 10.71.15.68 0 destination-port eq 111
rule 23 permit tcp source 10.202.0.14 0 destination 10.71.15.69 0 destination-port eq 111
rule 24 permit tcp source 10.202.0.14 0 destination 10.71.15.70 0 destination-port eq 111
rule 25 permit tcp source 10.202.0.15 0 destination 10.71.15.66 0 destination-port eq 111
rule 26 permit tcp source 10.202.0.15 0 destination 10.71.15.67 0 destination-port eq 111
rule 27 permit tcp source 10.202.0.15 0 destination 10.71.15.68 0 destination-port eq 111
rule 28 permit tcp source 10.202.0.15 0 destination 10.71.15.69 0 destination-port eq 111
rule 29 permit tcp source 10.202.0.15 0 destination 10.71.15.70 0 destination-port eq 111
# 复制以上规则,修改端口号为2049
rule 30 permit tcp source 10.202.0.11 0 destination 10.71.15.66 0 destination-port eq 2049
rule 31 permit tcp source 10.202.0.11 0 destination 10.71.15.67 0 destination-port eq 2049
rule 32 permit tcp source 10.202.0.11 0 destination 10.71.15.68 0 destination-port eq 2049
rule 33 permit tcp source 10.202.0.11 0 destination 10.71.15.69 0 destination-port eq 2049
rule 34 permit tcp source 10.202.0.11 0 destination 10.71.15.70 0 destination-port eq 2049
rule 35 permit tcp source 10.202.0.12 0 destination 10.71.15.66 0 destination-port eq 2049
rule 36 permit tcp source 10.202.0.12 0 destination 10.71.15.67 0 destination-port eq 2049
rule 37 permit tcp source 10.202.0.12 0 destination 10.71.15.68 0 destination-port eq 2049
rule 38 permit tcp source 10.202.0.12 0 destination 10.71.15.69 0 destination-port eq 2049
rule 39 permit tcp source 10.202.0.12 0 destination 10.71.15.70 0 destination-port eq 2049
rule 40 permit tcp source 10.202.0.13 0 destination 10.71.15.66 0 destination-port eq 2049
rule 41 permit tcp source 10.202.0.13 0 destination 10.71.15.67 0 destination-port eq 2049
rule 42 permit tcp source 10.202.0.13 0 destination 10.71.15.68 0 destination-port eq 2049
rule 43 permit tcp source 10.202.0.13 0 destination 10.71.15.69 0 destination-port eq 2049
rule 44 permit tcp source 10.202.0.13 0 destination 10.71.15.70 0 destination-port eq 2049
rule 45 permit tcp source 10.202.0.14 0 destination 10.71.15.66 0 destination-port eq 2049
rule 46 permit tcp source 10.202.0.14 0 destination 10.71.15.67 0 destination-port eq 2049
rule 47 permit tcp source 10.202.0.14 0 destination 10.71.15.68 0 destination-port eq 2049
rule 48 permit tcp source 10.202.0.14 0 destination 10.71.15.69 0 destination-port eq 2049
rule 49 permit tcp source 10.202.0.14 0 destination 10.71.15.70 0 destination-port eq 2049
rule 50 permit tcp source 10.202.0.15 0 destination 10.71.15.66 0 destination-port eq 2049
rule 51 permit tcp source 10.202.0.15 0 destination 10.71.15.67 0 destination-port eq 2049
rule 52 permit tcp source 10.202.0.15 0 destination 10.71.15.68 0 destination-port eq 2049
rule 53 permit tcp source 10.202.0.15 0 destination 10.71.15.69 0 destination-port eq 2049
rule 54 permit tcp source 10.202.0.15 0 destination 10.71.15.70 0 destination-port eq 2049
# 复制以上规则,修改端口号为20048
rule 55 permit tcp source 10.202.0.11 0 destination 10.71.15.66 0 destination-port eq 20048
rule 56 permit tcp source 10.202.0.11 0 destination 10.71.15.67 0 destination-port eq 20048
rule 57 permit tcp source 10.202.0.11 0 destination 10.71.15.68 0 destination-port eq 20048
rule 58 permit tcp source 10.202.0.11 0 destination 10.71.15.69 0 destination-port eq 20048
rule 59 permit tcp source 10.202.0.11 0 destination 10.71.15.70 0 destination-port eq 20048
rule 60 permit tcp source 10.202.0.12 0 destination 10.71.15.66 0 destination-port eq 20048
rule 61 permit tcp source 10.202.0.12 0 destination 10.71.15.67 0 destination-port eq 20048
rule 62 permit tcp source 10.202.0.12 0 destination 10.71.15.68 0 destination-port eq 20048
rule 63 permit tcp source 10.202.0.12 0 destination 10.71.15.69 0 destination-port eq 20048
rule 64 permit tcp source 10.202.0.12 0 destination 10.71.15.70 0 destination-port eq 20048
rule 65 permit tcp source 10.202.0.13 0 destination 10.71.15.66 0 destination-port eq 20048
rule 66 permit tcp source 10.202.0.13 0 destination 10.71.15.67 0 destination-port eq 20048
rule 67 permit tcp source 10.202.0.13 0 destination 10.71.15.68 0 destination-port eq 20048
rule 68 permit tcp source 10.202.0.13 0 destination 10.71.15.69 0 destination-port eq 20048
rule 69 permit tcp source 10.202.0.13 0 destination 10.71.15.70 0 destination-port eq 20048
rule 70 permit tcp source 10.202.0.14 0 destination 10.71.15.66 0 destination-port eq 20048
rule 71 permit tcp source 10.202.0.14 0 destination 10.71.15.67 0 destination-port eq 20048
rule 72 permit tcp source 10.202.0.14 0 destination 10.71.15.68 0 destination-port eq 20048
rule 73 permit tcp source 10.202.0.14 0 destination 10.71.15.69 0 destination-port eq 20048
rule 74 permit tcp source 10.202.0.14 0 destination 10.71.15.70 0 destination-port eq 20048
rule 75 permit tcp source 10.202.0.15 0 destination 10.71.15.66 0 destination-port eq 20048
rule 76 permit tcp source 10.202.0.15 0 destination 10.71.15.67 0 destination-port eq 20048
rule 77 permit tcp source 10.202.0.15 0 destination 10.71.15.68 0 destination-port eq 20048
rule 78 permit tcp source 10.202.0.15 0 destination 10.71.15.69 0 destination-port eq 20048
rule 79 permit tcp source 10.202.0.15 0 destination 10.71.15.70 0 destination-port eq 20048
# 默认拒绝所有
rule 100 deny ip
注意:上面的配置使用了75条规则,这是最精确的匹配方式。如果您想进一步减少规则数,可以考虑以下优化方案:
优化方案(使用通配符掩码)
# 创建高级ACL - 使用通配符掩码合并IP段
acl advanced 3000
# 放行111端口
rule 5 permit tcp source 10.202.0.11 0.0.0.4 destination 10.71.15.66 0.0.0.4 destination-port eq 111
# 放行2049端口
rule 6 permit tcp source 10.202.0.11 0.0.0.4 destination 10.71.15.66 0.0.0.4 destination-port eq 2049
# 放行20048端口
rule 7 permit tcp source 10.202.0.11 0.0.0.4 destination 10.71.15.66 0.0.0.4 destination-port eq 20048
# 默认拒绝
rule 100 deny ip
通配符掩码说明:
0.0.0.4表示前24位必须匹配,第4字节的最后3位(二进制位)可变
源IP范围:10.202.0.11-15(二进制最后8位:00001011-00001111)
目的IP范围:10.71.15.66-70(二进制最后8位:01000010-01000110)
注意:使用通配符掩码虽然减少了规则数(只需3条),但可能会稍微放宽匹配范围,不过在这个特定情况下是精确的,因为:
10.202.0.11-15 可以用掩码 0.0.0.4 精确匹配
10.71.15.66-70 也可以用掩码 0.0.0.4 精确匹配
应用ACL到接口:
# 进入接口视图
interface GigabitEthernet 1/0/1 # 替换为实际接口
# 在入方向应用ACL
packet-filter 3000 inbound
# 或在出方向应用ACL
packet-filter 3000 outbound
验证配置:
# 查看ACL配置
display acl 3000
# 查看ACL统计信息
display acl 3000 statistics
# 查看ACL命中计数
display packet-filter statistics interface GigabitEthernet 1/0/1
建议:如果您需要绝对精确的匹配,使用第一种75条规则的方案。如果您可以接受使用通配符掩码,第二种3条规则的方案更为简洁高效。
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论