怎么使用ACL禁止IP地址和MAC地址通过交换机的上行端口访问外网。
指定IP地址:192.168.21.0/24、192.168.23.0/24
指定的MAC地址:d076-e799-947e、0018-82a6-4dac、249e-abaa-2d70
交换机上行口为0/0/32(接外网路由器)
交换机版本H3C S7503E-S-6616P05
(1)
最佳答案
如果你是要过滤源mac和源IP,下边的要改为 dest-mac改为source-mac ,destination 改为source
acl number 4000
rule 0 deny dest-mac d076-e799-947e ffff-ffff-ffff
rule 5 deny dest-mac 0018-82a6-4dac ffff-ffff-ffff
rule 10 deny dest-mac 249e-abaa-2d70 ffff-ffff-ffff
acl number 3000
rule 0 deny destination 192.168.21.0 0.0.0.255
rule 5 deny destination 192.168.23.0 0.0.0.255
int g0/0/32
packet-filter 2000 outbound
packet-filter 3000 outbound
(1)
any Any source IP address [SNX_S7503E-acl-basic-2000]rule 0 deny ? counting Specify Rule Counting fragment Check fragment packet logging Log matched packet source Specify source address time-range Specify a special time vpn-instance Specify a VPN-Instance <cr> [SNX_S7503E-acl-basic-2000]rule 0 deny dest-mac [SNX_S7503E-acl-basic-2000]rule 0 deny dest-mac ? ^ % Too many parameters found at '^' position. [SNX_S7503E-acl-basic-2000]rule 0 deny dest-mac 这版版不支持这个命令
[图片]
补充说明 楼上回答存在问题;
1、dest-mac 不论V5还是V7中,是 acl number 4000-5000之间才可以,即 二层acl;
2、acl默认拒绝,写了deny这些ip、mac,记得最后一条加上ru 100 permit 已放行除此之外其他允许通过的ip、mac;
命令改为:
acl number 4000
rule 0 deny dest-mac d076-e799-947e ffff-ffff-ffff
rule 5 deny dest-mac 0018-82a6-4dac ffff-ffff-ffff
rule 10 deny dest-mac 249e-abaa-2d70 ffff-ffff-ffff
rule 100 permit
acl number 3000
rule 0 deny destination 192.168.21.0 0.0.0.255
rule 5 deny destination 192.168.23.0 0.0.0.255
rule 100 permit
int g0/0/32
packet-filter 2000 outbound
packet-filter 3000 outbound
如果有帮助到您,请点 “采纳” 按钮已完成您的提问,闭环问题单,谢谢!
(0)
[S7503E]ping -a 192.168.23.1 114.114.114.114 PING 114.114.114.114: 56 data bytes, press CTRL_C to break Reply from 114.114.114.114: bytes=56 Sequence=1 ttl=80 time=23 ms Reply from 114.114.114.114: bytes=56 Sequence=2 ttl=77 time=22 ms Reply from 114.114.114.114: bytes=56 Sequence=3 ttl=65 time=21 ms Reply from 114.114.114.114: bytes=56 Sequence=4 ttl=63 time=22 ms Reply from 114.114.114.114: bytes=56 Sequence=5 ttl=80 time=22 ms
配完了,用禁止了的源地址ping测试还是可以通过上行口访问到外网
[图片][图片][图片]
[S7503E]display acl all Advanced ACL 3000, named -none-, 3 rules, ACL's step is 5 rule 0 deny ip source 192.168.21.0 0.0.0.255 rule 5 deny ip source 192.168.23.0 0.0.0.255 rule 100 permit ip Ethernet frame ACL 4000, named -none-, 5 rules, ACL's step is 5 rule 0 deny dest-mac d076-e799-947e ffff-ffff-ffff rule 5 deny dest-mac 0018-82a6-4dac ffff-ffff-ffff rule 10 deny dest-mac 4c11-bf99-dca1 ffff-ffff-ffff rule 15 deny dest-mac 249e-abaa-2d70 ffff-ffff-ffff rule 100 permit
interface GigabitEthernet0/0/32 port link-mode bridge description up-link_HW6330FW-GE1/0/0 port access vlan 403 packet-filter 3000 outbound packet-filter 4000 outbound
[S7503E]ping -a 192.168.23.1 114.114.114.114 PING 114.114.114.114: 56 data bytes, press CTRL_C to break Reply from 114.114.114.114: bytes=56 Sequence=1 ttl=80 time=23 ms Reply from 114.114.114.114: bytes=56 Sequence=2 ttl=77 time=22 ms Reply from 114.114.114.114: bytes=56 Sequence=3 ttl=65 time=21 ms Reply from 114.114.114.114: bytes=56 Sequence=4 ttl=63 time=22 ms Reply from 114.114.114.114: bytes=56 Sequence=5 ttl=80 time=22 ms
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
[图片]