对特定vlan允许特定端口访问,其它vlan之间阻止对特定端口的访问。
校园网内,对访问vlan1000的端口445.135.137.138.139允许,其它vlan相互之间阻止访问445.135.137.138.139端口。这个怎么实现?
(0)
最佳答案
[H3C]acl number 3000【新版本命令为acl advance 3000】 [H3C-acl-ipv4-adv-3000] rule 5 permit tcp destination-port eq 135 [H3C-acl-ipv4-adv-3000] rule 10 permit tcp destination-port eq 137 [H3C-acl-ipv4-adv-3000] rule 15 permit tcp destination-port eq 138 [H3C-acl-ipv4-adv-3000] rule 20 permit tcp destination-port eq 139 [H3C-acl-ipv4-adv-3000] rule 25 permit tcp destination-port eq 445 [H3C-acl-ipv4-adv-3000] rule 30 permit udp destination-port eq 135 [H3C-acl-ipv4-adv-3000] rule 35 permit udp destination-port eq 137 [H3C-acl-ipv4-adv-3000] rule 40 permit udp destination-port eq 138 [H3C-acl-ipv4-adv-3000] rule 45 permit udp destination-port eq 139 [H3C-acl-ipv4-adv-3000] rule 50 permit udp destination-port eq 445 设置ACL3001目的地址是vlan1000的段的网段
|
[H3C]traffic classifier virus operator or [H3C-classifier-virus]if-match acl 3000 traffic classifier virus vlan1000 if-match acl 3000 |
[H3C]traffic behavior virus [H3C-behavior-virus]filter deny traffic behavior vlan1000 filter petmit |
[H3C]qos policy virus classifier virus behavior virus classifier vlan1000 behavior vlan1000 |
接口下调用: qos apply policy virus inbound |
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论