拓扑描述:
S5500交换机59.193.185.65/26>>>>10512交换机>>>>>目的服务器59.255.109.24/32
需求:
59.193.185.66;59.193.185.67可正常访问59.255.109.24,其他IP不能访问 如何实现?
在S5500交换机上配置完成没有生效
acl number 3003
rule 1 deny ip vpn-instance GGQSP_GJ source 59.193.185.64 0.0.0.63 destination 59.255.109.24 0
rule 5 deny ip vpn-instance GGQSP_GJ source 59.193.185.0 0.0.0.255 destination 59.255.109.24 0
#
traffic classifier 3003 operator and
traffic classifier deny operator and
if-match acl 3003
# traffic behavior 3003
traffic behavior deny filter deny
# qos policy 3003
classifier 3003 behavior 3003
classifier deny behavior deny
# interface GigabitEthernet1/0/25
port link-mode bridge
port link-type trunk
port trunk permit vlan all
qos apply policy 3003 inbound
(0)
最佳答案
acl number 3003
rule 1 deny ip source 59.193.185.66 32 destination 59.255.109.24 0
rule 5 deny ip source 59.193.185.67 32 destination 59.255.109.24 0
#
traffic classifier 3003 operator and
traffic classifier deny operator and
if-match acl 3003
# traffic behavior 3003
filter permit
traffic behavior deny
filter deny
# qos policy 3003
classifier 3003 behavior 3003
classifier deny behavior deny
# interface GigabitEthernet1/0/25
port link-mode bridge
port link-type trunk
port trunk permit vlan all
qos apply policy 3003 inbound
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论