请问如何禁止某网段如192.168.100.X 访问218.2.X.X
(0)
最佳答案
[Device] acl advanced 3000
[Device-acl-ipv4-adv-3000] rule deny ip source 192.168.100.0 0.0.0.255 destination 218.2.0.0 0.0.255.255
[Device-acl-ipv4-adv-3000] quit
# 应用IPv4高级ACL 3000对接口GigabitEthernet2/0/0出方向上的报文进行过滤。
[Device] interface gigabitethernet 2/0/0
[Device-GigabitEthernet2/0/0] packet-filter 3000 outbound
[Device-GigabitEthernet2/0/0] quit
(0)
如果是218.2.xxx在公网
在nat 调用的acl里面
acl ad 3000
rule 0 deny ip source 192.168.100.X 反掩码 destion ip 218.2.xxx
rule 10 permit ip source
interface g 1/0/x
nat outbound 3000
如果是218.2.xxx内网:
acl ad 3000
rule 0 deny ip source 192.168.100.X 反掩码 destion ip 218.2.xxx
在对应访问的接口下:
packet-fi 3000 inbound
packet-fi 3000 outbound 看访问方向来
(0)
访问的是外网,还是禁不了218.2.2.2仍能ping通218.2.2.2 acl number 3001 rule 10 permit ip rule 20 deny ip source 192.168.100.0 0.0.0.255 destination 218.2.0.0 0.0.255.255 # dhcp server ip-pool vlan100 network 192.168.100.0 mask 255.255.255.0 gateway-list 192.168.100.254 dns-list 218.2.2.2 interface Ethernet0/0 port link-mode route nat outbound 3001 ip address dhcp-alloc # interface Ethernet0/1 port link-mode route ip address 192.168.100.254 255.255.255.0 # ip route-static 0.0.0.0 0.0.0.0 Ethernet0/0 192.168.10.1 #
rule 10 rule 20 需要换位置 你rule 10是放行了所有,就不会匹配rule 20了
acl number 3001 rule 20 deny ip source 192.168.100.0 0.0.0.255 destination 218.2.0.0 0.0.255.25 5换了还是不行呀 rule 30 permit ip
acl number 3001 rule 0 deny ip source 192.168.100.0 0.0.0.255 destination 218.2.0.0 0.0.255.255 rule 10 permit ip interface Ethernet0/0 nat outbound 3001 ip address dhcp-alloc interface Ethernet0/1 ip address 192.168.100.254 255.255.255.0 ip route-static 0.0.0.0 0.0.0.0 Ethernet0/0 192.168.10.1 请帮我看看问题出哪了?
你用哪个终端ping的? 你不要告诉我在设备上面ping
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
访问的是外网,还是禁不了218.2.2.2仍能ping通218.2.2.2 acl number 3001 rule 10 permit ip rule 20 deny ip source 192.168.100.0 0.0.0.255 destination 218.2.0.0 0.0.255.255 # dhcp server ip-pool vlan100 network 192.168.100.0 mask 255.255.255.0 gateway-list 192.168.100.254 dns-list 218.2.2.2 interface Ethernet0/0 port link-mode route nat outbound 3001 ip address dhcp-alloc # interface Ethernet0/1 port link-mode route ip address 192.168.100.254 255.255.255.0 # ip route-static 0.0.0.0 0.0.0.0 Ethernet0/0 192.168.10.1 #
访问外网没有这么复杂 你哪些地址段需要上外网 你写条ACL把需要上外网的地址加上 在外网接口上NAT outbound 加上需要上外网的ACL就行