acl number 3000 name VIRUSrule 5 deny tcp destination-port eq 135rule 6 deny udp destination-port eq 135rule 10 deny tcp destination-port eq 137rule 11 deny udp destination-port eq netbios-nsrule 15 deny tcp destination-port eq 138rule 16 deny udp destination-port eq netbios-dgmrule 20 deny tcp destination-port eq 139rule 21 deny udp destination-port eq netbios-ssnrule 25 deny tcp destination-port eq 445rule 26 deny udp destination-port eq 445rule 30 deny tcp destination-port eq 3389rule 100 permit ip
做了一条封堵端口的ACL。需要到每个接口下引用,配置起来比较麻烦。
请教如何在全局应用该ACL规则?
(0)
最佳答案
参考:
acl advanced 3010
description deny_445
rule 0 permit tcp destination-port eq 445
rule 5 permit tcp destination-port eq 135
rule 10 permit tcp destination-port eq 137
rule 15 permit tcp destination-port eq 138
rule 20 permit tcp destination-port eq 139
acl advanced 3011
rule 0 permit tcp source X.X.X.X 0 destination-por t eq 445
traffic classifier deny_445
if-match acl 3010
traffic classifier permit_445
if-match acl 3011
traffic behavior deny_445
filter deny
accounting packet
traffic behavior permit_445
filter permit
accounting packet
qos policy deny_445
classifier dpermit_445 behavior permit_445
classifier deny_445 behavior deny_445
qos apply policy deny_445 global inbound
(0)
请教:为何 ACL 中是 Permit 而不是 Deny
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
请教:为何 ACL 中是 Permit 而不是 Deny