古詩詞大全網 - 口號大全 - 華為S3700交換機如何實現端口IP地址過濾

華為S3700交換機如何實現端口IP地址過濾

IP只能寫在vlan接口中,要做過濾可以寫ACL

例如 在系統配置模式下

acl number 3001

rule 1 permit ip source 192.168.100.32 0.0.0.28 destination any

rule 2 permit ip source 192.168.100.30 0.0.0.0 destination any

rule 3 permit ip source 192.168.100.31 0.0.0.0 destination any

rule 4 permit ip source 192.168.100.32 0.0.0.0 destination any

rule 5 permit ip source 192.168.100.47 0.0.0.0 destination any

rule 6 permit ip source 192.168.100.48 0.0.0.0 destination any

rule 7 permit ip source 192.168.100.49 0.0.0.0 destination any

rule 8 permit ip source 192.168.100.50 0.0.0.0 destination any

traffic classifier c_manage operator and

if-match acl 3001

traffic behavior b_manage

permit

traffic policy p_manage

classifier c_manage behavior b_manage

interface GigabitEthernet0/0/1 (要過濾的端口)

traffic-policy p_manage inbound