例如 在系統配置模式下
acl number 3001
rule 1 permit ip source 192.168.100.32 0.0.0.28 destination any
rule 2 permit ip source 192.168.100.30 0.0.0.0 destination any
rule 3 permit ip source 192.168.100.31 0.0.0.0 destination any
rule 4 permit ip source 192.168.100.32 0.0.0.0 destination any
rule 5 permit ip source 192.168.100.47 0.0.0.0 destination any
rule 6 permit ip source 192.168.100.48 0.0.0.0 destination any
rule 7 permit ip source 192.168.100.49 0.0.0.0 destination any
rule 8 permit ip source 192.168.100.50 0.0.0.0 destination any
traffic classifier c_manage operator and
if-match acl 3001
traffic behavior b_manage
permit
traffic policy p_manage
classifier c_manage behavior b_manage
interface GigabitEthernet0/0/1 (要過濾的端口)
traffic-policy p_manage inbound