华为s5700怎么做vlan间禁止访问?
2016-03-07 22:53
323 查看
1、用的华为S5700-24TP-SI,划了3个vlan,分别为vlan 2、vlan 3、vlan 4,对应的IP段为: vlan 2:192.168.2.0/255.255.255.0 vlan 3:192.168.3.0/255.255.255.0 vlan 4:192.186.4.0/255.255.255.0 2、怎么限制vlan2不可以访问vlan
3、vlan4; vlan3不可以访问vlan 2、vlan4; vlan4不可以访问vlan 2、vlan3;
用ACL来实现,具体如下:
acl number 3002
rule deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3003
rule deny ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule deny ip source 192.168.3.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3004
rule deny ip source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule deny ip source 192.168.4.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
用traffic-filter在vlan下应用ACL,
traffic-filter vlan 2 inbound acl 3002
traffic-filter vlan 3 inbound acl 3003
traffic-filter vlan 4 inbound acl 3004
3、vlan4; vlan3不可以访问vlan 2、vlan4; vlan4不可以访问vlan 2、vlan3;
用ACL来实现,具体如下:
acl number 3002
rule deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3003
rule deny ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule deny ip source 192.168.3.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
acl number 3004
rule deny ip source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule deny ip source 192.168.4.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
用traffic-filter在vlan下应用ACL,
traffic-filter vlan 2 inbound acl 3002
traffic-filter vlan 3 inbound acl 3003
traffic-filter vlan 4 inbound acl 3004
相关文章推荐
- 黄聪:PHP 防护XSS,SQL,代码执行,文件包含等多种高危漏洞
- 英文学习
- Codeforces 633 G. Yash And Trees (dfs序+线段树+位图)
- jvm(2)-JVM内存的设置(解决eclipse下out of memory问题)
- 设计模式之一(代码用java实现)
- Amoeba For MySQL入门:实现数据库水平切分
- 1.VS2005安装
- 单片机小记
- 【数组】C99的新特性:指定初始化项目
- hihoCoder 1269 优化延迟
- android实现socket连接(客户端)
- HDOJ 2149 Public Sale(巴士博弈)
- HDOJ 2018母牛的故事
- iOS绘图-UIBezierPath的使用
- 转载 JavaScript中的常规函数
- ArcGIS之基于GIS的旅游辐射区人口统计
- 错误的反思
- OLED取模笔记
- Service onStartCommand返回值问题
- [ML of Andrew Ng]Week 1 : Linear Regression with One Variable