1. 程式人生 > 實用技巧 >華為 eNSP 配置 ACL 擴充套件

華為 eNSP 配置 ACL 擴充套件

ACL基本擴充套件

1.實驗拓撲

使用ENSP模擬器(版本V100R002C001.2.00.350

wKiom1R5RHHTym0dAAE9dUu_RvA578.jpg


2.實驗需求

1:給R1做一個dhcp地址池

2:做基本的和擴充套件的NAT

3:用vm8綁在2008

3.實驗配置

wKiom1R5RImAmVwYAAGUCISI5no343.jpg


給網絡卡設ip

基本

[Huawei]intg0/0/1

[Huawei-GigabitEthernet0/0/1]ipadd192.168.10.124

[Huawei-GigabitEthernet0/0/1]intg0/0/0

[Huawei-GigabitEthernet0/0/0]ipadd192.168.20.124

[Huawei]dhcpenable做地址池

[Huawei]intg0/0/1

[Huawei-GigabitEthernet0/0/1]dhcpselectinterface放入

0/0/1介面

wKioL1R5RT_QMlPWAALls8bwFxg306.jpg

2008收到地址


wKioL1R5RT-AB6IxAAGgOtsIBGQ295.jpg

wKiom1R5RLrjuV5WAAPlNKognqA111.jpg


Huawei]acl2014

[Huawei-acl-basic-2014]ruledenysource192.168.10.252010.252不能上

[Huawei-acl-basic-2014]rulepermitsourceany

disthis


wKioL1R5RXrgVXh2AACAWQzUGMM730.jpg

[Huawei-acl-basic-2014]rule6denysource192.168.10.2530中間新增一個6

[Huawei-acl-basic-2014]disthis


wKiom1R5RPSxDGA9AACrqxbKd_0496.jpg

Huawei-acl-basic-2014]undorule6直接加上6就能刪了

[Huawei-acl-basic-2014]disthis

wKioL1R5RXqAGOVoAACu3kIGgkg599.jpg


[Huawei-acl-basic-2014]intg0/0/0

[Huawei-GigabitEthernet0/0/0]traffic-filteroutboundacl2014

[Huawei-GigabitEthernet0/0/0]displayaclall

wKiom1R5RPSDatwyAACiyJcONPY725.jpg


[Huawei-GigabitEthernet0/0/0]untraffic-filteroutbound

q

擴充套件

[Huawei]undoacl2014

[Huawei]acl3014

[Huawei-acl-adv-3014]ruledenytcpsource192.168.10.00.0.0.255destination192.168.20.80destination-porteq8010.0網段不能通過20.8獲取www

[Huawei-acl-adv-3014]rulepermitipsourceanydestinationany

Huawei-acl-adv-3014]intg0/0/1

[Huawei-GigabitEthernet0/0/1]traffic-filterinboundacl3014

[Huawei-GigabitEthernet0/0/1]disaclall

配置時間

[Huawei]time-rangework8:00to11:30working-day建立時間組

[Huawei-acl-adv-3014]ruledenytcpsource192.168.10.00.0.0.255destination192.168.20.80destination-porteq80time-rangeftp-access加上時間組

user-intvty04

acl3014inbound設在這裡安全

wKiom1R5RTnwWdMBAAIV7Zd9J0Q775.jpg

轉載於:https://blog.51cto.com/funinghua/1584424