Tp-Link T1700G-28TQ V2 — настройка ACL: Пример конфигурации для сетевой безопасности [564/772]

Превью страниц Страница 564 / 772
Tp-Link T1700G-28TQ V2 [564/772] Using the gui
Configuring ACL Configuration Example for ACL
Configuration Guide
539

Configuring ACL
1) Configure a rule to match packets with source IP address 10.10.70.0/24, and
destination IP address 110.10.80.0/24. This rule allows the Marketing department to
access internal network servers from intranet.
2) Configure permit rules to match the packets with source IP address 10.10.70.0/24,
and destination ports TCP 80, TCP 443 and TCP/UDP 53. These allow the Marketing
department to visit http and https websites on the internet.
3) Configure a deny rule to match the packets with source IP address 10.10.70.0. This rule
blocks other network services.
The switch matches the packets with the rules in order, starting with Rule 1. If a packet
matches a rule, the switch stops the matching process and initiates the action defined in
the rule.

Binding Configuration
Apply the Extend-IP ACL to a Policy and bind the Policy to port 1/0/1 so that the ACL rules
will apply to the Marketing department only.
Exampled with T1700G-28TQ, the following sections explain the configuration procedure
in two ways: using the GUI and using the CLI.
3.4 Using the GUI
1) Choose the menu ACL > ACL Config > ACL Create to load the following page. Then
create Extend- IP ACL 1600.
Figure 3-2 Creating an Extend-IP ACL
2) Choose the menu ACL > ACL Config > Extend-IP ACL to load the the following page.
Configure Rule 1 to match packets with the source IP address 10.10.70.0/24 and
destination IP address 10.10.80.0/24.

Содержание

3073

Узнайте, как настроить правила ACL для управления доступом в сети. Пример конфигурации для отдела маркетинга с использованием различных правил и методов.