Qtech QSW-2910-10T-POE-AC/DC [110/212] Use qacl to realize deny all packet expect

Qtech QSW-2910-10T-POE-AC/DC [110/212] Use qacl to realize deny all packet expect
+7(495) 797-3311 www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
110
!Define ACL transmitting packet with source interface to be Ethernet
interface 8,destination interface to be wthernet interface 1,source
MAC address to be 00:01:02:03:04:05
QTECH(config)#accesss-list 200 permit ingress 00:01:02:03:04:05
0:0:0:0:0:0 interface ethernet 0/0/8 egress egress interface ethernet
0/0/1
!Define ACL transmitting packet with source interface being Ethernet
interface 1,destination interface being Ethernet interface 8,source
MAC address being 00:01:02:03:04:05
QTECH(config)#accesss-list 201 permit ingress 00:01:02:03:04:05
0:0:0:0:0:0 interface fast-ethenet 1 egress egress interface ethernet
0/0/8
(2) Configure flow monitor of uplink and downlink interface
!Enter interface configuration mode of uplink interface 1
QTECH(config)#interface ethernet 0/1
!Configure corresponded flow monitor of uplink interface 1
QTECH(config-if-ethernet-0/0/1)##rate-limit input link-group 201 3
!Enter interface configuration mode of downlink interface 8
QTECH(config)#interface ethernet 0/0/8
!Configure corresponded flow monitor of downlink interface 8
QTECH(config-if-ethernet-0/0/8)##rate-limit input link-group 200 5
7.4.3 Use QACL to realize deny all packet expect
Brief introduction of deny all packet expect
deny all packet expect is used to drop all packet except needing transmitting. This function can
be realized by configuring QACL.
1. Configuration example
Configuring deny all packet expect PPPoE, the protocol number of PPPoE is 0x8863 (decimal
is 34915) and 0x8864 (decimal is 34916)
(1) Drop all packets
(2) Transmit PPPoE packet
Configuration is as following:
(1) Define needed ACL
!Configure deny ACL of all packet
QTECH(config)#access-list 200 deny ingress any egress any
!Configure ACL of transmitting PPPoE packet

Содержание

Скачать