Qtech QSW-3900-1x10GE [241/313] Example 2

Qtech QSW-3900-48-Т-AC [241/313] Example 2
QTECH Software Configuration Manual
15-240
QTECH(config)#access-list 1 permit 192.168.0.1 0
QTECH(config)#access-list 201 permit ingress interface ethernet 0/0/2 egress any
!Define ip+port+vid user to bind ACL with ip being 192.168.0.2port being Ethernet interface 2 and vid
being 2. This ip+port+vid user bound rule can be divided into 2 ACLsone is ACL to transmit packet with source
address being 192.168.0.2, the other is ACL to transmit packet with vid being 2 from Ethernet interface 2
QTECH(config)#access-list 1 permit 192.168.0.2 0
QTECH(config)#access-list 201 permit ingress 2 interface ethernet 0/0/2 egress any
!Define ip+port+mac user to bind ACL with ip being 192.168.0.3port being Ethernet interface 2 and mac
being 00:00:00:00:00:03. This ip+port+mac user bound rule can be divided into 2 ACLsone is ACL to transmit
packet with source address being 192.168.0.3, the other is ACL to transmit packet with mac being 00:00:00:00:00:03
from Ethernet interface 2
QTECH(config)#access-list 1 permit 192.168.0.3 0
QTECH(config)#access-list 201 permit ingress 00:00:00:00:00:03 0:0:0:0:0:0 interface ethernet 0/0/2 egress
any
2Activate ACL
QTECH(config)#access-group link-group 200
QTECH(config)#access-group ip-group 1 link-group 201
15.4.1.3 Example 2
Example 2 uses QACL to realize user isolation of not transmitting all ARP packet. This example can realize
following function:
1) Enable user isolation (prevent all packet and permit packet with VLAN id being 4016);
2) Configure Ethernet interface 1 to be uplink interface (permit all packet from uplink interface 1)
3) Configure binding rules of three users:
1> ip+portip is 192.168.0.1 and port to be Ethernet interface 2
2> ip+port+vidip is 192.168.0.2port is Ethernet interface 2 and vid is 2
3> ip+port+macip is 192.168.0.3port is Ethernet interface 2 and mac is 00:00:00:00:00:03
The configuration is as following:
1Define needed ACL
!Define to deny all packet ACL
QTECH(config)#access-list 200 deny ingress any egress any
!Define to transmit ACL to transmit packet from uplink interface 1
QTECH(config)#access-list 200 permit ingress interface ethernet 0/1 egress any
!Define ACL to transmit packet with VLAN ID being 4016 and from non-uplinkinterface 2
QTECH(config)#access-list 200 permit ingress 4016 interface ethernet 0/2 egress any
!Define ACL to transmit all ARP packet
!Define ip+port user to bind ACL with ip being 192.168.0.1port being Ethernet interface 2. This ip+port
user bound rule can be divided into 2 ACLsone is ACL to transmit packet with source address being 192.168.0.1, the
other is ACL to transmit packet from Ethernet interface 2
QTECH(config)#access-list 1 permit 192.168.0.1 0
QTECH(config)#access-list 201 permit ingress interface ethernet 0/0/2 egress any
!Define ip+port+vid user to bind ACL with ip being 192.168.0.2port being Ethernet interface 2 and vid
being 2. This ip+port+vid user bound rule can be divided into 3 ACLsone is ACL to transmit packet with source
address being 192.168.0.2, the other is ACL to transmit packet with vid being 2 from Ethernet interface 2 and the last
is ACL transferring ARP packet from Ethernet interface 2 with sending protocol being 192.168.0.1 and vid being 2.
QTECH(config)#access-list 1 permit 192.168.0.2 0
QTECH(config)#access-list 201 permit ingress 2 interface ethernet 0/0/2 egress any
!Define ip+port+mac user to bind ACL with ip being 192.168.0.3port being Ethernet interface 2 and mac
being 00:00:00:00:00:03. This ip+port+mac user bound rule can be divided into 2 ACLsone is ACL to transmit
packet with source address being 192.168.0.3, the other is ACL to transmit packet with mac being 00:00:00:00:00:03
from Ethernet interface 2 and the last is ACL transferring ARP packet from Ethernet interface 2 with sending protocol
being 192.168.0.1 and mac being 00:00:00:00:00:03.

Содержание

Скачать