SNR S2989G-48TX-RPS — настройка VLAN-ACL для IPv6: руководство по безопасности сети [341/553]

Превью страниц Страница 341 / 553
SNR S2989G-24TX-POE [341/553] Vlan acl configuration example
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-68
4. Configure VLAN-ACL of IPv6 type
Command
Explanation
Global mode
vacl ipv6 access-group (<500-699> |
WORD) {in | out} (traffic-statistic|) vlan
WORD
no ipv6 access-group {<500-699> |
WORD} {in | out} vlan WORD
Configure or delete IPv6 VLAN-ACL.
5. Show configuration and statistic information of VLAN-ACL
Command
Explanation
Admin mode
show vacl [in | out] vlan [<vlan-id>]
Show the configuration and the statistic
information of VACL.
6. Clear statistic information of VLAN-ACL
Command
Explanation
Admin mode
clear vacl [in | out] statistic vlan
[<vlan-id>]
Clear the statistic information of VACL.
6.8.3
VLAN-ACL Configuration Example
A company’s network configuration is as follows, all departments are divided by
different VLANs, technique department is Vlan1, finance department is Vlan2. It is
required that technique department can access the outside network at timeout, but
finance department are not allowed to access the outside network at any time for the
security. Then the following policies are configured:
Set the policy VACL_A for technique department. At timeout they can access the
outside network, the rule as permit, but other times the rule as deny, and the
policy is applied to Vlan1.
Set the policy VACL_B of ACL for finance department. At any time they can not
access the outside network, but can access the inside network with no limitation,
and apply the policy to Vlan2.
Network environment is shown as below:

Содержание

666

Изучите, как настроить VLAN-ACL для IPv6, чтобы обеспечить безопасность сети. Узнайте о командах для конфигурации и управления доступом между VLAN.