SNR S2989G-48TX-DC — настройка функций безопасности и фильтрации трафика на порту [292/553]

SNR S2989G-48TX [292/553] Acl example
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-19
{ip|ipv6|mac|mac-ip} access-group
<acl-name> {in|out} [traffic-statistic]
no {ip|ipv6|mac|mac-ip} access-group
<acl-name> {in|out}
Apply an access-list to the ingress or
egress direction on the port; the no
command deletes the access-list
bound to the port.
5. Clear the filtering information of the specified port
Command
Explanation
Admin Mode
clear access-group (in | out)
statistic interface
{ <interface-name> | ethernet
<interface-name> }
Clear the filtering information of the egress or
ingress for the specified port.
6.1.3
ACL Example
Scenario 1:
The user has the following configuration requirement: port 10 of the switch connects
to 10.0.0.0/24 segment, ftp is not desired for the user.
Configuration description:
1. Create a proper ACL
2. Configuring packet filtering function
3. Bind the ACL to the port
The configuration steps are listed below:
Switch(config)#access-list 110 deny tcp 10.0.0.0 0.0.0.255 any-destination d-port 21
Switch(config)#firewall enable
Switch(config)#interface ethernet 1/0/10
Switch(Config-If-Ethernet1/0/10)#ip access-group 110 in
Switch(Config-If-Ethernet1/0/10)#exit
Switch(config)#exit
Configuration result:
Switch#show firewall
Firewall status: enable.
Switch#show access-lists
access-list 110(used 1 time(s)) 1 rule(s)
access-list 110 deny tcp 10.0.0.0 0.0.0.255 any-destination d-port 21
Switch#show access-group interface ethernet 1/0/10

Содержание

Узнайте, как настроить функции безопасности и фильтрации трафика на порту с помощью списков доступа. Пошаговое руководство и примеры конфигурации.

Скачать