S5500三层交换机禁止某个ip访问特定网段:
目标 IP:192.168.0.31位于vlan3000段,禁止此ip访问10.10.11.01/24和192.168.99.0/24(规则内子网掩码要转换成通配符,/24转换成0.0.0.255,/32转换成0.0.0.0)
创建ACL及规则:
acl number 3001
rule 1 deny ip source 192.168.0.31 0.0.0.0 destination 10.10.11.0 0.0.0.255
rule 2 deny ip source 192.168.0.31 0.0.0.0 destination 192.168.99.0 0.0.0.255
应用在vlan3000段上:int vlan 3000
packet-filter 3001 inbound
S5100配置在 g1/0/16 trunk与二层交换机连接的网口上:
vlan91:192.168.91.0/24 ;vlan92:192.168.92.0/24 ;vlan93:192.168.93.0/24 ,规则为禁止91和92段访问93,但192.168.91.123获得例外访问93的权限
acl number 3001
rule 1 permit ip source 192.168.91.123 0.0.0.0
rule 2 deny ip source 192.168.91.0 0.0.0.255 destination 10.10.11.0 0.0.0.255
rule 3 deny ip source 192.168.92.0 0.0.0.255 destination 192.168.99.0 0.0.0.255
int g1/0/16
packet-filter inbound ip-group 3001