当前位置:网站首页>ACL实验演示(Huawei路由器设备配置)
ACL实验演示(Huawei路由器设备配置)
2022-07-26 16:53:00 【51CTO】
一、ACL介绍
ACL(Access Control List)访问控制列表,其目的是为了对某种访问进行控制,使用包过滤技术,在路由器上读取第三层及第四层包头中的信息如源地址、目的地址、源端口、目的端口等,根据预先定义好的规则对包进行过滤,从而达到访问控制的目的。
ps:华为默认允许通过数据包,思科默认拒绝通过。
二、ACL实验目的
允许技术部(192.168.3.0网段)访问服务器;
不允许事业部和外网访问服务器;
三、实验拓扑

四、实验配置
(1)R1配置
<Huawei>system-view
[Huawei]sysname R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.2.254 24
[R1-GigabitEthernet0/0/0]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 192.168.3.254 24
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]ip add 192.168.4.254 24
[R1-GigabitEthernet0/0/2]int g4/0/0
[R1-GigabitEthernet4/0/0]ip add 12.1.1.1 24
[R1-GigabitEthernet4/0/0]q
[R1]acl 3000
[R1-acl-adv-3000]rule 10 permit ip source 192.168.3.0 0.0.0.255 destination 192. 168.4.4 0
[R1-acl-adv-3000]rule 20 deny ip source 192.168.2.0 0.0.0.255 destination 192.16.4.4 0
[R1-acl-adv-3000]rule 30 deny ip source 12.1.1.0 0.0.0.255 destination 192.168.4.4 0
[R1-acl-adv-3000]q
[R1]int g0/0/2
[R1-GigabitEthernet0/0/2]traffic-filter outbound acl 3000
(2)R2配置
<Huawei>sys
[Huawei]sys R2
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.1.1.2 24
[R2]ip route-static 0.0.0.0 0 12.1.1.1
(3)用PC1 PC2 R2 ping Server1验证



用PC1 和 R2 ping Server1不通,PC2可以,实验验证成功。
边栏推荐
- JS 闭包 模拟私有变量 面试题 立即执行函数IIFE
- (25) top level menu of blender source code analysis blender menu
- 云渲染-体积云【理论基础与实现方案】
- The latest interface of Taobao / tmall keyword search
- 浅谈数据技术人员的成长之路
- We were tossed all night by a Kong performance bug
- uni-app
- Implement softmax classification from zero sum using mxnet
- In the first half of the year, sales increased by 10% against the trend. You can always trust Volvo, which is persistent and safe
- 一文详解吞吐量、QPS、TPS、并发数等高并发指标
猜你喜欢

JS 函数作用域 变量声明提升 作用域链 不加var的变量,是全局变量

Machine learning - what are machine learning, supervised learning, and unsupervised learning

浅析接口测试

(25)Blender源码分析之顶层菜单Blender菜单

Crazy God redis notes 02

6-19漏洞利用-nsf获取目标密码文件

机器视觉在服务机器人中的应用

SCCM tips - improve the download speed of drivers and shorten the deployment time of the system when deploying the system

In the first half of the year, sales increased by 10% against the trend. You can always trust Volvo, which is persistent and safe

Establishment of Eureka registration center Eureka server
随机推荐
浅析接口测试
#夏日挑战赛# OpenHarmony基于JS实现的贪吃蛇
如何快速使用 ELisp 进行插件编写
【虚拟机数据恢复】意外断电导致XenServer虚拟机不可用,虚拟磁盘文件丢失的数据恢复案例
Use replace regexp to add a sequence number at the beginning of a line
[virtual machine data recovery] data recovery cases in which XenServer virtual machine is unavailable due to accidental power failure and virtual disk files are lost
The user experience center of Analysys Qianfan bank was established to help upgrade the user experience of the banking industry
树形dp问题
Reuse idea through registry
一文详解吞吐量、QPS、TPS、并发数等高并发指标
Why are test / development programmers who are better paid than me? Abandoned by the times
Small application of C language using structure to simulate election
After Australia, New Zealand announced the ban on Huawei 5g! Huawei official response
Common super easy to use regular expressions!
Tree DP problem
How to use align regexp to align userscript meta information
Eureka Registry - from entry to application
二层管理型交换机如何设置IP
图解用户登录验证流程,写得太好了!
Create MySQL function: access denied; you need (at least one of) the SUPER privilege(s) for this operation