Users Guide

Table Of Contents
ACL
VLAN IP ACL IP ACL
VLAN ACL
ACL ACL ACLABCD使 in
ACL使 out ACL ACL
IP ACL VLAN ACL
1. CONFIGURATION
interface ethernet node/slot/port
2. INTERFACE IP L3
ip address ip-address
3. INTERFACE IP ACL 退
ip access-group access-list-name {in | out}
IP ACL
OS10(config)# interface ethernet 1/1/28
OS10(conf-if-eth1/1/28)# ip address 10.1.2.0/24
OS10(conf-if-eth1/1/28)# ip access-group abcd in
ACL
OS10# show ip access-lists in
Ingress IP access-list acl1
Active on interfaces :
ethernet1/1/28
seq 10 permit ip host 10.1.1.1 host 100.1.1.1 count (0 packets)
seq 20 deny ip host 20.1.1.1 host 200.1.1.1 count (0 packets)
seq 30 permit ip 10.1.2.0/24 100.1.2.0/24 count (0 packets)
seq 40 deny ip 20.1.2.0/24 200.1.2.0/24 count (0 packets)
seq 50 permit ip 10.0.3.0 255.0.255.0 any count (0 packets)
seq 60 deny ip 20.0.3.0 255.0.255.0 any count (0 packets)
seq 70 permit tcp any eq 1000 100.1.4.0/24 eq 1001 count (0 packets)
seq 80 deny tcp any eq 2100 200.1.4.0/24 eq 2200 count (0 packets)
seq 90 permit udp 10.1.5.0/28 eq 10000 any eq 10100 count (0 packets)
seq 100 deny tcp host 20.1.5.1 any rst psh count (0 packets)
seq 110 permit tcp any any fin syn rst psh ack urg count (0 packets)
seq 120 deny icmp 20.1.6.0/24 any fragment count (0 packets)
seq 130 permit 150 any any dscp 63 count (0 packets)
ACL ACL 使 count
使 ACL
ACL CONFIGURATION ACL ACL
show ip access-list {in | out}
ACL
ACL EXEC 使 ip access-group 使 in 使 ip
access-list acl-name ACL访使 show access-lists
1. INTERFACE 访
ip access-group access-group-name in
998