Figure 11-3 Networking Diagram For Configuring Layer 2 Acls; Example For Configuring A Layer 2 Acl - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

11 ACL Configuration
deny
traffic behavior b_rd
deny
#
traffic policy p_market
classifier c_market behavior b_market
traffic policy p_rd
classifier c_rd behavior b_rd
#
interface Vlanif10
ip address 10.164.1.1 255.255.255.0
#
interface Vlanif20
ip address 10.164.2.1 255.255.255.0
#
interface Vlanif30
ip address 10.164.3.1 255.255.255.0
#
interface Vlanif100
ip address 10.164.9.1 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-type access
port default vlan 10
#
interface GigabitEthernet1/0/2
port link-type access
port default vlan 20
traffic-policy p_rd inbound
#
interface GigabitEthernet1/0/3
port link-type access
port default vlan 30
traffic-policy p_rd inbound
#
interface GigabitEthernet2/0/1
port link-type access
port default vlan 100
#
return

11.5.3 Example for Configuring a Layer 2 ACL

Networking Requirements
As shown in
required that the ACL configured to prevent the packets with the source MAC address as 00e0-
f201-0101 and the destination MAC address as 0260-e207-0002 from passing through.

Figure 11-3 Networking diagram for configuring layer 2 ACLs

11-20
Figure
11-3, the S9300 that functions as the gateway is connected to the PC. It is
GE2/0/1
00e0-f201-0101
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
GE1/0/1
IP network
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents