User-Defined Acl Configuration Example - H3C S5600 Series Operation Manual

Hide thumbs Also See for H3C S5600 Series:
Table of Contents

Advertisement

Operation Manual – ACL
H3C S5600 Series Ethernet Switches
II. Network diagram
Figure 1-5 Network diagram for Layer 2 ACL
III. Configuration procedure
# Define a periodic time range that is active from 8:00 to 18:00 everyday.
<Sysname> system-view
[Sysname] time-range test 8:00 to 18:00 daily
# Define ACL 4000 to filter packets with the source MAC address of 0011-0011-0011
and the destination MAC address of 0011-0011-0012.
[Sysname] acl number 4000
[Sysname-acl-ethernetframe-4000]
ffff-ffff-ffff dest 0011-0011-0012 ffff-ffff-ffff time-range test
[Sysname-acl-ethernetframe-4000] quit
# Apply ACL 4000 on GigabitEthernet 1/0/1.
[Sysname] interface GigabitEthernet1/0/1
[Sysname-GigabitEthernet1/0/1] packet-filter inbound link-group 4000

1.5.4 User-defined ACL Configuration Example

I. Network requirements
As shown in
1/0/1 and Ethernet 1/0/2 respectively. They belong to VLAN 1 and access the Internet
through the same gateway, which has an IP address of 192.168.0.1 (the IP address of
VLAN-interface 1).
Configure a user-defined ACL to deny all ARP packets from PC 1 that use the gateway
IP address as the source address from 8:00 to 18:00 everyday.
Figure
1-6, PC 1 and PC 2 are connected to the switch through Ethernet
rule
1
deny
1-17
Chapter 1 ACL Configuration
source
0011-0011-0011

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5600-26cS5600-26c-pwrS5600-26fS5600-50cS5600-50c-pwr

Table of Contents