h3c acl配置一列
- acl number 3004
- rule 0 permit ip source 10.2.1.4 0
- rule 1 deny ip source 192.168.1.91 0
- rule 2 deny ip source 192.168.9.6 0
- rule 3 deny ip source 192.168.1.94 0
- rule 4 deny ip source 10.1.3.240 0
- rule 5 permit ip source 10.2.1.40 0
- rule 7 deny ip source 10.2.12.8 0
- rule 8 deny ip source 192.168.2.69 0
- rule 9 deny ip source 10.1.1.20 0
- rule 15 deny ip source 10.2.1.0 0.0.0.255
- rule 20 deny ip source 10.2.17.0 0.0.0.255
- rule 25 deny ip source 10.2.18.0 0.0.0.255
- rule 30 deny ip source 10.2.19.0 0.0.0.255
- rule 35 deny ip source 10.2.16.0 0.0.0.255
- rule 36 deny ip source 192.168.9.2 0
- rule 100 deny ip source 192.168.19.6 0
- rule 200 deny ip source 192.168.9.99 0
- rule 250 deny ip source 192.168.19.5 0
- rule 260 deny ip source 192.168.9.1 0
- #
- acl number 3005
- rule 50 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.9.0 0.0.0.255
- rule 60 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.91 0
- rule 70 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.90 0
- rule 80 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.92 0
- rule 90 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.95 0
- rule 100 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.7 0
- rule 110 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.19.6 0
- rule 120 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.19.5 0
- interface Vlan-interface999
- ip address 10.20.20.254 255.255.255.0
- packet-filter 3005 inbound
- #
- interface Vlan-interface1000
- ip address 10.10.10.254 255.255.255.0
- packet-filter 3004 outbound
关于怎么区分inbound 与 outbound ,:都看成网关, 出网关的是outbound,source ip 是内部ip
inbound是进网关,source ip是来源ip
注意2层协议时inbound,outbound刚好相反
-------------------
老的S5600 只支持网口做 inboud包过滤,下面是只允许指定电脑进行远程桌面
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】凌霞软件回馈社区,博客园 & 1Panel & Halo 联合会员上线
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 智能桌面机器人:用.NET IoT库控制舵机并多方法播放表情
· Linux glibc自带哈希表的用例及性能测试
· 深入理解 Mybatis 分库分表执行原理
· 如何打造一个高并发系统?
· .NET Core GC压缩(compact_phase)底层原理浅谈
· 新年开篇:在本地部署DeepSeek大模型实现联网增强的AI应用
· DeepSeek火爆全网,官网宕机?本地部署一个随便玩「LLM探索」
· Janus Pro:DeepSeek 开源革新,多模态 AI 的未来
· 互联网不景气了那就玩玩嵌入式吧,用纯.NET开发并制作一个智能桌面机器人(三):用.NET IoT库
· 上周热点回顾(1.20-1.26)