h3c acl配置一列
- acl number 3004
- rule 0 permit ip source 10.2.1.4 0
- rule 1 deny ip source 192.168.1.91 0
- rule 2 deny ip source 192.168.9.6 0
- rule 3 deny ip source 192.168.1.94 0
- rule 4 deny ip source 10.1.3.240 0
- rule 5 permit ip source 10.2.1.40 0
- rule 7 deny ip source 10.2.12.8 0
- rule 8 deny ip source 192.168.2.69 0
- rule 9 deny ip source 10.1.1.20 0
- rule 15 deny ip source 10.2.1.0 0.0.0.255
- rule 20 deny ip source 10.2.17.0 0.0.0.255
- rule 25 deny ip source 10.2.18.0 0.0.0.255
- rule 30 deny ip source 10.2.19.0 0.0.0.255
- rule 35 deny ip source 10.2.16.0 0.0.0.255
- rule 36 deny ip source 192.168.9.2 0
- rule 100 deny ip source 192.168.19.6 0
- rule 200 deny ip source 192.168.9.99 0
- rule 250 deny ip source 192.168.19.5 0
- rule 260 deny ip source 192.168.9.1 0
- #
- acl number 3005
- rule 50 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.9.0 0.0.0.255
- rule 60 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.91 0
- rule 70 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.90 0
- rule 80 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.92 0
- rule 90 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.95 0
- rule 100 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.1.7 0
- rule 110 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.19.6 0
- rule 120 deny ip source 10.1.0.0 0.0.255.255 destination 192.168.19.5 0
- interface Vlan-interface999
- ip address 10.20.20.254 255.255.255.0
- packet-filter 3005 inbound
- #
- interface Vlan-interface1000
- ip address 10.10.10.254 255.255.255.0
- packet-filter 3004 outbound
关于怎么区分inbound 与 outbound ,:都看成网关, 出网关的是outbound,source ip 是内部ip
inbound是进网关,source ip是来源ip
注意2层协议时inbound,outbound刚好相反
-------------------
老的S5600 只支持网口做 inboud包过滤,下面是只允许指定电脑进行远程桌面
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 如何编写易于单元测试的代码
· 10年+ .NET Coder 心语,封装的思维:从隐藏、稳定开始理解其本质意义
· .NET Core 中如何实现缓存的预热?
· 从 HTTP 原因短语缺失研究 HTTP/2 和 HTTP/3 的设计差异
· AI与.NET技术实操系列:向量存储与相似性搜索在 .NET 中的实现
· 周边上新:园子的第一款马克杯温暖上架
· Open-Sora 2.0 重磅开源!
· .NET周刊【3月第1期 2025-03-02】
· 分享 3 个 .NET 开源的文件压缩处理库,助力快速实现文件压缩解压功能!
· [AI/GPT/综述] AI Agent的设计模式综述