文本版|topic 高级搜索
   名人堂 帮助 论坛制度 意见反馈 | 首页 博客 周新贴 招聘 专题 新闻
RSS 底部
 
社区导航: 专家门诊   网络技术   操作系统   数据库   程序设计   系统应用   考试认证   CIO及信息化   站长交流   综合交流   下载基地  51CTO产品服务 设为首页 | 收藏本站
51CTO技术论坛» 华为技术 » 三层交换机ACL问题,三层配置详细过程.       [ 打印]  [ 订阅]  [ 收藏]  [ 推荐给朋友]   [ 本帖文本页]

论坛跳转:
     
标题: 三层交换机ACL问题,三层配置详细过程.  ( 查看:119  回复:0 )   
 
djw8844
技术员  点击可查看详细



十二生肖之猪   双鱼座   行业勋章   技术勋章   诚信兄弟  
帖子 217
精华 0
无忧币 1577
积分 829
阅读权限 30
注册日期 2006-11-10
最后登录 2008-7-2 离线

[查看资料]  [发短消息]  [Blog
  QQ       
发表于:2008-4-25 16:12   标题:三层交换机ACL问题,三层配置详细过程.
上一帖 |
以下配置,什么在7段(vlan10)里能侦察到2段(vlan4)的IP包?我已经用ACL限制了他们的访问?
请问为什么?




#
sysname Quidway
#
super password level 3 simple xxxxxxx
#
radius scheme system
server-type huawei
primary authentication 127.0.0.1 1645
primary accounting 127.0.0.1 1646
user-name-format without-domain
radius scheme cams
server-type portal
key authentication huawei3com
key accounting huawei3com
user-name-format without-domain
domain system
radius-scheme system
access-limit disable
state active
vlan-assignment-mode integer
idle-cut disable
self-service-url disable
messenger time disable
domain default enable cams
#
local-server nas-ip 127.0.0.1 key huawei
local-user xxxxxx
password simple xxxxxxx
service-type telnet level 3
#
temperature-limit 0 20 80
#
acl number 3001
rule 0 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 1 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 2 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 3 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 4 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.6.0 0.0.0.255
rule 5 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 6 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
rule 7 deny ip source 192.168.0.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
acl number 3002
rule 0 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 2 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 3 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 4 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.6.0 0.0.0.255
rule 5 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 6 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
rule 7 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
acl number 3003
rule 0 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 2 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 3 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 4 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 5 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
rule 6 deny ip source 192.168.3.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
acl number 3004
rule 0 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 2 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 3 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 4 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 5 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
rule 6 deny ip source 192.168.4.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
acl number 3005
rule 0 deny ip source 192.168.5.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.5.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 2 deny ip source 192.168.5.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 3 deny ip source 192.168.5.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 4 deny ip source 192.168.5.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 5 deny ip source 192.168.5.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
rule 6 deny ip source 192.168.5.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
acl number 3006
rule 0 deny ip source 192.168.6.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.6.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 2 deny ip source 192.168.6.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
acl number 3007
rule 0 permit ip source 192.168.7.117 0 destination any
rule 1 permit ip source any destination 192.168.7.117 0
rule 2 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 3 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 4 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 5 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 6 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 7 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.6.0 0.0.0.255
rule 8 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
rule 9 deny ip source 192.168.7.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
acl number 3008
rule 0 deny ip source 192.168.8.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.8.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 2 deny ip source 192.168.8.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 3 deny ip source 192.168.8.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 4 deny ip source 192.168.8.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 5 deny ip source 192.168.8.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 6 deny ip source 192.168.8.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
acl number 3009
rule 0 deny ip source 192.168.9.0 0.0.0.255 destination 192.168.0.0 0.0.0.255
rule 1 deny ip source 192.168.9.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
rule 2 deny ip source 192.168.9.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 3 deny ip source 192.168.9.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 4 deny ip source 192.168.9.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 5 deny ip source 192.168.9.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 6 deny ip source 192.168.9.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
acl number 3010
rule 0 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.3.0 0.0.0.255
rule 1 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.4.0 0.0.0.255
rule 2 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.5.0 0.0.0.255
rule 3 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.6.0 0.0.0.255
rule 4 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.7.0 0.0.0.255
rule 5 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.8.0 0.0.0.255
rule 6 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.9.0 0.0.0.255
#
vlan 1
#
vlan 2
description manager
#
vlan 3
description yanfa_a
#
vlan 4
description yanfa_b
#
vlan 5
description server
#
vlan 6
description caiwu
#
vlan 7
description other
#
vlan 8
description jingli
#
vlan 9
description erp
#
vlan 10
description test
#
vlan 11
description xiaoting_a
#
vlan 12
description xiaoting_b
#
interface Vlan-interface2
ip address 192.168.11.1 255.255.255.0
#
interface Vlan-interface3
ip address 192.168.0.1 255.255.255.0
#
interface Vlan-interface4
ip address 192.168.2.1 255.255.255.0
#
interface Vlan-interface5
ip address 192.168.1.1 255.255.255.0
#
interface Vlan-interface6
ip address 192.168.3.1 255.255.255.0
#
interface Vlan-interface7
ip address 192.168.4.1 255.255.255.0
#
interface Vlan-interface8
ip address 192.168.5.1 255.255.255.0
#
interface Vlan-interface9
ip address 192.168.6.1 255.255.255.0
#
interface Vlan-interface10
ip address 192.168.7.1 255.255.255.0
#
interface Vlan-interface11
ip address 192.168.8.1 255.255.255.0
#
interface Vlan-interface12
ip address 192.168.9.1 255.255.255.0
#
interface Aux0/0
#
interface Ethernet0/1
port access vlan 2
#
interface Ethernet0/2
port link-type trunk
port trunk permit vlan 3 to 4 12
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
packet-filter inbound ip-group 3001 rule 5
packet-filter inbound ip-group 3001 rule 6
packet-filter inbound ip-group 3001 rule 7
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3002 rule 4
packet-filter inbound ip-group 3002 rule 5
packet-filter inbound ip-group 3002 rule 6
packet-filter inbound ip-group 3002 rule 7
packet-filter inbound ip-group 3005 rule 0
packet-filter inbound ip-group 3009 rule 1
packet-filter inbound ip-group 3009 rule 2
packet-filter inbound ip-group 3009 rule 3
packet-filter inbound ip-group 3009 rule 4
packet-filter inbound ip-group 3009 rule 5
packet-filter inbound ip-group 3009 rule 6
#
interface Ethernet0/3
port link-type trunk
port trunk permit vlan 3 to 4 12
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
packet-filter inbound ip-group 3001 rule 5
packet-filter inbound ip-group 3001 rule 6
packet-filter inbound ip-group 3001 rule 7
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3002 rule 4
packet-filter inbound ip-group 3002 rule 5
packet-filter inbound ip-group 3002 rule 6
packet-filter inbound ip-group 3002 rule 7
packet-filter inbound ip-group 3009 rule 0
packet-filter inbound ip-group 3009 rule 1
packet-filter inbound ip-group 3009 rule 2
packet-filter inbound ip-group 3009 rule 3
packet-filter inbound ip-group 3009 rule 4
packet-filter inbound ip-group 3009 rule 5
packet-filter inbound ip-group 3009 rule 6
#
interface Ethernet0/4
port link-type trunk
port trunk permit vlan 3 to 4
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
packet-filter inbound ip-group 3001 rule 5
packet-filter inbound ip-group 3001 rule 6
packet-filter inbound ip-group 3001 rule 7
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3002 rule 4
packet-filter inbound ip-group 3002 rule 5
packet-filter inbound ip-group 3002 rule 6
packet-filter inbound ip-group 3002 rule 7
#
interface Ethernet0/5
port link-type trunk
port trunk permit vlan 3 to 4
packet-filter inbound ip-group 3001 rule 0
packet-filter inbound ip-group 3001 rule 1
packet-filter inbound ip-group 3001 rule 2
packet-filter inbound ip-group 3001 rule 3
packet-filter inbound ip-group 3001 rule 5
packet-filter inbound ip-group 3001 rule 6
packet-filter inbound ip-group 3001 rule 7
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3002 rule 4
packet-filter inbound ip-group 3002 rule 5
packet-filter inbound ip-group 3002 rule 6
packet-filter inbound ip-group 3002 rule 7
#
interface Ethernet0/6
port access vlan 10
packet-filter inbound ip-group 3007 rule 0
packet-filter inbound ip-group 3007 rule 1
packet-filter inbound ip-group 3007 rule 2
packet-filter inbound ip-group 3007 rule 3
packet-filter inbound ip-group 3007 rule 4
packet-filter inbound ip-group 3007 rule 5
packet-filter inbound ip-group 3007 rule 6
packet-filter inbound ip-group 3007 rule 7
packet-filter inbound ip-group 3007 rule 8
packet-filter inbound ip-group 3007 rule 9
#
interface Ethernet0/7
port access vlan 10
packet-filter inbound ip-group 3007 rule 0
packet-filter inbound ip-group 3007 rule 1
packet-filter inbound ip-group 3007 rule 2
packet-filter inbound ip-group 3007 rule 3
packet-filter inbound ip-group 3007 rule 4
packet-filter inbound ip-group 3007 rule 5
packet-filter inbound ip-group 3007 rule 6
packet-filter inbound ip-group 3007 rule 7
packet-filter inbound ip-group 3007 rule 8
packet-filter inbound ip-group 3007 rule 9
#
interface Ethernet0/8
port access vlan 10
packet-filter inbound ip-group 3007 rule 0
packet-filter inbound ip-group 3007 rule 1
packet-filter inbound ip-group 3007 rule 2
packet-filter inbound ip-group 3007 rule 3
packet-filter inbound ip-group 3007 rule 4
packet-filter inbound ip-group 3007 rule 5
packet-filter inbound ip-group 3007 rule 6
packet-filter inbound ip-group 3007 rule 7
packet-filter inbound ip-group 3007 rule 8
packet-filter inbound ip-group 3007 rule 9
#
interface Ethernet0/9
port link-type trunk
port trunk permit vlan 4 7 to 8 10 11 12
packet-filter inbound ip-group 3002 rule 0
packet-filter inbound ip-group 3002 rule 1
packet-filter inbound ip-group 3002 rule 2
packet-filter inbound ip-group 3002 rule 3
packet-filter inbound ip-group 3002 rule 4
packet-filter inbound ip-group 3002 rule 5
packet-filter inbound ip-group 3002 rule 6
packet-filter inbound ip-group 3002 rule 7
packet-filter inbound ip-group 3004 rule 0
packet-filter inbound ip-group 3004 rule 1
packet-filter inbound ip-group 3004 rule 2
packet-filter inbound ip-group 3004 rule 3
packet-filter inbound ip-group 3004 rule 4
packet-filter inbound ip-group 3004 rule 5
packet-filter inbound ip-group 3004 rule 6
packet-filter inbound ip-group 3005 rule 0
packet-filter inbound ip-group 3005 rule 1
packet-filter inbound ip-group 3005 rule 2
packet-filter inbound ip-group 3005 rule 3
packet-filter inbound ip-group 3005 rule 4
packet-filter inbound ip-group 3005 rule 5
packet-filter inbound ip-group 3005 rule 6
packet-filter inbound ip-group 3007 rule 0
packet-filter inbound ip-group 3007 rule 1
packet-filter inbound ip-group 3007 rule 2
packet-filter inbound ip-group 3007 rule 3
packet-filter inbound ip-group 3007 rule 4
packet-filter inbound ip-group 3007 rule 5
packet-filter inbound ip-group 3007 rule 6
packet-filter inbound ip-group 3007 rule 7
packet-filter inbound ip-group 3008 rule 0
packet-filter inbound ip-group 3008 rule 1
packet-filter inbound ip-group 3008 rule 2
packet-filter inbound ip-group 3008 rule 3
packet-filter inbound ip-group 3008 rule 4
packet-filter inbound ip-group 3008 rule 5
packet-filter inbound ip-group 3008 rule 6
packet-filter inbound ip-group 3009 rule 0
packet-filter inbound ip-group 3009 rule 1
packet-filter inbound ip-group 3009 rule 2
packet-filter inbound ip-group 3009 rule 3
packet-filter inbound ip-group 3009 rule 4
packet-filter inbound ip-group 3009 rule 5
packet-filter inbound ip-group 3009 rule 6
#
interface Ethernet0/10
port link-type trunk
port trunk permit vlan 6 to 7
packet-filter inbound ip-group 3003 rule 0
packet-filter inbound ip-group 3003 rule 1
packet-filter inbound ip-group 3003 rule 2
packet-filter inbound ip-group 3003 rule 3
packet-filter inbound ip-group 3003 rule 4
packet-filter inbound ip-group 3003 rule 5
packet-filter inbound ip-group 3003 rule 6
packet-filter inbound ip-group 3004 rule 0
packet-filter inbound ip-group 3004 rule 1
packet-filter inbound ip-group 3004 rule 2
packet-filter inbound ip-group 3004 rule 3
packet-filter inbound ip-group 3004 rule 4
packet-filter inbound ip-group 3004 rule 5
packet-filter inbound ip-group 3004 rule 6
#
interface Ethernet0/11
port access vlan 8
packet-filter inbound ip-group 3005 rule 0
packet-filter inbound ip-group 3005 rule 1
packet-filter inbound ip-group 3005 rule 2
packet-filter inbound ip-group 3005 rule 3
packet-filter inbound ip-group 3005 rule 4
packet-filter inbound ip-group 3005 rule 5
packet-filter inbound ip-group 3005 rule 6
#
interface Ethernet0/12
port access vlan 5
#
interface Ethernet0/13
port access vlan 8
packet-filter inbound ip-group 3005 rule 0
packet-filter inbound ip-group 3005 rule 1
packet-filter inbound ip-group 3005 rule 2
packet-filter inbound ip-group 3005 rule 3
packet-filter inbound ip-group 3005 rule 4
packet-filter inbound ip-group 3005 rule 5
packet-filter inbound ip-group 3005 rule 6
#
interface Ethernet0/14
port access vlan 8
packet-filter inbound ip-group 3005 rule 0
packet-filter inbound ip-group 3005 rule 1
packet-filter inbound ip-group 3005 rule 2
packet-filter inbound ip-group 3005 rule 3
packet-filter inbound ip-group 3005 rule 4
packet-filter inbound ip-group 3005 rule 5
packet-filter inbound ip-group 3005 rule 6
#
interface Ethernet0/15
port access vlan 8
packet-filter inbound ip-group 3005 rule 0
packet-filter inbound ip-group 3005 rule 1
packet-filter inbound ip-group 3005 rule 2
packet-filter inbound ip-group 3005 rule 3
packet-filter inbound ip-group 3005 rule 4
packet-filter inbound ip-group 3005 rule 5
packet-filter inbound ip-group 3005 rule 6
#
interface Ethernet0/16
port access vlan 5
#
interface Ethernet0/17
port access vlan 5
packet-filter inbound ip-group 3010 rule 0
packet-filter inbound ip-group 3010 rule 1
packet-filter inbound ip-group 3010 rule 2
packet-filter inbound ip-group 3010 rule 3
packet-filter inbound ip-group 3010 rule 4
packet-filter inbound ip-group 3010 rule 5
packet-filter inbound ip-group 3010 rule 6
#
interface Ethernet0/18
port access vlan 9
#
interface Ethernet0/19
port access vlan 9
#
interface Ethernet0/20
port access vlan 5
#
interface Ethernet0/21
port access vlan 9
#
interface Ethernet0/22
port access vlan 5
#
interface Ethernet0/23
port access vlan 5
#
interface Ethernet0/24
port access vlan 5
#
interface GigabitEthernet1/1
port access vlan 9
#
interface GigabitEthernet1/2
port access vlan 5
#
interface GigabitEthernet1/3
port link-type trunk
port trunk permit vlan 11 to 12
packet-filter inbound ip-group 3008 rule 0
packet-filter inbound ip-group 3008 rule 1
packet-filter inbound ip-group 3008 rule 2
packet-filter inbound ip-group 3008 rule 3
packet-filter inbound ip-group 3008 rule 4
packet-filter inbound ip-group 3008 rule 5
packet-filter inbound ip-group 3008 rule 6
packet-filter inbound ip-group 3009 rule 0
packet-filter inbound ip-group 3009 rule 1
packet-filter inbound ip-group 3009 rule 2
packet-filter inbound ip-group 3009 rule 3
packet-filter inbound ip-group 3009 rule 4
packet-filter inbound ip-group 3009 rule 5
packet-filter inbound ip-group 3009 rule 6
#
interface GigabitEthernet1/4
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 192.168.1.99 preference 60
#
user-interface aux 0
screen-length 0
user-interface vty 0 4
#
return



网络工程师到底该不该去考CCIE认证?
2008-4-25 16:121楼
[ 顶部 ]
     
论坛跳转:  

| | |

标记已读 · 删除论坛Cookies · 文本版 · WAP
 
| 诚征版主 | 版主堂 | 意见建议 | 大史记 | 论坛地图
Copyright©2005-2008 51CTO.COM  Powered by Discuz!
本论坛言论纯属发布者个人意见,不代表51CTO网站立场!如有疑义,请与管理员联系。
京ICP备05051492号