星期六, 十一月 25, 2006

ACL实现某端口只允许访问某IP地址

![QACL]
access-list 100 permit ip any 10.2.4.1 0.0.0.0
access-list 200 permit ingress interface ethernet 0/1 egress any
access-list 201 permit ingress any egress interface dlf
access-list link denyp1
deny ingress interface ethernet 0/1 egress any
exit
access-group link-group denyp1 subitem 0
access-group ip-group 100 subitem 0 link-group 200 subitem 0
access-group link-group 201 subitem 0

没有评论: