星期一, 十一月 27, 2006

ACL做mac和IP地址绑定

以下是IP+MAC+端口的绑定,如果只是 MAC+端口 绑定则不需要配IP地址那条。

access-list 200 deny ingress any egress any
access-list 200 permit ingress interface ethernet 0/1 egress any
access-list 200 permit ingress interface ethernet 0/2 egress interface ethernet 0/1
access-list 200 permit ingress interface ethernet 0/3 egress interface ethernet 0/1
access-list 200 permit ingress interface ethernet 0/4 egress interface ethernet 0/1
access-list 200 permit ingress interface ethernet 0/5 egress interface ethernet 0/1
access-list 200 permit ingress interface ethernet 0/6 egress interface ethernet 0/1
access-list 200 permit ingress interface ethernet 0/7 egress interface ethernet 0/1
access-list 200 permit ingress interface ethernet 0/8 egress interface ethernet 0/1
access-list 200 permit arp ingress any egress any
access-list 101 permit udp any eq 67 any
access-list 101 permit udp any eq 68 any

access-list 201 permit ingress interface ethernet 0/7 00:90:96:24:fa:c1 00:00:00:00:00:00 egress interface ethernet 0/1
access-list 100 permit 10.1.0.50 0 any

access-group link-group 200
access-group ip-group 101
access-group link-group 201 ip-group 100

没有评论: