Chapter7ACLConguration
Mailserver:192.168.4.50
FTPserver:192.168.4.60;
VODserver:192.168.4.70.
FIGURE18ACLCONFIGURATIONEXAMPLE
Congurationofswitch:
/*Configuretimerange*/
ZXR10(config)#time-rangeen
ZXR10(config)#time-rangeworking-time
ZXR10(config-tr)#periodicdaily09:00:00to17:00:00
/*DefineanextendedACLtolimitusersofdepartmentA*/
ZXR10(config)#aclextendnumber100
ZXR10(config-ext-acl)#rule1permitip192.168.1.1000.0.0.0any
ZXR10(config-ext-acl)#rule2denyip192.168.1.00.0.0.255
192.168.4.600.0.0.0time-rangeworking-time
ZXR10(config-ext-acl)#rule3denytcpany192.168.4.700.0.0.0
time-rangeworking-time
ZXR10(config-ext-acl)#rule4denyipany192.168.3.1000.0.0.0
time-rangeworking-time
ZXR10(config-ext-acl)#rule5permitipanyany
/*DefineanextendedACLtolimitusersofdepartmentB*/
ZXR10(config)#aclextendnumber101
ZXR10(config-ext-acl)#rule1permitip192.168.2.1000.0.0.0any
ZXR10(config-ext-acl)#rule2denyip192.168.2.00.0.0.255
192.168.4.600.0.0.0time-rangeworking-time
ZXR10(config-ext-acl)#rule3denytcpany192.168.4.700.0.0.0
time-rangeworking-time
ZXR10(config-ext-acl)#rule4permitipanyany
/*ApplytheACLtothecorrespondingphysicalport*/
ZXR10(config)#interfacegei_1/1
ZXR10(config-gei_1/1)#ipaccess-group100in
ZXR10(config-gei_1/1)#exit
ZXR10(config)#interfacegei_1/2
ZXR10(config-gei_1/2)#ipaccess-group101in
ZXR10(config-gei_1/2)#exit
CondentialandProprietaryInformationofZTECORPORATION67