3 acl example, Xample – PLANET XGS3-24040 User Manual

Page 455

Advertising
background image

Chapter 46 ACL Configuration

46-17

deletes the access-list

bound to the port.

VLAN interface mode:

Applies an access-list to the

specified direction on the

port

of VLAN;

the

no

command deletes the

access-list bound to the port

of VLAN.

5. Clear the filtering information of the specified port

Command

Explanation

Admin Mode

clear access-group statistic interface

{ <interface-name> | ethernet <interface-name> }

Clear the filtering information

of the specified port.

46.3 ACL Example

Scenario 1:

The user has the following configuration requirement: port 1/10 of the switch connects to 10.0.0.0/24 segment,

ftp is not desired for the user.

Configuration description:

1. Create a proper ACL

2. Configuring packet filtering function

3. Bind the ACL to the port

The configuration steps are listed below:

Switch(config)#access-list 110 deny tcp 10.0.0.0 0.0.0.255 any-destination d-port 21

Switch(config)#firewall enable

Switch(config)#firewall default permit

Switch(config)#interface ethernet 1/10

Switch(Config-If-Ethernet1/10)#ip access-group 110 in

Switch(Config-If-Ethernet1/10)#exit

Switch(config)#exit

Configuration result:

Switch#show firewall

Firewall status: enable.

Firewall default rule: permit.

Advertising