H3C-S5500 vlan-ACL配置

VLAN 内互访,vlan间禁止访问。(在三层交换机上启用了配置IP

1.      Switch A 配置:

#vlan       10

#port       Ethernet0/1

#vlan       20

#port       Ethernet0/2

 

#interface gigabitethernet       1/1

#port       link-type  trunk

#port       trunk       permit vlan     10   20

 

2.Switch B 配置

#vlan       10

#port       Ethernet0/10

#vlan       20

#port       Ethernet0/20

 

#interface gigabitethernet       1/1

#port       link-type  trunk

#port       trunk       permit vlan     10   20

 

Trunk 中继设置

#vlan 2

#undo managent-vlan    //取消默认的managent vlan 1

Managent-vlan 2

Interface vlan-interface 2

Ip addrss 172.16.25.1 255.255.255.0

Quit

Ip route-static

 

Interface gigabitethernet 1/1/1

Port link-type trunk   //进入trunk配置端口

Port trunk permit vlan all  //允许所有的vlan 通过该trunk

Port trunk pvid vlan 30  //默认VLAN标签

 

Interface vlan-interface 50

Ip address 172.16.50.1  255.255.255.0

Dhcp select relay

Dhcp relay server select 1

 

                    

以下为配置数据 

******************************************************************************

* Copyright (c) 2004-2010 Hangzhou H3C Tech. Co., Ltd. All rightsreserved.  *

* Without the owner's prior writtenconsent,                                 *

* no decompiling or reverse-engineeringshall be allowed.                    *

******************************************************************************

 

 

Login authentication

 

 

Password:

sys

system-view

System View: return to User View withCtrl+Z.

[H3C_5500]dis

[H3C_5500]displaycur

[H3C_5500]displaycurrent-configuration

#

 version 5.20, Release 2202P19

#

 sysname H3C_5500

#

 super password level 3 simple ******

#

 dhcprelay server-group 1 ip 172.16.1.7

#

 domain default enable system

#

 telnet server enable

#

acl number 3011 name Customer

 rule5 deny ip source 172.16.11.0 0.0.0.255 destination172.16.10.0 0.0.0.255

 rule6 deny ip source 172.16.11.0 0.0.0.255 destination172.16.12.0 0.0.0.255

 rule7 deny ip source 172.16.11.0 0.0.0.255 destination172.16.21.0 0.0.0.255

 rule8 deny ip source 172.16.11.0 0.0.0.255 destination172.16.30.0 0.0.0.255

acl number 3030 name vlan30

 rule3 permit ip source 172.16.30.69 0 destination 172.16.25.21 0

 rule4 permit ip source 172.16.30.49 0 destination 172.16.25.21 0

 rule5 deny ip source 172.16.30.0 0.0.0.255 destination172.16.25.0 0.0.0.255

 rule6 deny ip source 172.16.30.0 0.0.0.255 destination172.16.24.0 0.0.0.255

 rule7 deny ip source 172.16.30.0 0.0.0.255 destination172.16.23.0 0.0.0.255

 rule8 deny ip source 172.16.30.0 0.0.0.255 destination172.16.22.0 0.0.0.255

 rule9 deny ip source 172.16.30.0 0.0.0.255 destination172.16.21.0 0.0.0.255

 rule10 deny ip source 172.16.30.0 0.0.0.255 destination172.16.12.0 0.0.0.255

 rule11 deny ip source 172.16.30.0 0.0.0.255 destination172.16.11.0 0.0.0.255

 rule12 deny ip source 172.16.30.0 0.0.0.255 destination172.16.10.0 0.0.0.255

acl number 3050

 rule6 deny ip source 172.16.50.0 0.0.0.255 destination172.16.25.0 0.0.0.255

#

vlan 1

#

vlan 2 to 4

#

vlan 10 to 12

#

vlan 20 to 25

#

vlan 30

#

vlan 50

#

radius scheme system

 server-type extended

 primary authentication 127.0.0.1 1645

 primary accounting 127.0.0.1 1646

 user-name-format without-domain

#

domain system

 access-limit disable

 state active

 idle-cut disable

 self-service-url disable

#

traffic classifier Any operator and

traffic classifier Android operator and

 if-match any

 if-match source-mac 50af-7303-102f

#

traffic behavior Any

traffic behavior Android

 filter deny

#

user-group system

#

local-user admin

 password simple ******

 authorization-attribute level 3

 service-type lan-access

 service-type ssh telnet terminal

#

interface NULL0

#

interface Vlan-interface1

 ipaddress 172.16.1.1 255.255.255.0

#

interface Vlan-interface2

 ipaddress 172.16.2.1 255.255.255.0

#

interface Vlan-interface3

 ipaddress 172.16.3.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface4

 ipaddress 172.16.4.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface10

 ipaddress 172.16.10.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface11

 ipaddress 172.16.11.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

 packet-filter 3011 inbound

#

interface Vlan-interface12

 ipaddress 172.16.12.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface20

 ipaddress 172.16.20.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface21

 ipaddress 172.16.21.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface22

 ipaddress 172.16.22.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface23

 ipaddress 172.16.23.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface24

 ipaddress 172.16.24.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface25

 ipaddress 172.16.25.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

#

interface Vlan-interface30

 ipaddress 172.16.30.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

 packet-filter 3030 inbound

#

interface Vlan-interface50

 ipaddress 172.16.50.1 255.255.255.0

 dhcpselect relay

 dhcprelay server-select 1

 packet-filter 3050 inbound

#

interface GigabitEthernet1/0/1

 portaccess vlan 2

#

interface GigabitEthernet1/0/2

 portaccess vlan 2

#

interface GigabitEthernet1/0/3

 portaccess vlan 2

#

interface GigabitEthernet1/0/4

 portaccess vlan 2

#

interface GigabitEthernet1/0/5

#

interface GigabitEthernet1/0/6

#

interface GigabitEthernet1/0/7

 portlink-type trunk

 porttrunk permit vlan all

#

interface GigabitEthernet1/0/8

#

interface GigabitEthernet1/0/9

#

interface GigabitEthernet1/0/10

#

interface GigabitEthernet1/0/11

#

interface GigabitEthernet1/0/12

 portlink-type trunk

 porttrunk permit vlan all

#

interface GigabitEthernet1/0/13

#

interface GigabitEthernet1/0/14

#

interface GigabitEthernet1/0/15

#

interface GigabitEthernet1/0/16

#

interface GigabitEthernet1/0/17

 portaccess vlan 11

#

interface GigabitEthernet1/0/18

 portaccess vlan 11

#

interface GigabitEthernet1/0/19

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/0/20

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/0/21

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/0/22

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/0/23

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/0/24

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/0/25

 shutdown

#

interface GigabitEthernet1/0/26

 shutdown

#

interface GigabitEthernet1/0/27

 shutdown

#

interface GigabitEthernet1/0/28

 shutdown

#

nqa entry admin ***

 typeicmp-echo

 destination ip 172.16.100.1

 frequency 8000

 next-hop 172.16.2.252

 reaction 1 checked-element probe-fail threshold-type consecutive 5action-type

 trigger-only

 route-option bypass-route

#

 iproute-static 0.0.0.0 0.0.0.0 Vlan-interface2172.16.2.254

 ip route-static0.0.0.0 0.0.0.0 172.16.2.252 track 1preference 40

 iproute-static 172.16.100.0 255.255.255.0 172.16.2.252 preference 30

 iproute-static 192.168.122.0 255.255.254.0 Vlan-interface2 172.16.2.253 prefer

ence 50

 iproute-static 192.168.138.0 255.255.255.0 172.16.2.252 preference 30

 iproute-static 218.5.78.19 255.255.255.255 172.16.2.254 preference 50

#

 snmp-agent

 snmp-agent local-engineid 800063A203C4CAD9D4DEC8

 snmp-agent sys-info version v3

#

 track 1 nqa entry admin *** reaction 1

#

 dhcpenable

#

 nqaschedule admin *** start-time now lifetime forever

#

user-interface aux 0

user-interface vty 0

 userprivilege level 3

 setauthentication password simple ******

 protocol inbound telnet

user-interface vty 1 4

#

return

[H3C_5500]

 

 

 

********************************************************************************

* Copyright(c) 2004-2011 Hangzhou H3CTech. Co., Ltd. All rights reserved.    *

* Without the owner's prior written consent,                                  *

*  nodecompiling or reverse-engineering shall be allowed.                     *

********************************************************************************

 

 

Login authentication

 

 

Password:

%Jul 21 01:14:54:265 2000 H3C_3100_52TP_01 SHELL/5/LOGIN:- 1 -VTY(172.16.50.3)

in unit1 login

sys

system-view

System View: return to User View withCtrl+Z.

[H3C_3100_52TP_01]dis

[H3C_3100_52TP_01]displaycur

[H3C_3100_52TP_01]displaycurrent-configuration

#

 sysname H3C_3100_52TP_01

#

 loopback-detection enable

#

radius scheme system

#

domain system

#

vlan 1 to 2

#

vlan 21 to 22

#

vlan 30

#

interface Vlan-interface2

 ipaddress 172.16.2.241 255.255.255.0

#

interface Aux1/0/0

#

interface Ethernet1/0/1

 loopback-detection enable

#

interface Ethernet1/0/2

 loopback-detection enable

#

interface Ethernet1/0/3

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/4

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/5

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/6

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/7

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/8

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/9

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/10

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/11

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/12

 portaccess vlan 30

 loopback-detectionenable

#

interface Ethernet1/0/13

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/14

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/15

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/16

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/17

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/18

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/19

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/20

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/21

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/22

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/23

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/24

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/25

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/26

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/27

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/28

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/29

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/30

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/31

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/32

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/33

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/34

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/35

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/36

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/37

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/38

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/39

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/40

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/41

 portaccess vlan 21

 loopback-detection enable

#

interface Ethernet1/0/42

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/43

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/44

 portaccess vlan 22

 loopback-detection enable

#

interface Ethernet1/0/45

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/46

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/47

 portaccess vlan 30

 loopback-detection enable

#

interface Ethernet1/0/48

 portaccess vlan 30

 loopback-detection enable

#

interface GigabitEthernet1/1/1

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/1/2

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/2/1

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/2/2

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface NULL0

#

 management-vlan 2

#

 iproute-static 0.0.0.0 0.0.0.0 172.16.2.1preference 60

#

user-interface aux 0

user-interface vty 0

 userprivilege level 3

 setauthentication password simple ******

 protocol inbound telnet

user-interface vty 1 4

#

return

[H3C_3100_52TP_01]

 

 

 

********************************************************************************

* Copyright(c) 2004-2011 Hangzhou H3CTech. Co., Ltd. All rights reserved.    *

* Without the owner's prior written consent,                                  *

*  nodecompiling or reverse-engineering shall be allowed.                     *

********************************************************************************

 

 

Login authentication

 

 

Password:

%May 19 10:59:04:778 2000 H3C_3100_52TP_05 SHELL/5/LOGIN:- 1 -VTY(172.16.50.3)

in unit1 login

sys

system-view

System View: return to User View withCtrl+Z.

[H3C_3100_52TP_05]dis

[H3C_3100_52TP_05]displaycur

[H3C_3100_52TP_05]displaycurrent-configuration

#

 sysname H3C_3100_52TP_05

#

 loopback-detection enable

#

radius scheme system

#

domain system

#

local-user admin

 level 3

#

vlan 1 to 2

#

vlan 11

#

vlan 20

#

vlan 25

#

vlan 30

#

interface Vlan-interface2

 ipaddress 172.16.2.245 255.255.255.0

#

interface Aux1/0/0

#

interface Ethernet1/0/1

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/2

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/3

 portaccess vlan 20

 loopback-detection enable

#

interface Ethernet1/0/4

 portaccess vlan 11

 loopback-detection enable

#

interface Ethernet1/0/5

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/6

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/7

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/8

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/9

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/10

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/11

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/12

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/13

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/14

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/15

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/16

 portaccess vlan 11

 loopback-detectionenable

#

interface Ethernet1/0/17

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/18

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/19

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/20

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/21

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/22

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/23

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/24

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/25

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/26

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/27

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/28

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/29

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/30

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/31

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/32

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/33

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/34

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/35

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/36

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/37

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/38

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/39

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/40

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/41

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/42

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/43

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/44

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/45

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/46

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/47

 portaccess vlan 25

 loopback-detection enable

#

interface Ethernet1/0/48

 portaccess vlan 25

 loopback-detection enable

#

interface GigabitEthernet1/1/1

 portlink-type trunk

 porttrunk permit vlan all

 porttrunk pvid vlan 30

#

interface GigabitEthernet1/1/2

#

interface GigabitEthernet1/2/1

#

interface GigabitEthernet1/2/2

#

interface NULL0

#

 management-vlan 2

#

 iproute-static 0.0.0.0 0.0.0.0 172.16.2.1preference 60

#

user-interface aux 0

user-interface vty 0

 userprivilege level 3

 setauthentication password simple ******

 history-command max-size 256

user-interface vty 1 4

#

return

[H3C_3100_52TP_05]