H3C-S5500 vlan-ACL配置
VLAN 内互访,vlan间禁止访问。(在三层交换机上启用了配置IP
1. Switch A 配置:
#vlan 10
#port Ethernet0/1
#vlan 20
#port Ethernet0/2
#interface gigabitethernet 1/1
#port link-type trunk
#port trunk permit vlan 10 20
2.Switch B 配置
#vlan 10
#port Ethernet0/10
#vlan 20
#port Ethernet0/20
#interface gigabitethernet 1/1
#port link-type trunk
#port trunk permit vlan 10 20
Trunk 中继设置
#vlan 2
#undo managent-vlan //取消默认的managent vlan 1
Managent-vlan 2
Interface vlan-interface 2
Ip addrss 172.16.25.1 255.255.255.0
Quit
Ip route-static
Interface gigabitethernet 1/1/1
Port link-type trunk //进入trunk配置端口
Port trunk permit vlan all //允许所有的vlan 通过该trunk
Port trunk pvid vlan 30 //默认VLAN标签
Interface vlan-interface 50
Ip address 172.16.50.1 255.255.255.0
Dhcp select relay
Dhcp relay server select 1
以下为配置数据
******************************************************************************
* Copyright (c) 2004-2010 Hangzhou H3C Tech. Co., Ltd. All rightsreserved. *
* Without the owner's prior writtenconsent, *
* no decompiling or reverse-engineeringshall be allowed. *
******************************************************************************
Login authentication
Password:
System View: return to User View withCtrl+Z.
[H3C_5500]dis
[H3C_5500]displaycur
[H3C_5500]displaycurrent-configuration
#
version 5.20, Release 2202P19
#
sysname H3C_5500
#
super password level 3 simple ******
#
dhcprelay server-group 1 ip 172.16.1.7
#
domain default enable system
#
telnet server enable
#
acl number 3011 name Customer
rule5 deny ip source 172.16.11.0 0.0.0.255 destination172.16.10.0 0.0.0.255
rule6 deny ip source 172.16.11.0 0.0.0.255 destination172.16.12.0 0.0.0.255
rule7 deny ip source 172.16.11.0 0.0.0.255 destination172.16.21.0 0.0.0.255
rule8 deny ip source 172.16.11.0 0.0.0.255 destination172.16.30.0 0.0.0.255
acl number 3030 name vlan30
rule3 permit ip source 172.16.30.69 0 destination 172.16.25.21 0
rule4 permit ip source 172.16.30.49 0 destination 172.16.25.21 0
rule5 deny ip source 172.16.30.0 0.0.0.255 destination172.16.25.0 0.0.0.255
rule6 deny ip source 172.16.30.0 0.0.0.255 destination172.16.24.0 0.0.0.255
rule7 deny ip source 172.16.30.0 0.0.0.255 destination172.16.23.0 0.0.0.255
rule8 deny ip source 172.16.30.0 0.0.0.255 destination172.16.22.0 0.0.0.255
rule9 deny ip source 172.16.30.0 0.0.0.255 destination172.16.21.0 0.0.0.255
rule10 deny ip source 172.16.30.0 0.0.0.255 destination172.16.12.0 0.0.0.255
rule11 deny ip source 172.16.30.0 0.0.0.255 destination172.16.11.0 0.0.0.255
rule12 deny ip source 172.16.30.0 0.0.0.255 destination172.16.10.0 0.0.0.255
acl number 3050
rule6 deny ip source 172.16.50.0 0.0.0.255 destination172.16.25.0 0.0.0.255
#
vlan 1
#
vlan 2 to 4
#
vlan 10 to 12
#
vlan 20 to 25
#
vlan 30
#
vlan 50
#
radius scheme system
server-type extended
primary authentication 127.0.0.1 1645
primary accounting 127.0.0.1 1646
user-name-format without-domain
#
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
traffic classifier Any operator and
traffic classifier Android operator and
if-match any
if-match source-mac 50af-7303-102f
#
traffic behavior Any
traffic behavior Android
filter deny
#
user-group system
#
local-user admin
password simple ******
authorization-attribute level 3
service-type lan-access
service-type ssh telnet terminal
#
interface NULL0
#
interface Vlan-interface1
ipaddress 172.16.1.1 255.255.255.0
#
interface Vlan-interface2
ipaddress 172.16.2.1 255.255.255.0
#
interface Vlan-interface3
ipaddress 172.16.3.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface4
ipaddress 172.16.4.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface10
ipaddress 172.16.10.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface11
ipaddress 172.16.11.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
packet-filter 3011 inbound
#
interface Vlan-interface12
ipaddress 172.16.12.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface20
ipaddress 172.16.20.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface21
ipaddress 172.16.21.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface22
ipaddress 172.16.22.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface23
ipaddress 172.16.23.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface24
ipaddress 172.16.24.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface25
ipaddress 172.16.25.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
#
interface Vlan-interface30
ipaddress 172.16.30.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
packet-filter 3030 inbound
#
interface Vlan-interface50
ipaddress 172.16.50.1 255.255.255.0
dhcpselect relay
dhcprelay server-select 1
packet-filter 3050 inbound
#
interface GigabitEthernet1/0/1
portaccess vlan 2
#
interface GigabitEthernet1/0/2
portaccess vlan 2
#
interface GigabitEthernet1/0/3
portaccess vlan 2
#
interface GigabitEthernet1/0/4
portaccess vlan 2
#
interface GigabitEthernet1/0/5
#
interface GigabitEthernet1/0/6
#
interface GigabitEthernet1/0/7
portlink-type trunk
porttrunk permit vlan all
#
interface GigabitEthernet1/0/8
#
interface GigabitEthernet1/0/9
#
interface GigabitEthernet1/0/10
#
interface GigabitEthernet1/0/11
#
interface GigabitEthernet1/0/12
portlink-type trunk
porttrunk permit vlan all
#
interface GigabitEthernet1/0/13
#
interface GigabitEthernet1/0/14
#
interface GigabitEthernet1/0/15
#
interface GigabitEthernet1/0/16
#
interface GigabitEthernet1/0/17
portaccess vlan 11
#
interface GigabitEthernet1/0/18
portaccess vlan 11
#
interface GigabitEthernet1/0/19
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/0/20
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/0/21
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/0/22
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/0/23
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/0/24
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/0/25
shutdown
#
interface GigabitEthernet1/0/26
shutdown
#
interface GigabitEthernet1/0/27
shutdown
#
interface GigabitEthernet1/0/28
shutdown
#
nqa entry admin ***
typeicmp-echo
destination ip 172.16.100.1
frequency 8000
next-hop 172.16.2.252
reaction 1 checked-element probe-fail threshold-type consecutive 5action-type
trigger-only
route-option bypass-route
#
iproute-static 0.0.0.0 0.0.0.0 Vlan-interface2172.16.2.254
ip route-static0.0.0.0 0.0.0.0 172.16.2.252 track 1preference 40
iproute-static 172.16.100.0 255.255.255.0 172.16.2.252 preference 30
iproute-static 192.168.122.0 255.255.254.0 Vlan-interface2 172.16.2.253 prefer
ence 50
iproute-static 192.168.138.0 255.255.255.0 172.16.2.252 preference 30
iproute-static 218.5.78.19 255.255.255.255 172.16.2.254 preference 50
#
snmp-agent
snmp-agent local-engineid 800063A203C4CAD9D4DEC8
snmp-agent sys-info version v3
#
track 1 nqa entry admin *** reaction 1
#
dhcpenable
#
nqaschedule admin *** start-time now lifetime forever
#
user-interface aux 0
user-interface vty 0
userprivilege level 3
setauthentication password simple ******
protocol inbound telnet
user-interface vty 1 4
#
return
[H3C_5500]
********************************************************************************
* Copyright(c) 2004-2011 Hangzhou H3CTech. Co., Ltd. All rights reserved. *
* Without the owner's prior written consent, *
* nodecompiling or reverse-engineering shall be allowed. *
********************************************************************************
Login authentication
Password:
%Jul 21 01:14:54:265 2000 H3C_3100_52TP_01 SHELL/5/LOGIN:- 1 -VTY(172.16.50.3)
in unit1 login
System View: return to User View withCtrl+Z.
[H3C_3100_52TP_01]dis
[H3C_3100_52TP_01]displaycur
[H3C_3100_52TP_01]displaycurrent-configuration
#
sysname H3C_3100_52TP_01
#
loopback-detection enable
#
radius scheme system
#
domain system
#
vlan 1 to 2
#
vlan 21 to 22
#
vlan 30
#
interface Vlan-interface2
ipaddress 172.16.2.241 255.255.255.0
#
interface Aux1/0/0
#
interface Ethernet1/0/1
loopback-detection enable
#
interface Ethernet1/0/2
loopback-detection enable
#
interface Ethernet1/0/3
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/4
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/5
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/6
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/7
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/8
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/9
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/10
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/11
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/12
portaccess vlan 30
loopback-detectionenable
#
interface Ethernet1/0/13
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/14
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/15
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/16
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/17
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/18
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/19
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/20
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/21
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/22
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/23
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/24
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/25
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/26
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/27
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/28
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/29
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/30
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/31
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/32
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/33
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/34
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/35
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/36
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/37
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/38
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/39
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/40
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/41
portaccess vlan 21
loopback-detection enable
#
interface Ethernet1/0/42
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/43
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/44
portaccess vlan 22
loopback-detection enable
#
interface Ethernet1/0/45
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/46
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/47
portaccess vlan 30
loopback-detection enable
#
interface Ethernet1/0/48
portaccess vlan 30
loopback-detection enable
#
interface GigabitEthernet1/1/1
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/1/2
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/2/1
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/2/2
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface NULL0
#
management-vlan 2
#
iproute-static 0.0.0.0 0.0.0.0 172.16.2.1preference 60
#
user-interface aux 0
user-interface vty 0
userprivilege level 3
setauthentication password simple ******
protocol inbound telnet
user-interface vty 1 4
#
return
[H3C_3100_52TP_01]
********************************************************************************
* Copyright(c) 2004-2011 Hangzhou H3CTech. Co., Ltd. All rights reserved. *
* Without the owner's prior written consent, *
* nodecompiling or reverse-engineering shall be allowed. *
********************************************************************************
Login authentication
Password:
%May 19 10:59:04:778 2000 H3C_3100_52TP_05 SHELL/5/LOGIN:- 1 -VTY(172.16.50.3)
in unit1 login
System View: return to User View withCtrl+Z.
[H3C_3100_52TP_05]dis
[H3C_3100_52TP_05]displaycur
[H3C_3100_52TP_05]displaycurrent-configuration
#
sysname H3C_3100_52TP_05
#
loopback-detection enable
#
radius scheme system
#
domain system
#
local-user admin
level 3
#
vlan 1 to 2
#
vlan 11
#
vlan 20
#
vlan 25
#
vlan 30
#
interface Vlan-interface2
ipaddress 172.16.2.245 255.255.255.0
#
interface Aux1/0/0
#
interface Ethernet1/0/1
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/2
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/3
portaccess vlan 20
loopback-detection enable
#
interface Ethernet1/0/4
portaccess vlan 11
loopback-detection enable
#
interface Ethernet1/0/5
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/6
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/7
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/8
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/9
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/10
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/11
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/12
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/13
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/14
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/15
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/16
portaccess vlan 11
loopback-detectionenable
#
interface Ethernet1/0/17
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/18
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/19
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/20
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/21
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/22
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/23
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/24
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/25
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/26
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/27
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/28
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/29
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/30
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/31
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/32
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/33
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/34
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/35
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/36
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/37
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/38
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/39
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/40
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/41
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/42
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/43
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/44
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/45
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/46
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/47
portaccess vlan 25
loopback-detection enable
#
interface Ethernet1/0/48
portaccess vlan 25
loopback-detection enable
#
interface GigabitEthernet1/1/1
portlink-type trunk
porttrunk permit vlan all
porttrunk pvid vlan 30
#
interface GigabitEthernet1/1/2
#
interface GigabitEthernet1/2/1
#
interface GigabitEthernet1/2/2
#
interface NULL0
#
management-vlan 2
#
iproute-static 0.0.0.0 0.0.0.0 172.16.2.1preference 60
#
user-interface aux 0
user-interface vty 0
userprivilege level 3
setauthentication password simple ******
history-command max-size 256
user-interface vty 1 4
#
return
[H3C_3100_52TP_05]