华为S5700交换机禁ping

  1. 限制终端到终端的ping

acl number 3100
rule deny icmp

traffic classifier 1 operator and
if-match acl 3100

traffic behavior deny
permit

traffic policy icmp
classifier 1 behavior deny

interface GigabitEthernet0/0/1

traffic-policy icmp inbound

2.限制终端到交换机的ping

system-view

[HUAWEI] cpu-defend policy icmp

[HUAWEI-cpu-defend-policy-1] deny packet-type icmp

[HUAWEI-cpu-defend-policy-1] quit

[HUAWEI] cpu-defend-policy icmp global

你可能感兴趣的:(运维)