
1-16
Network diagram
Figure 1-6
Network diagram for applying an ACL to a VLAN
GE1/0/1
PC 1
PC 3
Database server
PC 2
VLAN 10
GE1/0/2
GE1/0/3
192.168.1.2
Configuration procedure
# Define a periodic time range that is active from 8:00 to 18:00 in working days.
<Sysname> system-view
[Sysname] time-range test 8:00 to 18:00 working-day
# Define an ACL to deny packets destined for the database server.
[Sysname] acl number 3000
[Sysname-acl-adv-3000] rule 1 deny ip destination 192.168.1.2 0 time-range test
[Sysname-acl-adv-3000] quit
# Apply ACL 3000 to VLAN 10.
[Sysname] packet-filter vlan 10 inbound ip-group 3000
Summary of Contents for H3C S5100-SI
Page 129: ...1 10...
Page 522: ...ii...
Page 701: ...3 2...
Page 797: ...1 20 0 00 packet loss round trip min avg max 50 60 70 ms...
Page 827: ...i Table of Contents 1 Acronyms 1 1...