7-6
Operation
Command
Description
Create a basic ACL or
enter basic ACL view
acl number
acl-number
[
match-order
{
config
|
auto
} ]
As for the
acl number
command, the
config
keyword is specified by default.
Define rules for the ACL
rule
[
rule-id
] {
deny |
permit
}
[
rule-string
]
Required
Quit to system view
quit
—
Apply the ACL to control
Web users
ip http acl
acl-number
Optional
By default, no ACL is applied for Web
users.
Disconnecting a Web User by Force
The administrator can disconnect a Web user by force using the related commands.
Table 7-6
Disconnect a Web user by force
Operation
Command
Description
Disconnect a Web user by
force
free web-users
{
all
|
user-id user-id
|
user-name user-name
}
Required
Execute this command in user view.
Configuration Example
Network requirements
Only the Web users sourced from the IP address of 10.110.100.52 are permitted to access the switch.
Network diagram
Figure 7-3
Network diagram for controlling Web users using ACLs
Switch
10.110.100.46
Host A
IP network
Host B
10.110.100.52
Configuration procedure
# Define a basic ACL.
<Sysname> system-view
[Sysname] acl number 2030
[Sysname-acl-basic-2030] rule 1 permit source 10.110.100.52 0
[Sysname-acl-basic-2030] quit
# Apply ACL 2030 to only permit the Web users sourced from the IP address of 10.110.100.52 to access
the switch.
Summary of Contents for S3100 Series
Page 74: ...7 7 Sysname ip http acl 2030...
Page 270: ...1 51 Sysname GigabitEthernet1 0 1 port trunk permit vlan all...
Page 579: ...ii Configuration Example 2 4 QoS Profile Configuration Example 2 4...
Page 713: ...1 22 Total associations 1...
Page 823: ...1 16...
Page 1054: ...i Table of Contents Appendix A Acronyms A 1...