21
ACL configuration examples
IPv4 ACL configuration example
Network Requirements
As shown in
Figure 1
, a company interconnects its wireless users and servers through the
access controller (AC). The salary server uses IP address 192.168.1.2. The wireless users in
the research and development (R&D) department are connected to the wireless
interface WLAN-ESS 1 of the AC.
Configure an ACL to deny access from the wireless users in R&D department to the
salary server during office hours (from 8:00 to 18:00) on working days.
Figure 1
Network diagram for ACL configuration
AC
GE 1/0/1
Server
192.168.1.2
IP network
AP 1
AP 2
Client A
Client B
Configuration procedure
1.
Create a time range for office hours:
Create a periodic time range from 8:00 to 18:00 on working days:
<AC> system-view
[AC] time-range trname 8:00 to 18:00 working-day
2.
Define an ACL to control access to the salary server:
a.
Create an advanced IPv4 ACL numbered 3000 and enter its view:
[AC] acl number 3000