data:image/s3,"s3://crabby-images/9b82a/9b82a71ea84cb13ad54b1eb812495aca933edaba" alt="Huawei AR1200-S Series Configuration Manual Download Page 223"
Figure 10-1
Configuring a basic ACL to limit user access to the FTP server
Router
PC A
PC B
PC C
Network
FTP Server
172.16.104.110
172.16.105.111
172.16.107.111
10.10.10.1
Configuration Roadmap
The configuration roadmap is as follows:
l
Create a basic ACL on the Router and configure rules in the basic ACL to classify users.
l
Configure basic FTP functions on the Router.
l
Apply a basic ACL to the Router to limit user access.
Data Preparation
To complete the configuration, you need the following data:
l
Number of a basic ACL: 2001
l
Name of a time range during which users in subnet2 access the FTP server: ftp-access
l
Time range: 14:00-18:00 on Saturday and Sunday from 2009 to 2011
Procedure
Step 1
Configure a time range.
<Huawei>
system-view
[Huawei]
sysname Router
[Router]
time-range ftp-access from 0:0 2009/1/1 to 23:59 2011/12/31
[Router]
time-range ftp-access 14:00 to 18:00 off-day
Step 2
Configure a basic ACL.
[Router]
acl number 2001
[Router-acl-basic-2001]
rule permit source 172.16.105.0 0.0.1.255
[Router-acl-basic-2001]
rule permit source 172.16.107.0 0.0.1.255 time-range ftp-
access
[Router-acl-basic-2001]
quit
Step 3
Configure basic FTP functions. The configuration details are not mentioned here.
Step 4
Configure access permissions on the FTP server.
[Router]
ftp acl 2001
Step 5
Verify the configuration.
Run the
ftp 172.16.104.110
command on PC A (172.16.105.111/24) in subnet 1. PC A can
connect to the FTP server.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
209