Configuring ACL
Configuration Example for ACL
Configuration Guide
531
3
Configuration Example for ACL
3.1 Network Requirements
A company’s server group can provide different types of services. It is required that:
The Marketing department can only access the server group.
The Marketing department can only visit HTTP and HTTPS websites on the Internet.
3.2 Network Topology
As shown below, computers in the Marketing department are connected to the switch via
port 1/0/1 , and the server group is connected to the switch via port 1/0/2.
Figure 3-1
Network Topology
Internet
Port1/0/1
Marketing
IP:10.10.70.0/24
Server group
IP:10.10.80.0/24
Port1/0/2
3.3 Configuration Scheme
To meet the requirements above, you can configure packet filtering by creating an Extend-
IP ACL and configuring rules for it.
Configuring ACL
1) Configure a permit rule to match packets with source IP address 10.10.70.0/24, and
destination IP address 110.10.80.0/24. This rule allows the Marketing department to
access the server group.