7-2
To do…
Use the command…
Remarks
Define rules for the ACL
rule
[
rule-id
] {
permit
|
deny
}
[
source
{
sour-addr
sour-wildcard
|
any
} |
time-range
time-name
|
fragment
|
logging
]*
Required
Quit to system view
quit
—
Enter user interface view
user-interface
[
type
]
first-number
[
last-number
]
—
Apply the ACL to control Telnet
users by source IP addresses
acl
[
ipv6
]
acl-number
{
inbound
|
outbound
}
Required
The
inbound
keyword specifies
to filter the users trying to Telnet
to the current switch.
The
outbound
keyword
specifies to filter users trying to
Telnet to other switches from
the current switch.
Controlling Telnet Users by Source and Destination IP Addresses
This configuration needs to be implemented by advanced ACL; an advanced ACL ranges from 3000 to
3999. For the definition of ACL, refer to
ACL Configuration
in the
Security Volume
.
Follow these steps to control Telnet users by source and destination IP addresses:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create an advanced ACL or
enter advanced ACL view
acl
[
ipv6
]
number
acl-number
[
match-order
{
config
|
auto
} ]
As for the
acl number
command, the
config
keyword
is specified by default.
Define rules for the ACL
rule
[
rule-id
] {
permit
|
deny
}
rule-string
Required
You can define rules as needed
to filter by specific source and
destination IP addresses.
Quit to system view
quit
—
Enter user interface view
user-interface
[
type
]
first-number
[
last-number
]
—
Apply the ACL to control Telnet
users by specified source and
destination IP addresses
acl
[
ipv6
]
acl-number
{
inbound
|
outbound
}
Required
The
inbound
keyword specifies
to filter the users trying to Telnet
to the current switch.
The
outbound
keyword
specifies to filter users trying to
Telnet to other switches from
the current switch.
Controlling Telnet Users by Source MAC Addresses
This configuration needs to be implemented by Layer 2 ACL; a Layer 2 ACL ranges from 4000 to 4999.
For the definition of ACL, refer to
ACL Configuration
in the
Security Volume
.
Содержание S5500-SI Series
Страница 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Страница 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Страница 250: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 310: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Страница 493: ...2 8...
Страница 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...