data:image/s3,"s3://crabby-images/5d36c/5d36cbdc72a306f4b6d44e6692bd5fb32cc5c6d5" alt="Huawei AR1200-S Series Скачать руководство пользователя страница 229"
Procedure
Step 1
Create a VLAN and configure each interface.
# Create VLAN 20.
<Huawei>
system-view
[Huawei]
sysname Router
[Router]
vlan 20
[Router-vlan20]
quit
# Configure Ethernet0/0/0 as a trunk interface and add Ethernet0/0/0 to VLAN 20.
[Router]
interface ethernet 0/0/0
[Router-Ethernet0/0/0]
port link-type trunk
[Router-Ethernet0/0/0]
port trunk allow-pass vlan 20
[Router-Ethernet0/0/0]
quit
NOTE
Configure the interface of the switch connecting to the Router as a trunk interface and add it to VLAN 20.
The configuration details are not mentioned here.
Configure the interface of the switch connecting to PC1 as an access interface and add it to VLAN 20. The
configuration details are not mentioned here.
Step 2
Configure an ACL.
# Create a Layer 2 ACL named
layer2
on the Router to match packets with the source MAC
address 0000-0000-0003.
[Router]
acl name layer2 link
[Router-acl-L2-layer2]
rule permit source-mac 0000-0000-0003 ffff-ffff-ffff
[Router-acl-L2-layer2]
quit
Step 3
Configure a traffic classifier.
# Create a traffic classifier
c1
on the Router to match ACL
layer2
.
[Router]
traffic classifier c1
[Router-classifier-c1]
if-match acl layer2
[Router-classifier-c1]
quit
Step 4
Configure a traffic behavior.
# Create a traffic behavior
b1
on the Router and configure the traffic statistics action in the traffic
behavior.
[Router]
traffic behavior b1
[Router-behavior-b1]
statistic enable
[Router-behavior-b1]
quit
Step 5
Configure a traffic policy and apply the traffic policy to an interface.
# Create a traffic policy
p1
on the Router and bind the traffic policy to the traffic classifier and
traffic behavior.
[Router]
traffic policy p1
[Router-trafficpolicy-p1]
classifier c1 behavior b1
[Router-trafficpolicy-p1]
quit
# Apply the traffic policy
p1
to Ethernet0/0/0.
[Router]
interface ethernet 0/0/0
[Router-Ethernet0/0/0]
traffic-policy p1 inbound
[Router-Ethernet0/0/0]
quit
[Router]
quit
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
215