130 CN4093 Application Guide for N/OS 8.4
ACL Configuration Examples
ACL Example 1
Usethisconfigurationtoblocktraffictoaspecifichost.Alltrafficthatingresseson
portEXT1isdeniedifitisdestinedforthehostatIPaddress100.10.1.1.
1. ConfigureanAccessControlList.
2. AddACL1toportEXT1.
ACL Example 2
Usethisconfigurationtoblocktrafficfromanetworkdestinedforaspecifichost
address.AlltrafficthatingressesinportEXT2withsourceIPfromclass
100.10.1.0/24anddestinationIP200.20.2.2isdenied.
1. ConfigureanAccessControlList.
2. AddACL2toportEXT2.
CN 4093(config)# access-control list 1 ipv4 destination-ip-address
100.10.1.1
CN 4093(config)# access-control list 1 action deny
CN 4093(config)# interface port EXT1
CN 4093(config-if)# access-control list 1
CN 4093(config-if)# exit
CN 4093(config)# access-control list 2 ipv4 source-ip-address 100.10.1.0
255.255.255.0
CN 4093(config)# access-control list 2 ipv4 destination-ip-address
200.20.2.2 255.255.255.255
CN 4093(config)# access-control list 2 action deny
CN 4093(config)# interface port EXT2
CN 4093(config-if)# access-control list 2
CN 4093(config-if)# exit