4.访问控制列表(ACL)
(1)标准
RouterA
[H3C]interface e0/0
[H3C-ethernet e0/0]ip address 192.168.1.1 255.255.255.0 [H3C]interface e0/1
[H3C-ethernet e0/1]ip address 198.1.1.1 255.255.255.0 [H3C]ospf 2
[H3C-ospf2]area 0
[H3C-ospf-area0]network 192.168.1.0 0.0.0.255
[H3C-ospf-area0]network 198.168.1.0 0.0.0.255
[H3C]display ip rout
[H3C] firewall enable
[H3C]firewall default deny/permit (默认为permit)
[H3C]acl number 2000
[H3C-acl-2000]rule permit source 192.168.2.0 0.0.0.255
[H3C]interface e1
[H3C-ui-ethernet1]firewall packet-filter 2000 inbound
[H3C]display acl 2000
[H3C]undo acl number 2000
RouterB
[H3C]interface e0/1
[H3C-ethernet e0/1]ip address 192.168.2.1 255.255.255.0 [H3C]interface e0/0
[H3C-ethernet e0/0]ip address 198.1.1.2 255.255.255.0 [H3C]ospf 2
[H3C-ospf2]area 0
[H3C-ospf-area0]network 192.168.2.0 0.0.0.255
]network 198.168.1.0 0.0.0.255
[H3C]display ip rout
(2)扩展
RouterA
[H3C]interface e0/0