Access Control Lists: Huawei Technologies Co., LTD
Access Control Lists: Huawei Technologies Co., LTD
HUAWEI TECHNOLOGIES CO., LTD.
Foreword
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 2
Objectives
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 3
Filtering Restricted Traffic
.1 192.168.1.0/24 .2
G0/0/0
G0/0/1 Server A
.1 192.168.2.0/24 .2
.1 192.168.1.0/24 .2
Data Data
No Match
G0/0/0
Match
Data Encrypted
.1 192.168.2.0/24 .2
Data
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 6
ACL Rule Management
acl 2000
rule 5 deny source 192.168.1.0 0.0.0.255
If no match
172.16.1.0/24
Rules are used to manage the decision process for each ACL.
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 7
Basic ACL
Host A
200.10.10.1/24
RTA
192.168.1.1/24
G0/0/0
Host B
192.168.2.1/24
[RTA]acl 2000
[RTA-acl-basic-2000]rule deny source 192.168.1.0 0.0.0.255
[RTA-acl-basic-2000]rule permit source 192.168.2.0 0.0.0.255
[RTA]interface GigabitEthernet 0/0/0
[RTA-GigabitEthernet0/0/0]traffic-filter outbound acl 2000
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 8
Configuration Validation
The rules and matching order can be verified for each ACL.
Host A
FTP Server
172.16.10.1/24
RTA
192.168.1.1/24
G0/0/1
Host B Private Server
192.168.2.1/24 172.16.10.2/24
[RTA]acl 3000
[RTA-acl-adv-3000]rule deny tcp source 192.168.1.0 0.0.0.255
destination 172.16.10.1 0.0.0.0 destination-port eq 21
[RTA-acl-adv-3000] rule deny ip source 192.168.2.0 0.0.0.255
destination 172.16.10.2 0.0.0.0
[RTA-GigabitEthernet0/0/1]traffic-filter inbound acl 3000
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 10
Configuration Validation
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 11
ACL Application - NAT
Host A
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 12
Summary
Copyright © 2016 Huawei Technologies Co., Ltd. All rights reserved. Page 13
Thank you
www.huawei.com