弱弱的请教:' ] r+ ~1 V T/ N/ M! B
公司不让上开心,但有两个人业务需要,要上。: l9 D! b: g J( d9 {) ~
, Q) Q0 x4 b) i5 X4 y/ b! @于是我就用扩展访问控制列表,先写允许,再写deny all.
; Q5 i; v+ b' `) o* H0 w2 {8 g2 A: j5 i, w8 V8 q& h$ I
可是公司内网是DHCP分配的,只好给他们两人固定IP.
3 |" T& w7 B6 N I, c: t1 r: W
& I" W& N p- k4 J于是乎,想到内否用基于MAC的访问控制?允许2个MAC访问开心,其余MAC不允许访问开心。- L- R) ?: K: ^" k4 C( F
) d" o& H( D# _: v
但命令也好,网上讨论也好,都没有提过这方面。' Q$ M2 M. v- [+ g' v) j6 A
$ ~* Z, S: w8 H) n/ ]5 O+ ]求助大家了。
7 n1 P: c5 H6 L1 C# }5 Fip access-list extended denyonline6 {! g. R; @; V0 `1 w: V4 [- d
deny ip host 123.125.44.242 host 192.168.40.2
( _2 r7 h* c5 i& U- M3 J* b: ]deny ip host 123.125.56.245 host 192.168.40.24 t1 V" }! K( ?$ x+ |: \
deny ip host 123.125.58.247 host 192.168.40.21 x* n0 n" X9 I# ^& E9 U! E# i' N
deny ip host 123.125.58.246 host 192.168.40.28 w) p/ j! O' h. Y9 D+ K1 N% p8 ~
deny ip host 123.125.59.16 host 192.168.40.2
0 F& s, l! M6 N& U) p& B# `deny ip host 123.125.56.246 host 192.168.40.2! _9 f- n( n- S$ j
deny ip host 123.125.58.245 host 192.168.40.2
1 O2 C4 t! [, `3 Hdeny ip host 123.125.56.248 host 192.168.40.2! r& R3 M' K' l6 w! f# |3 o
deny ip host 123.125.58.248 host 192.168.40.28 V& D3 V" k1 p) z% w- b: K
deny ip host 123.125.59.20 host 192.168.40.2
j' l, R) Q Odeny ip host 123.125.44.242 host 192.168.50.110
: P. N. e3 |" Sdeny ip host 123.125.56.245 host 192.168.50.1103 j8 M2 d& e$ E$ e8 C7 w
deny ip host 123.125.58.247 host 192.168.50.110
4 I' L* q* l( r% ldeny ip host 123.125.58.246 host 192.168.50.110
! R! o/ e# D' \- l! M& ?3 S: |" qdeny ip host 123.125.59.16 host 192.168.50.1109 Z) j9 p& k( C+ q
deny ip host 123.125.56.246 host 192.168.50.110! w% [5 X! b- T7 L( l6 B
deny ip host 123.125.58.245 host 192.168.50.110
5 S- x, x0 l# Gdeny ip host 123.125.56.248 host 192.168.50.110! d( S8 u% g+ Z# L% Q4 @5 O
deny ip host 123.125.58.248 host 192.168.50.110, {% D0 i/ ~( d
deny ip host 123.125.59.20 host 192.168.50.110
' T! ^, X/ ^' ]9 Z) m& Qdeny ip host 123.125.44.242 any8 b1 d' {& p& H+ _" m
deny ip host 123.125.56.245 any5 W3 H2 J/ Y) J8 I( ]' ~ {- t
deny ip host 123.125.58.247 any
S( s3 u) h- l& w' ~( Gdeny ip host 123.125.58.246 any
4 ~8 A5 H6 E! U& L5 A7 _deny ip host 123.125.59.16 any
j+ F6 \" u4 \2 B' J! j& t8 Zdeny ip host 123.125.56.246 any
- u5 `( @) T/ k8 [! ^8 \* rdeny ip host 123.125.58.245 any
7 C$ I) u) b( t6 u5 ~7 odeny ip host 123.125.56.248 any
$ B( o: p& j# I) s2 K% O3 `: a+ V! Fdeny ip host 123.125.58.248 any
" v( U1 _. ~, i M) T6 ]! hdeny ip host 123.125.59.20 any
0 g* L. q! _# [2 i. E. R
9 g# ]* K3 `' F0 {8 S& Z% ppermit ip any any |