弱弱的请教:! k% L; W) ?" \3 {# |
公司不让上开心,但有两个人业务需要,要上。
# c! r6 R. o' A9 b3 X# w/ ^$ j# O5 ?
1 _+ h, v) C2 J: m. _% m- n$ l于是我就用扩展访问控制列表,先写允许,再写deny all. N3 p& f) S6 c) ^! B
" B6 a+ l4 x2 e9 H5 Z可是公司内网是DHCP分配的,只好给他们两人固定IP.
& m8 D8 F) E/ ~7 z) s; [: c# G, @. g* W8 J
于是乎,想到内否用基于MAC的访问控制?允许2个MAC访问开心,其余MAC不允许访问开心。
( [9 F- L. K: o
[3 m3 d) v& y' h8 c0 f$ q F3 X4 k但命令也好,网上讨论也好,都没有提过这方面。+ c" l" J; A, }
! S4 \" ^5 B" Z8 O* K! i6 D) p( T求助大家了。
: Y G+ H) G. J4 [% B% Q! o- @* jip access-list extended denyonline: W0 W/ |9 j$ i: X B8 I. {6 z; [% T
deny ip host 123.125.44.242 host 192.168.40.2 w( u3 y. z' j+ [* \8 I3 d8 v
deny ip host 123.125.56.245 host 192.168.40.2+ ~ V6 h+ Z7 v
deny ip host 123.125.58.247 host 192.168.40.27 _" U/ W2 _4 Z( d: y& E
deny ip host 123.125.58.246 host 192.168.40.2
: w9 X* ]5 t- D6 R- T/ @deny ip host 123.125.59.16 host 192.168.40.2
0 |- ?3 }2 `0 b+ Ddeny ip host 123.125.56.246 host 192.168.40.2
# P- r. l2 f& j, G9 Sdeny ip host 123.125.58.245 host 192.168.40.2
: ?2 Z8 G& j T" c8 ]; Ddeny ip host 123.125.56.248 host 192.168.40.2" _) e7 `5 p% A, A
deny ip host 123.125.58.248 host 192.168.40.28 e) W, s; L3 c# Y0 g0 O' S
deny ip host 123.125.59.20 host 192.168.40.2- m6 A" Q6 b0 O! K7 W' J
deny ip host 123.125.44.242 host 192.168.50.110
) x9 L8 Q6 j$ \/ x- a5 y: w5 Fdeny ip host 123.125.56.245 host 192.168.50.110
+ [0 E& o0 o* @2 R K$ T; Jdeny ip host 123.125.58.247 host 192.168.50.110
( ^9 b/ u2 E+ N! F" g% V" ]/ [deny ip host 123.125.58.246 host 192.168.50.1104 X. w+ X3 A: C" T
deny ip host 123.125.59.16 host 192.168.50.1108 x" |( W8 f! \7 d5 Y9 r" y4 d
deny ip host 123.125.56.246 host 192.168.50.110
0 n: i$ l# b b3 v+ @# l3 {, Jdeny ip host 123.125.58.245 host 192.168.50.110
8 v' g8 k: U$ N( g2 X2 q$ o4 A8 ydeny ip host 123.125.56.248 host 192.168.50.110
3 e# |( M+ W, Fdeny ip host 123.125.58.248 host 192.168.50.1103 b5 w) ~# f- p; ^7 e! j& D& O
deny ip host 123.125.59.20 host 192.168.50.110
" }( Q( v9 O! \# W5 H3 Tdeny ip host 123.125.44.242 any
# D+ |* O' ~* O( b6 J- C. {deny ip host 123.125.56.245 any0 ~5 \" \% i: F$ P) \* K+ T
deny ip host 123.125.58.247 any" q3 X6 U- ^- v2 R" ]: `( u) J
deny ip host 123.125.58.246 any6 o0 U, [9 r" \1 Q1 Z' ]
deny ip host 123.125.59.16 any- d# l; `7 p9 [9 s" h. G
deny ip host 123.125.56.246 any
1 L: i+ a5 g N+ A; {$ rdeny ip host 123.125.58.245 any4 R _7 K9 O/ m" J
deny ip host 123.125.56.248 any
1 S; ^$ G. ?6 r+ {0 t4 N0 \deny ip host 123.125.58.248 any) U8 \2 Y/ ^7 o1 e% H0 I
deny ip host 123.125.59.20 any3 H/ ~+ h' U% \! o
1 J* y, |9 k/ c5 s6 b
permit ip any any |