用戶提了一個需求。,這邏輯我硬是繞了2小時。分享下
需求如表
解決方法如下,需要留意,直接調用在3層交換局全局模式下,可不是只能調用在接口下,h話外提一句 traffic-filte 也是個簡易很好用的工具
acl 3000
desc in
rule 5 deny ip source 172.26.68.0 0.0.0.255 destination 172.0.0.0 0.255.255.255
rule 10 deny ip source 172.26.68.0 0.0.0.255 destination 10.33.0.0 0.0.255.255
rule 15 deny ip source 172.25.0.0 0.0.255.255 destination 172.0.0.0 0.255.255.255
rule 20 deny ip source 172.25.0.0 0.0.255.255 destination 10.33.0.0 0.0.255.255
rule 25 permit ip source 172.26.36.0 0.0.0.255 destination 172.0.0.0 0.255.255.255
rule 30 deny ip source 172.26.36.0 0.0.0.255
rule 35 permit ip
acl 3001
desc out
rule 5 deny ip source 172.0.0.0 0.255.255.255 destination 172.26.68.0 0.0.0.255
rule 10 deny ip source 10.33.0.0 0.0.255.255 destination 172.26.68.0 0.0.0.255
rule 15 deny ip source 172.0.0.0 0.255.255.255 destination 172.25.0.0 0.0.255.255
rule 20 deny ip source 10.33.0.0 0.0.255.255 destination 172.25.0.0 0.0.255.255
rule 25 permit ip source 172.0.0.0 0.255.255.255 destination 172.26.36.0 0.0.0.255
rule 30 deny ip source 172.26.36.0 0.0.0.255
rule 35 permit ip
[Sw12700-Core]traffic-filter intbound acl 3000
[Sw12700-Core]traffic-filter outbound acl 3001