How to configure the access list of AR series router package filtering control

Source: Internet
Author: User

Access to the Internet from the Intranet Address 192.168.1.0/25 is not restricted.
Only sending and receiving mails are allowed for the Intranet address 192.168.1.128/25, and access to the Internet is not allowed
#
Sysname roupid
#
Firewall enable/Enable Firewall/
Firewall default deny/configure the default firewall operation as deny/

#

Radius scheme System

#

Domain System

#

ACL number 2000/define the ACL for Nat translation/

Rule 0 permit source 192.168.1.0 0.0.255

Rule 1 deny

#

ACL number 3001/define the ACL for packet filtering/

Rule 0 permit IP source 192.168.1.0 0.0.127

/Access to the Internet from the Intranet Address 192.168.1.0/25 is not restricted/

Rule 1 permit TCP source 192.168.1.128 0.0.127 destination-port EQ POP3

Rule 2 permit TCP source 192.168.1.128 0.0.127 destination-port EQ SMTP

/The intranet address 192.168.1.128/25 can only send and receive mails/

#

Interface ethernet1/0/0

IP address 192.168.1.1 255.255.255.0

Firewall packet-filter 3001 inbound/use package filter for inbound traffic/

#

Interface serial/0/0

Link-Protocol PPP

IP address 202.101.1.2 255.255.255.252

Nat outbound 2000

#

Interface null0

#

IP route-static 0.0.0.0 0.0.0.0 202.101.1.1 preference 60

#

User-interface con 0

User-interface vty 0 4

#

Return
Check disp firewall-statistics all and disp ACL 3001 to confirm that the firewall has taken effect.

Disp firewall-statistics all

Firewall is enable, default filtering method is 'deny '.

Interface: ethernet1/0/0

In-bound policy: ACL 3001

Fragments matched normally

From 5:05:50 to 6:32:49

198 packets, 24129 bytes, 4% permitted,

0 packets, 0 bytes, 0% denied,

0 packets, 0 bytes, 0% permitted default,

5919 packets, 1021492 bytes, 96% denied default,

Totally 198 packets, 24129 bytes, 4% permitted,

Totally 5919 packets, 1021492 bytes, 96% denied.

Disp ACL 3001.

Advanced ACL 3001, 3 Rules

ACL's step is 1

Rule 0 permit IP source 192.168.1.0 0.0.127 (194 times matched)

Rule 1 permit TCP source 192.168.1.128 0.0.127 destination-port EQ POP3 (9 times matched)

Rule 2 permit TCP source 192.168.1.128 0.0.127 destination-port eq smtp (0 times matched)

Tip]

1. Firewall disable by default. You need to run the "firewall enable" command to enable firewall functions.

2. The default firewall filtering method is allow pass (Permit). You can use "firewall default deny" to change it to allow pass.

3. When packet filtering is used in the intranet and DHCP server is used to allocate addresses, you must add a "rule 0 permit IP source 0.0.0.0 0" in ACL 3001. Otherwise, the DHCP server cannot allocate an address.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.