3-83
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create an advanced ACL and
enter its view, or enter the view of
an existing advanced ACL
acl
number
acl-number
[
match-order
{
config
|
auto
} ]
Required
By default, no advanced ACL
exists.
Configure rules for the ACL
rule
[
rule-id
] {
permit
|
deny
}
rule-string
Required
Exit the advanced ACL view
quit
—
Enter user interface view
user-interface
[
type
]
first-number
[
last-number
]
—
Use the ACL to control user login
by source MAC address
acl
acl-number inbound
Required
inbound
: Filters incoming telnet
packets.
The above configuration does not take effect if the telnet client and server are not in the same
subnet.
Source MAC-Based Login Control Configuration Example
Network requirements
As shown in
, configure an ACL on the Device to permit only incoming telnet packets
sourced from Host A and Host B.
Figure 5-1
Network diagram for configuring source MAC-based login control
Configuration procedure
# Configure basic ACL 2000, and configure rule 1 to permit packets sourced from Host B, and rule
2 to permit packets sourced from Host A.
<Sysname> system-view
[Sysname] acl number 2000 match-order config
[Sysname-acl-basic-2000] rule 1 permit source 10.110.100.52 0
[Sysname-acl-basic-2000] rule 2 permit source 10.110.100.46 0
Summary of Contents for SR6600 SPE-FWM
Page 112: ...6 101...