How to configure an interface to allow only access from certain IP addresses

Created: Jun 14, 2019 10:52:09Latest reply: Jun 16, 2019 09:19:05 57 2 0 0
  Rewarded Hi-coins: 0 (problem resolved)

How to configure an interface to allow only access from certain IP addresses

  • x
  • convention:

Featured Answers
Official Created Jun 14, 2019 10:52:33 Helpful(0) Helpful(0)

To configure an interface to allow access from certain IP addresses, configure an ACL to match the IP addresses, reference the ACL in a traffic policy, and apply the traffic policy to the interface. For example, to allow only the user with IP address 1.1.1.2 to access GE0/0/1, run the following commands:

[HUAWEI] acl number 3030
[HUAWEI-acl-adv-3030] rule permit ip source 1.1.1.2 0
[HUAWEI-acl-adv-3030] quit
[HUAWEI] acl number 3031
[HUAWEI-acl-adv-3031] rule permit ip
[HUAWEI] traffic classifier test1
[HUAWEI-classifier-test1] if-match acl 3030
[HUAWEI] traffic classifier test2
[HUAWEI-classifier-test2] if-match acl 3031
[HUAWEI] traffic behavior test1
[HUAWEI-behavior-test1] permit
[HUAWEI] traffic behavior test2
[HUAWEI-behavior-test2] deny
[HUAWEI] traffic policy test
[HUAWEI-trafficpolicy-test] classifier test1 behavior test1
[HUAWEI-trafficpolicy-test] classifier test2 behavior test2
[HUAWEI] interface gigabitethernet 0/0/1
[HUAWEI-GigabitEthernet0/0/1] traffic-policy test inbound
  • x
  • convention:

All Answers
All_About_Switch Official Created Jun 14, 2019 10:52:33 Helpful(0) Helpful(0)

To configure an interface to allow access from certain IP addresses, configure an ACL to match the IP addresses, reference the ACL in a traffic policy, and apply the traffic policy to the interface. For example, to allow only the user with IP address 1.1.1.2 to access GE0/0/1, run the following commands:

[HUAWEI] acl number 3030
[HUAWEI-acl-adv-3030] rule permit ip source 1.1.1.2 0
[HUAWEI-acl-adv-3030] quit
[HUAWEI] acl number 3031
[HUAWEI-acl-adv-3031] rule permit ip
[HUAWEI] traffic classifier test1
[HUAWEI-classifier-test1] if-match acl 3030
[HUAWEI] traffic classifier test2
[HUAWEI-classifier-test2] if-match acl 3031
[HUAWEI] traffic behavior test1
[HUAWEI-behavior-test1] permit
[HUAWEI] traffic behavior test2
[HUAWEI-behavior-test2] deny
[HUAWEI] traffic policy test
[HUAWEI-trafficpolicy-test] classifier test1 behavior test1
[HUAWEI-trafficpolicy-test] classifier test2 behavior test2
[HUAWEI] interface gigabitethernet 0/0/1
[HUAWEI-GigabitEthernet0/0/1] traffic-policy test inbound
  • x
  • convention:

ogh Created Jun 16, 2019 09:19:05 Helpful(0) Helpful(0)

Creare an ACL with accepting source IP you want, create a traffic classifier, a traffic behavior and a traffic policy including those items. Then apply on inbound direction on interface
  • x
  • convention:

Reply

Reply
You need to log in to reply to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

Login and enjoy all the member benefits

Login
Fast reply Scroll to top