ACL配置TCP单向通讯

ACL实现_TCP单向通讯

image-20250609163520376

image-20250609163326683

1.VMNET1网络设置

都不需要设置任何IP

image-20250609163505697

WIN7

image-20250609163603388

虚拟机选择VMNET1

image-20250609150340259

虚拟机选择仅主机

image-20250609150425148

2.VMNET8网络设置

WIN11

image-20250609163734643

虚拟机选择VMNET8

image-20250609163833194

3.ENSP设置

cloud4

image-20250609164131692

cloud2

image-20250609164157246

AR1

<Huawei>sys
[Huawei]interface GigabitEthernet 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.2.1 24
[Huawei-GigabitEthernet0/0/0]quit

[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.3.10 24

4.测试通讯情况

image-20250609164257518

WIN11开启远程桌面

image-20250609164747585

WIN7进行登录WIN11

image-20250609164814879

image-20250609164824464

WIN7开启远程桌面

image-20250609165017862

WIN11登录WIN7

image-20250609165043303

5.设置单向TCP

AR1

[Huawei-acl-adv-3000]rule 5 permit tcp destination 192.168.2.0 0.0.0.255 source 
192.168.3.0 0.0.0.255 tcp-flag ack

[Huawei-acl-adv-3000] rule 10 deny tcp source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255 tcp-flag syn 

[Huawei-acl-adv-3000]quit

[Huawei-GigabitEthernet0/0/0]traffic-filter inbound acl 3000

6.测试

WIN7登录WIN11可以正常通讯

image-20250609170446606

WIN11登录WIN7不能正常通讯

image-20250609175918855

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注