1. You can organize computers to log on to the Internet by creating ACL access control lists on H3C exit routers. In this case, as long as the ACL rule is triggered, the corresponding operation can be prohibited. For example, if you want to set the host192.168.1.10 to prohibit logging in to the Internet, write an acl.
Acl number 3000
The rule denies any tcp source192.168.1.10 target.
Then issue this ACL. Pay attention to the exit when sending: if your exit is E 1/0, it should be:
int e 1/0
Firewall Packet Filter 3000 Outbound
Attention, please open the firewall.
However, this configuration scheme is that if the user changes the IP address, the ACL cannot be triggered, so it is still not easy to use.
At this time, I will call you the ultimate weapon, and configure a layer 2 ACL, which is triggered by the MAC address. In this case, unless he changes the network card. Ah, ha ha ha. . . . . Don't ask me again. '