Current location - Health Preservation Learning Network - Slimming men and women - How does H3C server disable the external network without restricting the internal network?
How does H3C server disable the external network without restricting the internal network?
Your question can be answered from several aspects.

1. You can organize computers to log on to the Internet by creating ACL access control lists on H3C exit routers. In this case, as long as the ACL rule is triggered, the corresponding operation can be prohibited. For example, if you want to set the host192.168.1.10 to prohibit logging in to the Internet, write an acl.

Acl number 3000

The rule denies any tcp source192.168.1.10 target.

Then issue this ACL. Pay attention to the exit when sending: if your exit is E 1/0, it should be:

int e 1/0

Firewall Packet Filter 3000 Outbound

Attention, please open the firewall.

However, this configuration scheme is that if the user changes the IP address, the ACL cannot be triggered, so it is still not easy to use.

At this time, I will call you the ultimate weapon, and configure a layer 2 ACL, which is triggered by the MAC address. In this case, unless he changes the network card. Ah, ha ha ha. . . . . Don't ask me again. '