命令:
firewall enable
acl number 3000
rule 0 deny ip
interface Ethernet0/1
firewall packet-filter 3000 inbound
具体配置:
[H3C]firewall enable /*使能防火墙功能*/
[H3C]acl number 3000 /*创建安全的ACL*/
[H3C-acl-adv-3000]rule deny ip /*拒绝规则*/
[H3C]interface Ethernet0/1 /*进入接口模式*/
[H3C-Ethernet0/1]firewall packet-filter 3000 inbound (outbound) /*应用在接口上的进(出)方向*/