S5700-24TP-SI 同网段限制DHCP地址段访问服务器
网段 192.168.10.0 /24
服务器 192.168.10.254 /24 --- interface GE0/0/24
DHCP pool 192.168.10.128 /25
system-view
acl 3001
rule permit ip source 192.168.1.241 0.0.0.0 destination 192.168.1.254 0.0.0.0 //.允许需要通过的主机
rule permit ip source 192.168.1.253 0.0.0.0 destination 192.168.1.254 0.0.0.0
rule deny ip source 192.168.1.128 0.0.0.127 destination 192.168.1.254 0.0.0.0 // 拒绝dhcp所在网段
quit
traffic classifier c1
if-match acl 3001
quit
traffic behavior b1
permit
quit
traffic policy p1
classifier c1 behavior b1
quit
interface GE0/0/24 //. 一定要配置在出方向,若配置在入方向,有可能导致网络中断
traffic-policy p1 outbound
quit
网段 192.168.10.0 /24
服务器 192.168.10.254 /24 --- interface GE0/0/24
DHCP pool 192.168.10.128 /25
system-view
acl 3001
rule permit ip source 192.168.1.241 0.0.0.0 destination 192.168.1.254 0.0.0.0 //.允许需要通过的主机
rule permit ip source 192.168.1.253 0.0.0.0 destination 192.168.1.254 0.0.0.0
rule deny ip source 192.168.1.128 0.0.0.127 destination 192.168.1.254 0.0.0.0 // 拒绝dhcp所在网段
quit
traffic classifier c1
if-match acl 3001
quit
traffic behavior b1
permit
quit
traffic policy p1
classifier c1 behavior b1
quit
interface GE0/0/24 //. 一定要配置在出方向,若配置在入方向,有可能导致网络中断
traffic-policy p1 outbound
quit