Configuring ACL Control 177

Figure 48 Control TELNET User With ACL

Internet

Switch

Use the following commands to control TELNET users with ACL.

1Define the basic ACLs.

[SW7750]acl number 2000 match-order config [SW7750-acl-basic-2000]rule 1 permit source 10.110.100.52 0

[SW7750-acl-basic-2000]rule 2 permit source 10.110.100.46 0

[SW7750-acl-basic-2000]quit

2Call an ACL.

[SW7750]user-interface vty 0 4

[SW7750-user-interface-vty0-4]acl 2000 inbound

Configuring ACL Control The Switch 7750 supports remote management with the network management for SNMP Users software. The network management users can access the switch with SNMP.

Controlling such users with an ACL can filter the illegal network management users, and prevent them from accessing the local switch.

The steps to control SNMP users with ACL are described in the following sections:

Defining an ACL

Importing an ACL to Control SNMP Users

Defining an ACL

To implement the ACL control function, you can only call the numbered basic ACL, ranging from 2000 to 2999. Use the configuration commands introduced in “Configuring ACL Control for TELNET Users”.

Importing an ACL to Control SNMP Users

To control network management users with an ACL, import the defined ACL when configuring the SNMP community name, username, and group name.

Perform the following configuration in system view.

Table 188 Define a Numbered Basic ACL

Operation

Command

 

 

Import an ACL when configuring the SNMP

snmp-agent community { read write }

community name

community-name [ [ mib-viewview-name ] [

 

acl acl-number ] ]*

Page 177
Image 177
3Com 10014298 manual Call an ACL, Importing an ACL to Control Snmp Users, Define a Numbered Basic ACL