zApplying the ACL to control Web users

Prerequisites

The controlling policy against Web users is determined, including the source IP addresses to be controlled and the controlling actions (permitting or denying).

Controlling Web Users by Source IP Addresses

Controlling Web users by source IP addresses is achieved by applying basic ACLs, which are numbered from 2000 to 2999.

Follow these steps to control Web users by source IP addresses:

To do…

Use the command…

Remarks

Enter system view

system-view

 

 

 

Create a basic ACL or

acl number acl-number

As for the acl number command,

the config keyword is specified by

enter basic ACL view

[ match-order { config auto } ]

default.

 

 

 

 

 

Define rules for the

rule [ rule-id] { deny permit }

Required

ACL

[ rule-string ]

 

 

 

 

Quit to system view

quit

 

 

 

Apply the ACL to

 

Optional

ip http acl acl-number

By default, no ACL is applied for

control Web users

 

Web users.

 

 

 

 

 

Disconnecting a Web User by Force

The administrator can disconnect a Web user by force using the related commands.

Follow these steps to disconnect a Web user by force:

To do…

Use the command…

Remarks

Disconnect a Web user

free web-users { all user-id

Required

by force

user-id user-nameuser-name }

Execute this command in user view.

 

 

 

Configuration Example

Network requirements

As shown in Figure 7-3, only the Web users sourced from the IP address of 10.110.100.52 are permitted to access the switching engine.

Figure 7-3Network diagram for controlling Web users using ACLs

7-6

Page 53
Image 53
3Com WX3000 Controlling Web Users by Source IP Addresses, Disconnecting a Web User by Force, Ip http acl acl-number