华三交换机ACL单向TCP互通组网

一 组网说明

用户需求:

客户网络建设初期规划比较乱,并且经过多位运维工程师,不同区域之间服务器又没有防火墙,如果不同区域服务器之间互相通信会存在数据丢失的风险,所以需要不同区域服务器之间经过交换机的时候只能实现类似防火墙的单向访问。

如上图要实现Server1不可以主动telnet Server2,但是Server2可以主动telnet Server1,这样以保障Server2的数据不会丢失。(Server1和Server2都开启telnet服务)

二 设备配置

sysname SW

acl advanced 3000

description deny-tcp

rule 0 deny tcp source 192.168.1.1 0 destination 192.168.1.2 0 destination-port eq telnet syn 1

rule 5 permit ip

//限制Server1访问Server2的tcp syn包,1代表syn包置位,这里通过telnet tcp协议模拟

interface GigabitEthernet1/0/1

port link-mode bridge

description To-Server1 //在Server1的入方向接口是应用

combo enable fiber

packet-filter 3000 inbound

三 访问验证

3.1 SW配置ACL单向TCP访问前测试

1.Server1可以telnet Server2

<Server1>telnet 192.168.1.2

Trying 192.168.1.2 ...

Press CTRL+K to abort

Connected to 192.168.1.2 ...

******************************************************************************

* Copyright (c) 2004-2021 New H3C Technologies Co., Ltd. All rights reserved.*

* Without the owner's prior written consent, *

* no decompiling or reverse-engineering shall be allowed. *

******************************************************************************

<Server1>

2.Server2可以telnet Server1

<Server2>telnet 192.168.1.1

Trying 192.168.1.1 ...

Press CTRL+K to abort

Connected to 192.168.1.1 ...

******************************************************************************

* Copyright (c) 2004-2021 New H3C Technologies Co., Ltd. All rights reserved.*

* Without the owner's prior written consent, *

* no decompiling or reverse-engineering shall be allowed. *

******************************************************************************

<Server2>

3.2 SW配置ACL单向TCP访问后测试

1.Server1不能telnet Server2

<Server1>telnet 192.168.1.2

Trying 192.168.1.2 ...

Press CTRL+K to abort

Connected to 192.168.1.2 ...

2.但是Server2可以telnet Server1

<Server2>telnet 192.168.1.1

Trying 192.168.1.1 ...

Press CTRL+K to abort

Connected to 192.168.1.1 ...

******************************************************************************

* Copyright (c) 2004-2021 New H3C Technologies Co., Ltd. All rights reserved.*

* Without the owner's prior written consent, *

* no decompiling or reverse-engineering shall be allowed. *

******************************************************************************

<Server1>