原理:
在接入交換機(jī)的每個端口出方向部署ACL
該方案的缺點:
很多舊的交換機(jī)不支持每端口ACL(華為S5700-LI支持)
交換機(jī)配置舉例(S5700 V200R007C00SPC500):
acl number 3019
description Deny_Virus
rule 100 deny tcp destination-port eq 135
rule 105 deny tcp destination-port eq 139
rule 110 deny tcp destination-port eq 445
rule 115 deny udp destination-port eq 135
rule 117 deny udp destination-port eq netbios-ns
rule 118 deny udp destination-port eq netbios-dgm
rule 120 deny udp destination-port eq netbios-ssn
rule 125 deny udp destination-port eq 445
interface GigabitEthernet0/0/7
traffic-filter outbound acl 3019