ASA防火墙限速

目的:对192.168.57.0段用户限速30M(即下载速度30/8,上传同),192.168.57.1和192.168.57.127除外ide


access-list rate-limiting extended deny ip any  192.168.57.1 255.255.255.255ip

access-list rate-limiting extended deny ip 192.168.57.1 255.255.255.255 anyinput

access-list rate-limiting extended deny ip any  192.168.57.127 255.255.255.255it

access-list rate-limiting extended deny ip 192.168.57.127 255.255.255.255 anyclass

access-list rate-limiting extended permit ip 192.168.57.0 255.255.255.0 any service

access-list rate-limiting extended permit ip any  192.168.57.0 255.255.255.0map


class-map rate-limiting下载

match access-list rate-limitingim

policy-map xs10mdi

class rate-limiting

police input 30000000

police output 30000000

!


service-policy xs10m interface inside  //应用在inside口。在outside应用时不生效,因nat的应用,使得内外网IP不是一一对应,不法正常限制。

相关文章
相关标签/搜索