码迷,mamicode.com
首页 > 其他好文 > 详细

ASA防火墙限速

时间:2017-08-03 20:08:13      阅读:134      评论:0      收藏:0      [点我收藏+]

标签:限速

目的:对192.168.57.0段用户限速30M(即下载速度30/8,上传同),192.168.57.1和192.168.57.127除外


access-list rate-limiting extended deny ip any  192.168.57.1 255.255.255.255

access-list rate-limiting extended deny ip 192.168.57.1 255.255.255.255 any

access-list rate-limiting extended deny ip any  192.168.57.127 255.255.255.255

access-list rate-limiting extended deny ip 192.168.57.127 255.255.255.255 any

access-list rate-limiting extended permit ip 192.168.57.0 255.255.255.0 any 

access-list rate-limiting extended permit ip any  192.168.57.0 255.255.255.0


class-map rate-limiting

match access-list rate-limiting

policy-map xs10m

class rate-limiting

police input 30000000

police output 30000000

!


service-policy xs10m interface inside  //应用在inside口。在outside应用时不生效,因nat的应用,使得内外网IP不是一一对应,不法正常限制。


ASA防火墙限速

标签:限速

原文地址:http://sunrc.blog.51cto.com/747991/1953293

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!