第一步:创建ACL ip access-list extended test-down-in 10 permit icmp host 172.31.13.220 host 172.31.13.1 20 permit icmp host 172.31.13.1 host 172.31.13.220 100 permit ip any any ! ip access-list extended test-down-out 10 permit icmp host 172.31.13.220 host 172.31.13.1 20 permit icmp host 172.31.13.1 host 172.31.13.220 100 permit ip any any ! ip access-list extended test-up-in 10 permit icmp host 172.31.13.220 host 172.31.13.1 20 permit icmp host 172.31.13.1 host 172.31.13.220 100 permit ip any any ! ip access-list extended test-up-out 10 permit icmp host 172.31.13.220 host 172.31.13.1 20 permit icmp host 172.31.13.1 host 172.31.13.220 100 permit ip any any 第二步:开启ACL计数 ! ip access-list counter test-up-in ! ip access-list counter test-up-out ! ip access-list counter test-down-out ! ip access-list counter test-down-in 第三步: 上下联口调用ACL: 上联口: ip access-group test-up-in in ip access-group test-up-out out 下连口: ip access-group test-down-in in ip access-group test-down-out out 清楚计数命令: Ruijie#clear counters access-list