在外网出口禁用这两个地址即可ACL 3001rule 1 deny ip source 10.10.130.55 0rule 2 deny ip source 10.10.150.55 0rule 3 permit ip anytraffic classifier JZFW operator and //随便你用其他也行if-match acl 3001tra behavior JZFW filter denyqos pollicy JZFWclassifier JZFW behavior JZFWint g1/0/1 //S7506的公网出口qos apply policy JZFW inbound