access-list 189 deny   tcp any host 202.102.81.231
access-list 189 deny   tcp any host 202.102.81.232
access-list 189 deny   tcp any host 61.164.47.226
access-list 189 deny   tcp any host 61.164.47.166
access-list 189 deny   tcp any host 203.161.230.171
access-list 189 deny   tcp any host 118.67.120.125
access-list 189 deny   tcp any host 116.252.179.16
access-list 189 deny   tcp any host 58.215.110.126
access-list 189 deny   tcp any host 220.170.79.25
access-list 189 deny   tcp any host 125.90.88.148
access-list 189 deny   ip any 58.254.39.0 0.0.0.255
access-list 189 deny   ip any 58.39.61.0 0.0.0.255
access-list 189 deny   ip any 60.19.64.0 0.0.0.255
access-list 189 deny   ip any 60.28.178.0 0.0.0.255
access-list 189 deny   ip any 121.17.126.0 0.0.0.255
access-list 189 deny   ip any 125.46.42.0 0.0.0.255
access-list 189 deny   ip any 210.21.206.0 0.0.0.255
access-list 189 deny   ip any 210.21.204.0 0.0.0.255
access-list 189 deny   ip any 210.72.224.0 0.0.0.255
access-list 189 deny   ip any 221.5.250.0 0.0.0.255
access-list 189 deny   ip any 221.12.90.0 0.0.0.255
access-list 189 deny   ip any 221.196.146.0 0.0.0.255
access-list 189 deny   ip any host 119.147.41.48
access-list 189 deny   ip any host 125.90.93.136
access-list 189 deny   ip any host 119.147.41.13
access-list 189 deny   ip any 119.147.41.0 0.0.0.255

这里已经封掉了基本流行的视频网站,外加迅雷

你要封的自己PING就可以了~

记得最后一定要加
access-list 189 permit ip any any

道理就不说了,太长了~

然后
interface Vlan30
  ip access-group 189 in

直接做在VLAN或者INTERFACE上,都可以