如图网关在FW插卡上面
在FW插卡上写了ACL
然后在VLAN IF里面调用
然后做完这些理论上806是无法和172.31.0.0段通的
补充dhcp网关信息,但是分配出去的是核心上做dhcp的,但是网关在核心上的FW插卡上
(0)
方向改一下再试试
(0)
改变不了方向
acl rule的源目地址改一下方向
acl advanced 3806 description ==Deny-NW-to-Wlan-in-valn806== rule 5 deny ip source 172.31.0.0 0.0.0.255 destination 172.31.232.0 0.0.3.255 Vlan806 UP UP 172.31.232.62 Vlan2000 UP UP 172.31.250.80 Brief information on interfaces in bridge mode: Link: ADM - administratively down; Stby - standby Speed: (a) - auto Duplex: (a)/A - auto; H - half; F - full Type: A - access; T - trunk; H - hybrid Interface Link Speed Duplex Type PVID Description GE1/0/1 UP 1G(a) F(a) A 804 GE1/0/2 UP 1G(a) F(a) A 804 GE1/0/3 UP 1G(a) F(a) A 804 GE1/0/4 UP 1G(a) F(a) A 804 GE1/0/5 UP 1G(a) F(a) A 804 GE1/0/6 UP 1G(a) F(a) A 804 GE1/0/7 UP 1G(a) F(a) A 804 <ZYB2_9F_W_S5130_24POE-1> <ZYB2_9F_W_S5130_24POE-1>ping -a 172.31.232.62 172.31.0.1 Ping 172.31.0.1 (172.31.0.1) from 172.31.232.62: 56 data bytes, press CTRL_C to break 56 bytes from 172.31.0.1: icmp_seq=0 ttl=255 time=8.333 ms 56 bytes from 172.31.0.1: icmp_seq=1 ttl=255 time=1.198 ms 56 bytes from 172.31.0.1: icmp_seq=2 ttl=255 time=4.282 ms 56 bytes from 172.31.0.1: icmp_seq=3 ttl=255 time=1.277 ms 56 bytes from 172.31.0.1: icmp_seq=4 ttl=255 time=5.767 ms
您好,请知:
从反馈的信息来看,不排除可能ACL有拦截,可尝试把ACL去掉后是否能访问,如果可以,那就是ACL的问题。
可尝试调整ACL的方向或调用到其他接口比如上行接口看下是否能生效,但是ACL的调整可能会影响业务,建议窗口期操作。
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
acl advanced 3806 description ==Deny-NW-to-Wlan-in-valn806== rule 5 deny ip source 172.31.0.0 0.0.0.255 destination 172.31.232.0 0.0.3.255 Vlan806 UP UP 172.31.232.62 Vlan2000 UP UP 172.31.250.80 Brief information on interfaces in bridge mode: Link: ADM - administratively down; Stby - standby Speed: (a) - auto Duplex: (a)/A - auto; H - half; F - full Type: A - access; T - trunk; H - hybrid Interface Link Speed Duplex Type PVID Description GE1/0/1 UP 1G(a) F(a) A 804 GE1/0/2 UP 1G(a) F(a) A 804 GE1/0/3 UP 1G(a) F(a) A 804 GE1/0/4 UP 1G(a) F(a) A 804 GE1/0/5 UP 1G(a) F(a) A 804 GE1/0/6 UP 1G(a) F(a) A 804 GE1/0/7 UP 1G(a) F(a) A 804 <ZYB2_9F_W_S5130_24POE-1> <ZYB2_9F_W_S5130_24POE-1>ping -a 172.31.232.62 172.31.0.1 Ping 172.31.0.1 (172.31.0.1) from 172.31.232.62: 56 data bytes, press CTRL_C to break 56 bytes from 172.31.0.1: icmp_seq=0 ttl=255 time=8.333 ms 56 bytes from 172.31.0.1: icmp_seq=1 ttl=255 time=1.198 ms 56 bytes from 172.31.0.1: icmp_seq=2 ttl=255 time=4.282 ms 56 bytes from 172.31.0.1: icmp_seq=3 ttl=255 time=1.277 ms 56 bytes from 172.31.0.1: icmp_seq=4 ttl=255 time=5.767 ms