我的设备是H3C S5500-52C-EI
之前acl 是这样的,一直是没问题的,后来加了几条就报错 Reason: Not supported by hardware. acl总条数有限制吗。我的有50多条了,
acl number 3001
rule 0 permit tcp destination 192.168.3.200 0 destination-port eq 22
rule 5 permit tcp destination 192.168.7.20 0 destination-port eq 22
rule 10 permit tcp destination 192.168.4.243 0 destination-port eq 22
rule 15 permit tcp destination 192.168.4.242 0 destination-port eq 22
rule 20 permit tcp destination 192.168.7.112 0 destination-port eq 22
rule 25 permit tcp destination 192.168.7.113 0 destination-port eq 22
rule 30 permit tcp destination 192.168.8.134 0 destination-port eq 22
rule 35 permit tcp destination 192.168.9.166 0 destination-port eq 22
acl number 3002
rule 0 deny tcp destination 192.168.9.0 0.0.0.255 destination-port eq 22
rule 5 deny tcp destination 192.168.8.0 0.0.0.255 destination-port eq 22
rule 10 deny tcp destination 192.168.7.0 0.0.0.255 destination-port eq 22
rule 15 deny tcp destination 192.168.10.0 0.0.0.255 destination-port eq 22
rule 20 deny tcp destination 192.168.4.0 0.0.0.255 destination
修改成如下后就不行了,
acl number 3001
rule 0 permit tcp destination 192.168.3.200 0 destination-port eq 22
rule 5 permit tcp destination 192.168.7.20 0 destination-port eq 22
rule 10 permit tcp destination 192.168.4.243 0 destination-port eq 22
rule 15 permit tcp destination 192.168.4.242 0 destination-port eq 22
rule 20 permit tcp destination 192.168.7.112 0 destination-port eq 22
rule 25 permit tcp destination 192.168.7.113 0 destination-port eq 22
rule 30 permit tcp destination 192.168.8.134 0 destination-port eq 22
rule 35 permit tcp destination 192.168.9.166 0 destination-port eq 22
rule 40 permit tcp destination 192.168.8.0 0.0.0.255 destination-port eq 443
rule 45 permit tcp destination 192.168.8.0 0.0.0.255 destination-port eq 80
rule 50 permit tcp destination 192.168.9.0 0.0.0.255 destination-port eq 443
rule 55 permit tcp destination 192.168.9.0 0.0.0.255 destination-port eq 80
rule 60 permit tcp destination 192.168.10.0 0.0.0.255 destination-port eq 443
rule 65 permit tcp destination 192.168.10.0 0.0.0.255 destination-port eq 80
rule 70 permit tcp destination 192.168.4.0 0.0.0.255 destination-port eq 443
rule 75 permit tcp destination 192.168.4.0 0.0.0.255 destination-port eq 80
rule 80 permit tcp destination 192.168.7.0 0.0.0.255 destination-port eq 443
rule 85 permit tcp destination 192.168.7.0 0.0.0.255 destination-port eq 80
acl number 3002
rule 25 deny tcp destination 192.168.4.0 0.0.0.255 destination-port lt 8000
rule 30 deny tcp destination 192.168.7.0 0.0.0.255 destination-port lt 8000
rule 35 deny tcp destination 192.168.8.0 0.0.0.255 destination-port lt 8000
rule 40 deny tcp destination 192.168.9.0 0.0.0.255 destination-port lt 8000
rule 45 deny tcp destination 192.168.10.0 0.0.0.255 destination-port lt 8000
三层核心交换,控制不能访问vlan 4,7,8,9 的800以下的端口,只允许访问80和443端口和几条机器的22端口,如何修改。
(0)
最佳答案
那如何改下,rang 1-8000 这样也可以吗?
(0)
可以试试
可以试试
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明