无
现场使用如下源地址ping目的地址能通,在设备上1/0/0/48口出方向做流统,发现匹配不到报文。
acl number 3200
rule 5 permit icmp source 21.10.174.29 0 destination 21.9.196.133 0
设备上到21.9.196.133的下一跳为防火墙地址,走默认路由,出口是1/0/0/48
21.7.157.221 001c-54ff-0807 1001 GE1/1/0/48 17 D
Destination/Mask Nexthop Flag OutInterface/Token Label
0.0.0.0/0 21.7.157.221 USGR Vlan1001 Null
interface Ten-GigabitEthernet1/0/0/9
port link-mode route
description To_FT-3HL-2F-SC-S-MP4320-VST
speed 1000
ip address 21.7.156.153 255.255.255.252
qos apply policy liutong1 inbound
interface GigabitEthernet1/1/0/48
port link-mode bridge
description To-F4-SC-F-HS6110-1
port access vlan 1001
packet-filter 3100 inbound
packet-filter 3100 outbound
mirroring-group 1 mirroring-port both
qos apply policy liutong1 outbound
现场两个本地镜像组,都是both方向,单芯片6个资源,镜像资源是够的
mirroring-group 1 local
mirroring-group 2 local
但是设备出方向资源有限,不同业务会下在同一个group、bank,而该接口下同时下发了包过滤,由于包过滤的优先级高于mqc,所以一旦包过滤命中了,mqc就无法命中了。
interface GigabitEthernet1/1/0/48
port link-mode bridge
description To-F4-SC-F-HS6110-1
port access vlan 1001
packet-filter 3100 inbound
packet-filter 3100 outbound
mirroring-group 1 mirroring-port both
qos apply policy liutong1 outbound
#
====debug qacl show acl-resc chassis 1 slot 1 chip 1====
---------------Qacl Group UsedResc Info---------------
Acl Hw Resource: EFP
------------------------------------------------------
L2 PROGRAM : Line 0x8000-0 ProId 0
------------------------------------------------------
Pri 1, Group 4,usedEntries 387,mode Double,
ResDb 4, KeySize 160Bit, Bank 2/First-pass KeyA
=========================================
acl type usedEntries[387]
=========================================
[2 ]MQC Port 1
[95 ]PktFilter IP on PORT 360
[96 ]PktFilter IP on VRF 26
======================================
========
Acl-Type PktFilter IP on PORT, Stage EFP, SinglePort, Installed, vsiifdex=0x0, Active
L2 PROGRAM : Prio Mjr/Sub 6/634, Group 4 [4], enRtnHealth 1, Entry 143,
ACL GroupNo : 3100, RuleID : 1000 V4v6 1
Rule Match --------
Out Port: 24
Forwarding Type: ipv4_uc
Actions --------
Permit
L2 PROGRAM : Bank 4 Location 358 HIT(read-clear): YES
========
建议现场按照情况优化配置
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作