pc--------- 1/0/47 sw(网关)
不涉及
ip source binding 没生效
[sw-probe]debug port mapping slot 1
[Interface] [Unit] [Port] [Combo?] [Active?] [IfIndex] [MID] [Link]
GE1/0/47 1 22 no no 0x2f 1 up
47接口对应chap 1
[sw-probe]debug qacl show acl-resc slot 1 chip 1
---------------Qacl VTcam UsedResc Info---------------
Acl Hw Resource: Group 0, VTcamId 0, Client TTI 0
------------------------------------------------------
Pri 0, usedEntries 1, mode Double
=========================================
acl type usedEntries[1]
=========================================
[341]Zero-Mac-Deny 1
======================================
------------------------------------------------------
Acl Hw Resource: Group 0, VTcamId 1, Client TTI 1
------------------------------------------------------
Acl Hw Resource: Group 0, VTcamId 1, Client IPCL 0
------------------------------------------------------
Pri 2, usedEntries 2, mode Double
=========================================
acl type usedEntries[2]
=========================================
[32 ]PortBind Bind 1
[31 ]PortBind Default 1
======================================
------------------------------------------------------
Pri 9, usedEntries 360, mode Double
=========================================
acl type usedEntries[360]
=========================================
[229]Subnet Vlan 360
======================================
------------------------------------------------------
Acl Hw Resource: Group 0, VTcamId 1, Client IPCL 1
------------------------------------------------------
Acl Hw Resource: Group 0, VTcamId 1, Client IPCL 2
------------------------------------------------------
Pri 11, usedEntries 13, mode Double
=========================================
acl type usedEntries[13]
=========================================
[7 ]RX IPv4 Super High 1
[8 ]RX IPv4 High 4
[10 ]RX IPv4 Middle 8
======================================
------------------------------------------------------
Acl Hw Resource: Group 0, VTcamId 1, Client EPCL
------------------------------------------------------
发现PortBind Bind 和subvlan在同一个查找引擎
debug qacl show slot 1 chip 1 verbose 发现subvlan更优先
Acl-Type PortBind Bind, Stage IPCL 0, SinglePort, Installed, Active
Prio Mjr/Sub 0x202/0x5, RuleFormat INGRESS_EXT_NOT_IPV6, Vtcame/Idx 1/374,
Rule Match --------
Port: 22
Source mac: 5405-DBCF-5080, FFFF-FFFF-FFFF
Source IP: 172.18.8.169, 255.255.255.255
IP Type: Any IPv4 packet
Actions --------
Permit
Acl-Type Subnet Vlan, Stage IPCL 0, SinglePort, Installed, Active
Prio Mjr/Sub 0x209/0x5, RuleFormat INGRESS_EXT_NOT_IPV6, Vtcame/Idx 1/189,
Rule Match --------
Port: 22
Source IP: 172.18.8.0, 255.255.255.0
Number-of-tags: 0x0
Actions --------
Insert vlan 8
[sw-probe]debug qacl show acl-prioinfo slot 1
Type Acl Type Name Reserved Major Sub
32 PortBind Bind FALSE 2 5
229 Subnet Vlan FALSE 9 5
同一个查找引擎中
acl优先级高的策略,先安装到对应引擎ind-id数值小的位置
同一个查找引擎中,根据 Idx_ID,由小到大依次查找
通过Vtcame/ldx 参数进行判断,后面的ID越小越优先
Vtcame相同直接比Idx,Vtcame不同比Mir/Sub,先比Mir,后Sub
major越大越优先,major相同,sub越大越优先
匹配了subvlan就匹配不上portbind了
修改subvlan为普通的access口测试正常
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作