我在acl number 3052增加如下条目时,会产生增加新的permit条目后(单独增加一条测试也不行),原有的permit条目失效
rule 34 permit ip source 10.99.72.0 0.0.7.255 destination 192.168.11.110 0
rule 51 permit ip source 10.99.74.0 0.0.0.255 destination 192.168.11.214 0
测试设备IP为:192.168.11.111;增加以上任意一条规则后均会出现目标地址无法访问
设备ACL部分配置
qos vlan-policy vlan1052 vlan 1052 inbound
qos vlan-policy vlan1052 vlan 1053 inbound
qos vlan-policy vlan1052 vlan 1054 inbound
qos vlan-policy vlan1052 vlan 1055 inbound
qos vlan-policy vlan1052 vlan 1072 inbound
qos vlan-policy vlan1052 vlan 1073 inbound
qos vlan-policy vlan1052 vlan 1074 inbound
qos vlan-policy vlan1052 vlan 1075 inbound
qos vlan-policy vlan1052 vlan 1076 inbound
qos vlan-policy vlan1052 vlan 1077 inbound
qos vlan-policy vlan1052 vlan 1078 inbound
qos vlan-policy vlan1052 vlan 1079 inbound
#
acl number 3052
rule 0 permit ip source 10.99.52.0 0.0.3.255 destination 192.168.11.225 0
rule 10 permit ip source 10.99.52.0 0.0.3.255 destination 192.168.11.241 0
rule 20 permit ip source 10.99.52.0 0.0.3.255 destination 192.168.11.99 0
rule 30 permit ip source 10.99.72.0 0.0.7.255 destination 192.168.11.225 0
rule 32 permit ip source 10.99.52.0 0.0.3.255 destination 192.168.11.110 0
rule 33 permit ip source 10.99.111.0 0.0.0.255 destination 192.168.11.110 0
rule 40 permit ip source 10.99.72.0 0.0.7.255 destination 192.168.11.241 0
rule 50 permit ip source 10.99.72.0 0.0.7.255 destination 192.168.11.99 0
rule 60 permit ip source 10.99.0.0 0.0.255.255 destination 192.168.11.222 0
rule 61 permit ip source 10.99.0.0 0.0.255.255 destination 192.168.11.241 0
rule 70 permit ip source 10.99.0.0 0.0.255.255 destination 192.168.11.111 0
rule 100 permit ip source 10.99.74.0 0.0.0.255 destination 192.168.11.226 0
rule 101 permit ip source 10.99.74.0 0.0.0.255 destination 192.168.11.193 0
rule 102 permit ip source 10.99.74.0 0.0.0.255 destination 192.168.11.237 0
rule 103 permit ip source 10.99.74.0 0.0.0.255 destination 192.168.11.211 0
rule 104 permit ip source 10.99.74.0 0.0.0.255 destination 192.168.11.228 0
rule 105 permit ip source 10.99.74.0 0.0.0.255 destination 192.168.11.155 0
rule 200 permit ip source 10.99.0.0 0.0.255.255 destination 192.168.11.18 0
rule 201 permit ip source 10.99.0.0 0.0.255.255 destination 192.168.11.15 0
#
acl number 3053
rule 0 deny ip source 10.99.52.0 0.0.3.255 destination 192.168.0.0 0.0.255.255
rule 5 deny ip source 10.99.52.0 0.0.3.255 destination 172.40.0.0 0.0.255.255
rule 10 deny ip source 10.99.72.0 0.0.7.255 destination 192.168.0.0 0.0.255.255
rule 11 deny ip source 10.99.104.0 0.0.7.255 destination 192.168.0.0 0.0.255.255
rule 12 deny ip source 10.99.104.0 0.0.7.255 destination 172.40.0.0 0.0.255.255
rule 15 deny ip source 10.99.72.0 0.0.7.255 destination 172.40.0.0 0.0.255.255
rule 20 deny ip source 172.40.0.0 0.0.255.255 destination 10.99.52.0 0.0.3.255
rule 21 deny ip source 172.40.0.0 0.0.255.255 destination 10.99.72.0 0.0.7.255
rule 22 deny ip source 172.40.0.0 0.0.255.255 destination 10.99.104.0 0.0.7.255
rule 23 deny ip source 192.168.0.0 0.0.255.255 destination 10.99.104.0 0.0.7.255
rule 25 deny ip source 192.168.0.0 0.0.255.255 destination 10.99.72.0 0.0.7.255
rule 26 deny ip source 192.168.0.0 0.0.255.255 destination 10.99.52.0 0.0.3.255
#
S7503E通过trunk口下联若干交换机,问题网段部分全部为二层接入。
下联交换机没有ACL等安全类配置,仅用作接入层使用。
(0)
最佳答案
这个acl配置是用来干什么的?
(0)
ACL用来限制非指定IP地址与该网段间通信
ACL用来限制非指定IP地址与该网段间通信
针对于QOS来说,ACL只是匹配工具,无论ACL中的动作是permit还是deny ,只要匹配上了就算抓取到了流量,最终流量禁止还是放行需要看QOS的behavior动作是什么,behavior是permit那就是放行,deny或filter就是禁止。
(0)
traffic classifier 3052 operator and if-match acl 3052 # traffic classifier 3053 operator and if-match acl 3053 # traffic behavior 3052 filter permit # traffic behavior 3053 filter deny # qos policy vlan1052 classifier 3052 behavior 3052 classifier 3053 behavior 3053
traffic classifier 3052 operator and if-match acl 3052 # traffic classifier 3053 operator and if-match acl 3053 # traffic behavior 3052 filter permit # traffic behavior 3053 filter deny # qos policy vlan1052 classifier 3052 behavior 3052 classifier 3053 behavior 3053
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
跟上边一样,看掩码位数。24位