内网要求控制特定终端的上网时间,配置了ACL,物理接口和vlan接口都试了,不生效,求解答?
(0)
配置贴上来
(0)
Advanced IPv4 ACL 3000, 2 rules, ACL"s step is 5, start ID is 0 rule 0 permit tcp source 10.50.51.232 0 destination-port eq www time-range sw (Inactive) rule 5 deny tcp source 10.50.51.232 0 destination-port eq www time-range sw (Inactive) interface Vlan-interface1315 packet-filter 3000 outbound [ASYHXX_HX]dis time-range all Current time is 10:00:55 12/10/2021 Friday Time-range: sw (Inactive) 09:00 to 09:10 daily
请参考一下官方的配置指导:
https://www.h3c.com/cn/d_202111/1489435_30005_0.htm#_Toc86427599
(0)
Advanced IPv4 ACL 3000, 2 rules,
ACL"s step is 5, start ID is 0
rule 0 permit tcp source 10.50.51.232 0 destination-port eq www time-range sw (Inactive)
rule 5 deny tcp source 10.50.51.232 0 destination-port eq www time-range sw (Inactive)
interface Vlan-interface1315
packet-filter 3000 outbound
[ASYHXX_HX]dis time-range all Current time is 10:00:55 12/10/2021 Friday Time-range: sw (Inactive) 09:00 to 09:10 daily
(0)
ACL的两条规则是矛盾的,在09:00 to 09:10 daily这个时间段内,到底是permit还是deny?
ACL的两条规则是矛盾的,在09:00 to 09:10 daily这个时间段内,到底是permit还是deny?
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
Advanced IPv4 ACL 3000, 2 rules, ACL"s step is 5, start ID is 0 rule 0 permit tcp source 10.50.51.232 0 destination-port eq www time-range sw (Inactive) rule 5 deny tcp source 10.50.51.232 0 destination-port eq www time-range sw (Inactive) interface Vlan-interface1315 packet-filter 3000 outbound [ASYHXX_HX]dis time-range all Current time is 10:00:55 12/10/2021 Friday Time-range: sw (Inactive) 09:00 to 09:10 daily