在S5560上创建VLAN 10和VLAN 20, 并设置ACL限制VLAN20内的主机访问VLAN10的主机:
<H3C>system-view
[H3C]vlan 10
[H3C-vlan10]port GigabitEthernet 1/0/1
H3C-vlan10]vlan 20
[H3C-vlan20]port GigabitEthernet 1/0/2
H3C]interface vlan 10
[H3C-Vlan-interface10]ip address 192.168.10.254 24
[H3C-Vlan-interface10]quit
[H3C]interface vlan 20
[H3C-Vlan-interface20]ip address 192.168.20.254 24
[H3C-Vlan-interface20] quit
[H3C] time-range H3CTEST1 8:00 to 18:00 working-day
[H3C] interface G 1/0/1
[H3C-GigabitEthernet1/0/1] acl number 2000
[H3C-acl-basic-2000] rule 1 deny source 192.168.20.2 0 time-range H3CTEST1
[H3C-acl-basic-2000] interface G 1/0/1
[H3C-GigabitEthernet1/0/1] packet-filter inbound ip-group 2000
此时提示: packet-filter ^inbound ip-group 2000
% Wrong parameter found at '^' position
[H3C]vlan 10
[H3C-vlan10]port GigabitEthernet 1/0/1
H3C-vlan10]vlan 20
[H3C-vlan20]port GigabitEthernet 1/0/2
H3C]interface vlan 10
[H3C-Vlan-interface10]ip address 192.168.10.254 24
[H3C-Vlan-interface10]quit
[H3C]interface vlan 20
[H3C-Vlan-interface20]ip address 192.168.20.254 24
[H3C-Vlan-interface20] quit
[H3C] time-range H3CTEST1 8:00 to 18:00 working-day
[H3C] interface G 1/0/1
[H3C-GigabitEthernet1/0/1] acl number 2000
[H3C-acl-basic-2000] rule 1 deny source 192.168.20.2 0 time-range H3CTEST1
[H3C-acl-basic-2000] interface G 1/0/1
[H3C-GigabitEthernet1/0/1] packet-filter inbound ip-group 2000
此时提示: packet-filter ^inbound ip-group 2000
% Wrong parameter found at '^' position
(0)
最佳答案
[H3C-GigabitEthernet1/0/1] packet-filter inbound ip-group 2000
此时提示: packet-filter ^inbound ip-group 2000
% Wrong parameter found at '^' position
报错的三角指在哪里? 试试packet-filter inbound acl 2000
(0)
用packet-filter 2000 inbound 问题解决了
packet-filter 2000 inbound
报错三角指在inbound的i字符下面,用packet-filter inbound acl 2000也出现同样的提示
用packet-filter 2000 inbound 问题解决了
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明