问题:目前允许ping通211.140.133.46的同时并开放其它相关端口,其余端口全部封堵。
目前是classifier PermitPortOutbound-HaiKang所关联acl3107中的icmp相关配置未生效,应用策略后,直接无法ping通211.140.133.46,取消策略后,立马可正常ping通211.140.133.46.
型号:S12508F-AF 版本:7.1.045, Release 1138P01 连接方式:测试PC---S12508(Ten1/2/0/15)---211.140.133.46
(0)
最佳答案
qos 的acl里的permit和deny都是匹配流量,因此会在动作中deny。
(0)
acl number 3102 description match-all rule 0 permit ip acl number 3107 description PermitPortOutbound-HaiKang rule 0 permit tcp destination 211.140.133.46 0 destination-port eq www rule 5 permit tcp destination 211.140.133.46 0 destination-port eq 82 rule 10 permit tcp destination 211.140.133.46 0 destination-port eq 83 rule 15 permit tcp destination 211.140.133.46 0 destination-port eq 161 rule 20 permit tcp destination 211.140.133.46 0 destination-port eq 443 rule 25 permit tcp destination 211.140.133.46 0 destination-port eq 554 rule 30 permit tcp destination 211.140.133.46 0 destination-port eq 556 rule 35 permit tcp destination 211.140.133.46 0 destination-port eq 557 rule 40 permit tcp destination 211.140.133.46 0 destination-port eq 655 rule 45 permit tcp destination 211.140.133.46 0 destination-port eq 5300 rule 50 permit tcp destination 211.140.133.46 0 destination-port eq 5432 rule 55 permit tcp destination 211.140.133.46 0 destination-port eq 6000 rule 60 permit tcp destination 211.140.133.46 0 destination-port eq 6021 rule 65 permit tcp destination 211.140.133.46 0 destination-port eq 6300 rule 70 permit tcp destination 211.140.133.46 0 destination-port eq 6302 rule 75 permit tcp destination 211.140.133.46 0 destination-port eq 6304 rule 80 permit tcp destination 211.140.133.46 0 destination-port eq 6308 rule 85 permit tcp destination 211.140.133.46 0 destination-port eq 6309 rule 90 permit tcp destination 211.140.133.46 0 destination-port eq 6379 rule 95 permit tcp destination 211.140.133.46 0 destination-port eq 6506 rule 100 permit tcp destination 211.140.133.46 0 destination-port eq 6530 rule 105 permit tcp destination 211.140.133.46 0 destination-port eq 6550 rule 110 permit tcp destination 211.140.133.46 0 destination-port eq 6600 rule 115 permit tcp destination 211.140.133.46 0 destination-port eq 6628 rule 120 permit tcp destination 211.140.133.46 0 destination-port eq 6666 rule 125 permit tcp destination 211.140.133.46 0 destination-port eq 6667 rule 130 permit tcp destination 211.140.133.46 0 destination-port eq 6700 rule 135 permit tcp destination 211.140.133.46 0 destination-port eq 6710 rule 140 permit tcp destination 211.140.133.46 0 destination-port eq 6711 rule 145 permit tcp destination 211.140.133.46 0 destination-port eq 6713 rule 150 permit tcp destination 211.140.133.46 0 destination-port eq 6715 rule 155 permit tcp destination 211.140.133.46 0 destination-port eq 7010 rule 160 permit tcp destination 211.140.133.46 0 destination-port eq 7087 rule 165 permit tcp destination 211.140.133.46 0 destination-port eq 7088 rule 170 permit tcp destination 211.140.133.46 0 destination-port eq 7099 rule 175 permit tcp destination 211.140.133.46 0 destination-port eq 7102 rule 180 permit tcp destination 211.140.133.46 0 destination-port eq 7200 rule 185 permit tcp destination 211.140.133.46 0 destination-port eq 7300 rule 190 permit tcp destination 211.140.133.46 0 destination-port eq 7302 rule 195 permit tcp destination 211.140.133.46 0 destination-port eq 7303 rule 200 permit tcp destination 211.140.133.46 0 destination-port eq 7304 rule 205 permit tcp destination 211.140.133.46 0 destination-port eq 7305 rule 210 permit tcp destination 211.140.133.46 0 destination-port eq 7306 rule 215 permit tcp destination 211.140.133.46 0 destination-port eq 7308 rule 220 permit tcp destination 211.140.133.46 0 destination-port eq 7309 rule 225 permit tcp destination 211.140.133.46 0 destination-port eq 7314 rule 230 permit tcp destination 211.140.133.46 0 destination-port eq 7400 rule 235 permit tcp destination 211.140.133.46 0 destination-port eq 7500 rule 240 permit tcp destination 211.140.133.46 0 destination-port eq 7600 rule 245 permit tcp destination 211.140.133.46 0 destination-port eq 7660 rule 250 permit tcp destination 211.140.133.46 0 destination-port eq 7661 rule 255 permit tcp destination 211.140.133.46 0 destination-port eq 7800 rule 260 permit tcp destination 211.140.133.46 0 destination-port eq 7820 rule 265 permit tcp destination 211.140.133.46 0 destination-port eq 8000 rule 270 permit tcp destination 211.140.133.46 0 destination-port eq 8005 rule 275 permit tcp destination 211.140.133.46 0 destination-port eq 8008 rule 280 permit tcp destination 211.140.133.46 0 destination-port eq 8088 rule 285 permit tcp destination 211.140.133.46 0 destination-port eq 8089 rule 290 permit tcp destination 211.140.133.46 0 destination-port eq 8100 rule 295 permit tcp destination 211.140.133.46 0 destination-port eq 8101 rule 300 permit tcp destination 211.140.133.46 0 destination-port eq 8163 rule 305 permit tcp destination 211.140.133.46 0 destination-port eq 8300 rule 310 permit tcp destination 211.140.133.46 0 destination-port eq 8301 rule 315 permit tcp destination 211.140.133.46 0 destination-port eq 8500 rule 320 permit tcp destination 211.140.133.46 0 destination-port eq 8501 rule 325 permit tcp destination 211.140.133.46 0 destination-port eq 8503 rule 330 permit tcp destination 211.140.133.46 0 destination-port eq 8504 rule 335 permit tcp destination 211.140.133.46 0 destination-port eq 8700 rule 340 permit tcp destination 211.140.133.46 0 destination-port eq 8701 rule 345 permit tcp destination 211.140.133.46 0 destination-port eq 8888 rule 350 permit tcp destination 211.140.133.46 0 destination-port eq 8910 rule 355 permit tcp destination 211.140.133.46 0 destination-port eq 8911 rule 360 permit tcp destination 211.140.133.46 0 destination-port eq 9300 rule 365 permit tcp destination 211.140.133.46 0 destination-port eq 9302 rule 370 permit tcp destination 211.140.133.46 0 destination-port eq 9310 rule 375 permit tcp destination 211.140.133.46 0 destination-port eq 9312 rule 380 permit tcp destination 211.140.133.46 0 destination-port eq 9314 rule 385 permit tcp destination 211.140.133.46 0 destination-port eq 9400 rule 390 permit tcp destination 211.140.133.46 0 destination-port eq 27777 rule 395 permit tcp destination 211.140.133.46 0 destination-port eq 51377 rule 400 permit tcp destination 211.140.133.46 0 destination-port eq 61618 rule 405 permit tcp destination 211.140.133.46 0 destination-port range 5001 5002 rule 410 permit tcp destination 211.140.133.46 0 destination-port range 15000 19000 rule 415 permit tcp destination 211.140.133.46 0 destination-port range 20000 21999 rule 420 permit tcp destination 211.140.133.46 0 destination-port eq dns rule 425 permit tcp destination 211.140.133.46 0 destination-port eq 5938 rule 430 permit icmp destination 211.140.133.46 0 icmp-type echo-reply rule 435 permit icmp destination 211.140.133.46 0 rule 440 permit icmp destination 211.140.133.46 0 icmp-type echo rule 1000 permit udp destination 211.140.133.46 0 destination-port eq 6701 rule 1005 permit udp destination 211.140.133.46 0 destination-port eq 7302 rule 1010 permit udp destination 211.140.133.46 0 destination-port eq snmp rule 1015 permit udp destination 211.140.133.46 0 destination-port eq 7660 rule 1020 permit udp destination 211.140.133.46 0 destination-port eq 5060 rule 1025 permit udp destination 211.140.133.46 0 destination-port eq 7100 rule 1030 permit udp destination 211.140.133.46 0 destination-port eq 9303 rule 1035 permit udp destination 211.140.133.46 0 destination-port range 20000 21999 rule 1040 permit udp destination 211.140.133.46 0 destination-port range 15000 19000 rule 1045 permit udp destination 211.140.133.46 0 destination-port range 5100 5700 traffic classifier deny-all operator or if-match acl 3102 traffic classifier PermitPortOutbound-HaiKang operator or if-match acl 3107 traffic behavior permit-all filter permit traffic behavior deny-all filter deny qos policy PermitPortOutbound-HaiKang classifier PermitPortOutbound-HaiKang behavior permit-all classifier deny-all behavior deny-all interface Ten-GigabitEthernet1/2/0/15 port link-mode bridge description to SER03-Ten_1-Internet port access vlan 4094 qos apply policy PermitPortOutbound-HaiKang outbound 这是相关配置。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
acl number 3102 description match-all rule 0 permit ip acl number 3107 description PermitPortOutbound-HaiKang rule 0 permit tcp destination 211.140.133.46 0 destination-port eq www rule 5 permit tcp destination 211.140.133.46 0 destination-port eq 82 rule 10 permit tcp destination 211.140.133.46 0 destination-port eq 83 rule 15 permit tcp destination 211.140.133.46 0 destination-port eq 161 rule 20 permit tcp destination 211.140.133.46 0 destination-port eq 443 rule 25 permit tcp destination 211.140.133.46 0 destination-port eq 554 rule 30 permit tcp destination 211.140.133.46 0 destination-port eq 556 rule 35 permit tcp destination 211.140.133.46 0 destination-port eq 557 rule 40 permit tcp destination 211.140.133.46 0 destination-port eq 655 rule 45 permit tcp destination 211.140.133.46 0 destination-port eq 5300 rule 50 permit tcp destination 211.140.133.46 0 destination-port eq 5432 rule 55 permit tcp destination 211.140.133.46 0 destination-port eq 6000 rule 60 permit tcp destination 211.140.133.46 0 destination-port eq 6021 rule 65 permit tcp destination 211.140.133.46 0 destination-port eq 6300 rule 70 permit tcp destination 211.140.133.46 0 destination-port eq 6302 rule 75 permit tcp destination 211.140.133.46 0 destination-port eq 6304 rule 80 permit tcp destination 211.140.133.46 0 destination-port eq 6308 rule 85 permit tcp destination 211.140.133.46 0 destination-port eq 6309 rule 90 permit tcp destination 211.140.133.46 0 destination-port eq 6379 rule 95 permit tcp destination 211.140.133.46 0 destination-port eq 6506 rule 100 permit tcp destination 211.140.133.46 0 destination-port eq 6530 rule 105 permit tcp destination 211.140.133.46 0 destination-port eq 6550 rule 110 permit tcp destination 211.140.133.46 0 destination-port eq 6600 rule 115 permit tcp destination 211.140.133.46 0 destination-port eq 6628 rule 120 permit tcp destination 211.140.133.46 0 destination-port eq 6666 rule 125 permit tcp destination 211.140.133.46 0 destination-port eq 6667 rule 130 permit tcp destination 211.140.133.46 0 destination-port eq 6700 rule 135 permit tcp destination 211.140.133.46 0 destination-port eq 6710 rule 140 permit tcp destination 211.140.133.46 0 destination-port eq 6711 rule 145 permit tcp destination 211.140.133.46 0 destination-port eq 6713 rule 150 permit tcp destination 211.140.133.46 0 destination-port eq 6715 rule 155 permit tcp destination 211.140.133.46 0 destination-port eq 7010 rule 160 permit tcp destination 211.140.133.46 0 destination-port eq 7087 rule 165 permit tcp destination 211.140.133.46 0 destination-port eq 7088 rule 170 permit tcp destination 211.140.133.46 0 destination-port eq 7099 rule 175 permit tcp destination 211.140.133.46 0 destination-port eq 7102 rule 180 permit tcp destination 211.140.133.46 0 destination-port eq 7200 rule 185 permit tcp destination 211.140.133.46 0 destination-port eq 7300 rule 190 permit tcp destination 211.140.133.46 0 destination-port eq 7302 rule 195 permit tcp destination 211.140.133.46 0 destination-port eq 7303 rule 200 permit tcp destination 211.140.133.46 0 destination-port eq 7304 rule 205 permit tcp destination 211.140.133.46 0 destination-port eq 7305 rule 210 permit tcp destination 211.140.133.46 0 destination-port eq 7306 rule 215 permit tcp destination 211.140.133.46 0 destination-port eq 7308 rule 220 permit tcp destination 211.140.133.46 0 destination-port eq 7309 rule 225 permit tcp destination 211.140.133.46 0 destination-port eq 7314 rule 230 permit tcp destination 211.140.133.46 0 destination-port eq 7400 rule 235 permit tcp destination 211.140.133.46 0 destination-port eq 7500 rule 240 permit tcp destination 211.140.133.46 0 destination-port eq 7600 rule 245 permit tcp destination 211.140.133.46 0 destination-port eq 7660 rule 250 permit tcp destination 211.140.133.46 0 destination-port eq 7661 rule 255 permit tcp destination 211.140.133.46 0 destination-port eq 7800 rule 260 permit tcp destination 211.140.133.46 0 destination-port eq 7820 rule 265 permit tcp destination 211.140.133.46 0 destination-port eq 8000 rule 270 permit tcp destination 211.140.133.46 0 destination-port eq 8005 rule 275 permit tcp destination 211.140.133.46 0 destination-port eq 8008 rule 280 permit tcp destination 211.140.133.46 0 destination-port eq 8088 rule 285 permit tcp destination 211.140.133.46 0 destination-port eq 8089 rule 290 permit tcp destination 211.140.133.46 0 destination-port eq 8100 rule 295 permit tcp destination 211.140.133.46 0 destination-port eq 8101 rule 300 permit tcp destination 211.140.133.46 0 destination-port eq 8163 rule 305 permit tcp destination 211.140.133.46 0 destination-port eq 8300 rule 310 permit tcp destination 211.140.133.46 0 destination-port eq 8301 rule 315 permit tcp destination 211.140.133.46 0 destination-port eq 8500 rule 320 permit tcp destination 211.140.133.46 0 destination-port eq 8501 rule 325 permit tcp destination 211.140.133.46 0 destination-port eq 8503 rule 330 permit tcp destination 211.140.133.46 0 destination-port eq 8504 rule 335 permit tcp destination 211.140.133.46 0 destination-port eq 8700 rule 340 permit tcp destination 211.140.133.46 0 destination-port eq 8701 rule 345 permit tcp destination 211.140.133.46 0 destination-port eq 8888 rule 350 permit tcp destination 211.140.133.46 0 destination-port eq 8910 rule 355 permit tcp destination 211.140.133.46 0 destination-port eq 8911 rule 360 permit tcp destination 211.140.133.46 0 destination-port eq 9300 rule 365 permit tcp destination 211.140.133.46 0 destination-port eq 9302 rule 370 permit tcp destination 211.140.133.46 0 destination-port eq 9310 rule 375 permit tcp destination 211.140.133.46 0 destination-port eq 9312 rule 380 permit tcp destination 211.140.133.46 0 destination-port eq 9314 rule 385 permit tcp destination 211.140.133.46 0 destination-port eq 9400 rule 390 permit tcp destination 211.140.133.46 0 destination-port eq 27777 rule 395 permit tcp destination 211.140.133.46 0 destination-port eq 51377 rule 400 permit tcp destination 211.140.133.46 0 destination-port eq 61618 rule 405 permit tcp destination 211.140.133.46 0 destination-port range 5001 5002 rule 410 permit tcp destination 211.140.133.46 0 destination-port range 15000 19000 rule 415 permit tcp destination 211.140.133.46 0 destination-port range 20000 21999 rule 420 permit tcp destination 211.140.133.46 0 destination-port eq dns rule 425 permit tcp destination 211.140.133.46 0 destination-port eq 5938 rule 430 permit icmp destination 211.140.133.46 0 icmp-type echo-reply rule 435 permit icmp destination 211.140.133.46 0 rule 440 permit icmp destination 211.140.133.46 0 icmp-type echo rule 1000 permit udp destination 211.140.133.46 0 destination-port eq 6701 rule 1005 permit udp destination 211.140.133.46 0 destination-port eq 7302 rule 1010 permit udp destination 211.140.133.46 0 destination-port eq snmp rule 1015 permit udp destination 211.140.133.46 0 destination-port eq 7660 rule 1020 permit udp destination 211.140.133.46 0 destination-port eq 5060 rule 1025 permit udp destination 211.140.133.46 0 destination-port eq 7100 rule 1030 permit udp destination 211.140.133.46 0 destination-port eq 9303 rule 1035 permit udp destination 211.140.133.46 0 destination-port range 20000 21999 rule 1040 permit udp destination 211.140.133.46 0 destination-port range 15000 19000 rule 1045 permit udp destination 211.140.133.46 0 destination-port range 5100 5700 traffic classifier deny-all operator or if-match acl 3102 traffic classifier PermitPortOutbound-HaiKang operator or if-match acl 3107 traffic behavior permit-all filter permit traffic behavior deny-all filter deny qos policy PermitPortOutbound-HaiKang classifier PermitPortOutbound-HaiKang behavior permit-all classifier deny-all behavior deny-all interface Ten-GigabitEthernet1/2/0/15 port link-mode bridge description to SER03-Ten_1-Internet port access vlan 4094 qos apply policy PermitPortOutbound-HaiKang outbound 这是相关配置。