要求vlan400 和vlan600隔离,vlan600的IP段仅可以访问vlan400的141.121.11.19一个IP.
我通过acl隔离报错
提示
%Jun 18 15:43:34:016 2022 NDGW-2F-S10508 PFILTER/3/PFILTER_IF_NOT_SUPPORT: -MDC=1; Failed to apply or refresh IPv4 ACL 3200 to the outbound direction of interface Bridge-Aggregation13. The ACL is not supported.
Failed to apply IPv4 ACL 3200 to the outbound direction of interface Bridge-Aggregation13 on chassis 1 (slot 2, 4, 5, 7), chassis 2 (slot 2, 4, 5, 7).
命令:
object-group ip address vlan600
0 network subnet 141.121.13.0 255.255.255.0
10 network subnet 141.121.14.0 255.255.255.0
20 network subnet 141.121.15.0 255.255.255.0
30 network subnet 141.121.16.0 255.255.255.0
40 network subnet 141.121.17.0 255.255.255.0
50 network subnet 141.121.18.0 255.255.255.0
60 network subnet 141.121.19.0 255.255.255.0
70 network subnet 141.121.20.0 255.255.255.0
acl advanced 3200
rule 0 permit ip source 141.121.11.19 0 destination object-group vlan600
rule 5 permit ip source object-group vlan600 destination object-group vlan600
rule 100 deny ip destination object-group vlan600
rule 65534 permit ip
int GE 1/0/45
description TO_huawei-6857-ҵ-1
port link-type trunk
port trunk permit vlan 1 400 to 401 410 500 600
packet-filter 3200 outbound
packet-filter 3200 inbound
(0)
不支持聚合口,下发在聚合成员口下
(0)
Failed to apply or refresh IPv4 ACL 3200 rule 0 to the inbound direction of interface Ten-GigabitEthernet1/7/0/45. The ACL is not supported.
报了这个错误
https://zhiliao.h3c.com/theme/details/188095 参考这个案例,交换机包过滤不支持这个object group功能
Failed to apply or refresh IPv4 ACL 3200 rule 0 to the inbound direction of interface Ten-GigabitEthernet1/7/0/45. The ACL is not supported.
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
https://zhiliao.h3c.com/theme/details/188095 参考这个案例,交换机包过滤不支持这个object group功能