原有配置:ACL生效的,全部正常
增加如下配置导致acl失效
ACL3002增加配置
rule 97 permit ip source 10.165.233.0 0.0.0.255 destination 10.165.0.0 0.0.0.255
rule 98 permit ip source 10.165.234.0 0.0.0.255 destination 10.165.0.0 0.0.0.255
rule 99 permit ip source 10.165.235.0 0.0.0.255 destination 10.165.0.0 0.0.0.255
rule 100 permit ip source 10.165.236.0 0.0.0.255 destination 10.165.0.0 0.0.0.255
rule 101 permit ip source 10.165.237.0 0.0.0.255 destination 10.165.0.0 0.0.0.255
rule 102 permit tcp source 10.165.233.0 0.0.0.255 source-port eq 1935
rule 103 permit tcp source 10.165.233.0 0.0.0.255 source-port eq 1937
rule 104 permit tcp source 10.165.233.0 0.0.0.255 source-port eq 1938
rule 105 permit tcp source 10.165.233.0 0.0.0.255 source-port eq 7681
rule 106 permit tcp source 10.165.233.0 0.0.0.255 source-port eq 7682
rule 107 permit ip source 10.165.233.0 0.0.0.255 destination 82.157.72.62 0
rule 108 permit ip source 10.165.233.0 0.0.0.255 destination 120.26.203.179 0
rule 109 permit tcp source 10.165.234.0 0.0.0.255 source-port eq 1935
rule 110 permit tcp source 10.165.234.0 0.0.0.255 source-port eq 1937
rule 111 permit tcp source 10.165.234.0 0.0.0.255 source-port eq 1938
rule 112 permit tcp source 10.165.234.0 0.0.0.255 source-port eq 7681
rule 113 permit tcp source 10.165.234.0 0.0.0.255 source-port eq 7682
rule 114 permit ip source 10.165.234.0 0.0.0.255 destination 82.157.72.62 0
rule 115 permit ip source 10.165.234.0 0.0.0.255 destination 120.26.203.179 0
rule 116 permit tcp source 10.165.235.0 0.0.0.255 source-port eq 1935
rule 117 permit tcp source 10.165.235.0 0.0.0.255 source-port eq 1937
rule 118 permit tcp source 10.165.235.0 0.0.0.255 source-port eq 1938
rule 119 permit tcp source 10.165.235.0 0.0.0.255 source-port eq 7681
rule 120 permit tcp source 10.165.235.0 0.0.0.255 source-port eq 7682
rule 121 permit ip source 10.165.235.0 0.0.0.255 destination 82.157.72.62 0
rule 122 permit ip source 10.165.235.0 0.0.0.255 destination 120.26.203.179 0
rule 123 permit tcp source 10.165.236.0 0.0.0.255 source-port eq 1935
rule 124 permit tcp source 10.165.236.0 0.0.0.255 source-port eq 1937
rule 125 permit tcp source 10.165.236.0 0.0.0.255 source-port eq 1938
rule 126 permit tcp source 10.165.236.0 0.0.0.255 source-port eq 7681
rule 127 permit tcp source 10.165.236.0 0.0.0.255 source-port eq 7682
rule 128 permit ip source 10.165.236.0 0.0.0.255 destination 82.157.72.62 0
rule 129 permit ip source 10.165.236.0 0.0.0.255 destination 120.26.203.179 0
rule 130 permit tcp source 10.165.237.0 0.0.0.255 source-port eq 1935
rule 131 permit tcp source 10.165.237.0 0.0.0.255 source-port eq 1937
rule 132 permit tcp source 10.165.237.0 0.0.0.255 source-port eq 1938
rule 133 permit tcp source 10.165.237.0 0.0.0.255 source-port eq 7681
rule 134 permit tcp source 10.165.237.0 0.0.0.255 source-port eq 7682
rule 135 permit ip source 10.165.237.0 0.0.0.255 destination 82.157.72.62 0
rule 136 permit ip source 10.165.237.0 0.0.0.255 destination 120.26.203.179 0
acl3003增加配置:
rule 26 permit ip source 10.165.233.0 0.0.0.255
rule 27 permit ip source 10.165.234.0 0.0.0.255
rule 28 permit ip source 10.165.235.0 0.0.0.255
rule 29 permit ip source 10.165.236.0 0.0.0.255
rule 30 permit ip source 10.165.237.0 0.0.0.255
######这个时候出问题了,ACL3002 看当时状态应该是失效了,主要是导致之前的 rule1-rule96都异常,acl 3003是否失效,因为访问不通无法验证。推断是只有ACL 3002不生效,acl 3003正常。
删除新增配置恢复正常。
再acl 3002里面测试再几条rule 就会导致有些rule失效,增加多条导致整个ACL3002失效
帮忙定位下问题,这个级别的交换机不应该配置这几条ACL就满足不了把
暂无评论