%Oct 9 14:57:13:799 2022 GZEZ_hexin_s7508 SHELL/6/SHELL_CMD: -Task=vt0-IPAddr=192.168.102.3-User=admin; Command is dis cu int %Oct 9 14:57:16:159 2022 GZEZ_hexin_s7508 DHCPS/5/DHCPS_ALLOCATE_IP: DHCP server information: Server IP = 192.168.44.254, DHCP client IP = 192.168.44.3, DHCP client hardware address = 3cd2-e546-721d, DHCP client lease = 86400. %Oct 9 14:57:34:758 2022 GZEZ_hexin_s7508 DHCPS/5/DHCPS_ALLOCATE_IP: DHCP server information: Server IP = 192.168.44.254, DHCP client IP = 192.168.44.4, DHCP client hardware address = 3cd2-e546-27dd, DHCP client lease = 86400. %Oct 9 14:57:51:659 2022 GZEZ_hexin_s7508 DHCPS/5/DHCPS_RECLAIM_IP: DHCP server information: Server IP = 192.168.44.254, DHCP client IP = 192.168.44.3, DHCP client hardware address = 3cd2-e546-721d, DHCP client lease = 86400. %Oct 9 14:58:01:160 2022 GZEZ_hexin_s7508 DHCPS/5/DHCPS_ALLOCATE_IP: DHCP server information: Server IP = 192.168.44.254, DHCP client IP = 192.168.44.3, DHCP client hardware address = 3cd2-e546-721d, DHCP client lease = 86400. %Oct 9 14:58:16:758 2022 GZEZ_hexin_s7508 DHCPS/5/DHCPS_ALLOCATE_IP: DHCP server information: Server IP = 192.168.44.254, DHCP client IP = 192.168.44.4, DHCP client hardware address = 3cd2-e546-27dd, DHCP client lease = 86400. 导致核心交换机日志一直在被刷屏,在对接端口配置二层acl限制源mac与限制dhcp端口均没有效果 nterface GigabitEthernet0/0/22 port link-mode bridge port link-type trunk port trunk permit vlan all packet-filter 4100 inbound packet-filter 3300 inbound stp disable arp rate-limit rate 50 drop Advanced ACL 3300, named -none-, 2 rules, ACL's step is 5 rule 0 deny udp destination-port eq bootpc rule 5 deny udp destination-port eq bootps Ethernet frame ACL 4100, named -none-, 3 rules, ACL's step is 5 rule 0 deny source-mac 3cd2-e546-27dd ffff-ffff-ffff rule 5 deny source-mac 3cd2-e546-721d ffff-ffff-ffff rule 10 permit 如何让分支网络无法获取这边网络的dhcp
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
那边对接是trunk,然后vlan1000地址对接写路由过去的,那只放通vlan1000就行了吗?还需要把我们这边服务器的vlan段,那边访问的段也放通吗?
你确认下是不是三层路由互通,如果是的话,只放行VLAN1000就可以了,如果是三层互通,最优的做法是用三层口互联,这样可以避免STP的互相干扰
唉,这个是很久之前问题了,我只负责我这一边的.....网段都是不一样的,端口关闭了stp
哈哈,那就看是不是三层路由互通的,看看有没有互联地址,如果有互联地址,可以先只放行互联地址的VLAN试试
可以了。谢谢靓仔!是路由互通的
不客气的