三层交换,vlan2 ,vlan33在同一设备
已有VLAN2 vlanif配置192.168.2.1/24,新加VLAN33 ,vlanif配置192.168.33.1/24,ACL3000已配置
rule permit ip source 192.168.2.0 0.0.0.255 destination 192.168.33.0 0.0.0.255
现在2网段的PC无法ping通192.168.33.1,或者33段其他
(0)
1、acl下面默认是拒绝
2、你的acl套用怎么写的,发出来看看
(0)
acl advanced 3000 rule 0 permit ip source 192.168.2.0 0.0.0.255 rule 1 permit ip source 192.168.6.0 0.0.1.255 rule 2 permit ip source 192.168.8.0 0.0.0.255 # acl advanced 3001 rule 1 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255 rule 2 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.50.0 0.0.1.255 rule 3 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.100.0 0.0.1.255 rule 4 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.222.0 0.0.1.255 rule 5 permit ip source 192.168.2.0 0.0.0.255 destination 10.1.1.0 0.0.0.255 rule 6 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.30.0 0.0.0.255 rule 7 permit ip source 192.168.2.0 0.0.0.255 destination 10.0.12.0 0.0.0.255 rule 8 permit ip source 192.168.6.0 0.0.1.255 destination 192.168.3.0 0.0.0.255 rule 9 permit ip source 192.168.6.0 0.0.1.255 destination 192.168.50.0 0.0.1.255 rule 10 permit ip source 192.168.6.0 0.0.1.255 destination 192.168.100.0 0.0.1.255 rule 11 permit ip source 192.168.6.0 0.0.1.255 destination 192.168.222.0 0.0.1.255 rule 12 permit ip source 192.168.6.0 0.0.1.255 destination 10.1.1.0 0.0.0.255 rule 13 permit ip source 192.168.6.0 0.0.1.255 destination 192.168.30.0 0.0.0.255 rule 14 permit ip source 192.168.6.0 0.0.1.255 destination 10.0.12.0 0.0.0.255 rule 15 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.5.0 0.0.0.255 rule 16 permit ip source 192.168.6.0 0.0.0.255 destination 192.168.5.0 0.0.0.255 rule 17 permit ip source 192.168.8.0 0.0.0.255 destination 192.168.3.0 0.0.0.255 rule 18 permit ip source 192.168.8.0 0.0.0.255 destination 192.168.50.0 0.0.1.255 rule 19 permit ip source 192.168.8.0 0.0.0.255 destination 192.168.100.0 0.0.1.255 rule 20 permit ip source 192.168.8.0 0.0.0.255 destination 192.168.222.0 0.0.1.255 rule 21 permit ip source 192.168.8.0 0.0.0.255 destination 10.1.1.0 0.0.0.255 rule 22 permit ip source 192.168.8.0 0.0.0.255 destination 192.168.30.0 0.0.0.255 rule 23 permit ip source 192.168.8.0 0.0.0.255 destination 10.0.12.0 0.0.0.255 rule 24 permit ip source 192.168.8.0 0.0.0.255 destination 192.168.5.0 0.0.0.255 rule 25 permit ip source 192.168.2.0 0.0.0.255 destination 192.168.33.0 0.0.0.255 # acl advanced 3002 rule 1 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.222.0 0.0.1.255 rule 2 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.30.0 0.0.0.255 rule 3 permit ip source 192.168.5.0 0.0.0.255 destination 192.168.222.0 0.0.1.255 rule 4 permit ip source 192.168.5.0 0.0.0.255 destination 192.168.30.0 0.0.0.255 rule 5 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 rule 6 permit ip source 192.168.5.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 # acl advanced 3003 rule 1 permit ip source 192.168.222.0 0.0.1.255 destination 192.168.3.0 0.0.0.255 rule 2 permit ip source 192.168.222.0 0.0.1.255 destination 192.168.5.0 0.0.0.255 rule 3 permit ip source 192.168.30.0 0.0.0.255 destination 192.168.3.0 0.0.0.255 rule 4 permit ip source 192.168.30.0 0.0.0.255 destination 192.168.5.0 0.0.0.255 rule 5 permit ip source 192.168.222.0 0.0.1.255 destination 192.168.2.0 0.0.0.255 rule 6 permit ip source 192.168.30.0 0.0.1.255 destination 192.168.2.0 0.0.0.255
dis curr 在下面截图,麻烦帮忙看看呢
去除掉包过滤配置后能通吗
(0)
看vlan2接口下配置了策略路由,并且还有deny的mode,如果把策略路由先删除后能通吗,如果不能通终端配网关地址了吗,如果通了的话排查策略路由里acl写的情况
dis curr 在下面截图,麻烦帮忙看看呢
看vlan2接口下配置了策略路由,并且还有deny的mode,如果把策略路由先删除后能通吗,如果不能通终端配网关地址了吗,如果通了的话排查策略路由里acl写的情况
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
dis curr 在下面截图,麻烦帮忙看看呢