客户在vlanif502入接口上调用了acl3002不生效改成了调用acl3001就生效了,acl3001和acl3002是相同的配置,为什么会出现这样的情况,而且使用
display packet-filter statistics sum inbound 3001查看却发现Totally 0 packets permitted, 0 packets denied Totally 0% permitted, 0% denied
显示 该ACL允许符合条件报文的个数和通过率和拒绝符合条件报文的个数和丢弃率都为0,请问是什么原因
# acl number 3001
rule 0 permit ip destination 10.3.123.69 0
rule 5 permit ip destination 10.3.123.70 0
rule 10 permit ip destination 10.2.193.238 0
rule 15 permit ip destination 10.2.193.183 0
rule 20 permit ip destination 10.2.193.234 0
rule 25 permit ip destination 10.2.193.235 0
rule 30 permit ip destination 10.2.193.236 0
rule 35 permit ip destination 10.2.193.188 0
rule 40 permit ip destination 10.2.193.237 0
rule 45 permit ip destination 10.2.193.187 0
rule 50 permit ip destination 10.2.193.233 0
rule 55 permit ip destination 10.2.192.37 0
rule 60 permit ip destination 10.248.132.219 0
rule 65 permit ip destination 10.248.132.220 0
rule 70 permit ip destination 10.6.0.196 0
rule 75 permit ip destination 10.6.0.197 0
rule 80 permit ip destination 10.246.136.132 0
rule 85 permit ip destination 10.5.42.200 0
rule 90 permit ip destination 10.5.131.32 0
rule 95 permit ip destination 10.5.131.33 0
rule 100 permit tcp destination 10.246.185.244 0 destination-port eq www
rule 105 permit tcp destination 10.246.185.244 0 destination-port eq 443
rule 110 permit tcp destination 10.246.167.236 0 destination-port eq www
rule 115 permit tcp destination 10.246.167.11 0 destination-port eq www
rule 120 permit tcp destination 10.246.167.12 0 destination-port eq www
rule 125 permit tcp destination 10.246.167.13 0 destination-port eq www
rule 130 permit tcp destination 10.246.167.14 0 destination-port eq www
rule 135 permit tcp destination 10.246.167.15 0 destination-port eq www
rule 140 permit tcp destination 10.246.167.16 0 destination-port eq www
rule 145 deny ip destination 10.0.0.0 0.255.255.255
rule 1000 permit ip
#
acl number 3002
rule 0 permit ip destination 10.3.123.69 0
rule 5 permit ip destination 10.3.123.70 0
rule 10 permit ip destination 10.2.193.238 0
rule 15 permit ip destination 10.2.193.183 0
rule 20 permit ip destination 10.2.193.234 0
rule 25 permit ip destination 10.2.193.235 0
rule 30 permit ip destination 10.2.193.236 0
rule 35 permit ip destination 10.2.193.188 0
rule 40 permit ip destination 10.2.193.237 0
rule 45 permit ip destination 10.2.193.187 0
rule 50 permit ip destination 10.2.193.233 0
rule 55 permit ip destination 10.2.192.37 0
rule 60 permit ip destination 10.248.132.219 0
rule 65 permit ip destination 10.248.132.220 0
rule 70 permit ip destination 10.6.0.196 0
rule 75 permit ip destination 10.6.0.197 0
rule 80 permit ip destination 10.246.136.132 0
rule 85 permit ip destination 10.5.42.200 0
rule 90 permit ip destination 10.5.131.32 0
rule 95 permit ip destination 10.5.131.33 0
rule 100 permit tcp destination 10.246.185.244 0 destination-port eq www
rule 105 permit tcp destination 10.246.185.244 0 destination-port eq 443
rule 110 permit tcp destination 10.246.167.236 0 destination-port eq www
rule 115 permit tcp destination 10.246.167.11 0 destination-port eq www
rule 120 permit tcp destination 10.246.167.12 0 destination-port eq www
rule 125 permit tcp destination 10.246.167.13 0 destination-port eq www
rule 130 permit tcp destination 10.246.167.14 0 destination-port eq www
rule 135 permit tcp destination 10.246.167.15 0 destination-port eq www
rule 140 permit tcp destination 10.246.167.16 0 destination-port eq www
rule 145 deny ip destination 10.0.0.0 0.255.255.255
rule 1000 permit ip
#
(0)
最佳答案
策略相同,理论上不会有区别,因为都是下发到芯片的,现场下发对应策略时,确认下是否有报错等信息。
(0)
没有报错信息,就是acl3002调用了也不生效,调用acl3001才能生效
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
没有报错信息,就是acl3002调用了也不生效,调用acl3001才能生效