用户需要下联端口拒绝访问远程端口(除堡垒机外),此端口跑的mpls 为什么,在启用MPLS 物理端口下面做qos策略 不会生效呀。 在物理口在的SVI口用ACL也不生效(包括加了VPN实例与不加VPN实例)是他端口跑的都只是mpls的标签,不检测原始数据的原因吗,还是什么原因,以及如何解决
qos 配置,具体就是先允许一段地址(堡垒机)的远程端口filter permit,然后拒绝所有源远程端口filter deny, 再允许所有
qos policy deny_yuancheng
classifier permit_baoleiji behavior permit_baoleiji
classifier deny_yuancheng behavior deny_yuancheng
classifier permitall behavior permitall
物理接口配置
interface GigabitEthernet2/1/0/5
port link-mode bridge
port access vlan 1005 s
peed 1000
duplex full
qos apply policy deny_yuancheng inbound
qos apply policy deny_yuancheng outbound
SVI口配置
interface Vlan-interface1005
ip address 1.1.1.1 255.255.255.252
mpls enable
mpls ldp enable
(0)
最佳答案
MPLS报文需要匹配EXP字段,ping带tos字段流统或remark流统。
高端路由器不要加filter-permit参数。
给出一种方法:
重新标记优先级,但队列会对报文转发造成影响
#
acl advanced 3000
rule 0 permit ip source 11.1.1.0 0.0.0.255
#
traffic classifier 1 operator and
if-match acl 3000
#
traffic classifier 2 operator and
if-match mpls-exp 4
#
traffic behavior 1
remark dscp af41
accounting packet
#
traffic behavior 2
accounting packet
#
qos policy 1
classifier 1 behavior 1
#
qos policy 2
classifier 2 behavior 2
#
interface GigabitEthernet0/0
ip address 10.1.1.1 255.255.255.0
mpls enable
mpls ldp enable
qos apply policy 2 outbound
#
interface GigabitEthernet0/1
ip address 11.1.1.1 255.255.255.0
qos apply policy 1 inbound
#
[RTA]dis qos policy int g0/0
Interface: GigabitEthernet0/0
Direction: Outbound
Policy: 2
Classifier: default-class
Matched : 31 (Packets) 2388 (Bytes)
5-minute statistics:
Forwarded: 0/53 (pps/bps)
Dropped : 0/0 (pps/bps)
Operator: AND
Rule(s) :
If-match any
Behavior: be
Default Queue:
Flow based Weighted Fair Queue:
Max number of hashed queues: 256
Matched : 0 (Packets) 0 (Bytes)
Enqueued : 0 (Packets) 0 (Bytes)
Discarded: 0 (Packets) 0 (Bytes)
Discard Method: Tail
Classifier: 2
Matched : 5 (Packets) 510 (Bytes)
5-minute statistics:
Forwarded: 0/13 (pps/bps)
Dropped : 0/0 (pps/bps)
Operator: AND
Rule(s) :
If-match mpls-exp 4
Behavior: 2
Assured Forwarding:
Bandwidth 560000 (kbps)
Matched : 0 (Packets) 0 (Bytes)
Enqueued : 0 (Packets) 0 (Bytes)
Discarded: 0 (Packets) 0 (Bytes)
Discard Method: Tail
(0)
请问有关于这个更详细的案例吗,或者说在配置指导手册上面是否有关于讲解此问题的章节
https://zhiliao.h3c.com/Theme/details/20699
这个qos是有限制的,和单板有关。高端限制很多。
(0)
具体是怎么样的限制呀,那如果有限制应该怎么解决呀 ,您那有解决方案吗
具体是怎么样的限制呀,那如果有限制应该怎么解决呀 ,您那有解决方案吗
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
https://zhiliao.h3c.com/Theme/details/20699