vlan下配置的acl失效原因


  1. 锐捷:接口acl vlanacl 全局acl
  2. 故障现象:vlan下配置的acl失效
  3. 配置的acl规则
  4. ip access-list extended deny_by_8
  5. 20 permit ip host 192.168.8.22 192.168.10.0 0.0.0.255
  6. 60 permit ip 192.168.8.0 0.0.0.255 host 192.168.20.18
  7. 90 permit tcp 192.168.8.0 0.0.0.255 192.168.9.0 0.0.0.255 eq 9999
  8. 1001 deny ip 192.168.8.0 0.0.0.255 192.168.0.0 0.0.255.255
  9. 1002 deny ip 192.168.8.0 0.0.0.255 172.16.0.0 0.15.255.255
  10. 1003 deny ip 192.168.8.0 0.0.0.255 10.0.0.0 0.255.255.255
  11. vlan接口下引用acl
  12. !
  13. interface VLAN 8
  14. description onesec
  15. ip access-group deny_by_8 in
  16. ip address 192.168.8.10 255.255.255.0
  17. !
  18. 查看到的原因,是接口下遗留名为jishu的历史acl,删掉就好了
  19. RuiJie(config-ext-nacl)#show arp de 192.168.8.102
  20. IP Address MAC Address Type Age(min) Interface Port SubVlan
  21. 192.168.8.102 ba86.88be.8b8e Dynamic 1 VLAN 10 Te0/7 10
  22. RuiJie(config-ext-nacl)#show run int te0/7
  23. Building configuration...
  24. Current configuration: 115 bytes
  25. interface TenGigabitEthernet 0/7
  26. switchport mode trunk
  27. ip access-group jishu in
  28. ip access-group jishu out
  29. RuiJie#show access-lists jishu
  30. ip access-list extended jishu
  31. 10 permit ip host 192.168.8.1 host 192.168.20.120
  32. 20 permit ip host 192.168.20.120 host 192.168.8.1
  33. 30 permit ip any any (46357001755 matchs)

local 2023年2月14日 21:01 收藏文档