锐捷:接口acl vlan下acl 全局acl
故障现象:vlan下配置的acl失效
配置的acl规则
ip access-list extended deny_by_8
20 permit ip host 192.168.8.22 192.168.10.0 0.0.0.255
60 permit ip 192.168.8.0 0.0.0.255 host 192.168.20.18
90 permit tcp 192.168.8.0 0.0.0.255 192.168.9.0 0.0.0.255 eq 9999
1001 deny ip 192.168.8.0 0.0.0.255 192.168.0.0 0.0.255.255
1002 deny ip 192.168.8.0 0.0.0.255 172.16.0.0 0.15.255.255
1003 deny ip 192.168.8.0 0.0.0.255 10.0.0.0 0.255.255.255
vlan接口下引用acl
!
interface VLAN 8
description onesec
ip access-group deny_by_8 in
ip address 192.168.8.10 255.255.255.0
!
查看到的原因,是接口下遗留名为jishu的历史acl,删掉就好了
RuiJie(config-ext-nacl)#show arp de 192.168.8.102
IP Address MAC Address Type Age(min) Interface Port SubVlan
192.168.8.102 ba86.88be.8b8e Dynamic 1 VLAN 10 Te0/7 10
RuiJie(config-ext-nacl)#show run int te0/7
Building configuration...
Current configuration: 115 bytes
interface TenGigabitEthernet 0/7
switchport mode trunk
ip access-group jishu in
ip access-group jishu out
RuiJie#show access-lists jishu
ip access-list extended jishu
10 permit ip host 192.168.8.1 host 192.168.20.120
20 permit ip host 192.168.20.120 host 192.168.8.1
30 permit ip any any (46357001755 matchs)