华为9303交换机ACL问题,急死人咯!
9303是核心,做了ACL,公司要放行IP都在这条规则上实现的,大概如下:[zjds(switchA)]aclnumber3000[zjds(switchA)-acl-a...
9303是核心,做了ACL,公司要放行IP都在这条规则上实现的,大概如下:
[zjds(switchA)]acl number 3000
[zjds(switchA)-acl-adv-3000]rule 740 per?
permit
[zjds(switchA)-acl-adv-3000]rule 740 per
[zjds(switchA)-acl-adv-3000]rule 740 permit ip sou?
source
[zjds(switchA)-acl-adv-3000]rule 740 permit ip sou
[zjds(switchA)-acl-adv-3000]rule 740 permit ip source 172.16.6.200 0
Error: The ACL rules have reached upper the limit in the group.
[zjds(switchA)-acl-adv-3000]
现在不知道应该怎么做,大概意思是说ACL达到上限了,望高人指点啊!
#
traffic classifier denyisp-deny-2 operator or precedence 10
if-match acl 3101
traffic classifier denyisp-permit-1 operator or precedence 5
if-match acl 3000
#
traffic behavior denyisp-deny-2
deny
traffic behavior denyisp-permit-1
#
traffic policy denyisp
classifier denyisp-permit-1 behavior denyisp-permit-1
classifier denyisp-deny-2 behavior denyisp-deny-2
这样的ACL是怎么配的,是9303里的配置 展开
[zjds(switchA)]acl number 3000
[zjds(switchA)-acl-adv-3000]rule 740 per?
permit
[zjds(switchA)-acl-adv-3000]rule 740 per
[zjds(switchA)-acl-adv-3000]rule 740 permit ip sou?
source
[zjds(switchA)-acl-adv-3000]rule 740 permit ip sou
[zjds(switchA)-acl-adv-3000]rule 740 permit ip source 172.16.6.200 0
Error: The ACL rules have reached upper the limit in the group.
[zjds(switchA)-acl-adv-3000]
现在不知道应该怎么做,大概意思是说ACL达到上限了,望高人指点啊!
#
traffic classifier denyisp-deny-2 operator or precedence 10
if-match acl 3101
traffic classifier denyisp-permit-1 operator or precedence 5
if-match acl 3000
#
traffic behavior denyisp-deny-2
deny
traffic behavior denyisp-permit-1
#
traffic policy denyisp
classifier denyisp-permit-1 behavior denyisp-permit-1
classifier denyisp-deny-2 behavior denyisp-deny-2
这样的ACL是怎么配的,是9303里的配置 展开
1个回答
展开全部
不会吧,你敲个rule 然后敲? ,貌似最大支持65534个rule id
更多追问追答
追问
Error: The ACL rules have reached upper the limit in the group.
这条命令已经说了,达到了上限啊
追答
这个只能使用route-map 来实现了,或者使用QOS,两种方法都是调用多个acl配合实现。
例如route-map
route-policy cisco permit node 10
if-match acl 3000
apply ip-address next-hop 1.1.1.1
display this
qu
route-policy cisco permit node 20
if-match acl 3001
apply ip-address next-hop 1.1.1.1
推荐律师服务:
若未解决您的问题,请您详细描述您的问题,通过百度律临进行免费专业咨询