网络拓扑及问题:核心交换机S6502,接入层交换机S3026,pc ip 地址为192.168.2.x,并在接口下发ACL.同网段192.168.2.x机器无法互相访问.
s6502 configure:
acl number 3003
rule 0 deny ip
rule 1 permit ip source 192.168.2.0 0.0.0.255 destination 10.138.0.0 0.1.255.25
5
rule 2 deny ip source 192.168.2.0 0.0.0.255 destination 10.139.165.0 0.0.0.255
rule 3 permit tcp source 192.168.2.0 0.0.0.255 destination 10.139.165.2 0 desti
nation-port eq www
rule 4 permit ip source 192.168.2.0 0.0.0.255 destination 10.139.165.1 0
rule 5 permit ip source 192.168.2.0 0.0.0.255 destination 10.139.165.8 0
rule 6 permit ip source 192.168.2.0 0.0.0.255 destination 10.139.165.3 0
rule 7 permit ip source 192.168.2.0 0.0.0.255 destination 10.139.165.4 0
rule 8 permit ip source 192.168.2.0 0.0.0.255 destination 10.139.165.5 0
rule 9 permit ip source 192.168.2.0 0.0.0.255 destination 10.139.165.253 0
rule 10 permit ip source 192.168.2.1 0
rule 11 permit ip source 192.168.2.2 0
rule 12 permit ip source 192.168.2.3 0
rule 13 permit ip source 192.168.2.4 0
rule 14 permit ip destination 10.139.165.222 0
interface GigabitEthernet0/0/3
port access vlan 3
qos
packet-filter inbound ip-group 3003 rule 0 system-index 1
packet-filter inbound ip-group 3003 rule 1 system-index 2
packet-filter inbound ip-group 3003 rule 2 system-index 3
packet-filter inbound ip-group 3003 rule 3 system-index 4
packet-filter inbound ip-group 3003 rule 4 system-index 5
packet-filter inbound ip-group 3003 rule 5 system-index 6
packet-filter inbound ip-group 3003 rule 6 system-index 7
packet-filter inbound ip-group 3003 rule 7 system-index 8
packet-filter inbound ip-group 3003 rule 8 system-index 9
packet-filter inbound ip-group 3003 rule 9 system-index 10
packet-filter inbound ip-group 3003 rule 10 system-index 11
packet-filter inbound ip-group 3003 rule 11 system-index 12
packet-filter inbound ip-group 3003 rule 12 system-index 13
packet-filter inbound ip-group 3003 rule 13 system-index 14
packet-filter inbound ip-group 3003 rule 14 system-index 82
S3026上没有做任何配置,运行时发现,S3026交换机下每台PC,竟然无法访问.一时纳闷,在同一交换机上竟然无法访问,奇怪!
而且PING测试时,发现第一个数据包是通的,接着就无法PING通了.
从H3论坛也得知,华为65..交换机本来就比较特别,下发ACL也是与其他设备不一样.于是再分析,客户机发现PING测试,首先发现ARP请求到网关,在这里也就是S6502交换机的一个接口,此时同样执行所在接口下发的ACL,发现192.168.2.x访问同网段的ACL 没有,是不是还要在接口下发访问同网段的ACL RULE呢.
于是:
acl nu 3003 ma confg
rule 15 permit sour ip 192.168.2.0 0.0.0.255 des 192.168.2.0 0.0.0.255
再重新下发到接口,
int g0/0/3
qos
pa in i 300 rule 15
测试通过.