cosa bizzarra su access-list
Inviato: lun 11 set , 2006 10:56 am
Buongiorno a tutti,
ho due access-list UGUALI...la 130 e la 135...una collegata ad una interfaccia attiva, l'altra collegata ad un'interfaccia in backup..
Eccone il codice:
access-list 130 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255
access-list 130 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 130 permit ip 192.168.0.0 0.0.0.255 any
access-list 135 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255
access-list 135 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 135 permit ip 192.168.0.0 0.0.0.255 any
La domanda è: perchè la terza acl del gruppo 135 non viene mai matchata???
Ecco uno "show access-list":
Extended IP access list 130
10 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255 (6 matches)
20 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255 (24570 matches)
30 permit ip 192.168.0.0 0.0.0.255 any (985 matches)
Extended IP access list 135
10 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255 (6 matches)
20 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255 (24570 matches)
30 permit ip 192.168.0.0 0.0.0.255 any
Grazie
Marco
ho due access-list UGUALI...la 130 e la 135...una collegata ad una interfaccia attiva, l'altra collegata ad un'interfaccia in backup..
Eccone il codice:
access-list 130 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255
access-list 130 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 130 permit ip 192.168.0.0 0.0.0.255 any
access-list 135 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255
access-list 135 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 135 permit ip 192.168.0.0 0.0.0.255 any
La domanda è: perchè la terza acl del gruppo 135 non viene mai matchata???
Ecco uno "show access-list":
Extended IP access list 130
10 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255 (6 matches)
20 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255 (24570 matches)
30 permit ip 192.168.0.0 0.0.0.255 any (985 matches)
Extended IP access list 135
10 deny ip 192.168.0.0 0.0.0.255 14.1.1.0 0.0.0.255 (6 matches)
20 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255 (24570 matches)
30 permit ip 192.168.0.0 0.0.0.255 any
Grazie
Marco