Хорошо, тогда что не так в такой конфигурации:
Сначала разрешаем ip профилем №4 трафик с определённых ip, потом при помощи PCF профиля №5 со смещением разрешаем ARP и запрещаем всё остальное PCF профилем со смещением №6, результат - ничего не ходит.
Код:
create access_profile ip source_ip 255.255.255.255 profile_id 4
config access_profile profile_id 4 add access_id 1 ip source_ip 10.xx.19.198 port 15 permit
config access_profile profile_id 4 add access_id 2 ip source_ip 10.xx.19.220 port 14 permit
config access_profile profile_id 4 add access_id 3 ip source_ip 10.xx.19.209 port 7 permit
config access_profile profile_id 4 add access_id 4 ip source_ip 10.xx.19.235 port 11 permit
config access_profile profile_id 4 add access_id 5 ip source_ip 10.xx.19.221 port 16 permit
config access_profile profile_id 4 add access_id 10 ip source_ip 10.xx.19.201 port 24 permit
config access_profile profile_id 4 add access_id 13 ip source_ip 10.xx.19.233 port 18 permit
config access_profile profile_id 4 add access_id 14 ip source_ip 10.xx.19.193 port 6 permit
config access_profile profile_id 4 add access_id 47 ip source_ip 10.xx.19.217 port 3 permit
config access_profile profile_id 4 add access_id 56 ip source_ip 10.xx.19.194 port 13 permit
config access_profile profile_id 4 add access_id 75 ip source_ip 10.xx.19.195 port 12 permit
create access_profile packet_content_mask offset1 l2 0 0xFFFF offset2 l2 10 0xFFFF offset3 l2 12 0xFFFF offset4 l2 14 0xFFFF offset5 l2 16 0xFFFF offset6 l2 18 0xFFFF profile_id 5
config access_profile profile_id 5 add access_id 1 packet_content offset1 0x0806 mask 0xffff offset2 0x00a0 mask 0xffff offset3 0x0005 mask 0xffff offset4 0xbda3 mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13c6 maskffff port 15 permit
config access_profile profile_id 5 add access_id 2 packet_content offset1 0x0806 mask 0xffff offset2 0x0030 mask 0xffff offset3 0x4f61 mask 0xffff offset4 0x13c4 mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13dc maskffff port 14 permit
config access_profile profile_id 5 add access_id 3 packet_content offset1 0x0806 mask 0xffff offset2 0x001f mask 0xffff offset3 0xc6a4 mask 0xffff offset4 0x98bf mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13d1 maskffff port 7 permit
config access_profile profile_id 5 add access_id 4 packet_content offset1 0x0806 mask 0xffff offset2 0x0024 mask 0xffff offset3 0x0112 mask 0xffff offset4 0x54b5 mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13eb maskffff port 11 permit
config access_profile profile_id 5 add access_id 5 packet_content offset1 0x0806 mask 0xffff offset2 0x001e mask 0xffff offset3 0x8cd8 mask 0xffff offset4 0xec0b mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13dd maskffff port 16 permit
config access_profile profile_id 5 add access_id 10 packet_content offset1 0x0806 mask 0xffff offset2 0x001e mask 0xffff offset3 0xec52 mask 0xffff offset4 0x31d0 mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13c9 masxffff port 24 permit
config access_profile profile_id 5 add access_id 13 packet_content offset1 0x0806 mask 0xffff offset2 0x00a0 mask 0xffff offset3 0xd1c8 mask 0xffff offset4 0xbcf8 mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13e9 masxffff port 18 permit
config access_profile profile_id 5 add access_id 14 packet_content offset1 0x0806 mask 0xffff offset2 0x0040 mask 0xffff offset3 0xf4ea mask 0xffff offset4 0x6a4a mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13c1 masxffff port 6 permit
config access_profile profile_id 5 add access_id 47 packet_content offset1 0x0806 mask 0xffff offset2 0x001d mask 0xffff offset3 0x7d9f mask 0xffff offset4 0x3beb mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13d9 masxffff port 3 permit
config access_profile profile_id 5 add access_id 56 packet_content offset1 0x0806 mask 0xffff offset2 0x0040 mask 0xffff offset3 0xf4ea mask 0xffff offset4 0x635a mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13c2 masxffff port 13 permit
config access_profile profile_id 5 add access_id 75 packet_content offset1 0x0806 mask 0xffff offset2 0x0013 mask 0xffff offset3 0x8f30 mask 0xffff offset4 0xfb70 mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13c3 masxffff port 12 permit
config access_profile profile_id 5 add access_id 90 packet_content offset1 0x0806 mask 0xffff offset2 0x0022 mask 0xffff offset3 0x1538 mask 0xffff offset4 0xc437 mask 0xffff offset5 0x0a31 mask 0xffff offset6 0x13c5 masxffff port 1 permit
create access_profile packet_content_mask offset1 l2 0 0x0 profile_id 6
config access_profile profile_id 6 add access_id 1 packet_content offset1 0x0000 port 1-24 deny
Получается нужно запретить левые arp при помощи PCF правила со смещением и отдельно создать профиль без смещения запрещающий всё остальное?