Bigarov Ruslan писал(а):
Нужно учитывать что проверка пакетов происходит от наименьшего ID до максимального до первого совпадения.
create access_profile profile_id 1 ip source_ip_mask 255.255.255.0 destination_ip_mask 255.255.0.0
config access_profile profile_id 1 add access_id 1 ip source_ip 192.168.100.0 destination_ip 192.168.0.0 port 1-12 permit rx_rate no_limit
config access_profile profile_id 1 add access_id 2 ip source_ip 192.168.0.0 destination_ip 192.168.0.0 port 1-12 permit rx_rate no_limit
config access_profile profile_id 1 add access_id 3 ip source_ip 192.168.0.0 destination_ip 192.168.100.0 port 1-12 permit rx_rate no_limit
create access_profile profile_id 2 ip source_ip_mask 255.255.252.0 destination_ip_mask 255.255.252.0
config access_profile profile_id 2 add access_id 1 ip source_ip 192.168.0.0 destination_ip 192.168.0.0 port 1-12 permit rx_rate no_limit
create access_profile profile_id 3 ip source_ip_mask 255.255.0.0 destination_ip_mask 255.255.255.255 tcp dst_port_mask 0xFFFF
config access_profile profile_id 3 add access_id auto_assign ip source_ip 192.168.0.0 destination_ip 192.168.0.3 tcp dst_port 80 port 1-12 permit rx_rate no_limit
config access_profile profile_id 3 add access_id auto_assign ip source_ip 192.168.0.0 destination_ip 192.168.0.3 tcp dst_port 25 port 1-12 permit rx_rate no_limit
create access_profile profile_id 4 ip source_ip_mask 255.255.0.0 destination_ip_mask 255.255.255.255 udp dst_port_mask 0xFFFF
config access_profile profile_id 4 add access_id auto_assign ip source_ip 192.168.0.0 destination_ip 192.168.0.2 udp dst_port 53 port 1-12 permit rx_rate no_limit
create access_profile profile_id 5 ip source_ip_mask 255.255.0.0 destination_ip_mask 255.255.255.255 icmp
config access_profile profile_id 5 add access_id 1 ip source_ip 192.168.0.0 destination_ip 192.168.0.2 icmp port 1-12 permit rx_rate no_limit
config access_profile profile_id 5 add access_id auto_assign ip source_ip 192.168.0.0 destination_ip 192.168.0.3 icmp port 1-12 permit rx_rate no_limit
create access_profile profile_id 6 ip source_ip_mask 255.255.0.0 destination_ip_mask 255.255.255.252
config access_profile profile_id 6 add access_id 1 ip source_ip 192.168.0.0 destination_ip 192.168.0.12 port 1-12 permit rx_rate no_limit
create access_profile profile_id 7 ip source_ip_mask 255.255.0.0 destination_ip_mask 255.255.252.0
config access_profile profile_id 7 add access_id 10 ip source_ip 192.168.0.0 destination_ip 192.168.0.0 port 1-12 deny
create access_profile profile_id 8 ip source_ip_mask 255.255.252.0 destination_ip_mask 255.255.0.0
config access_profile profile_id 8 add access_id 10 ip source_ip 192.168.0.0 destination_ip 192.168.0.0 port 1-12 deny
Вот добавил правила. Но все равно с 192.168.100.1 нет доступа к подсетям 192.168.0-3
