Denis Evgraphov писал(а):
На DHCP сервер запросы релеятся (приходят) от PXE-клиентов? Какая версия прошивки на коммутаторе?
Версия прошивки коммутатора Build 4.50.B52.
Вот такие правила написаны у меня:
# ACL
create access_profile ip udp src_port_mask 0xFFFF profile_id 1
config access_profile profile_id 1 add access_id 1 ip udp src_port 67 port 25 permit
config access_profile profile_id 1 add access_id 2 ip udp src_port 67 port 1 deny
config access_profile profile_id 1 add access_id 3 ip udp src_port 67 port 2 deny
config access_profile profile_id 1 add access_id 4 ip udp src_port 67 port 3 deny
config access_profile profile_id 1 add access_id 5 ip udp src_port 67 port 4 deny
config access_profile profile_id 1 add access_id 6 ip udp src_port 67 port 5 deny
config access_profile profile_id 1 add access_id 7 ip udp src_port 67 port 6 deny
config access_profile profile_id 1 add access_id 8 ip udp src_port 67 port 7 deny
config access_profile profile_id 1 add access_id 9 ip udp src_port 67 port 8 deny
config access_profile profile_id 1 add access_id 10 ip udp src_port 67 port 9 deny
config access_profile profile_id 1 add access_id 11 ip udp src_port 67 port 10 deny
config access_profile profile_id 1 add access_id 12 ip udp src_port 67 port 11 deny
config access_profile profile_id 1 add access_id 13 ip udp src_port 67 port 12 deny
config access_profile profile_id 1 add access_id 14 ip udp src_port 67 port 13 deny
config access_profile profile_id 1 add access_id 15 ip udp src_port 67 port 14 deny
config access_profile profile_id 1 add access_id 16 ip udp src_port 67 port 15 deny
config access_profile profile_id 1 add access_id 17 ip udp src_port 67 port 16 deny
config access_profile profile_id 1 add access_id 18 ip udp src_port 67 port 17 deny
config access_profile profile_id 1 add access_id 19 ip udp src_port 67 port 18 deny
config access_profile profile_id 1 add access_id 20 ip udp src_port 67 port 19 deny
config access_profile profile_id 1 add access_id 21 ip udp src_port 67 port 20 deny
config access_profile profile_id 1 add access_id 22 ip udp src_port 67 port 21 deny
config access_profile profile_id 1 add access_id 23 ip udp src_port 67 port 22 deny
config access_profile profile_id 1 add access_id 24 ip udp src_port 67 port 23 deny
config access_profile profile_id 1 add access_id 25 ip udp src_port 67 port 24 deny
config access_profile profile_id 1 add access_id 26 ip udp src_port 67 port 26 deny
config access_profile profile_id 1 add access_id 27 ip udp src_port 67 port 27 deny
config access_profile profile_id 1 add access_id 28 ip udp src_port 67 port 28 deny
create access_profile ip vlan destination_ip_mask 255.255.255.0 profile_id 5
config access_profile profile_id 5 add access_id 1 ip vlan Adm destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 2 ip vlan Adm destination_ip 192.168.1.0 port 27 permit
config access_profile profile_id 5 add access_id 3 ip vlan Adm destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 4 ip vlan 511 destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 5 ip vlan 512 destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 6 ip vlan 513 destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 7 ip vlan 514 destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 8 ip vlan 515 destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 9 ip vlan 517 destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 10 ip vlan 518 destination_ip 192.168.1.0 port 26 permit
config access_profile profile_id 5 add access_id 11 ip vlan 210 destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 12 ip vlan 111 destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 13 ip vlan 35 destination_ip 192.168.1.0 port 24 permit
config access_profile profile_id 5 add access_id 14 ip vlan 36 destination_ip 192.168.1.0 port 24 permit
config access_profile profile_id 5 add access_id 15 ip vlan 414 destination_ip 192.168.1.0 port 27 permit
config access_profile profile_id 5 add access_id 16 ip vlan 211 destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 17 ip vlan 212 destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 18 ip vlan 213 destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 19 ip vlan 31 destination_ip 192.168.1.0 port 24 permit
config access_profile profile_id 5 add access_id 20 ip vlan 32 destination_ip 192.168.1.0 port 24 permit
config access_profile profile_id 5 add access_id 21 ip vlan 37 destination_ip 192.168.1.0 port 24 permit
config access_profile profile_id 5 add access_id 22 ip vlan 38 destination_ip 192.168.1.0 port 24 permit
config access_profile profile_id 5 add access_id 23 ip vlan Library destination_ip 192.168.1.0 port 27 permit
config access_profile profile_id 5 add access_id 24 ip vlan Adm destination_ip 192.168.1.0 port 24 permit
config access_profile profile_id 5 add access_id 25 ip vlan Adm destination_ip 192.168.2.0 port 24 permit
config access_profile profile_id 5 add access_id 26 ip vlan Adm destination_ip 192.168.2.0 port 26 permit
config access_profile profile_id 5 add access_id 27 ip vlan Adm destination_ip 192.168.2.0 port 27 permit
config access_profile profile_id 5 add access_id 28 ip vlan Adm destination_ip 192.168.2.0 port 28 permit
config access_profile profile_id 5 add access_id 30 ip vlan 410 destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 31 ip vlan 412 destination_ip 192.168.1.0 port 28 permit
config access_profile profile_id 5 add access_id 32 ip vlan Stud destination_ip 192.168.1.0 port 2 permit
config access_profile profile_id 5 add access_id 33 ip vlan Stud destination_ip 192.168.1.0 port 27 permit
config access_profile profile_id 5 add access_id 34 ip vlan Stud destination_ip 192.168.1.0 port 28 permit
create access_profile ip vlan destination_ip_mask 255.255.0.0 profile_id 10
config access_profile profile_id 10 add access_id 1 ip vlan Adm destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 2 ip vlan Adm destination_ip 192.168.0.0 port 27 deny
config access_profile profile_id 10 add access_id 3 ip vlan Adm destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 4 ip vlan 511 destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 5 ip vlan 512 destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 6 ip vlan 513 destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 7 ip vlan 514 destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 8 ip vlan 515 destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 9 ip vlan 517 destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 10 ip vlan 518 destination_ip 192.168.0.0 port 26 deny
config access_profile profile_id 10 add access_id 11 ip vlan 210 destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 12 ip vlan 111 destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 13 ip vlan 35 destination_ip 192.168.0.0 port 24 deny
config access_profile profile_id 10 add access_id 14 ip vlan 36 destination_ip 192.168.0.0 port 24 deny
config access_profile profile_id 10 add access_id 15 ip vlan 414 destination_ip 192.168.0.0 port 27 deny
config access_profile profile_id 10 add access_id 16 ip vlan 211 destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 17 ip vlan 212 destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 18 ip vlan 213 destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 19 ip vlan 31 destination_ip 192.168.0.0 port 24 deny
config access_profile profile_id 10 add access_id 20 ip vlan 32 destination_ip 192.168.0.0 port 24 deny
config access_profile profile_id 10 add access_id 21 ip vlan 37 destination_ip 192.168.0.0 port 24 deny
config access_profile profile_id 10 add access_id 22 ip vlan 38 destination_ip 192.168.0.0 port 24 deny
config access_profile profile_id 10 add access_id 23 ip vlan Library destination_ip 192.168.0.0 port 27 deny
config access_profile profile_id 10 add access_id 24 ip vlan Adm destination_ip 192.168.0.0 port 24 deny
config access_profile profile_id 10 add access_id 25 ip vlan 410 destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 26 ip vlan 412 destination_ip 192.168.0.0 port 28 deny
config access_profile profile_id 10 add access_id 27 ip vlan Stud destination_ip 192.168.0.0 port 2 deny
config access_profile profile_id 10 add access_id 28 ip vlan Stud destination_ip 192.168.0.0 port 27 deny
config access_profile profile_id 10 add access_id 29 ip vlan Stud destination_ip 192.168.0.0 port 28 deny