Denis Evgraphov писал(а):
Попробуйте, пожалуйста, ситуацию с прошивкой, которую я выслал Вам на почту и сообщите по результатам.
Протестировал.
После применения acl, "отваливается" функциональность dhcp relay.
Код:
> tcpdump -i eth0 -n -p port 67
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
10:14:23.975074 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 300
10:14:30.975087 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 300
10:14:46.975163 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 300
10:15:24.136746 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 300
10:15:29.136504 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 300
10:15:36.136511 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 300
а должно быть, до acl
Код:
11:31:52.673095 IP 10.164.0.9.67 > 10.164.0.1.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 330
11:31:52.673319 IP 10.164.0.9.67 > 10.164.0.1.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 330
11:31:53.675421 IP 10.164.0.1.67 > 10.164.0.9.67: BOOTP/DHCP, Reply, length 302
11:31:53.682260 IP 10.164.0.9.67 > 255.255.255.255.68: BOOTP/DHCP, Reply, length 278
11:31:53.682463 IP 10.164.0.9.67 > 255.255.255.255.68: BOOTP/DHCP, Reply, length 278
11:31:53.682667 IP 10.164.0.9.67 > 255.255.255.255.68: BOOTP/DHCP, Reply, length 278
11:31:53.691932 IP 10.164.0.9.67 > 10.164.0.1.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 355
11:31:53.692155 IP 10.164.0.9.67 > 10.164.0.1.67: BOOTP/DHCP, Request from 14:da:e9:c4:eb:c0, length 355
11:31:53.723100 IP 10.164.0.1.67 > 10.164.0.9.67: BOOTP/DHCP, Reply, length 302
Что то не доделали...