Здравствуйте.
Пытаюсь отфильтровать все запросы
IGMP Query на портах пользователей. Почему-то не получается, запросы проходят.
Конфиг:
Код:
create access_profile ip igmp type profile_id 8
config access_profile profile_id 8 add access_id 1 ip igmp type 17 port 1-24,26-28 deny
create access_profile packet_content_mask offset1 l2 0 0xFFFF offset2 l3 0 0xFF00 offset3 l3 12 0xFFFF offset4 l3 14 0xFFFF profile_id 10
config access_profile profile_id 10 add access_id 1 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x01af mask 0xffff port 15 permit
config access_profile profile_id 10 add access_id 2 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x0010 mask 0xffff port 17 permit
config access_profile profile_id 10 add access_id 3 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x0245 mask 0xffff port 3 permit
config access_profile profile_id 10 add access_id 4 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x0242 mask 0xffff port 16 permit
config access_profile profile_id 10 add access_id 5 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x0163 mask 0xffff port 8 permit
config access_profile profile_id 10 add access_id 6 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x0050 mask 0xffff port 14 permit
config access_profile profile_id 10 add access_id 7 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x0090 mask 0xffff port 10 permit
config access_profile profile_id 10 add access_id 8 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x000c mask 0xffff port 6 permit
config access_profile profile_id 10 add access_id 9 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0a0b mask 0xffff offset4 0x000a mask 0xffff port 2 permit
config access_profile profile_id 10 add access_id 10 packet_content offset1 0x0800 mask 0xffff offset2 0x4500 mask 0xff00 offset3 0x0000 mask 0xffff offset4 0x0000 mask 0xffff port 2-3,6,8,10,14-17 permit
create access_profile packet_content_mask offset1 l2 0 0xFFFF offset2 l3 2 0xFFFF offset3 l3 14 0xFFFF offset4 l3 16 0xFFFF profile_id 20
config access_profile profile_id 20 add access_id 1 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x01af mask 0xffff port 15 permit
config access_profile profile_id 20 add access_id 2 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x0010 mask 0xffff port 17 permit
config access_profile profile_id 20 add access_id 3 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x0245 mask 0xffff port 3 permit
config access_profile profile_id 20 add access_id 4 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x0242 mask 0xffff port 16 permit
config access_profile profile_id 20 add access_id 5 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x0163 mask 0xffff port 8 permit
config access_profile profile_id 20 add access_id 6 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x0050 mask 0xffff port 14 permit
config access_profile profile_id 20 add access_id 7 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x0090 mask 0xffff port 10 permit
config access_profile profile_id 20 add access_id 8 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x000c mask 0xffff port 6 permit
config access_profile profile_id 20 add access_id 9 packet_content offset1 0x0806 mask 0xffff offset2 0x0800 mask 0xffff offset3 0x0a0b mask 0xffff offset4 0x000a mask 0xffff port 2 permit
config access_profile profile_id 20 add access_id 10 packet_content port 2-3,6,8,10,14-17 deny
create access_profile ip destination_ip 255.0.0.0 profile_id 25
config access_profile profile_id 25 add access_id 1 ip destination_ip 234.0.0.0 port 1-28 permit priority 7 replace_priority
disable cpu_interface_filtering
Профиль с ID 8 должен фильтровать IGMP Query.
Профили 10/20 пропускают только IPv4/ARP с указанных IP, все остальные пакеты отбрасываются.
Профиль ID 25 изменяет приоритет IPTV трафика.
Дамп пропущенного пакета (клиент на 17-м порту):
Вложение:
2015-03-16_172846.png [ 40.75 KiB | Просмотров: 3542 ]
Прошивка 2.50.B004, аппаратная версия B1.
Что я делаю не так?