Demin Ivan писал(а):
Приведите пожалуйста полный конфиг ACL.
create access_profile profile_id 1 ip source_ip_mask 255.255.255.0 destination_ip_mask 255.255.255.0
config access_profile profile_id 1 add access_id 1 ip source_ip 10.10.1.0 destination_ip 10.10.1.0 port 14,21-24 permit rx_rate no_limit
create access_profile profile_id 2 ip tcp dst_port_mask 0xFFFF
config access_profile profile_id 2 add access_id auto_assign ip tcp dst_port 135 port 1-27 deny
config access_profile profile_id 2 add access_id auto_assign ip tcp dst_port 137 port 1-27 deny
config access_profile profile_id 2 add access_id auto_assign ip tcp dst_port 138 port 1-27 deny
config access_profile profile_id 2 add access_id auto_assign ip tcp dst_port 139 port 1-27 deny
config access_profile profile_id 2 add access_id auto_assign ip tcp dst_port 445 port 1-27 deny
config access_profile profile_id 2 add access_id auto_assign ip tcp dst_port 2869 port 1-27 deny
create access_profile profile_id 3 ip udp dst_port_mask 0xFFFF
config access_profile profile_id 3 add access_id auto_assign ip udp dst_port 135 port 1-27 deny
config access_profile profile_id 3 add access_id auto_assign ip udp dst_port 137 port 1-27 deny
config access_profile profile_id 3 add access_id auto_assign ip udp dst_port 138 port 1-27 deny
config access_profile profile_id 3 add access_id auto_assign ip udp dst_port 139 port 1-27 deny
config access_profile profile_id 3 add access_id auto_assign ip udp dst_port 445 port 1-27 deny
config access_profile profile_id 3 add access_id auto_assign ip udp dst_port 1900 port 1-27 deny
create access_profile profile_id 4 ip source_ip_mask 255.255.255.0
config access_profile profile_id 4 add access_id 1 ip source_ip 10.1.50.0 port 1-24 permit rx_rate 80
disable cpu_interface_filtering