Устанавливая свич:
Цитата:
DGS-3610#sh version
System description : DGS-3610-26G Gigabit Ethernet Switch
System start time : 2010-02-04 13:16:31
System uptime : 1:7:20:9
System hardware version : A1.0
System software version : v10.3(5), Release(70398)
System BOOT version : 10.3.70398
System CTRL version : 10.3.70398
Device information:
Device-1
Hardware version : A1.0
Software version : v10.3(5), Release(70398)
BOOT version : 10.3.70398
CTRL version : 10.3.70398
не смог привязать ip access-group {id|name} out на GigabitEthernet 0/2 интерфейс при таком конфиге
Цитата:
DGS-3610(config)#sh running-config
Building configuration...
Current configuration : 3021 bytes
!
version v10.3(5), Release(70398)(Mon Nov 30 20:26:30 CST 2009 -ngcf49)
co-operate enable
!
!
!
!
route-map local permit 10
match ip address 1
set ip next-hop 192.168.132.200
!
vlan 1
!
vlan 2
!
vlan 4
!
!
no service password-encryption
!
ip access-list standard 1
10 permit host 194.116.195.234
20 permit host 192.168.58.6
30 permit host 192.168.58.10
!
!
ip access-list extended 101
10 deny icmp any any
20 permit ip any any
!
!
!
interface GigabitEthernet 0/1
!
interface GigabitEthernet 0/2
no switchport
ip policy route-map local
no ip proxy-arp
ip access-group 101 out
ip address 213.151.2.246 255.255.255.252
!
interface GigabitEthernet 0/3
!
...
!
interface GigabitEthernet 0/8
switchport access vlan 2
!
interface GigabitEthernet 0/9
!
...
!
interface GigabitEthernet 0/13
switchport access vlan 2
!
interface GigabitEthernet 0/14
switchport access vlan 2
!
interface GigabitEthernet 0/15
switchport access vlan 2
!
interface GigabitEthernet 0/16
no switchport
no ip proxy-arp
!
interface GigabitEthernet 0/17
switchport access vlan 2
!
interface GigabitEthernet 0/18
switchport access vlan 2
!
interface GigabitEthernet 0/19
switchport access vlan 2
!
interface GigabitEthernet 0/20
switchport access vlan 2
!
interface GigabitEthernet 0/21
!
interface GigabitEthernet 0/22
switchport access vlan 4
!
interface GigabitEthernet 0/23
!
interface GigabitEthernet 0/24
no switchport
no ip proxy-arp
ip access-group 101 out
ip address 213.151.1.6 255.255.255.248
description Games
!
interface VLAN 1
no ip proxy-arp
!
interface VLAN 2
no ip proxy-arp
ip address 192.168.101.51 255.255.255.240
!
interface VLAN 4
no ip proxy-arp
ip access-group 101 out
ip address 192.168.132.199 255.255.255.240
!
!
!
line con 0
line vty 0 4
login
!
!
end
ip access-list extended 101 с блокировкой icmp взят для теста, на интерфейсах VLAN4 и GigabitEthernet 0/24 ip access-group 101 out отрабатывается, на GigabitEthernet 0/2 цепочка out не работает
отключение ip policy route-map local на GigabitEthernet 0/2 положения не меняет, в документации ответа не нашел, нужен свежий взгляд на проблему...