【交换机】S26I/S2924G-P/S5750E/S6000系列在配置安全通道放通DHCP报文时候报错无法应用

发布时间: 2013-09-25 点击量:2293 打印 字体:

Ruijie(config)#security global access-group 2700

Setting the security access-group failure

Ruijie(config)#*Aug 18 11:27:01: %SECURITY-3-TCAM_RESOURCE_LIMIT: The operation is not allowed.

*Aug 18 11:27:01: %SECURITY-3-TCAM_RESOURCE_LIMIT: The operation is not allowed.

*Aug 18 11:27:01: %FP_CORE-4-FIELD_NOT_SUPPORTED: [Switch0/slot0]: Hardware doesn't support field [L4 source port].

*Aug 18 11:27:01: %FP_CORE-4-RESOURCE_LIMIT: Failed to install entries to hardware due to shortage of TCAM resources.

 

报错原因是由于,S26I/S2924G-P/S5750E/S6000系列产品的ACL里针对四层源端口(TCP/UDP)不支持定义具体的值只能是any

expert access-list extended 2700

 10 permit arp any any any any any

 20 permit udp any any eq bootpc any any eq bootps

 30 permit ip any any 210.44.112.64 0.0.0.63 any

 40 permit ip any any 210.44.112.128 0.0.0.127 any

修改为:

expert access-list extended 2700

 10 permit arp any any any any any

 20 permit udp any any any any eq bootps        ---->UDP的源端口号只能是any

 30 permit ip any any 210.44.112.64 0.0.0.63 any

 40 permit ip any any 210.44.112.128 0.0.0.127 any

 

00 分享 纠错
相关条目