Traffic-filter is not working on CE6810 LI ?

Created Apr 01, 2019 17:42:21Latest reply Apr 03, 2019 15:30:50 67 3 0 0
  Rewarded E Coins: 0 (problem resolved)

A simple question.There is a ACL on vlan 20 and it works. Only the allowed 2 source addresses can connect to vlan 20.But why I don’t see any matches?

<sw01>disp acl name vlan20-out

Advanced Name vlan20-out, 3 rules

ACL's step is 5

rule 10 permit ipsource 0 destination (0 times matched)

rule 11 permit ipsource 0 destination (0 times matched)

rule 20 deny ip (0 times matched)

<sw01>disp cur int vlan 20


interface Vlanif20

ip address172.16.100.254

traffic-filter acl vlan20-out outbound


< sw01>disp version

Huawei Versatile Routing Platform Software

VRP (R) software, Version 8.150 (CE6810LI V200R002C50SPC800)

  • x
  • convention:

Popeye_Wang  Moderator   Created Apr 01, 2019 18:05:01 Helpful(1) Helpful(1)

Dear @user_3358183,

Actually, CE6810LI is just a layer 2 switch. In the forwarding chip, all the ARP, host routing and direct routing entries are implemented via ACL. The ACL unit does not have the longest mask matching function - ACL is just matched one by one in order. If all of the above are updated, the ACL module needs to adjust all the ACL orders frequently to implement the longest mask matching function.

There have been posts explained that the CE6810LI almost doesn’t support layer 3 forwarding: ... n/thread/451335-861.

In your case, I think this is probably due the fact that traffic-policy in VLANIF is implemented by ACL. Routing and forwarding are also implemented by ACL on this type of device. Maybe there is a conflict. Setting the traffic-filter on the VLAN not VLANIF, maybe it’ll work.
  • x
  • convention:

Hobbit     Created Apr 01, 2019 19:08:45 Helpful(0) Helpful(0)

Posted by Popeye_Wang at 2019-04-01 18:05 @user_3358183 Actually, CE6810LI is just a layer 2 switch, in the forwarding chip, all the ARP, ho ...
“Setting the traffic-filter on the VLAN” thanks,it works。
  • x
  • convention:

joedenly     Created Apr 03, 2019 15:30:50 Helpful(0) Helpful(0)

Oh ya this i is the best way to filter traffic, can you mention the software you have used? 
itunes error 0xe80000a
 helped me to know more about this.
  • x
  • convention:


You need to log in to reply to the post Login | Register

Notice:To ensure the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but not limited to politically sensitive content, content concerning pornography, gambling, drug abuse and trafficking, content that may disclose or infringe upon others' intellectual properties, including commercial secrets, trade marks, copyrights, and patents, and personal privacy. Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see“ Privacy Policy.”
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Fast reply Scroll to top