Got it

can not filter out PPPoE packets

Created: Mar 11, 2021 12:04:15Latest reply: Mar 12, 2021 00:46:23 537 3 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

we has some S2300 switches and found abnormal on it, trying to filter out packet wih intruder source MAC:


acl number 4005

 rule 10 deny source-mac 0017-df00-0000 ffff-ff00-0000

 rule 100 permit


interface Ethernet0/0/21

 traffic-filter inbound acl 4005 rule 10

traffic-filter inbound acl 4005 rule 100

 undo lldp enable

 port-isolate enable group 1

 multicast-suppression 2

 broadcast-suppression 1


but such packet S23 can not drop, intruder send  such packet to Eth/0/21 and packets succefully out from Gigabitethernet uplink, , any undocumented restriction at S23 ? May be it check ether-type frame as PPPoE and fail apply traffic-filter ?


spacer.gif

intruder pcket






Featured Answers

Recommended answer

chenhui
Admin Created Mar 12, 2021 00:46:23

Hello Kolli,
Please trying remove the parameter rule when assigning the traffic filter under the interface view, or replace the traffic filter with traffic policy. When the deny action is defined in the ACL rule associated with the traffic-filter command, the ACL rule can only be associated with the traffic-mirror (interface view), traffic-mirror (system view), traffic-statistic (interface view), or traffic-statistic (system view) command. If the ACL rule is associated with other simplified traffic policies, the simplified traffic policies may not take effect.
View more
  • x
  • convention:

All Answers
Hello,
We're working on your problem. Please be patient.
View more
  • x
  • convention:

Hi,
I'm not sure if Layer 2 ACLs have such a limitation. You can try to apply the traffic filter to a blank interface to check whether common packets (non-PPPoE packets) can be filtered.
View more
  • x
  • convention:

Hello Kolli,
Please trying remove the parameter rule when assigning the traffic filter under the interface view, or replace the traffic filter with traffic policy. When the deny action is defined in the ACL rule associated with the traffic-filter command, the ACL rule can only be associated with the traffic-mirror (interface view), traffic-mirror (system view), traffic-statistic (interface view), or traffic-statistic (system view) command. If the ACL rule is associated with other simplified traffic policies, the simplified traffic policies may not take effect.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.