Traffic-filter is not working on CE6810 LI ?

Created: Apr 1, 2019 09:42:21Latest reply: Apr 3, 2019 07:30:50 141 3 0 0
  Rewarded Hi-coins: 0 (problem resolved)

A simple question.There is a ACL on vlan 20 and it works. Only the allowed 2 source addresses can connect to vlan 20.But why I don’t see any matches?

<sw01>disp acl name vlan20-out

Advanced Name vlan20-out, 3 rules

ACL's step is 5

rule 10 permit ipsource 172.16.100.11 0 destination 10.20.110.0 0.0.0.255 (0 times matched)

rule 11 permit ipsource 172.16.100.21 0 destination 10.20.110.0 0.0.0.255 (0 times matched)

rule 20 deny ip (0 times matched)

<sw01>disp cur int vlan 20

#

interface Vlanif20

ip address172.16.100.254 255.255.255.0

traffic-filter acl vlan20-out outbound

#

< sw01>disp version

Huawei Versatile Routing Platform Software

VRP (R) software, Version 8.150 (CE6810LI V200R002C50SPC800)


  • x
  • convention:

Featured Answers
Admin Created Apr 1, 2019 10:05:01 Helpful(1) Helpful(1)

Dear @user_3358183,

Actually, CE6810LI is just a layer 2 switch. In the forwarding chip, all the ARP, host routing and direct routing entries are implemented via ACL. The ACL unit does not have the longest mask matching function - ACL is just matched one by one in order. If all of the above are updated, the ACL module needs to adjust all the ACL orders frequently to implement the longest mask matching function.

There have been posts explained that the CE6810LI almost doesn’t support layer 3 forwarding: https://forum.huawei.com/enterpr ... n/thread/451335-861.

In your case, I think this is probably due the fact that traffic-policy in VLANIF is implemented by ACL. Routing and forwarding are also implemented by ACL on this type of device. Maybe there is a conflict. Setting the traffic-filter on the VLAN not VLANIF, maybe it’ll work.
  • x
  • convention:

All Answers
Popeye_Wang Admin Created Apr 1, 2019 10:05:01 Helpful(1) Helpful(1)

Dear @user_3358183,

Actually, CE6810LI is just a layer 2 switch. In the forwarding chip, all the ARP, host routing and direct routing entries are implemented via ACL. The ACL unit does not have the longest mask matching function - ACL is just matched one by one in order. If all of the above are updated, the ACL module needs to adjust all the ACL orders frequently to implement the longest mask matching function.

There have been posts explained that the CE6810LI almost doesn’t support layer 3 forwarding: https://forum.huawei.com/enterpr ... n/thread/451335-861.

In your case, I think this is probably due the fact that traffic-policy in VLANIF is implemented by ACL. Routing and forwarding are also implemented by ACL on this type of device. Maybe there is a conflict. Setting the traffic-filter on the VLAN not VLANIF, maybe it’ll work.
  • x
  • convention:

Hobbit Created Apr 1, 2019 11:08:45 Helpful(0) Helpful(0)

Posted by Popeye_Wang at 2019-04-01 10:05 @user_3358183 Actually, CE6810LI is just a layer 2 switch, in the forwarding chip, all the ARP, ho ...
“Setting the traffic-filter on the VLAN” thanks,it works。Traffic-filter is not working on CE6810 LI ?-2905599-1
  • x
  • convention:

joedenly Created Apr 3, 2019 07:30:50 Helpful(0) Helpful(0)

Oh ya this i is the best way to filter traffic, can you mention the software you have used? 
itunes error 0xe80000a
 helped me to know more about this.
  • x
  • convention:

Reply

Reply
You need to log in to reply to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

Login and enjoy all the member benefits

Login
Fast reply Scroll to top