- 论坛徽章:
- 0
|
15可用积分
两台unix设备不同网段,中间有一台cisco防火墙,两台设备可相互ping通。当防火墙上设置策略为只开放部分端口时,如5510到5519,5510、5514能通,但是5512、5513等其它端口都不通。但是如果将策略改为两个ip地址间所有端口都放开,则所有端口就都正常了。
此问题如何解决?如何定位?以下为策略配置:
access-list out-in extended permit tcp host 134.32.32.93 any eq ftp
access-list out-in extended permit tcp host 134.32.32.94 any eq ftp
access-list out-in extended permit tcp host 134.32.32.95 any eq ftp
access-list out-in extended permit tcp host 134.32.32.95 any eq 5510
access-list out-in extended permit tcp host 134.32.32.95 any eq 5511
access-list out-in extended permit tcp host 134.32.32.95 any eq 5512
access-list out-in extended permit tcp host 134.32.32.95 any eq 5513
access-list out-in extended permit tcp host 134.32.32.95 any eq 5514
access-list out-in extended permit tcp host 134.32.32.95 any eq 5515
access-list out-in extended permit tcp host 134.32.32.95 any eq 5516
access-list out-in extended permit tcp host 134.32.32.95 any eq 5517
access-list out-in extended permit tcp host 134.32.32.95 any eq 5518
access-list out-in extended permit tcp host 134.32.32.95 any eq 5519
access-list out-in extended permit tcp host 134.32.32.95 any eq 5520
access-list out-in extended permit tcp host 134.32.32.93 any range 5510 5519
access-list out-in extended permit tcp host 134.32.32.94 any range 5510 5519 |
|