Rootop 服务器运维与web架构

acl rule id重新排序

当插入的规则过多,没有空闲的id可用时,可以重新排序,这样就多出来可以插入的空间。
方法就是通过设置步长的方式重新生成rule id

[Huawei]acl name ui
[Huawei-acl-adv-ui]dis th
# 现在的序号是3、4、5
acl name ui 3000
 rule 3 permit ip source 192.168.1.3 0 destination 192.168.2.0 0.0.0.255
 rule 4 permit ip source 192.168.1.2 0 destination 192.168.2.0 0.0.0.255
 rule 5 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255

# 使其从1开始重新排序
[Huawei-acl-adv-ui]step 1
[Huawei-acl-adv-ui]dis th
#
acl name ui 3000
 step 1
 rule 1 permit ip source 192.168.1.3 0 destination 192.168.2.0 0.0.0.255
 rule 2 permit ip source 192.168.1.2 0 destination 192.168.2.0 0.0.0.255
 rule 3 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255

# 从5开始重新排序
[Huawei-acl-adv-ui]step 5
[Huawei-acl-adv-ui]dis	
[Huawei-acl-adv-ui]display this
#
acl name ui 3000
 rule 5 permit ip source 192.168.1.3 0 destination 192.168.2.0 0.0.0.255
 rule 10 permit ip source 192.168.1.2 0 destination 192.168.2.0 0.0.0.255
 rule 15 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255

原创文章,转载请注明。本文链接地址: https://www.rootop.org/pages/5285.html

作者:Venus

服务器运维与性能优化

评论已关闭。