You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nexus 3K三层接口路由ACL失效问题求助

问题:Nexus 3K ACL无法阻断指定流量排查

环境与问题

两台Nexus 3K交换机R1与R2通过三层接口Eth1/1互联,配置ACL r1r2 试图阻断R1的loopback1(1.1.1.1/32)到R2的loopback2(2.2.2.2/32)的流量,但ACL无命中计数,流量仍正常通行。尝试重启设备、为ACL条目添加日志均无效,相同配置在ASR1000v上测试可正常阻断流量,需排查原因及解决办法。

R1配置

ip route 0.0.0.0/0 12.12.12.2
interface Ethernet1/1
  no switchport
  ip address 12.12.12.1/24
  no shutdown
!
interface loopback1
  ip address 1.1.1.1/32

R2配置

interface Ethernet1/1
  no switchport
  ip access-group r1r2 in
  ip address 12.12.12.2/24
  no shutdown
!
interface loopback2
  ip address 2.2.2.2/32
!
ip route 0.0.0.0/0 12.12.12.1
!
ip access-list r1r2
  statistics per-entry
  10 deny ip 1.1.1.1/32 2.2.2.2/32
  100 permit ip any any
!

测试结果

R1# ping 2.2.2.2 source 1.1.1.1
PING 2.2.2.2 (2.2.2.2) from 1.1.1.1: 56 data bytes
64 bytes from 2.2.2.2: icmp_seq=0 ttl=254 time=3.382 ms
64 bytes from 2.2.2.2: icmp_seq=1 ttl=254 time=2.666 ms
64 bytes from 2.2.2.2: icmp_seq=2 ttl=254 time=2.639 ms
64 bytes from 2.2.2.2: icmp_seq=3 ttl=254 time=2.494 ms
64 bytes from 2.2.2.2: icmp_seq=4 ttl=254 time=2.526 ms

--- 2.2.2.2 ping statistics ---
5 packets transmitted, 5 packets received, 0.00% packet loss
round-trip min/avg/max = 2.494/2.741/3.382 ms
R1# 

原因分析

Nexus 3K作为数据中心交换机,其ACL应用逻辑与路由器(如ASR1000v)存在核心差异:

  • 当流量的目的地址是设备自身的接口(如R2的loopback2)时,流量会直接进入设备的控制平面处理;
  • Nexus 3K上的入方向接口ACL仅对通过数据平面转发的流量生效,不会拦截发往控制平面的流量,因此原有ACL没有命中计数,流量依然正常通行。

解决办法

方案一:配置控制平面ACL(CoPP)拦截控制平面流量

在R2上配置CoPP,对发往自身loopback2的指定流量进行过滤:

  1. 创建匹配目标流量的控制平面类映射
class-map type control-plane match-any COPP-BLOCK-R1-TO-LB2
  match destination-address ipv4 2.2.2.2/32
  match source-address ipv4 1.1.1.1/32
  1. 创建策略映射,定义对匹配流量的动作
policy-map type control-plane COPP-POLICY
  class COPP-BLOCK-R1-TO-LB2
    drop
  class class-default
    police cir 1000000 bc 100000
    transmit
  1. 将策略映射应用到控制平面
control-plane
  service-policy input COPP-POLICY

方案二:将ACL应用到R1的出方向接口

修改ACL的应用位置,让流量在离开R1的数据平面时就被过滤,无需进入R2的控制平面:

! 在R1上执行以下配置
ip access-list r1r2
  statistics per-entry
  10 deny ip 1.1.1.1/32 2.2.2.2/32
  100 permit ip any any
!
interface Ethernet1/1
  ip access-group r1r2 out

内容的提问来源于stack exchange,提问作者Wukong

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 05:10:08