在以下场景中,安全级别50(dmz-1) 到安全级别75(dmz-2) 跟踪路由不起作用。我认为 traceroute 使用特定端口来实现无法访问的功能,但在以下场景中,我不知道它将选择哪个 udp 端口。
我有以下配置
access-list DMZ-1-IN extended permit icmp any any unreachable
access-list DMZ-1-IN extended permit icmp any any time-exceeded
access-list DMZ-1-IN extended permit icmp any any traceroute
!
access-group DMZ-1-IN in interface dmz-1
!
class class-default
set connection decrement-ttl
更新:
这是日志
Oct 20 2017 09:47:04: %ASA-4-106023: Deny udp src dmz-1:10.5.8.40/48236 dst dmz-1:10.5.16.40/33434 by access-group "DMZ-1-IN" [0x0, 0x0]
Oct 20 2017 09:47:04: %ASA-4-106023: Deny udp src dmz-2:10.5.8.40/53052 dst dmz-2:10.5.16.40/33435 by access-group "DMZ-1-IN" [0x0, 0x0]
