nat conne
source-ip dest-ip dest-port vpn-instance
192.168.0.11 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
2 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.10 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
6 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.3 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
1 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.23 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
9 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.24 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
3 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.20 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
2 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.22 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
8 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.17 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
7 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.13 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
2 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.15 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
1 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.36 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
1 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.29 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
10 10 9 1
source-ip dest-ip dest-port vpn-instance
192.168.0.31 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
1 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.48 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
2 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.45 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
4 10 9 0
source-ip dest-ip dest-port vpn-instance
192.168.0.39 --- --- ---
-------------------------------------------------------------------------------
NAT amount upper-limit lower-limit limit-flag
1 10 9 0
<TYS-ZongGongHui-AR28-11> dis acl all
Total ACL Number: 3
Basic ACL 2000, 2 rules, match-order is auto
Acl's step is 1
rule 1 permit source 192.168.0.0 0.0.0.255 (6210378 times matched)
rule 10 deny (0 times matched)
Advanced ACL 3001, 110 rules
WAN-WaiWang
Acl's step is 1
rule 0 deny tcp source-port eq 67 destination-port eq 9996 (0 times matched)
rule 1 deny tcp source-port range 135 139 (0 times matched)
rule 2 deny tcp source-port eq 138 destination-port eq 445 (0 times matched)
rule 3 deny tcp source-port eq 445 destination-port eq 135 (0 times matched)
rule 4 deny tcp source-port eq 445 (0 times matched)
rule 5 deny tcp source-port eq 555 (0 times matched)
rule 6 deny tcp source-port eq 593 (0 times matched)
rule 7 deny tcp source-port range 1022 1025 (9 times matched)
rule 8 deny tcp source-port eq 1034 destination-port eq www (2 times matched)
rule 9 deny tcp source-port eq 1068 (4 times matched)
rule 10 deny tcp source-port range 1433 1434 (13 times matched)
rule 12 deny tcp source-port eq 1871 (6 times matched)
rule 13 deny tcp source-port eq 2745 (3 times matched)
rule 14 deny tcp source-port eq 3127 (7 times matched)
rule 15 deny tcp source-port eq 3127 destination-port eq 1434 (0 times matched)
rule 16 deny tcp source-port eq 3208 (14 times matched)
rule 17 deny tcp source-port range 4331 4334 (28 times matched)
rule 18 deny tcp source-port eq 4444 (4 times matched)
rule 19 deny tcp source-port eq 4510 (11 times matched)
rule 20 deny tcp source-port eq 4557 (7 times matched)
rule 21 deny tcp source-port eq 5554 (0 times matched)
rule 22 deny tcp source-port eq 5554 destination-port range 9995 9996 (0 times matched)
rule 23 deny tcp source-port eq 5800 (0 times matched)
rule 24 deny tcp source-port eq 5900 (6 times matched)
rule 25 deny tcp source-port eq 6129 (0 times matched)
rule 26 deny tcp source-port eq 6667 (4 times matched)
rule 27 deny tcp source-port eq 8998 (0 times matched)
rule 28 deny tcp source-port range 9995 9996 (0 times matched)
rule 29 deny tcp source-port eq 10080 (0 times matched)
rule 30 deny tcp destination-port eq 8 (0 times matched)
rule 31 deny tcp destination-port eq 69 (0 times matched)
rule 32 deny tcp destination-port eq www (12764 times matched)
rule 33 deny tcp destination-port eq ftp (5 times matched)
rule 34 deny tcp destination-port eq exec (0 times matched)
rule 35 deny tcp destination-port range 133 139 (2950 times matched)
rule 36 deny tcp destination-port eq 445 (1398 times matched)
rule 37 deny tcp destination-port eq 539 (0 times matched)
rule 38 deny tcp destination-port eq 593 (0 times matched)
rule 39 deny tcp destination-port eq 707 (0 times matched)
rule 40 deny tcp destination-port range 1022 1025 (4 times matched)
rule 41 deny tcp destination-port eq 1068 (0 times matched)
rule 42 deny tcp destination-port eq 1080 (1232 times matched)
rule 43 deny tcp destination-port eq 1334 (765 times matched)
rule 44 deny tcp destination-port range 1433 1434 (700 times matched)
rule 45 deny tcp destination-port eq 1871 (0 times matched)
rule 46 deny tcp destination-port eq 1978 (414 times matched)
rule 47 deny tcp destination-port eq 2710 (265 times matched)
rule 48 deny tcp destination-port eq 2745 (0 times matched)
rule 49 deny tcp destination-port range 3127 3128 (355 times matched)
rule 50 deny tcp destination-port eq 3208 (0 times matched)
rule 51 deny tcp destination-port eq 3389 (377 times matched)
rule 52 deny tcp destination-port range 4331 4334 (0 times matched)
rule 53 deny tcp destination-port eq 4444 (0 times matched)
rule 54 deny tcp destination-port eq 4510 (0 times matched)
rule 55 deny tcp destination-port eq 4557 (0 times matched)
rule 56 deny tcp destination-port range 4661 4662 (254 times matched)
rule 57 deny tcp destination-port eq 4899 (361 times matched)
rule 58 deny tcp destination-port range 5554 5556 (1 times matched)
rule 59 deny tcp destination-port eq 5800 (0 times matched)
rule 60 deny tcp destination-port eq 5900 (130 times matched)
rule 61 deny tcp destination-port eq 6129 (0 times matched)
rule 62 deny tcp destination-port eq 6588 (1 times matched)
rule 63 deny tcp destination-port eq 6667 (2 times matched)
rule 64 deny tcp destination-port range 6881 6889 (0 times matched)
rule 65 deny tcp destination-port eq 6969 (0 times matched)
rule 66 deny tcp destination-port eq 8080 (564 times matched)
rule 67 deny tcp destination-port range 8881 8999 (3 times matched)
rule 68 deny tcp destination-port range 9995 9996 (0 times matched)
rule 69 deny tcp destination-port eq 10080 (0 times matched)
rule 70 deny tcp destination-port eq 10137 (0 times matched)
rule 71 deny tcp destination-port eq 16881 (0 times matched)
rule 72 deny tcp destination-port eq 64444 (0 times matched)
rule 73 deny tcp destination-port eq sunrpc (2 times matched)
rule 74 deny udp source-port eq 135 (0 times matched)
rule 75 deny udp source-port eq 445 (0 times matched)
rule 76 deny udp source-port eq 1068 (210 times matched)
rule 77 deny udp source-port range 1433 1434 (62 times matched)
rule 78 deny udp source-port eq 1434 destination-port eq 135 (0 times matched)
rule 79 deny udp source-port eq bootps (0 times matched)
rule 80 deny udp source-port eq netbios-ns (75 times matched)
rule 81 deny udp source-port eq netbios-ssn (0 times matched)
rule 82 deny udp source-port eq netbios-ssn destination-port eq 445 (0 times matched)
rule 83 deny udp source-port eq netbios-dgm (0 times matched)
rule 84 deny udp destination-port range 133 136 (0 times matched)
rule 85 deny udp destination-port eq 389 (0 times matched)
rule 86 deny udp destination-port eq 445 (0 times matched)
rule 87 deny udp destination-port eq 539 (0 times matched)
rule 88 deny udp destination-port eq 593 (0 times matched)
rule 89 deny udp destination-port eq 1025 (11472 times matched)
rule 90 deny udp destination-port eq 1334 (16 times matched)
rule 91 deny udp destination-port range 1433 1434 (93 times matched)
rule 92 deny udp destination-port eq 3500 (0 times matched)
rule 93 deny udp destination-port eq 4665 (1 times matched)
rule 94 deny udp destination-port eq 4672 (0 times matched)
rule 95 deny udp destination-port eq 5556 (0 times matched)
rule 96 deny udp destination-port range 6881 6889 (63 times matched)
rule 97 deny udp destination-port eq 9996 (0 times matched)
rule 98 deny udp destination-port eq snmp (0 times matched)
rule 99 deny udp destination-port eq tftp (0 times matched)
rule 100 deny udp destination-port eq netbios-ns (159 times matched)
rule 101 deny udp destination-port eq netbios-dgm (0 times matched)
rule 102 deny udp destination-port eq netbios-ssn (0 times matched)
rule 103 permit icmp icmp-type echo (9293 times matched)
rule 104 permit icmp icmp-type echo-reply (124 times matched)
rule 105 permit icmp icmp-type ttl-exceeded (5971 times matched)
rule 106 deny icmp (325193 times matched)
rule 107 permit ip destination 28.236.9.100 0.0.0.3 (561501 times matched)
rule 108 permit ip destination 192.168.0.0 0.0.0.255 (31681651 times matched)
rule 2000 deny ip (0 times matched)
rule 2001 deny udp destination-port eq 13945 (0 times matched)
Advanced ACL 3002, 108 rules
LAN-NeiWang
Acl's step is 1
rule 0 deny tcp source-port eq 67 destination-port eq 9996 (0 times matched)
rule 1 deny tcp source-port range 135 139 (0 times matched)
rule 2 deny tcp source-port eq 138 destination-port eq 445 (0 times matched)
rule 3 deny tcp source-port eq 445 destination-port eq 135 (0 times matched)
rule 4 deny tcp source-port eq 445 (0 times matched)
rule 5 deny tcp source-port eq 555 (0 times matched)
rule 6 deny tcp source-port eq 593 (0 times matched)
rule 7 deny tcp source-port range 1022 1025 (9 times matched)
rule 8 deny tcp source-port eq 1034 destination-port eq www (0 times matched)
rule 9 deny tcp source-port eq 1068 (0 times matched)
rule 10 deny tcp source-port range 1433 1434 (177 times matched)
rule 12 deny tcp source-port eq 1871 (0 times matched)
rule 13 deny tcp source-port eq 2745 (0 times matched)
rule 14 deny tcp source-port eq 3127 (0 times matched)
rule 15 deny tcp source-port eq 3127 destination-port eq 1434 (0 times matched)
rule 16 deny tcp source-port eq 3208 (0 times matched)
rule 17 deny tcp source-port range 4331 4334 (134 times matched)
rule 18 deny tcp source-port eq 4444 (0 times matched)
rule 19 deny tcp source-port eq 4510 (0 times matched)
rule 20 deny tcp source-port eq 4557 (0 times matched)
rule 21 deny tcp source-port eq 5554 (0 times matched)
rule 22 deny tcp source-port eq 5554 destination-port range 9995 9996 (0 times matched)
rule 23 deny tcp source-port eq 5800 (0 times matched)
rule 24 deny tcp source-port eq 5900 (0 times matched)
rule 25 deny tcp source-port eq 6129 (0 times matched)
rule 26 deny tcp source-port eq 6667 (0 times matched)
rule 27 deny tcp source-port eq 8998 (0 times matched)
rule 28 deny tcp source-port range 9995 9996 (0 times matched)
rule 29 deny tcp source-port eq 10080 (0 times matched)
rule 30 deny tcp destination-port eq 8 (0 times matched)
rule 31 deny tcp destination-port eq 69 (0 times matched)
rule 33 deny tcp destination-port eq ftp (10623 times matched)
rule 34 deny tcp destination-port eq exec (0 times matched)
rule 35 deny tcp destination-port range 133 139 (0 times matched)
rule 36 deny tcp destination-port eq 445 (0 times matched)
rule 37 deny tcp destination-port eq 539 (0 times matched)
rule 38 deny tcp destination-port eq 593 (0 times matched)
rule 39 deny tcp destination-port eq 707 (0 times matched)
rule 40 deny tcp destination-port range 1022 1025 (3 times matched)
rule 41 deny tcp destination-port eq 1068 (0 times matched)
rule 42 deny tcp destination-port eq 1080 (0 times matched)
rule 43 deny tcp destination-port eq 1334 (0 times matched)
rule 44 deny tcp destination-port range 1433 1434 (0 times matched)
rule 45 deny tcp destination-port eq 1871 (0 times matched)
rule 46 deny tcp destination-port eq 1978 (0 times matched)
rule 47 deny tcp destination-port eq 2710 (0 times matched)
rule 48 deny tcp destination-port eq 2745 (0 times matched)
rule 49 deny tcp destination-port range 3127 3128 (0 times matched)
rule 50 deny tcp destination-port eq 3208 (0 times matched)
rule 51 deny tcp destination-port eq 3389 (0 times matched)
rule 52 deny tcp destination-port range 4331 4334 (0 times matched)
rule 53 deny tcp destination-port eq 4444 (0 times matched)
rule 54 deny tcp destination-port eq 4510 (0 times matched)
rule 55 deny tcp destination-port eq 4557 (0 times matched)
rule 56 deny tcp destination-port range 4661 4662 (0 times matched)
rule 57 deny tcp destination-port eq 4899 (0 times matched)
rule 58 deny tcp destination-port range 5554 5556 (0 times matched)
rule 59 deny tcp destination-port eq 5800 (0 times matched)
rule 60 deny tcp destination-port eq 5900 (0 times matched)
rule 61 deny tcp destination-port eq 6129 (0 times matched)
rule 62 deny tcp destination-port eq 6588 (0 times matched)
rule 63 deny tcp destination-port eq 6667 (0 times matched)
rule 64 deny tcp destination-port range 6881 6889 (0 times matched)
rule 65 deny tcp destination-port eq 6969 (0 times matched)
rule 66 deny tcp destination-port eq 8080 (0 times matched)
rule 67 deny tcp destination-port range 8881 8999 (66351 times matched)
rule 68 deny tcp destination-port range 9995 9996 (0 times matched)
rule 69 deny tcp destination-port eq 10080 (0 times matched)
rule 70 deny tcp destination-port eq 10137 (0 times matched)
rule 71 deny tcp destination-port eq 16881 (0 times matched)
rule 72 deny tcp destination-port eq 64444 (0 times matched)
rule 73 deny tcp destination-port eq sunrpc (0 times matched)
rule 74 deny udp source-port eq 135 (0 times matched)
rule 75 deny udp source-port eq 445 (0 times matched)
rule 76 deny udp source-port eq 1068 (0 times matched)
rule 77 deny udp source-port range 1433 1434 (13 times matched)
rule 78 deny udp source-port eq 1434 destination-port eq 135 (0 times matched)
rule 79 deny udp source-port eq bootps (0 times matched)
rule 80 deny udp source-port eq netbios-ns (0 times matched)
rule 81 deny udp source-port eq netbios-ssn (0 times matched)
rule 82 deny udp source-port eq netbios-ssn destination-port eq 445 (0 times matched)
rule 83 deny udp source-port eq netbios-dgm (0 times matched)
rule 84 deny udp destination-port range 133 136 (0 times matched)
rule 85 deny udp destination-port eq 389 (0 times matched)
rule 86 deny udp destination-port eq 445 (0 times matched)
rule 87 deny udp destination-port eq 539 (0 times matched)
rule 88 deny udp destination-port eq 593 (0 times matched)
rule 89 deny udp destination-port eq 1025 (415 times matched)
rule 90 deny udp destination-port eq 1334 (178 times matched)
rule 91 deny udp destination-port range 1433 1434 (2929 times matched)
rule 92 deny udp destination-port eq 3500 (65 times matched)
rule 93 deny udp destination-port eq 4665 (100 times matched)
rule 94 deny udp destination-port eq 4672 (64 times matched)
rule 95 deny udp destination-port eq 5556 (6 times matched)
rule 96 deny udp destination-port range 6881 6889 (128 times matched)
rule 97 deny udp destination-port eq 9996 (54 times matched)
rule 98 deny udp destination-port eq snmp (0 times matched)
rule 99 deny udp destination-port eq tftp (0 times matched)
rule 100 deny udp destination-port eq netbios-ns (0 times matched)
rule 101 deny udp destination-port eq netbios-dgm (0 times matched)
rule 102 deny udp destination-port eq netbios-ssn (0 times matched)
rule 103 permit icmp icmp-type echo (374 times matched)
rule 104 permit icmp icmp-type echo-reply (0 times matched)
rule 105 permit icmp icmp-type ttl-exceeded (0 times matched)
rule 106 deny icmp (0 times matched)
rule 2000 permit ip source 192.168.0.0 0.0.0.255 (35832890 times matched)
rule 3000 deny ip (103632 times matched)
rule 3001 deny udp destination-port eq 13945 (0 times matched)
<TYS-ZongGongHui-AR28-11>
[ 本帖最后由 ATWX 于 2007-9-30 10:47 编辑 ]