CPUDEFEND/4/SECACL

Message

CPUDEFEND/4/SECACL: The acl rule cannot be delivered on this board. (ChassisId=[ChassisId],SlotId=[SlotId],Reason=[Reason])

In VS mode, this log is supported only by the admin VS.

Description

The ACL rule did not take effect on a board.

Parameters

Parameter Name Parameter Meaning

ChassisId

Chassis ID

SlotId

Slot ID

Reason

Cause of the ACL rule being ineffective:

  • The address pool was not enabled.
  • The vpn-instance configuration item was not supported.
  • The time range configuration item was not supported.

Possible Causes

The attack defense policy applied to the board contained the port and address pool configuration, but the address pool was not enabled.

Procedure

1. Run the display cpu-defend policy policy-number command in any view to check the rule configuration in the attack defense policy.

2. Run the display acl {acl-number | all} command in any view to check information about a specified ACL or all ACL rules and packet matching statistics. Check whether unsupported rules are configured.

  • If yes, go to Step 3.
  • If no, go to Step 4.

3. Run the undo rule rule-id command in the advanced ACL view to delete unsupported rules. Wait for 10 minutes and check whether the log is generated again.

  • If yes, go to Step 4.
  • If no, go to Step 5.

4. Collect trap, log, and configuration information, and contact Huawei technical support personnel.

5. End.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >