Error: The ACL group 3000 is in use, deletion forbidden!
删除acl3000时候提示这个信息,那么查询一下吧,是被什么调用的
[lsw1]display current-configuration 执行查询命令
#
sysname lsw1
#
undo info-center enable
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
acl number 3000
rule 5 deny ip source 192.168.10.1 0 destination 192.168.10.3 0 创建的acl3000
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
traffic-filter outbound acl 3000 端口3调用了acl3000
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
traffic-filter inbound acl 3000
#
user-interface con 0
user-interface vty 0 4
#
return
既然发现了ACL3000被端口3调用了,那么去端口3里面删除调用
[lsw1]interface GigabitEthernet 0/0/3 进入端口3
[lsw1-GigabitEthernet0/0/3]undo traffic-filter outbound acl 3000 删除acl3000的应用
这时候在视图模式下,在执行undo acl 3000
[lsw1]undo acl 3000
Error: The ACL group 3000 is in use, deletion forbidden!
还是不让删除,那么问题出在哪里呢?好多新手找不到原因,就是反复查询都没找到,大家返回上方,看我标注红色部分的acl调用,这个是在视图模式下直接调用的,虽然和端口调用重复,但是策略规则还是好使的,有的可能是误操作,有的可能是工程师开始做的后期没用删除,总之在视图模式下删除这个调用就可以删除ACL3000了。
[lsw1]undo traffic-filter inbound acl 3000 删除视图下的acl 3000 调用
[lsw1]undo acl 3000 删除acl3000 这回就没有报错了吧
[lsw1]
[lsw1]display this 查询一下,发现就没有acl3000信息了,证明已经被删除掉
[lsw1]display this
#
sysname lsw1
#
undo info-center enable
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
return
[lsw1]