Cisco交换机,使用sh ip access-lists命令后,每一台主机后面有个(1 match),这个是什么意思?

SW3750V2#sh ip access-lists
Extended IP access list ip_acl_out
50 permit ip host 192.168.40.2 any
60 permit ip host 192.168.40.3 any
70 permit ip host 192.168.40.5 any (1 match)
80 permit ip host 192.168.40.6 any
90 permit ip host 192.168.40.7 any (1 match)
240 permit ip host 192.168.20.8 any (1 match)
330 permit ip host 192.168.30.12 any (1 match)
350 permit ip host 192.168.30.15 any (1 match)
370 permit ip host 192.168.30.17 any
380 permit ip host 192.168.30.18 any (1 match)
400 permit ip host 192.168.30.20 any (1 match)
420 permit ip host 192.168.20.9 any
430 permit ip host 192.168.10.4 any
440 permit ip host 192.168.10.3 any
450 permit ip host 192.168.10.5 any
470 permit ip host 192.168.20.10 any
480 permit ip host 192.168.20.2 any
490 permit ip host 192.168.30.16 any
500 permit ip host 192.168.30.19 any
510 permit ip host 192.168.20.11 any
520 permit ip host 192.168.10.253 any
530 permit ip host 192.168.30.14 any
540 permit ip host 192.168.30.21 any
550 permit ip host 192.168.40.14 any (3 matches)
560 permit ip host 192.168.20.22 any

70 permit ip host 192.168.40.5 any (1 match)这条命令后面的1match的意思是匹配到了1个从主机192.168.40.5 到任意目的IP的IP包
温馨提示:答案为网友推荐,仅供参考
第1个回答  2014-07-07
就是有流量匹配了这个条ACL