see #2352 test case

This commit is contained in:
Vadim Kurland
2011-04-15 16:17:13 -07:00
parent 7260649b16
commit c51a8123c8
3 changed files with 25 additions and 23 deletions
+11 -11
View File
@@ -1,6 +1,6 @@
<?xml version="1.0" encoding="utf-8"?> <?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE FWObjectDatabase SYSTEM "fwbuilder.dtd"> <!DOCTYPE FWObjectDatabase SYSTEM "fwbuilder.dtd">
<FWObjectDatabase xmlns="http://www.fwbuilder.org/1.0/" version="18" lastModified="1301288681" id="root"> <FWObjectDatabase xmlns="http://www.fwbuilder.org/1.0/" version="18" lastModified="1302909350" id="root">
<Library id="syslib000" color="#d4f8ff" name="Standard" comment="Standard objects" ro="True"> <Library id="syslib000" color="#d4f8ff" name="Standard" comment="Standard objects" ro="True">
<AnyNetwork id="sysid0" name="Any" comment="Any Network" ro="False" address="0.0.0.0" netmask="0.0.0.0"/> <AnyNetwork id="sysid0" name="Any" comment="Any Network" ro="False" address="0.0.0.0" netmask="0.0.0.0"/>
<AnyIPService id="sysid1" protocol_num="0" name="Any" comment="Any IP Service" ro="False"/> <AnyIPService id="sysid1" protocol_num="0" name="Any" comment="Any IP Service" ro="False"/>
@@ -435,14 +435,14 @@
<IPv4 id="id3" name="h-10.3.14.40" comment="Created during import of line 176" ro="False" address="10.3.14.40" netmask="255.255.255.255"/> <IPv4 id="id3" name="h-10.3.14.40" comment="Created during import of line 176" ro="False" address="10.3.14.40" netmask="255.255.255.255"/>
<IPv4 id="id4" name="h-192.168.171.2" comment="Created during import of line 176" ro="False" address="192.168.171.2" netmask="255.255.255.255"/> <IPv4 id="id4" name="h-192.168.171.2" comment="Created during import of line 176" ro="False" address="192.168.171.2" netmask="255.255.255.255"/>
<IPv4 id="id5" name="h-10.3.14.201" comment="Created during import of line 177" ro="False" address="10.3.14.201" netmask="255.255.255.255"/> <IPv4 id="id5" name="h-10.3.14.201" comment="Created during import of line 177" ro="False" address="10.3.14.201" netmask="255.255.255.255"/>
<IPv4 id="id6" name="h-192.168.171.1" comment="Created during import of line 250" ro="False" address="192.168.171.1" netmask="255.255.255.255"/> <IPv4 id="id6" name="h-192.168.171.1" comment="Created during import of line 252" ro="False" address="192.168.171.1" netmask="255.255.255.255"/>
<IPv4 id="id7" name="h-22.22.22.21" comment="Created during import of line 258" ro="False" address="22.22.22.21" netmask="255.255.255.255"/> <IPv4 id="id7" name="h-22.22.22.21" comment="Created during import of line 260" ro="False" address="22.22.22.21" netmask="255.255.255.255"/>
<IPv4 id="id8" name="h-22.23.24.25" comment="Created during import of line 259" ro="False" address="22.23.24.25" netmask="255.255.255.255"/> <IPv4 id="id8" name="h-22.23.24.25" comment="Created during import of line 261" ro="False" address="22.23.24.25" netmask="255.255.255.255"/>
</ObjectGroup> </ObjectGroup>
<ObjectGroup id="id9" name="DNS Names" comment="" ro="False"/> <ObjectGroup id="id9" name="DNS Names" comment="" ro="False"/>
<ObjectGroup id="id10" name="Address Tables" comment="" ro="False"/> <ObjectGroup id="id10" name="Address Tables" comment="" ro="False"/>
<ObjectGroup id="id11" name="Groups" comment="" ro="False"> <ObjectGroup id="id11" name="Groups" comment="" ro="False">
<ObjectGroup id="id12" name="intf-acl_133" comment="Created during import of line 261" ro="False"> <ObjectGroup id="id12" name="intf-acl_133" comment="Created during import of line 263" ro="False">
<ObjectRef ref="id263"/> <ObjectRef ref="id263"/>
<ObjectRef ref="id265"/> <ObjectRef ref="id265"/>
</ObjectGroup> </ObjectGroup>
@@ -451,9 +451,9 @@
<ObjectGroup id="id16" name="Networks" comment="" ro="False"> <ObjectGroup id="id16" name="Networks" comment="" ro="False">
<Network id="id17" name="net-10.3.14.0/255.255.255.0" comment="Created during import of line 178" ro="False" address="10.3.14.0" netmask="255.255.255.0"/> <Network id="id17" name="net-10.3.14.0/255.255.255.0" comment="Created during import of line 178" ro="False" address="10.3.14.0" netmask="255.255.255.0"/>
<Network id="id18" name="net-10.10.10.0/255.255.255.0" comment="Created during import of line 236" ro="False" address="10.10.10.0" netmask="255.255.255.0"/> <Network id="id18" name="net-10.10.10.0/255.255.255.0" comment="Created during import of line 236" ro="False" address="10.10.10.0" netmask="255.255.255.0"/>
<Network id="id19" name="net-10.2.1.0/255.255.255.0" comment="Created during import of line 246" ro="False" address="10.2.1.0" netmask="255.255.255.0"/> <Network id="id19" name="net-10.2.1.0/255.255.255.0" comment="Created during import of line 248" ro="False" address="10.2.1.0" netmask="255.255.255.0"/>
<Network id="id20" name="net-22.23.25.0/255.255.255.240" comment="Created during import of line 260" ro="False" address="22.23.25.0" netmask="255.255.255.240"/> <Network id="id20" name="net-22.23.25.0/255.255.255.240" comment="Created during import of line 262" ro="False" address="22.23.25.0" netmask="255.255.255.240"/>
<Network id="id21" name="net-10.0.0.0/255.0.0.0" comment="Created during import of line 261" ro="False" address="10.0.0.0" netmask="255.0.0.0"/> <Network id="id21" name="net-10.0.0.0/255.0.0.0" comment="Created during import of line 263" ro="False" address="10.0.0.0" netmask="255.0.0.0"/>
</ObjectGroup> </ObjectGroup>
<ObjectGroup id="id22" name="Address Ranges" comment="" ro="False"/> <ObjectGroup id="id22" name="Address Ranges" comment="" ro="False"/>
</ObjectGroup> </ObjectGroup>
@@ -501,7 +501,7 @@
<RuleSetOptions/> <RuleSetOptions/>
</NAT> </NAT>
<Policy id="id59" name="Policy" comment="" ro="False" ipv4_rule_set="False" ipv6_rule_set="False" top_rule_set="True"> <Policy id="id59" name="Policy" comment="" ro="False" ipv4_rule_set="False" ipv6_rule_set="False" top_rule_set="True">
<PolicyRule id="id61" disabled="False" group="" log="False" position="0" action="Accept" direction="Both" comment="Imported from acl_133&#10;Created during import of line 243"> <PolicyRule id="id61" disabled="False" group="" log="False" position="0" action="Accept" direction="Both" comment="Imported from acl_133&#10;Created during import of line 245">
<Src neg="False"> <Src neg="False">
<ObjectRef ref="id17"/> <ObjectRef ref="id17"/>
</Src> </Src>
@@ -521,7 +521,7 @@
<Option name="stateless">False</Option> <Option name="stateless">False</Option>
</PolicyRuleOptions> </PolicyRuleOptions>
</PolicyRule> </PolicyRule>
<PolicyRule id="id73" disabled="False" group="" log="False" position="1" action="Accept" direction="Both" comment="Imported from acl_133&#10;Created during import of line 244"> <PolicyRule id="id73" disabled="False" group="" log="False" position="1" action="Accept" direction="Both" comment="Imported from acl_133&#10;Created during import of line 246">
<Src neg="False"> <Src neg="False">
<ObjectRef ref="id18"/> <ObjectRef ref="id18"/>
</Src> </Src>
@@ -541,7 +541,7 @@
<Option name="stateless">False</Option> <Option name="stateless">False</Option>
</PolicyRuleOptions> </PolicyRuleOptions>
</PolicyRule> </PolicyRule>
<PolicyRule id="id85" disabled="False" group="" log="True" position="2" action="Deny" direction="Both" comment="Imported from acl_133&#10;Created during import of line 245"> <PolicyRule id="id85" disabled="False" group="" log="True" position="2" action="Deny" direction="Both" comment="Imported from acl_133&#10;Created during import of line 247">
<Src neg="False"> <Src neg="False">
<ObjectRef ref="sysid0"/> <ObjectRef ref="sysid0"/>
</Src> </Src>
@@ -57,23 +57,23 @@
234: access list rule: access list outside, action permit 234: access list rule: access list outside, action permit
236: access list rule: access list outside, action permit 236: access list rule: access list outside, action permit
237: access list rule: access list outside, action deny 237: access list rule: access list outside, action deny
240: access list rule: access list tmp_acl, action permit 242: access list rule: access list tmp_acl, action permit
241: access list rule: access list tmp_acl, action deny 243: access list rule: access list tmp_acl, action deny
243: access list rule: access list acl_133, action permit 245: access list rule: access list acl_133, action permit
244: access list rule: access list acl_133, action permit 246: access list rule: access list acl_133, action permit
245: access list rule: access list acl_133, action deny 247: access list rule: access list acl_133, action deny
246: access list rule: access list acl_144, action permit
247: access list rule: access list acl_144, action permit
248: access list rule: access list acl_144, action permit 248: access list rule: access list acl_144, action permit
249: access list rule: access list acl_144, action permit 249: access list rule: access list acl_144, action permit
250: access list rule: access list acl_144, action permit 250: access list rule: access list acl_144, action permit
251: access list rule: access list acl_144, action permit 251: access list rule: access list acl_144, action permit
252: access list rule: access list acl_144, action permit 252: access list rule: access list acl_144, action permit
253: access list rule: access list acl_144, action permit 253: access list rule: access list acl_144, action permit
254: access list rule: access list acl_199, action permit 254: access list rule: access list acl_144, action permit
255: access list rule: access list acl_199, action permit 255: access list rule: access list acl_144, action permit
257: Rule comment: Standard access lists are 1 to 99 and 1300 to 1999 256: access list rule: access list acl_199, action permit
258: access list rule: access list acl_1300, action permit 257: access list rule: access list acl_199, action permit
259: access list rule: access list acl_1300, action permit 259: Rule comment: Standard access lists are 1 to 99 and 1300 to 1999
260: access list rule: access list acl_1300, action permit 260: access list rule: access list acl_1300, action permit
261: access list rule: access list acl_1300, action permit 261: access list rule: access list acl_1300, action permit
262: access list rule: access list acl_1300, action permit
263: access list rule: access list acl_1300, action permit
@@ -236,6 +236,8 @@ ip access-list extended outside
permit tcp 10.10.10.0 0.0.0.255 eq 80 host 10.3.14.40 established time-range evening permit tcp 10.10.10.0 0.0.0.255 eq 80 host 10.3.14.40 established time-range evening
deny ip any any log deny ip any any log
!################################################################ !################################################################
! empty access list declaration
ip access-list extended foo
ip access-list extended tmp_acl ip access-list extended tmp_acl
permit ip 10.3.14.0 0.0.0.255 any permit ip 10.3.14.0 0.0.0.255 any
deny ip any any deny ip any any