ACL可以这样写:
acl number 3000
rule 5 permit ip source 192.168.33.0 0.0.0.255 destination 192.168.142.106 0
rule 10 deny ip source 192.168.33.0 0.0.0.255 destination 192.168.142.0 0.0.0.255
rule 15 permit ip
然后在vlan下启用ACL:
interface vlan 33(192.168.33.0/24所在的vlan接口,在vlan 接口下,启用上面定义的规则)
packet-filter inbound ip-group 3000
rule 5是允许33段访问服务器host地址;rule 10是拒绝2个网段互访;rule 15是允许上网。
架设是vlan1 192.168.0.0/24
acl nu 3000
rule 10 deny ip sou 192.168.1.0 0.0.0.255 des 192.168.2.0 0.0.0.255
rule 20 deny ip sou 192.168.1.0 0.0.0.255 des 192.168.3.0 0.0.0.255
rule 30 deny ip sou 192.168.2.0 0.0.0.255 des 192.168.0.0 0.0.0.255
rule 40 deny ip sou 192.168.2.0 0.0.0.255 des 192.168.3.0 0.0.0.255
rule 50 deny ip sou 192.168.3.0 0.0.0.255 des 192.168.0.0 0.0.0.255
int vlan 10
packet-fi 3000 in
int vlan 20
packet-fi 3000 in
int vlan 30
packet-fi 3000 in
本文链接:https://www.kinber.cn/post/1950.html 转载需授权!
推荐本站淘宝优惠价购买喜欢的宝贝: