交换机1、交换机2接路由器1,路由器1出外网,交换机1有vlan2 3 ,交换机2有vlan 4 5,路由器通过子接口接交换机vlan,路由器余外网和vlan网段都在ospf路由表里,,如何用ACL使得vlan2与vlan4通不与vlan5通,vlan3与vlan5通不与vlan4通
交换机1、交换机2接路由器1,路由器1出外网,交换机1有vlan2 3 ,交换机2有vlan 4 5,路由器通过子接口接交换机vlan,路由器余外网和vlan网段都在ospf路由表里,,如何用ACL使得vlan2与vlan4通不与vlan5通,vlan3与vlan5通不与vlan4通
(0)
在网关处套用ACL过滤就行了
(0)
网关是在路由器的子接口,我做的限制在子接口上绑定ACL,但是还是所有vlan能互相通信
网关配在子接口上,在子接口上绑定ACL,所有vlan网关还是能通
acl adv 3000 rule 1 deny ip source 192.168.110.0 0.0.0.15 destination 192.168.122.0 0.0.0.15 rule 2 deny ip source 192.168.110.0 0.0.0.15 destination 192.168.122.16 0.0.0.15 rule 3 deny ip source 192.168.110.0 0.0.0.15 destination 192.168.122.32 0.0.0.15
interface GigabitEthernet0/2.101 ip address 192.168.110.14 255.255.255.240 packet-filter 3000 inbound vlan-type dot1q vid 101
acl adv 3000 rule 1 deny ip source 192.168.110.0 0.0.0.15 destination 192.168.122.0 0.0.0.15 rule 2 deny ip source 192.168.110.0 0.0.0.15 destination 192.168.122.16 0.0.0.15 rule 3 deny ip source 192.168.110.0 0.0.0.15 destination 192.168.122.32 0.0.0.15
interface GigabitEthernet0/2.101 ip address 192.168.110.14 255.255.255.240 packet-filter 3000 inbound vlan-type dot1q vid 101
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
interface GigabitEthernet0/2.101 ip address 192.168.110.14 255.255.255.240 packet-filter 3000 inbound vlan-type dot1q vid 101