您好,请知:
可通过acl去禁止这3个vlan的互通。具体操作如下:
假设:
vlan 10采用192.168.10.0/24
vlan 20采用192.168.20.0/24
vlan 30采用192.168.30.0/24
使用acl禁止互访:
acl number 3000
rule 0 deny ip source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
rule 1 deny ip source 192.168.10.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
rule 2 deny ip source 192.168.20.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
quit
将acl应用到vlan下:
int vlan 10
packet-filter 3000 inbound
packet-filter 3000 outbound
quit
int vlan 20
packet-filter 3000 inbound
packet-filtet 3000 outbound
quit
int vlan 30
packet-filter 3000 inbound
packet-filter 3000 outbound
quit
暂无评论