您好,请知:
要实现2台PC能通到路由器及两台电脑不能互通,首先需要基础网络互通,再通过ACL进行限制,以下是配置过程(配置过程仅供参考):
1、LSW1配置过程:(配置要点:创建VLAN,并划分到相应接口为PC接入做准备,并向上透传)
vlan 10
quit
vlan 20
quit
int gi 0/0/1
port link-type access
port access vlan 10
quit
int gi 0/0/2
port link-type access
port access vlan 20
quit
int gi 0/0/3
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 10 20
quit
2、LSW2配置过程:(配置要点:创建VLAN,做好透传)
vlan 10
quit
vlan 20
quit
int range gi 0/0/1 to gi 0/0/2
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 10 20
quit
3、路由器配置:(配置要点:创建单臂路由,为各pc接入提供网关,同时通过ACL实现两台PC之间不能互访)
int gi 0/0.1
[H3C-GigabitEthernet0/0.1]vlan-type dot1q vid 10
[H3C-GigabitEthernet0/0.1]ip address 192.168.1.254 24
[H3C-GigabitEthernet0/0.1]quit
[H3C]int gi 0/0.2
[H3C-GigabitEthernet0/0.2]vlan-type dot1q vid 20
[H3C-GigabitEthernet0/0.2]ip address 192.168.2.254 24
[H3C-GigabitEthernet0/0.2]quit
[H3C]acl advanced 3000
[H3C-acl-ipv4-adv-3000]rule 0 deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255
[H3C-acl-ipv4-adv-3000]rule 1 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
[H3C]int gi 0/0.1
[H3C-GigabitEthernet0/0.1]packet-filter 3000 inbound
[H3C-GigabitEthernet0/0.1]quit
[H3C]int gi 0/0.2
[H3C-GigabitEthernet0/0.2]packet-filter 3000 inbound
[H3C-GigabitEthernet0/0.2]quit
[H3C]
您在检查下配置,我的这个只是参考