问题描述:
问题描述:
三层S5500划分了三个vlan vlan10 192.168.0.1 vlan20 192.168.1.1 vlan30 192.168.2.1需求是vlan10 vlan20不能互相访问但是可以同时访问vlan30这个需求如何用acl访问控制实现 我用了下面这些命令不成功啊 总是全通
组网及组网描述:
vlan 10
port g1/0/10
vlan 20
port g1/0/20
vlan 30
port g1/0/1
int vlan-interface 10
ip address 192.168.0.1 255.255.255.0
int vlan-interface 20
ip address 192.168.1.1 255.255.255.0
int vlan-interface 30
ip address 192.168.2.1 255.255.255.0
acl advanced 3000
ru 10 per ip so 192.168.0.0 0.0.255.255 des 192.168.3.0 0.0.0.255
ru 100 den ip so 192.168.0.0 0.0.255.255 des 192.168.0.0 0.0.255.255
ru 1000 per ip
int vlan 10
packet-fi 3000 in
int vlan 20
packet-fi 3000 in
暂无评论