如图所示,希望实现企业外来访客、企业员工都能够访问企业服务器,而企业同部门员工可以通信,不同部门员工不能通信;企业外来访客间不能通信;企业外来访客和企业员工之间不能互访。
PC1(1.1.1.1/24)
PC2(1.1.1.2/24)
PC3(1.1.1.3/24)
PC4(1.1.1.4/24)
PC5(1.1.1.5/24)
PC6(1.1.1.6/24)
PC7(1.1.1.7/24)
PC8(1.1.1.8/24)
Server1(1.1.1.9/24)
[Huawei]sysname SWB
[SWB]vlan batch 10 20 30 40
[SWB]vlan 10
[SWB-vlan10]description Financial VlAN
[SWB-vlan10]qu
[SWB]vlan 20
[SWB-vlan20]description Marketing VLAN
[SWB-vlan20]qu
[SWB]vlan 30
[SWB-vlan30]description Client VLAN
[SWB-vlan30]qu
[SWB]vlan 40
[SWB-vlan40]description Principal VLAN
[SWB-vlan40]mux-vlan
[SWB-vlan40]subordinate separate 30
[SWB-vlan40]subordinate group 10 20
[SWB-vlan40]qu
[SWB]interface GigabitEthernet 0/0/1
[SWB-GigabitEthernet0/0/1]port link-type trunk
[SWB-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 30 40
[SWB-GigabitEthernet0/0/1]qu
[SWB]interface GigabitEthernet 0/0/3
[SWB-GigabitEthernet0/0/3]port link-type trunk
[SWB-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20 30 40
[SWB-GigabitEthernet0/0/3]qu
[SWB]interface GigabitEthernet 0/0/2
[SWB-GigabitEthernet0/0/2]port link-type access
[SWB-GigabitEthernet0/0/2]port default vlan 40
[SWB-GigabitEthernet0/0/2]port mux-vlan enable
[SWB-GigabitEthernet0/0/2]qu
[Huawei]sysname SWC
[SWC]vlan batch 10 20 30 40
[SWC]vlan 10
[SWC-vlan10]description Financial VlAN
[SWC-vlan10]qu
[SWC]vlan 20
[SWC-vlan20]description Marketing VLAN
[SWC-vlan20]qu
[SWC]vlan 30
[SWC-vlan30]description Client VLAN
[SWC-vlan30]qu
[SWC]vlan 40
[SWC-vlan40]description Principal VLAN
[SWC-vlan40]mux-vlan
[SWC-vlan40]subordinate separate 30
[SWC-vlan40]subordinate group 10 20
[SWC-vlan40]qu
[SWC]interface Eth0/0/2
[SWC-Ethernet0/0/2]port link-type trunk
[SWC-Ethernet0/0/2]port trunk allow-pass vlan 10 20 30 40
[SWC-Ethernet0/0/2]qu
[SWC]interface Eth0/0/1
[SWC-Ethernet0/0/1]port link-type access
[SWC-Ethernet0/0/1]port default vlan 10
[SWC-Ethernet0/0/1]port mux-vlan enable
[SWC-Ethernet0/0/1]qu
[SWC]interface Eth0/0/3
[SWC-Ethernet0/0/3]port link-type access
[SWC-Ethernet0/0/3]port default vlan 10
[SWC-Ethernet0/0/3]port mux-vlan enable
[SWC-Ethernet0/0/3]qu
[SWC]interface Eth0/0/4
[SWC-Ethernet0/0/4]port link-type access
[SWC-Ethernet0/0/4]port default vlan 20
[SWC-Ethernet0/0/4]port mux-vlan enable
[SWC-Ethernet0/0/4]qu
[SWC]interface Eth0/0/5
[SWC-Ethernet0/0/5]port link-type access
[SWC-Ethernet0/0/5]port default vlan 20
[SWC-Ethernet0/0/5]port mux-vlan enable
[SWC-Ethernet0/0/5]qu
[Huawei]sysname SWD
[SWD]vlan batch 10 20 30 40
[SWD]vlan 10
[SWD-vlan10]description Financial VlAN
[SWD-vlan10]qu
[SWD]vlan 20
[SWD-vlan20]description Marketing VLAN
[SWD-vlan20]qu
[SWD]vlan 30
[SWD-vlan30]description Client VLAN
[SWD-vlan30]qu
[SWD]vlan 40
[SWD-vlan40]description Principal VLAN
[SWD-vlan40]mux-vlan
[SWD-vlan40]subordinate separate 30
[SWD-vlan40]subordinate group 10 20
[SWD-vlan40]qu
[SWD]interface Eth0/0/1
[SWD-Ethernet0/0/1]port link-type trunk
[SWD-Ethernet0/0/1]port trunk allow-pass vlan 10 20 30 40
[SWD-Ethernet0/0/1]qu
[SWD]interface Eth0/0/2
[SWD-Ethernet0/0/2]port link-type access
[SWD-Ethernet0/0/2]port default vlan 30
[SWD-Ethernet0/0/2]port mux-vlan enable
[SWD-Ethernet0/0/2]qu
[SWD]interface Eth0/0/3
[SWD-Ethernet0/0/3]port link-type access
[SWD-Ethernet0/0/3]port default vlan 30
[SWD-Ethernet0/0/3]port mux-vlan enable
[SWD-Ethernet0/0/3]qu
[SWD]interface Eth0/0/4
[SWD-Ethernet0/0/4]port link-type access
[SWD-Ethernet0/0/4]port default vlan 30
[SWD-Ethernet0/0/4]port mux-vlan enable
[SWD-Ethernet0/0/4]qu
[SWD]interface Eth0/0/5
[SWD-Ethernet0/0/5]port link-type access
[SWD-Ethernet0/0/5]port default vlan 30
[SWD-Ethernet0/0/5]port mux-vlan enable
[SWD-Ethernet0/0/5]qu