vlan之间拒绝互访配置实例

步骤一、定义 vlan30拒绝互通的网段,然后在最后一条配置允许所有到所有的规则
ip access-list extended vlan30

    12 permit ip host 172.24.30.13 host 172.24.39.40

    31 deny ip 172.24.30.0 0.0.0.255 172.24.31.0 0.0.0.255 

    32 deny ip 172.24.30.0 0.0.0.255 172.24.32.0 0.0.0.255

    100 permit ip 172.24.30.0 0.0.0.255 any 


步骤二、将定义的ACL应用在vlan接口下

interface Vlan30

ip address 172.24.30.1 255.255.255.0

ip access-group vlan30 in

你可能感兴趣的:(vlan之间拒绝互访配置实例)