
实验目的: 实现vlan 10 和vlan 20无法互通,vlan 10 和vlan 30之间访问正常.
#
vlan batch 10 20 30
acl number 3000
rule 5 deny ip source 10.0.0.0 0.0.0.255 destination 20.0.0.0 0.0.0.255
traffic classifier c0 operator and
if-match acl 3000
traffic behavior b0
deny
traffic policy p0
classifier c0 behavior b0
interface Vlanif10
ip address 10.0.0.1 255.255.255.0
interface Vlanif20
ip address 20.0.0.1 255.255.255.0
interface Vlanif100
ip address 100.0.0.1 255.255.255.0
interface GigabitEthernet0/0/10
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/11
port link-type access
port default vlan 20
#
interface GigabitEthernet0/0/12
port link-type access
port default vlan 30
#
# 方式1 VLAN上应用流策略
vlan 100
traffic-policy p0 inbound
# 方式2 VLANIF接口上应用流策略
int vlan 10
traffic-filter inbound acl 3001
注意:在策略中匹配到的流量会执行相应动作,未匹配的流量安装原始规则转发.
acl 应用不同场景默认动作
7633

被折叠的 条评论
为什么被折叠?



