VLAN 之間的訪問控制
更新時間:2007年09月19日 10:20:07 作者:
路由器通過以太網(wǎng)的子口建立與下連交換機TRUNK口相連。
要求管理VLAN可以訪問其它業(yè)務VLAN、辦公VLAN、財務VLAN、家庭網(wǎng)VLAN,但是其它VLAN不可以訪問管理VLAN。
下面把路由器上的配置附上:
ip access-list extended infilter
evaluate mppacket
deny ip 10.54.16.0 0.0.0.255 10.54.17.0 0.0.0.255
deny ip 10.54.16.0 0.0.0.255 10.54.18.0 0.0.0.255
deny ip 10.54.16.0 0.0.0.255 10.54.19.0 0.0.0.255
deny ip 10.54.16.0 0.0.0.255 10.54.31.0 0.0.0.255
deny ip 10.54.17.0 0.0.0.255 10.54.16.0 0.0.0.255
deny ip 10.54.17.0 0.0.0.255 10.54.18.0 0.0.0.255
deny ip 10.54.17.0 0.0.0.255 10.54.19.0 0.0.0.255
deny ip 10.54.17.0 0.0.0.255 10.54.31.0 0.0.0.255
deny ip 10.54.18.0 0.0.0.255 10.54.16.0 0.0.0.255
deny ip 10.54.18.0 0.0.0.255 10.54.17.0 0.0.0.255
deny ip 10.54.18.0 0.0.0.255 10.54.19.0 0.0.0.255
deny ip 10.54.18.0 0.0.0.255 10.54.31.0 0.0.0.255
deny ip 10.54.19.0 0.0.0.255 10.54.16.0 0.0.0.255
deny ip 10.54.19.0 0.0.0.255 10.54.17.0 0.0.0.255
deny ip 10.54.19.0 0.0.0.255 10.54.18.0 0.0.0.255
deny ip 10.54.19.0 0.0.0.255 10.54.31.0 0.0.0.255
permit ip any any
exit
ip access-list extended outfilter
permit ip any any reflect mppacket
exit
interface fastethernet0
ip address 10.255.49.2 255.255.255.252
exit
interface fastethernet1
exit
interface fastethernet1.1
description Guanli
ip address 10.54.31.254 255.255.255.0
encapsulation dot1q 1
exit
interface fastethernet1.2
description Yewu
ip address 10.54.17.254 255.255.255.0
encapsulation dot1q 2
ip access-group outfilter out
ip access-group infilter in
exit
interface fastethernet1.3
description Bangong
ip address 10.54.16.254 255.255.255.0
encapsulation dot1q 3
ip access-group outfilter out
ip access-group infilter in
exit
interface fastethernet1.4
description Caiwu
ip address 10.54.18.254 255.255.255.0
encapsulation dot1q 4
ip access-group outfilter out
ip access-group infilter in
exit
interface fastethernet1.5
description Jiating
ip address 10.54.19.254 255.255.255.0
encapsulation dot1q 5
ip access-group outfilter out
ip access-group infilter in
exit
ip route 0.0.0.0 0.0.0.0 10.255.49.1文章錄入:csh 責任編輯:csh
相關文章
Windows XP+SP2系統(tǒng)屬性的造假原理正文分析錯誤
Windows XP+SP2系統(tǒng)屬性的造假原理正文分析錯誤...2007-09-09路由網(wǎng)關網(wǎng)絡管理和監(jiān)控功能介紹
路由網(wǎng)關網(wǎng)絡管理和監(jiān)控功能介紹...2007-09-09用QFunction-0.txt實現(xiàn)傳奇世界回城石腳本
用QFunction-0.txt實現(xiàn)傳奇世界回城石腳本...2007-09-09基于寬帶接入網(wǎng)絡遠程視頻監(jiān)控系統(tǒng)
基于寬帶接入網(wǎng)絡遠程視頻監(jiān)控系統(tǒng)...2007-09-09why is it preferable to use OSPF over RIP
why is it preferable to use OSPF over RIP...2007-09-09