思科三层交换机ACL配置

2025-01-20 03:48:52
推荐回答(2个)
回答1:

int vlan 2
ip add 192.168.0.1 255.255.255.0

int vlan 3
ip add 192.168.3.1 255.255.255.0

int vlan 4
ip add 192.168.4.1 255.255.255.0

int vlan 5
ip add 192.168.5.1 255.255.255.0

access-list 1 permit ip 192.168.3.188 0.0.0.0 192.168.0.6 0.0.0.0

int vlan 1
ip access-group 1 out

这样就192.168.3.188就可以访问192.168.0.6了但是其他的就不能访问了

回答2:

int vlan 2(f0/1-f0/5)
ip add 192.168.2.1 255.255.255.0

int vlan 3(f0/6-f0/10)
ip add 192.168.3.1 255.255.255.0

int vlan 4(f0/11-f0/15)
ip add 192.168.4.1 255.255.255.0

int vlan 5(f0/16)
ip add 192.168.5.1 255.255.255.0
access-list 101 deny ip any 192.168.4.0 0.0.0.255
int vlan 4
ip access-group 101 out
access-list 102 permit ip 192.168.4.0 0.0.0.255 192.168.2.0 0.0.0.255

int vlan 2
ip access-group 102 out
access-list 103 permit ip 192.168.4.0 0.0.0.255 192.168.3.0 0.0.0.255
int vlan 3
ip access-group 103 out