我的一亩三分地 我就喜欢!
13fen  设为主页
 收藏本站
 
当前位置: > 一亩三分地:首页 > 网络技术 > VLAN > VLAN 之间的访问控制
热门文章排行
热门文章排行 VLAN技术简单谈(11-17)
VLAN升级难题 增加交换机后的苦恼(11-17)
VLAN 之间的访问控制(11-17)
VLAN技术入门(11-17)
VLAN,VLAN聚合,PVLAN, GVRP,VTP(11-17)
精采文章排行
精采文章排行
技术专题推荐
网管论坛交流
 

VLAN 之间的访问控制 

作者:   来源:   点击:   日期:2007-11-17

  路由器通过以太网的子口建立与下连交换机TRUNK口相连。
  要求管理VLAN可以访问其它业务VLAN、办公VLAN、财务VLAN、家庭网VLAN,但是其它VLAN不可以访问管理VLAN。
  下面把路由器上的配置附上:
  
  ip access-list extended infilter
  evaluate mppacket
  deny ip 10.54.16.0 0.0.0.255 10.54.17.0 0.0.0.255
  deny ip 10.54.16.0 0.0.0.255 10.54.18.0 0.0.0.255
  deny ip 10.54.16.0 0.0.0.255 10.54.19.0 0.0.0.255
  deny ip 10.54.16.0 0.0.0.255 10.54.31.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.16.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.18.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.19.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.31.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.16.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.17.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.19.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.31.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.16.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.17.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.18.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.31.0 0.0.0.255
  permit ip any any
  exit
  
  ip access-list extended outfilter
  permit ip any any reflect mppacket
  exit
  
  interface fastethernet0
  ip address 10.255.49.2 255.255.255.252
  exit
  
  interface fastethernet1
  exit    
  
  interface fastethernet1.1
  description Guanli
  ip address 10.54.31.254 255.255.255.0
  encapsulation dot1q 1
  exit
  
  interface fastethernet1.2
  description Yewu
  ip address 10.54.17.254 255.255.255.0
  encapsulation dot1q 2
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  interface fastethernet1.3
  description Bangong
  ip address 10.54.16.254 255.255.255.0
  encapsulation dot1q 3
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  interface fastethernet1.4
  description Caiwu
  ip address 10.54.18.254 255.255.255.0
  encapsulation dot1q 4
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  interface fastethernet1.5
  description Jiating
  ip address 10.54.19.254 255.255.255.0
  encapsulation dot1q 5
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  ip route 0.0.0.0 0.0.0.0 10.255.49.1

文章评论】 【收藏本文】 【推荐好友】 【打印本文】 【论坛讨论

   相关文章:
·VLAN技术入门 ·VLAN 之间的访问控制
·VLAN,VLAN聚合,PVLAN, GVRP,VTP的含 ·VLAN间路由的配置实现
·VLAN,VLAN聚合,PVLAN, GVRP,VTP的含 ·用三层交换机实现大中型企业VLAN方案

   文章评论:(条)
  
 请留名: 匿名评论   点击查看所有评论 网管论坛
 

  责任编辑:一分  声明:刊登此文章是为了传递更多信息,文章内容仅供参考,转载请注明出处。