Chinaunix首页 | 论坛 | 博客
  • 博客访问: 508673
  • 博文数量: 694
  • 博客积分: 40000
  • 博客等级: 大将
  • 技术积分: 4840
  • 用 户 组: 普通用户
  • 注册时间: 2008-10-16 19:30
文章分类

全部博文(694)

文章存档

2011年(1)

2008年(693)

我的朋友

分类:

2008-10-16 19:33:15


  器通过以太网的子口建立与下连机TRUNK口相连。
  要求管理VLAN可以访问其它业务VLAN、办公VLAN、财务VLAN、家庭网VLAN,但是其它VLAN不可以访问管理VLAN。
  下面把路由器上的配置附上:
  
  ip access-list extended infilter
  evaluate mppacket
  deny ip 10.54.16.0 0.0.0.255 10.54.17.0 0.0.0.255
  deny ip 10.54.16.0 0.0.0.255 10.54.18.0 0.0.0.255
  deny ip 10.54.16.0 0.0.0.255 10.54.19.0 0.0.0.255
  deny ip 10.54.16.0 0.0.0.255 10.54.31.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.16.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.18.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.19.0 0.0.0.255
  deny ip 10.54.17.0 0.0.0.255 10.54.31.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.16.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.17.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.19.0 0.0.0.255
  deny ip 10.54.18.0 0.0.0.255 10.54.31.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.16.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.17.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.18.0 0.0.0.255
  deny ip 10.54.19.0 0.0.0.255 10.54.31.0 0.0.0.255
  permit ip any any
  exit
  
  ip access-list extended outfilter
  permit ip any any reflect mppacket
  exit
  
  interface fastethernet0
  ip address 10.255.49.2 255.255.255.252
  exit
  
  interface fastethernet1
  exit    
  
  interface fastethernet1.1
  description Guanli
  ip address 10.54.31.254 255.255.255.0
  encapsulation dot1q 1
  exit
  
  interface fastethernet1.2
  description Yewu
  ip address 10.54.17.254 255.255.255.0
  encapsulation dot1q 2
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  interface fastethernet1.3
  description Bangong
  ip address 10.54.16.254 255.255.255.0
  encapsulation dot1q 3
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  interface fastethernet1.4
  description Caiwu
  ip address 10.54.18.254 255.255.255.0
  encapsulation dot1q 4
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  interface fastethernet1.5
  description Jiating
  ip address 10.54.19.254 255.255.255.0
  encapsulation dot1q 5
  ip access-group outfilter out
  ip access-group infilter in
  exit
  
  ip route 0.0.0.0 0.0.0.0 10.255.49.1
【责编:admin】

--------------------next---------------------

阅读(161) | 评论(0) | 转发(0) |
给主人留下些什么吧!~~