我要设置成VLAN1 可以访问VLAN2, VLAN2不可以访问VLAN1,
应该如何配置啊!
ip access-list extended out-filter
permit ip address(vlan1) address(vlan2) reflect v1-to-v2
permit ip any any
ip access-list extended in-filter
evaluate v1-to-v2
deny ip address(vlan2) address(vlan1)
permit ip any any
int vlan 1
ip access-group in-filter in
ip access-group out-filter out
可以在ACL中进行设置.VLAN之间的访问策略.
可以在ACL中进行设置.VLAN之间的访问策略.
ip access-list extended out-filter
permit ip address(vlan1) address(vlan2) reflect v1-to-v2
permit ip any any
ip access-list extended in-filter
evaluate v1-to-v2
deny ip address(vlan2) address(vlan1)
permit ip any any
int vlan 1
ip access-group in-filter in
ip access-group out-filter out
就这个好用了,我也用这个的啊安全
