|
|
发表于 2008-9-18 17:07:33
|
显示全部楼层
先定义一个acl,假定子网172.16.0.0跟172.17.0.0分属vlan 1和vlan2
<H3C> system-view
[H3C] acl number 3000
rule 0 deny ip source 172.16.0.0 0.0.255.255 destination 172.17.0.0 0.0.255.255
然后在vlan1 下发那个acl
packet-filter vlan 1 inbound ip-group 3000
请试试行不行 |
|