在三个VLAN下分别配三段地址(如:ip address 192.168.0.1 255.255.255.0等),然后在全局模式下配acl访问列表,例如:
acl 3000 match-order auto
rule normal deny ip source 192.168.0.0 0.0.0.255 destination 192.168.1.0 0.0
.0.255
rule normal deny ip source 192.168.1.0 0.0.0.255 destination 192.168.0.0 0.0
.0.255
rule normal deny ip source 192.168.2.0 0.0.0.255 destination 192.168.1.0 0.0
.0.255
rule normal deny ip source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0
.0.255
rule normal permit ip source 192.168.0.0 0.0.0.255 destination 192.168.2.0 0
.0.0.255
rule normal permit ip source 192.168.2.0 0.0.0.255 destination 192.168.0.0 0
.0.0.255
让该通的通,不该通的不通(permit 表示通,deny 表示不通) |