華為交換機(jī)默認(rèn)是VLAN間可以互相訪問的,如果要限制VLAN間不能互訪,,就要做ACL,,
舉個(gè)例子,比如要讓VLAN 2 網(wǎng)關(guān)是192.168.2.1 與VLAN 3網(wǎng)關(guān)是192.168.3.1兩個(gè)VLAN不 允許互訪,,可以這樣設(shè)置: acl number 3000 rule 0 deny ip source 192.168.2.0 0.0.0.255 destination 192.168.3.0 0.0.0.255 packer-filter inbound ip-group 3000 rule 0 |
|