wifi 段禁止访问局域网和专网,只能访问互联网:
ip access-list extended wifi80
remark 80NoAccessLocalPrivatManageSegment
6 permit udp any any eq bootps log
7 permit udp any any eq bootpc log
10 deny ip 172.1.80.0 0.0.0.255 10.3.0.0 0.0.255.255
15 deny ip 172.1.80.0 0.0.0.255 172.16.10.0 0.0.0.255
20 deny ip 172.1.80.0 0.0.0.255 172.17.10.0 0.0.0.255
25 permit ip 172.18.80.0 0.0.0.255 any
interface VLAN 80
description Wifi
ip access-group wifi80 in
ip address 172.1.80.1 255.255.255.0