SW .254
R2 R3 R4 R5
vlan20
192.168.20.1
R2:
int e0/0
ip add 192.168.20.1 255.255.255.0
no sh
ip route 0.0.0.0 0.0.0.0 192.168.20.254
SW:
vlan 20,30,40,50
int e0/0
switchport mode access
switchport aeescc vlan 20
int e0/1
switchport mode access
switchport aeescc vlan 30
int e0/2
switchport mode access
switchport aeescc vlan 40
int e0/3
switchport mode access
switchport aeescc vlan 50
int vlan 20
ip add 192.168.20.254 255.255.255.0
no sh
int vlan 30
ip add 192.168.30.254 255.255.255.0
no sh
int vlan 40
ip add 192.168.40.254 255.255.255.0
no sh
int vlan 50
ip add 192.168.50.254 255.255.255.0
no sh
ip access-list ex cisco
per ip host 192.168.20.1 host 192.168.40.1
per ip host 192.168.20.1 host 192.168.50.1
ip access-list ex cisco-1 //可以不写
per ip any any
vlan access-map VACL 10
match ip add cisco
action drop
vlan access-map VACL 20
match ip add cisco-1 //可以不写
action forward
vlan filter VACL vlan-list 20
R2 ping R4、R5