三层交换机配置ACL,禁止VLAN20对VLAN40中的服务器192.168.40.2的访问。
Switch3 (config)# access-list 101 deny ip 192.168.20.0 0.0.0.255 host 192.168.40.4
Switch3 (config)# access-list 101 permit ip any any
Switch3 (config)# interface vlan 40
Switch3 (config-if)# ip access-group 101 out
三层交换机配置ACL,让VLAN20、VLAN30、VLAN40不能跟VLAN50通信。
Switch3 (config)# access-list 100 deny ip 192.168.20.0 0.0.0.255 192.168.50.0 0.0.0.255
Switch3 (config)# access-list 100 deny ip 192.168.30.0 0.0.0.255 192.168.50.0 0.0.0.255
Switch3 (config)# access-list 100 deny ip 192.168.40.0 0.0.0.255 192.168.50.0 0.0.0.255
Switch3 (config)# access-list 100 permit ip any any
Switch3 (config)# interface vlan 50
Switch3 (config-if)# ip access-group 100 out
禁止vlan20对FTPserver 192.168.40.2 访问
sw3(config)# access-list 100 deny tcp 192.168.20.0 0.0.0.255 host 192.168.40.2 eq 20
sw3(config)# access-list 100 deny tcp 192.168.20.0 0.0.0.255 host 192.168.40.2 eq 21
sw3(config)# access-list 100 permit ip any any
sw3(config)# interface vlan 20
sw3(config-if)# ip access-group 100 in
sw3(config-if)# exit