要求: vlan10 20 30 不能互访 vlan10可以访问vlan150 vlan10 20可以上网 vlan30不能 主要配置如下: SWR上的配置: ip routing interface Vlan10 ip address 192.168.10.254 255.255.255.0 ip access-group vlan10 in ! interface Vlan20 ip address 192.168.20.254 255.255.255.0 ip access-group vlan20 in ! interface Vlan30 ip address 192.168.30.254 255.255.255.0 ip access-group vlan30 in ! interface Vlan100 ip address 192.168.100.123 255.255.255.0 ! interface Vlan150 ip address 192.168.150.254 255.255.255.0 ! ip classless ip route 192.168.200.0 255.255.255.0 192.168.1.1 ip access-list extended vlan10 deny ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255 permit ip any any ip access-list extended vlan20 deny ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255 deny ip 192.168.20.0 0.0.0.255 192.168.30.0 0.0.0.255 deny ip 192.168.20.0 0.0.0.255 192.168.150.0 0.0.0.255 permit ip any any ip access-list extended vlan20-2 permit ip 192.168.20.0 0.0.0.255 192.168.200.0 0.0.0.255 ip access-list extended vlan30 deny ip 192.168.30.0 0.0.0.255 any ! R1上配置 ip route 192.168.20.0 255.255.255.0 192.168.1.2 ip route 192.168.10.0 255.255.255.0 192.168.1.2