要求:vlan20和vlan30不能访问vlan10,三个vlan都能访问英特网
我是这么做的,
access-list 100 deny ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255
access-list 100 deny ip 192.168.30.0 0.0.0.255 192.168.10.0 0.0.0.255
access-list 100 permit ip any any
然后应用到vlan 10
ip access-list 100 in