ip access-list extended test
deny ip 10.32.0.0 0.255.255.255 172.31.0.0 0.0.255.255
deny ip 172.31.0.0 0.0.255.255 10.32.0.0 0.255.255.255
permit ip any any
情况就是172段的主机无法ping通10段的主机,但是可以ping通10.32.8.254这个网关
若是改成
ip access-list extended test
deny ip 10.32.0.0 0.0.255.255 172.31.0.0 0.0.255.255
deny ip 172.31.0.0 0.0.255.255 10.32.0.0 0.0.255.255
permit ip any any