要实现不同接口网络(vlan也是接口哈)的单向访问,比如f0/0和f0/1
int f0/0
ip add 10.0.0.1 255.255.255.0
int f0/1
ip add 192.168.10.235 255.255.255.0
允许10.0.0.1接口所接的网络,10.0.0.0/24这个网段访问192.168.10.0/24这个网段,但是不允许192.168.10.0/24访问10.0.0.0/24
办法有两种:
1.
ip access-list extended in_acl
permit ip 10.0.0.0 0.0.0.255 192.168.10.0 0.0.0.255 reflect reflect_acl
ip access-list extended out_acl
evaluate reflect_acl
int f0/0
ip access-group in_acl in
ip access-group ou_acl out
2.
ip access-list extended in_acl
permit ip 10.0.0.0 0.0.0.255 192.168.10.0 0.0.0.255 reflect reflect_acl
ip access-list extended in2_acl
evaluate reflect_acl
int f0/0
ip access-list in_acl in
int f0/1
ip access-list in2_acl in
哈哈,其实就是evaluate的那条acl应用的接口和方向不同罢了,可以根据自己的需要做选择