环境:
VLAN2:192.168.2.1 255.255.255.0
VLAN3:192.168.3.1 255.255.255.0
VLAN4:192.168.4.1 255.255.255.0
我想实现vlan2(总经理)能够访问VLAN3(财务)、VLAN4(员工),反之则不行;vlan3(财务)能够访问vlan4(员工)但不能访问vlan2(总经理);vlan4(员工)不能访问vlan2(总经理)和vlan3(财务)的三级访问策略
ip access ex vlan2_in
per ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255 reflect vlan2_3
per ip 192.168.2.0 0.0.0.255 192.168.4.0 0.0.0.255 reflect vlan2_4
ip access ex vlan3_in
evaluate vlan2_3
per ip 192.168.3.0 0.0.0.255 192.168.4.0 0.0.0.255 reflect vlan3_4
ip access ex vlan4_in
evaluate vlan2_4
evaluate vlan3_4
int vlan 2
ip access vlan2_in in
int vlan 3
ip access vlan3_in in
int vlan 4
ip access vlan4_in in