假如 A 交换机 vlan100,vlan200,B 交换机 vlan300,vlan400,怎样配置可以让vlan300 不能访问 vlan100
vlan200 可以访问 vlan400
有多种方法可以实现:比如 PVLAN,ACL 等
按照你的拓扑,我用 PT 模拟了一种做法:单臂路由+ACL,可以参考一下,有图,有配置: 交换机 A:interface FastEthernet0/2 switchport access vlan 100 switchport mode access
interface FastEthernet0/3 switchport access vlan 100 switchport mode access
interface FastEthernet0/11 switchport access vlan 200 switchport mode access
interface FastEthernet0/12 switchport access vlan 200 switchport mode access
interface FastEthernet0/1 switchport trunk allowed vlan 100,200 switchport mode trunk 交换机 B:interface FastEthernet0/2 switchport access vlan 300 switchport mode access
interface FastEthernet0/3 switchport access vlan 300 switchport mode access
interface FastEthernet0/11 switchport access vlan 400 switchport mode access