在 Cisco 设备上,我希望为一个特定的 vlan(id 110)启用一些过滤。
这是我的配置:(192.33.57.177 是 DHCP 服务器主机)
ip access-list extended VLAN110-DHCP
permit ip any host 192.33.57.177
permit ip host 192.33.57.177 any
permit ip any host 192.33.57.7
permit ip host 192.33.57.7 any
ip access-list extended VLAN110-RFC
permit ip any 192.168.0.0 0.0.255.255
permit ip 192.168.0.0 0.0.255.255 any
permit ip any 172.16.0.0 0.15.255.255
permit ip 172.16.0.0 0.15.255.255 any
permit ip any 10.0.0.0 0.255.255.255
permit ip 10.0.0.0 0.255.255.255 any
vlan access-map VMAP-VLAN110 5
match ip address VLAN110-DHCP
action forward
vlan access-map VMAP-VLAN110 10
match ip address VLAN110-RFC
action drop
vlan access-map VMAP-VLAN110 20
action forward
vlan filter VMAP-VLAN110 vlan-list 110
然而,当我在 VLAN110 中获得设备时,我根本没有连接......我只想连接到 DHCP 服务器和公共 IP。我想过滤私有 IP。我的配置有什么遗漏吗?
谢谢