China 3 layer Switch VLAN isolation
192.168.1.0---------g1/0/1 S SW g1/0/2-------192.168.2.0
192.168.3.0-----------------------|
192.168.4.0-----------------------|
Prohibition of 1.0, 3.0, 4.0 and 2.0 visits
[H3c]acl Num 3000
[H3c-acl-adv-3000]rule deny IP source 192.168.1.0 0.0.0.255 destination 192.168.2.0 0.0.0.255//Forbidden 1.0 Access 2.0
[H3c-acl-adv-3000]rule deny IP source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255//Forbidden 1.0 Access 2.0
[H3c-acl-adv-3000]rule deny IP source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255//Forbidden 1.0 Access 2.0
[H3c-acl-adv-3000]quit
[H3c]int G1/0/2
[H3c-gigabitethernet1/0/2]packet-filter Outbound//ACL issued
The above is port isolation under the 3-layer Switch VLAN interface packet-filter This command can also be isolated.
This article from "Think One or two" blog, declined reprint!
China 3 Switch 3 layer VLAN isolation Configuration