求大侠看看cisco3560配置后VLAN之间ping不通,在线等

3560的1-46是办公网口,47是VLAN2,48是VLAN3,40是trunk口,42接防火墙,VLAN1、3要求可以上外网,2不能。下面是配置
no aaa new-model
ip subnet-zero
ip routing
!
!
!
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
interface FastEthernet0/1
!
interface FastEthernet0/2
!
interface FastEthernet0/3
!
interface FastEthernet0/4
!
interface FastEthernet0/5
!
interface FastEthernet0/6
!
interface FastEthernet0/7
!
interface FastEthernet0/8
!
interface FastEthernet0/9
!
interface FastEthernet0/10
!
interface FastEthernet0/11
!
interface FastEthernet0/12
!
interface FastEthernet0/13
!
interface FastEthernet0/14
!
interface FastEthernet0/15
!
interface FastEthernet0/16
!
interface FastEthernet0/17
!
interface FastEthernet0/18
!
interface FastEthernet0/19
!
interface FastEthernet0/20
!
interface FastEthernet0/21
!
interface FastEthernet0/22
!
interface FastEthernet0/23
!
interface FastEthernet0/24
!
interface FastEthernet0/25
!
interface FastEthernet0/26
!
interface FastEthernet0/27
!
interface FastEthernet0/28
!
interface FastEthernet0/29
!
interface FastEthernet0/30
!
interface FastEthernet0/31
!
interface FastEthernet0/32
!
interface FastEthernet0/33
!
interface FastEthernet0/34
!
interface FastEthernet0/35
!
interface FastEthernet0/36
!
interface FastEthernet0/37
!
interface FastEthernet0/38
!
interface FastEthernet0/39
!
interface FastEthernet0/40
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet0/41
!
interface FastEthernet0/42
no switchport
no ip address
!
interface FastEthernet0/43
!
interface FastEthernet0/44
!
interface FastEthernet0/45
!
interface FastEthernet0/46
!
interface FastEthernet0/47
switchport access vlan 2
!
interface FastEthernet0/48
switchport access vlan 3
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface GigabitEthernet0/3
!
interface GigabitEthernet0/4
!
interface Vlan1
ip address 192.168.1.2 255.255.255.0
!
interface Vlan2
ip address 192.168.0.254 255.255.255.0
!
interface Vlan3
ip address 192.168.2.254 255.255.255.0
ip access-group 105 out
!
ip classless
ip route 0.0.0.0 0.0.0.0 0.0.0.0
ip route 192.168.2.0 255.255.255.0 192.168.1.1
ip http server
ip http secure-server
!
!
access-list 105 permit ip 192.168.2.0 0.0.1.255 any
access-list 105 permit ip 192.168.2.0 0.0.1.255 host 192.168.1.1
access-list 105 permit udp any any eq bootpc
access-list 105 permit udp any any eq tftp
!
control-plane
!
!
line con 0
line vty 0 4

没太看懂你的意思。

给你两条小意见:
1,42口都变成三层了,怎么不配ip地址呢?
2,interface vlan 3上调用105的时候方向错了吧? 应该是in方向吧? 另外你105的那个列表为啥是0.0.1.255捏?上边都是24位的啊,到列表这里怎么变了?追问

本人刚初次弄,42口是办公网用的,DHCP自动获取的

追答

第一,先把列表重新写,好好写
第二,把调用的方向改一下,我看应该是in方向。

温馨提示:内容为网友见解,仅供参考
无其他回答
相似回答
大家正在搜