核心
業務vlan 10 192.168.10.0/24
業務vlan 20 192.168.20.0/24
互聯vlan 30 192.168.30.0/24
vlan30 互聯防火牆
需求 :
拒絕業務地址 192.168.20.2 去連接防火牆(禁止該地址上網),也就是拒絕去連接互聯vlan 30
set firewall family ethernet-switching filter deny term 1 from ip-source-address 192.168.20.2/32
set firewall family ethernet-switching filter deny term 1 from ip-destination-address 192.168.30.100/32
set firewall family ethernet-switching filter deny term 1 then discard
set firewall family ethernet-switching filter deny term 2 then accept
set vlans vlan20 forwarding-options filter input deny
filter 名稱deny 掛到業務vlan vlan20
set vlans vlan20 forwarding-options filter input denyide