vlan 10
name first_vlan
!
vlan 17
name second_vlan
!
interface GigabitEthernet2/1
description DHCP_Server
switchport trunk native vlan 10
switchport mode trunk
ip access-group accesslist_vlan10
!
interface GigabitEthernet2/6
description test Vlan on laptop
switchport access vlan 17
switchport mode access
ip helper-address 10.0.10.110
ip access-group accesslist_vlan17
!
!
interface Vlan10
description first vlan
ip address 10.0.1.44 255.255.0.0
no ip redirects
ip helper-address 10.0.10.110
!
interface Vlan17
description second Vlan
ip address 10.17.0.1 255.255.255.0 {don't use .0 as an ipaddress}
ip helper-address 10.0.10.110
!
!
ip access-list extended accesslist_vlan10
permit udp any host 10.0.10.100 eq bootpc {allow requests from any to dhcp server}
permit udp host 10.0.10.100 any eq bootps {allow reply back to any)
permit ip 10.0.0.0 0.0.255.255 10.0.0.0 0.0.255.255 {allow traphic in vlan10}
deny ip 10.0.0.0 0.0.255.255 10.17.0.0 0.0.0.255 {deny traphic from vlan10 to vlan17}
ip access-list extended accesslist_vlan17
permit udp any host 10.0.10.100 eq bootpc {allow requests from any to dhcp server}
permit udp host 10.0.10.100 any eq bootps {allow reply back to any)
permit ip 10.17.0.0 0.0.0.255 10.17.0.0 0.0.0.255 {allow traphic in vlan17}
deny ip 10.17.0.0 0.0.0.255 10.0.0.0 0.0.255.255 {deny traphic from vlan17 to vlan10}