As shown in Figure 1, the departments of an enterprise are connected through a switch. To facilitate network management, the administrator allocates IP addresses of different network segments to the R&D and marketing departments. In addition, the administrator adds the two departments to different VLANs for broadcast domain isolation. For information security purposes, the enterprise requires that the switch prevent user hosts on different network segments from communicating with each other.