After the above problem was solved, I have another question about it:
In layer 2 switch, We can separate different traffic through different vlan. However, in layer 3 switch, how to keep traffic in one vlan away from the traffic in other vlan ? I mean, I do not allow users in vlan 10 to reach users in vlan 20, but vlan 10 and vlan 20 have to go through layer 3 switch. Thank you.