一.实验拓扑图
二.实验需求
- PC1、PC3属于Vlan2
- PC2、PC4属于Vlan3
- 使用DHCP分配PC的IP地址
- 全网可达
三.实验分析
- 路由器R1创建两个子接口,划分进相应vid
- 两个子接口配置IP地址,开启ARP协议与DHCP协议
- 两个交换机的接口划分进相应VLAN
- 主干道允许VLAN2和VLAN3通过
四.配置
1.SW1
[lsw1]int g 0/0/1
[lsw1-GigabitEthernet0/0/1]port link-t
[lsw1-GigabitEthernet0/0/1]port link-type ac
[lsw1-GigabitEthernet0/0/1]port link-type access
[lsw1-GigabitEthernet0/0/1]port de
[lsw1-GigabitEthernet0/0/1]port default vlan 2
[lsw1-GigabitEthernet0/0/1]int g 0/0/2
[lsw1-GigabitEthernet0/0/2]port hy
[lsw1-GigabitEthernet0/0/2]port hybrid pvid vlan 3
[lsw1-GigabitEthernet0/0/2]po
[lsw1-GigabitEthernet0/0/2]port hy
[lsw1-GigabitEthernet0/0/2]port hybrid un
[lsw1-GigabitEthernet0/0/2]port hybrid untagged vlan 3 4 5 6
[lsw1-GigabitEthernet0/0/2]int g 0/0/3
[lsw1-GigabitEthernet0/0/3]port link
[lsw1-GigabitEthernet0/0/3]port link-ty
[lsw1-GigabitEthernet0/0/3]port link-type tr
[lsw1-GigabitEthernet0/0/3]port link-type trunk
[lsw1-GigabitEthernet0/0/3]port tru
[lsw1-GigabitEthernet0/0/3]port trunk al
[lsw1-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6
[lsw1-GigabitEthernet0/0/3]int g 0/0/4
[lsw1-GigabitEthernet0/0/4]port hy
[lsw1-GigabitEthernet0/0/4]port hybrid un
[lsw1-GigabitEthernet0/0/4]port hybrid untagged vlan 3 4 5 6
[lsw1-GigabitEthernet0/0/4]port hy
[lsw1-GigabitEthernet0/0/4]port hybrid ta
[lsw1-GigabitEthernet0/0/4]port hybrid tagged vlan 2
[lsw1-GigabitEthernet0/0/4]dis port vlan a
[lsw1-GigabitEthernet0/0/4]dis port vlan active
2.SW2
[lsw2]int g 0/0/1
[lsw2-GigabitEthernet0/0/1]port l ac
[lsw2-GigabitEthernet0/0/1]port de vlan 2
[lsw2-GigabitEthernet0/0/1]int g0/0/2
[lsw2-GigabitEthernet0/0/2]port hy
[lsw2-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[lsw2-GigabitEthernet0/0/2]port hy
[lsw2-GigabitEthernet0/0/2]port hybrid un
[lsw2-GigabitEthernet0/0/2]port hybrid untagged vlan 3 to 6
[lsw2-GigabitEthernet0/0/2]int g 0/0/3
[lsw2-GigabitEthernet0/0/3]port link-ty
[lsw2-GigabitEthernet0/0/3]port link-type trunk
[lsw2-GigabitEthernet0/0/3]po
[lsw2-GigabitEthernet0/0/3]portt
[lsw2-GigabitEthernet0/0/3]port t
[lsw2-GigabitEthernet0/0/3]port trunk al
[lsw2-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6
[lsw2-GigabitEthernet0/0/3]int g 0/0/4
[lsw2-GigabitEthernet0/0/4]port link-ty t
[lsw2-GigabitEthernet0/0/4]port link-ty trunk
[lsw2-GigabitEthernet0/0/4]port t
[lsw2-GigabitEthernet0/0/4]port trunk al
[lsw2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 6
3.SW3
[Huawei]sysn lsw3
[lsw3]int g 0/0/1
[lsw3-GigabitEthernet0/0/1]port hy
[lsw3-GigabitEthernet0/0/1]port hybrid pvid vlan 5
Error: The VLAN does not exist.
[lsw3-GigabitEthernet0/0/1]q
[lsw3]vlan b 2 to 6
Info: This operation may take a few seconds. Please wait for a moment...done.
[lsw3]int g 0/0/1
[lsw3-GigabitEthernet0/0/1]port hy
[lsw3-GigabitEthernet0/0/1]port hybrid p
[lsw3-GigabitEthernet0/0/1]port hybrid pvid vlan 5
[lsw3-GigabitEthernet0/0/1]po
[lsw3-GigabitEthernet0/0/1]port hy
[lsw3-GigabitEthernet0/0/1]port hybrid un
[lsw3-GigabitEthernet0/0/1]port hybrid untagged vla
[lsw3-GigabitEthernet0/0/1]port hybrid untagged vlan 3 4 5
[lsw3-GigabitEthernet0/0/1]int g 0/0/2
[lsw3-GigabitEthernet0/0/2]port hy
[lsw3-GigabitEthernet0/0/2]port hybrid pvid vlan 6
[lsw3-GigabitEthernet0/0/2]port hy
[lsw3-GigabitEthernet0/0/2]port hybrid un
[lsw3-GigabitEthernet0/0/2]port hybrid untagged vlan 3 4 6
[lsw3-GigabitEthernet0/0/2]int g 0/0/3
[lsw3-GigabitEthernet0/0/3]port link-ty
[lsw3-GigabitEthernet0/0/3]port link-type tr
[lsw3-GigabitEthernet0/0/3]port link-type trunk
[lsw3-GigabitEthernet0/0/3]port tr
[lsw3-GigabitEthernet0/0/3]port trunk al
[lsw3-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6
[lsw3-GigabitEthernet0/0/3]dis po
[lsw3-GigabitEthernet0/0/3]dis port vlan a
[lsw3-GigabitEthernet0/0/3]dis port vlan active
4.路由器
[R]int e 0/0/0
[R-Ethernet0/0/0]ip ad 192.168.1.254 24
[R]dhcp enabl
[R]dhcp enable
[R]ip pool a
Info:It's successful to create an IP address pool.
[R-ip-pool-a]net
[R-ip-pool-a]network 192.168.1.0 mask 24
[R-ip-pool-a]dns
[R-ip-pool-a]dns-list 8.8.8.8
[R-ip-pool-a]gat
[R-ip-pool-a]gateway-list 192.168.1.254
[R-ip-pool-a]q
[R]int e 0/0/0
[R-Ethernet0/0/0]dhcp sel
[R-Ethernet0/0/0]dhcp select g
[R-Ethernet0/0/0]dhcp select global
[R-Ethernet0/0/0]q
[R]int e 0/0/0.2
[R-Ethernet0/0/0.2]ip ad
[R-Ethernet0/0/0.2]ip address 192.168.2.254 24
Error: The specified address conflicts with another address.
[R-Ethernet0/0/0.2]q
[R]int g0/0/0.2
[R-GigabitEthernet0/0/0.2]undo ip ad
[R-GigabitEthernet0/0/0.2]undo ip address 192.168.2.254 24
[R-GigabitEthernet0/0/0.2]q
[R]int e 0/0/0.2
[R-Ethernet0/0/0.2]ip ad 192.168.2.254 24
[R-Ethernet0/0/0.2]do
[R-Ethernet0/0/0.2]dot1q ter
[R-Ethernet0/0/0.2]dot1q termination v
[R-Ethernet0/0/0.2]dot1q termination vid 2
[R-Ethernet0/0/0.2]arp
[R-Ethernet0/0/0.2]a
[R-Ethernet0/0/0.2]arp b
[R-Ethernet0/0/0.2]arp broadcast e
[R-Ethernet0/0/0.2]arp broadcast enable
[R-Ethernet0/0/0.2]q
[R]ip pool b
Info:It's successful to create an IP address pool.
[R-ip-pool-b]net
[R-ip-pool-b]network 192.168.2.0 mask 24
[R-ip-pool-b]gate
[R-ip-pool-b]gateway-list 192.168.2.254
[R-ip-pool-b]dns
[R-ip-pool-b]dns-list 8.8.8.8
[R-ip-pool-b]q
[R]int e 0/0/0.2
[R-Ethernet0/0/0.2]dhcp s
[R-Ethernet0/0/0.2]dhcp se
[R-Ethernet0/0/0.2]dhcp selecten
[R-Ethernet0/0/0.2]dhcp select en
[R-Ethernet0/0/0.2]dhcp select g
[R-Ethernet0/0/0.2]dhcp select global
[R-Ethernet0/0/0.2]q
通过ACL访问控制pc4 ping pc5
在sw2和sw3分别配置acl3000
五.ping通
[lsw3-acl-adv-3000] rule deny ip source 192.168.1.252 0 destination 192.168.1.250 0
[lsw2-GigabitEthernet0/0/2]traffic-filter inbound acl 3000[lsw3-GigabitEthernet0/0/2]traffic-filter inbound acl 3000
PC5pingPC6