1.vlan综述
vlan实现原理:一个vlan=一个广播域=逻辑网段(子网)
vlan——虚拟局域网
冲突:两个节点同时发送数据的情况
冲突域:产生冲突的范围
集线器/交换机的冲突域:集线器所有接口都处于一个冲突域,交换机一个接口一个冲突域
本网段广播:发送的消息会传达给这个网段的全体成员
广播域:广播扩散的范围
交换机/路由器的广播域:交换机的所有接口处于一个广播域中,路由器一个接口一个广播域
2.vlan的好处
1.隔离了广播域——端口的分隔。即便在同一个交换机上,处于不同vlan的端口也是不能通信的。这样一个物理的交换机可以当作多个逻辑的交换机使用。
2.安全性更好——网络的安全。不同vlan不能直接通信,杜绝了广播信息的不安全性。
3.灵活性——更易管理。更改用户所属的网络不必换端口和连线,只更改软件配置就可以了。
3.vlan管理的方式
1.静态vlan(比较常用,简单经济)
基于端口划分静态vlan
2.动态vlan(复杂成本高不常用)
基于MAC地址划分动态vlan
注:vlan的数量一共是4096ge,其中vlan0,4095系统保留,不可见也不可用,vlan1系统默认vlan,用户可以使用,但不能删除,vlan2-4094,用户可以创建、使用、删除
4.静态vlan的创建
创建步骤:1.三条必打命令
< >undo terminal monitor
< >system-view
[ ]sysname sw1
[ ]user-interface console 0
[ ]idle-timeout 0 0
2.交换机上创建vlan
2.1创建一个vlan
[ ]vlan 2
2.2创建多个不连续的vlan
例:一次性创建vlan3,vlan6,vlan9
[ ]vlan batch 3 6 9
2.3创建多个连续的vlan
例:一次性创建vlan10,vlan11,vlan12,vlan13,vlan14,vlan15
[ ]vlan batch 10 to 15
2.4验证vlan是否创建成功
[ ]display vlan
3.接口划分进对应的vlan
3.1进入接口
[ ]interface vlan 0e/0/1
3.2设置该接口的链路类型
[ ]port link-type access
3.3将该接口划分进对应的vlan
[ ]port default vlan3
补充:交换机根据连接对象的不同,会有不同的链路类型,交换机的连接对象是电脑,那么接口链路类型为access,注意:access这种类型接口只能属于一个vlan。交换机连接的对象是交换机,那么接口链路类型为trunk,注意:trunk不属于任何vlan,它是一条公有链路,用来在单条链路上承载不同的vlan流量,让其通过。
[ ]undo shudown 开启接口
[ ]clear configuration interface e0/0/1 清除接口下所有配置
[ ]display vlan 显示当前vlan




PC机命令
Welcome to use PC Simulator!
PC>ping 192.168.1.20
Ping 192.168.1.20: 32 data bytes, Press Ctrl_C to break
From 192.168.1.20: bytes=32 seq=1 ttl=128 time=63 ms
From 192.168.1.20: bytes=32 seq=2 ttl=128 time=47 ms
From 192.168.1.20: bytes=32 seq=3 ttl=128 time=47 ms
From 192.168.1.20: bytes=32 seq=4 ttl=128 time=47 ms
From 192.168.1.20: bytes=32 seq=5 ttl=128 time=46 ms
--- 192.168.1.20 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 46/50/63 ms
PC>ping 198.1681.30
host 198.1681.30 unreachable
PC>ping 192.168.1.30
Ping 192.168.1.30: 32 data bytes, Press Ctrl_C to break
From 192.168.1.30: bytes=32 seq=1 ttl=128 time=32 ms
From 192.168.1.30: bytes=32 seq=2 ttl=128 time=47 ms
From 192.168.1.30: bytes=32 seq=3 ttl=128 time=47 ms
From 192.168.1.30: bytes=32 seq=4 ttl=128 time=31 ms
From 192.168.1.30: bytes=32 seq=5 ttl=128 time=63 ms
--- 192.168.1.30 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/44/63 ms
PC>display mac-address
Invalid command!
PC>ping 192.168.1.20
Ping 192.168.1.20: 32 data bytes, Press Ctrl_C to break
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
--- 192.168.1.20 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
PC>192.168.1.30
Invalid command!
PC>ping 192.168.1.30
Ping 192.168.1.30: 32 data bytes, Press Ctrl_C to break
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
--- 192.168.1.30 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
SW交换机命令
Ethernet0/0/2 has been available.
Aug 6 2021 22:54:18-08:00 Huawei %%01PHY/1/PHY(l)[50]: Ethernet0/0/1: change
status to up
Aug 6 2021 22:54:18-08:00 Huawei %%01IFNET/4/IF_STATE(l)[51]:Interface Vlanif1
has turned into UP state.
Aug 6 2021 22:54:18-08:00 Huawei %%01PHY/1/PHY(l)[52]: Ethernet0/0/2: change
status to up
Aug 6 2021 22:54:18-08:00 Huawei %%01PHY/1/PHY(l)[53]: Ethernet0/0/3: change
status to up
<Huawei>
<Huawei>dis
<Huawei>display ma
<Huawei>display mac-ad
<Huawei>display mac-address
<Huawei>un
<Huawei>undo te
<Huawei>undo terminal mo
<Huawei>undo terminal monitor
Info: Current terminal monitor is off.
<Huawei>sy
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sys
[Huawei]sysname sw7
[sw7]ur
[sw7]urus
[sw7]us
[sw7]user-in
[sw7]user-interface co
[sw7]user-interface console 0
[sw7-ui-console0]id
[sw7-ui-console0]idle-timeout 0 0
[sw7-ui-console0]q
[sw7]vl
[sw7]vlan 2 3 5
^
Error:Too many parameters found at '^' position.
[sw7]vlan 2 5 7
^
Error:Too many parameters found at '^' position.
[sw7]vlan ba
[sw7]vlan batch 2 3 5
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw7]DIS
[sw7]display V
[sw7]display vL
[sw7]display vlaN
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:Eth0/0/1(U) Eth0/0/2(U) Eth0/0/3(U) Eth0/0/4(D)
Eth0/0/5(D) Eth0/0/6(D) Eth0/0/7(D) Eth0/0/8(D)
Eth0/0/9(D) Eth0/0/10(D) Eth0/0/11(D) Eth0/0/12(D)
Eth0/0/13(D) Eth0/0/14(D) Eth0/0/15(D) Eth0/0/16(D)
Eth0/0/17(D) Eth0/0/18(D) Eth0/0/19(D) Eth0/0/20(D)
Eth0/0/21(D) Eth0/0/22(D) GE0/0/1(D) GE0/0/2(D)
2 common
3 common
5 common
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
2 enable default enable disable VLAN 0002
3 enable default enable disable VLAN 0003
5 enable default enable disable VLAN 0005
[sw7]di
[sw7]display ma
[sw7]display mac-ad
[sw7]display mac-address
[sw7]dis
[sw7]display ma
[sw7]display mac-ad
[sw7]display mac-address
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-98bc-6861 1 - - Eth0/0/1 dynamic 0/-
5489-9882-7e94 1 - - Eth0/0/2 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2
[sw7]
[sw7]dis
[sw7]display ma
[sw7]display mac-ad
[sw7]display mac-address
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-98bc-6861 1 - - Eth0/0/1 dynamic 0/-
5489-9882-7e94 1 - - Eth0/0/2 dynamic 0/-
5489-9812-4b02 1 - - Eth0/0/3 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 3
[sw7]
[sw7]dis
[sw7]display vl
[sw7]display vlan
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:Eth0/0/1(U) Eth0/0/2(U) Eth0/0/3(U) Eth0/0/4(D)
Eth0/0/5(D) Eth0/0/6(D) Eth0/0/7(D) Eth0/0/8(D)
Eth0/0/9(D) Eth0/0/10(D) Eth0/0/11(D) Eth0/0/12(D)
Eth0/0/13(D) Eth0/0/14(D) Eth0/0/15(D) Eth0/0/16(D)
Eth0/0/17(D) Eth0/0/18(D) Eth0/0/19(D) Eth0/0/20(D)
Eth0/0/21(D) Eth0/0/22(D) GE0/0/1(D) GE0/0/2(D)
2 common
3 common
5 common
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
2 enable default enable disable VLAN 0002
3 enable default enable disable VLAN 0003
5 enable default enable disable VLAN 0005
[sw7]in
[sw7]int
[sw7]interface e0
[sw7]interface e0/0/1
[sw7-Ethernet0/0/1]port link-type access
[sw7-Ethernet0/0/1]port de
[sw7-Ethernet0/0/1]port default vl
[sw7-Ethernet0/0/1]port default vlan 2
[sw7-Ethernet0/0/1]q
[sw7]inter
[sw7]interface e0/0/2
[sw7-Ethernet0/0/2]po
[sw7-Ethernet0/0/2]portli
[sw7-Ethernet0/0/2]port li
[sw7-Ethernet0/0/2]port link-ty
[sw7-Ethernet0/0/2]port link-type ac
[sw7-Ethernet0/0/2]port link-type access
[sw7-Ethernet0/0/2]po
[sw7-Ethernet0/0/2]port li
[sw7-Ethernet0/0/2]port link-ty
[sw7-Ethernet0/0/2]port de
[sw7-Ethernet0/0/2]port default vl
[sw7-Ethernet0/0/2]port default vlan 3
[sw7-Ethernet0/0/2]q
[sw7]in
[sw7]int
[sw7]interface e0/0/3
[sw7-Ethernet0/0/3]po
[sw7-Ethernet0/0/3]port li
[sw7-Ethernet0/0/3]port link-ty
[sw7-Ethernet0/0/3]port link-type ac
[sw7-Ethernet0/0/3]port link-type access
[sw7-Ethernet0/0/3]po
[sw7-Ethernet0/0/3]port de
[sw7-Ethernet0/0/3]port default vl
[sw7-Ethernet0/0/3]port default vlan 5
[sw7-Ethernet0/0/3]return
<sw7>save
The current configuration will be written to the device.
Are you sure to continue?[Y/N]y
Info: Please input the file name ( *.cfg, *.zip ) [vrpcfg.zip]:
Now saving the current configuration to the slot 0.
Save the configuration successfully.
<sw7>dis
<sw7>display vl
<sw7>display vlan
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:Eth0/0/4(D) Eth0/0/5(D) Eth0/0/6(D) Eth0/0/7(D)
Eth0/0/8(D) Eth0/0/9(D) Eth0/0/10(D) Eth0/0/11(D)
Eth0/0/12(D) Eth0/0/13(D) Eth0/0/14(D) Eth0/0/15(D)
Eth0/0/16(D) Eth0/0/17(D) Eth0/0/18(D) Eth0/0/19(D)
Eth0/0/20(D) Eth0/0/21(D) Eth0/0/22(D) GE0/0/1(D)
GE0/0/2(D)
2 common UT:Eth0/0/1(U)
3 common UT:Eth0/0/2(U)
5 common UT:Eth0/0/3(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
2 enable default enable disable VLAN 0002
3 enable default enable disable VLAN 0003
5 enable default enable disable VLAN 0005
<sw7>
5.vlan跨交换机的传输过程
pc机经过发送方交换机某个接口发送数据,此时交换机会以对应vlan信息表,给经过某接口的数据打上对应的标签,打上对应标签的数据经由trunk(主干)链路验证这个vlan id是不是在trunk链路的白名单范围内,若是在白名单范围内,无条件放行,若不在白名单范围内,则该流量不予通过,当打了标签的数据到达接收方交换机后,接收方交换机会解开这个数据对应的vlan标签,对照本地mac地址表和vlan信息表,将此数据转发到该vlan对应的端口上。
[ ]display port vlan查看白名单
[ ]port link-type trunk接口链路类型为trunk
[ ]port trunk allow-pass vlan 10 20 30白名单放行的vlan
跨交换机相同vlan间通信



The device is running!
########
<Huawei>########
<Huawei>un
<Huawei>undo te
<Huawei>undo terminal mo
<Huawei>undo terminal monitor
Info: Current terminal monitor is off.
<Huawei>sy
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysn
[Huawei]sysname sw2
[sw2]us
[sw2]user-li
[sw2]user-in
[sw2]user-interface co
[sw2]user-interface console 0
[sw2-ui-console0]id
[sw2-ui-console0]idle-timeout 0 0
[sw2-ui-console0]q
[sw2]vl
[sw2]vlan ba
[sw2]vlan batch 10 20 30
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw2]int e0/0/1
[sw2-Ethernet0/0/1]po
[sw2-Ethernet0/0/1]port li
[sw2-Ethernet0/0/1]port link-ty
[sw2-Ethernet0/0/1]port link-type ac
[sw2-Ethernet0/0/1]port link-type access
[sw2-Ethernet0/0/1]po
[sw2-Ethernet0/0/1]port de
[sw2-Ethernet0/0/1]port default vl
[sw2-Ethernet0/0/1]port default vlan 30
[sw2-Ethernet0/0/1]int e0/0/2
[sw2-Ethernet0/0/2]po
[sw2-Ethernet0/0/2]port li
[sw2-Ethernet0/0/2]port link-ty
[sw2-Ethernet0/0/2]port link-type ac
[sw2-Ethernet0/0/2]port link-type access
[sw2-Ethernet0/0/2]po
[sw2-Ethernet0/0/2]port de
[sw2-Ethernet0/0/2]port default vl
[sw2-Ethernet0/0/2]port default vlan 20
[sw2-Ethernet0/0/2]int e0/0/3
[sw2-Ethernet0/0/3]po
[sw2-Ethernet0/0/3]port li
[sw2-Ethernet0/0/3]port link- ty
[sw2-Ethernet0/0/3]port link-ty
[sw2-Ethernet0/0/3]port link-type avc
[sw2-Ethernet0/0/3]port link-type ac
[sw2-Ethernet0/0/3]port link-type access
[sw2-Ethernet0/0/3]po
[sw2-Ethernet0/0/3]port de
[sw2-Ethernet0/0/3]port default vl
[sw2-Ethernet0/0/3]port default vlan 10
[sw2-Ethernet0/0/3]int g0/0/1
[sw2-GigabitEthernet0/0/1]po
[sw2-GigabitEthernet0/0/1]port li
[sw2-GigabitEthernet0/0/1]port link-ty
[sw2-GigabitEthernet0/0/1]port link-type tr
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]dis
[sw2-GigabitEthernet0/0/1]display po
[sw2-GigabitEthernet0/0/1]display policy-vlan
^
Error:Incomplete command found at '^' position.
[sw2-GigabitEthernet0/0/1]dis
[sw2-GigabitEthernet0/0/1]display por
[sw2-GigabitEthernet0/0/1]display port vl
[sw2-GigabitEthernet0/0/1]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1 access 30 -
Ethernet0/0/2 access 20 -
Ethernet0/0/3 access 10 -
Ethernet0/0/4 hybrid 1 -
Ethernet0/0/5 hybrid 1 -
Ethernet0/0/6 hybrid 1 -
Ethernet0/0/7 hybrid 1 -
Ethernet0/0/8 hybrid 1 -
Ethernet0/0/9 hybrid 1 -
Ethernet0/0/10 hybrid 1 -
Ethernet0/0/11 hybrid 1 -
Ethernet0/0/12 hybrid 1 -
Ethernet0/0/13 hybrid 1 -
Ethernet0/0/14 hybrid 1 -
Ethernet0/0/15 hybrid 1 -
Ethernet0/0/16 hybrid 1 -
Ethernet0/0/17 hybrid 1 -
Ethernet0/0/18 hybrid 1 -
Ethernet0/0/19 hybrid 1 -
Ethernet0/0/20 hybrid 1 -
Ethernet0/0/21 hybrid 1 -
Ethernet0/0/22 hybrid 1 -
GigabitEthernet0/0/1 trunk 1 1
GigabitEthernet0/0/2 hybrid 1 -
[sw2-GigabitEthernet0/0/1]tr
[sw2-GigabitEthernet0/0/1]po
[sw2-GigabitEthernet0/0/1]port tr
[sw2-GigabitEthernet0/0/1]port trunk al
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vl
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 30
[sw2-GigabitEthernet0/0/1]dis
[sw2-GigabitEthernet0/0/1]display po
[sw2-GigabitEthernet0/0/1]display por
[sw2-GigabitEthernet0/0/1]display portvl
[sw2-GigabitEthernet0/0/1]display port vl
[sw2-GigabitEthernet0/0/1]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1 access 30 -
Ethernet0/0/2 access 20 -
Ethernet0/0/3 access 10 -
Ethernet0/0/4 hybrid 1 -
Ethernet0/0/5 hybrid 1 -
Ethernet0/0/6 hybrid 1 -
Ethernet0/0/7 hybrid 1 -
Ethernet0/0/8 hybrid 1 -
Ethernet0/0/9 hybrid 1 -
Ethernet0/0/10 hybrid 1 -
Ethernet0/0/11 hybrid 1 -
Ethernet0/0/12 hybrid 1 -
Ethernet0/0/13 hybrid 1 -
Ethernet0/0/14 hybrid 1 -
Ethernet0/0/15 hybrid 1 -
Ethernet0/0/16 hybrid 1 -
Ethernet0/0/17 hybrid 1 -
Ethernet0/0/18 hybrid 1 -
Ethernet0/0/19 hybrid 1 -
Ethernet0/0/20 hybrid 1 -
Ethernet0/0/21 hybrid 1 -
Ethernet0/0/22 hybrid 1 -
GigabitEthernet0/0/1 trunk 1 1 10 20 30
GigabitEthernet0/0/2 hybrid 1 -
[sw2-GigabitEthernet0/0/1]q
[sw2]
<Huawei>un
<Huawei>undo te
<Huawei>undo terminal mo
<Huawei>undo terminal monitor
Info: Current terminal monitor is off.
<Huawei>sys
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysn
[Huawei]sysname sw1
[sw1]us
[sw1]user-in
[sw1]user-interface co
[sw1]user-interface console 0
[sw1-ui-console0]id
[sw1-ui-console0]idle-timeout 0 0
[sw1-ui-console0]q
[sw1]vl
[sw1]vlan ba
[sw1]vlan batch 10 20 30
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw1]int e0/0/1
[sw1-Ethernet0/0/1]po
[sw1-Ethernet0/0/1]port li
[sw1-Ethernet0/0/1]port link-ty
[sw1-Ethernet0/0/1]port link-type ac
[sw1-Ethernet0/0/1]port link-type access
[sw1-Ethernet0/0/1]po
[sw1-Ethernet0/0/1]port de
[sw1-Ethernet0/0/1]port default vl
[sw1-Ethernet0/0/1]port default vlan 10
[sw1-Ethernet0/0/1]int e0/0/2
[sw1-Ethernet0/0/2]po
[sw1-Ethernet0/0/2]port loi
[sw1-Ethernet0/0/2]port li
[sw1-Ethernet0/0/2]port link-ty
[sw1-Ethernet0/0/2]port link-type ac
[sw1-Ethernet0/0/2]port link-type access
[sw1-Ethernet0/0/2]po
[sw1-Ethernet0/0/2]port de
[sw1-Ethernet0/0/2]port default vl
[sw1-Ethernet0/0/2]port default vlan 20
[sw1-Ethernet0/0/2]int e0/0/3
[sw1-Ethernet0/0/3]po
[sw1-Ethernet0/0/3]port li
[sw1-Ethernet0/0/3]port link-ty
[sw1-Ethernet0/0/3]port link-type ac
[sw1-Ethernet0/0/3]port link-type access
[sw1-Ethernet0/0/3]po
[sw1-Ethernet0/0/3]port de
[sw1-Ethernet0/0/3]port default vl
[sw1-Ethernet0/0/3]port default vlan 30
[sw1-Ethernet0/0/3]display po
[sw1-Ethernet0/0/3]display port vl
[sw1-Ethernet0/0/3]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1 access 10 -
Ethernet0/0/2 access 20 -
Ethernet0/0/3 access 30 -
Ethernet0/0/4 hybrid 1 -
Ethernet0/0/5 hybrid 1 -
Ethernet0/0/6 hybrid 1 -
Ethernet0/0/7 hybrid 1 -
Ethernet0/0/8 hybrid 1 -
Ethernet0/0/9 hybrid 1 -
Ethernet0/0/10 hybrid 1 -
Ethernet0/0/11 hybrid 1 -
Ethernet0/0/12 hybrid 1 -
Ethernet0/0/13 hybrid 1 -
Ethernet0/0/14 hybrid 1 -
Ethernet0/0/15 hybrid 1 -
Ethernet0/0/16 hybrid 1 -
Ethernet0/0/17 hybrid 1 -
Ethernet0/0/18 hybrid 1 -
Ethernet0/0/19 hybrid 1 -
Ethernet0/0/20 hybrid 1 -
Ethernet0/0/21 hybrid 1 -
Ethernet0/0/22 hybrid 1 -
GigabitEthernet0/0/1 hybrid 1 -
GigabitEthernet0/0/2 hybrid 1 -
[sw1-Ethernet0/0/3]int g0/0/1
[sw1-GigabitEthernet0/0/1]po
[sw1-GigabitEthernet0/0/1]port li
[sw1-GigabitEthernet0/0/1]port link-ty
[sw1-GigabitEthernet0/0/1]port link-type tr
[sw1-GigabitEthernet0/0/1]port link-type trunk
[sw1-GigabitEthernet0/0/1]dis
[sw1-GigabitEthernet0/0/1]display por
[sw1-GigabitEthernet0/0/1]display port vl
[sw1-GigabitEthernet0/0/1]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1 access 10 -
Ethernet0/0/2 access 20 -
Ethernet0/0/3 access 30 -
Ethernet0/0/4 hybrid 1 -
Ethernet0/0/5 hybrid 1 -
Ethernet0/0/6 hybrid 1 -
Ethernet0/0/7 hybrid 1 -
Ethernet0/0/8 hybrid 1 -
Ethernet0/0/9 hybrid 1 -
Ethernet0/0/10 hybrid 1 -
Ethernet0/0/11 hybrid 1 -
Ethernet0/0/12 hybrid 1 -
Ethernet0/0/13 hybrid 1 -
Ethernet0/0/14 hybrid 1 -
Ethernet0/0/15 hybrid 1 -
Ethernet0/0/16 hybrid 1 -
Ethernet0/0/17 hybrid 1 -
Ethernet0/0/18 hybrid 1 -
Ethernet0/0/19 hybrid 1 -
Ethernet0/0/20 hybrid 1 -
Ethernet0/0/21 hybrid 1 -
Ethernet0/0/22 hybrid 1 -
GigabitEthernet0/0/1 trunk 1 1
GigabitEthernet0/0/2 hybrid 1 -
[sw1-GigabitEthernet0/0/1]por
[sw1-GigabitEthernet0/0/1]port tr
[sw1-GigabitEthernet0/0/1]port trunk al
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vl
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 30
[sw1-GigabitEthernet0/0/1]dis
[sw1-GigabitEthernet0/0/1]display po
[sw1-GigabitEthernet0/0/1]display por
[sw1-GigabitEthernet0/0/1]display port vl
[sw1-GigabitEthernet0/0/1]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1 access 10 -
Ethernet0/0/2 access 20 -
Ethernet0/0/3 access 30 -
Ethernet0/0/4 hybrid 1 -
Ethernet0/0/5 hybrid 1 -
Ethernet0/0/6 hybrid 1 -
Ethernet0/0/7 hybrid 1 -
Ethernet0/0/8 hybrid 1 -
Ethernet0/0/9 hybrid 1 -
Ethernet0/0/10 hybrid 1 -
Ethernet0/0/11 hybrid 1 -
Ethernet0/0/12 hybrid 1 -
Ethernet0/0/13 hybrid 1 -
Ethernet0/0/14 hybrid 1 -
Ethernet0/0/15 hybrid 1 -
Ethernet0/0/16 hybrid 1 -
Ethernet0/0/17 hybrid 1 -
Ethernet0/0/18 hybrid 1 -
Ethernet0/0/19 hybrid 1 -
Ethernet0/0/20 hybrid 1 -
Ethernet0/0/21 hybrid 1 -
Ethernet0/0/22 hybrid 1 -
GigabitEthernet0/0/1 trunk 1 1 10 20 30
GigabitEthernet0/0/2 hybrid 1 -
[sw1-GigabitEthernet0/0/1]q
[sw1]
6.vlan间的通信
相同vlan间通信:
情况一:同一台交换机相同vlan间通信,查看本地mac地址表,将打了相同pvid标签的数据包转发到对应的端口上去
情况二:跨交换机,通过trunk技术实现多vlan数据通信,可以帮助我们实现相同vlan间通信
不同vlan间通信(不同网段):
单臂路由 组成:一台二层交换机和一台路由器
三层交换 组成:三层交换机
vlan封装的方式:802.1q
单臂路由不同vlan间通信




The device is running!
<Huawei>
<Huawei>un
<Huawei>undo te
<Huawei>undo terminal mo
<Huawei>undo terminal monitor
Info: Current terminal monitor is off.
<Huawei>sys
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysn
[Huawei]sysname sw3
[sw3]us
[sw3]user-in
[sw3]user-interface co
[sw3]user-interface console 0
[sw3-ui-console0]id
[sw3-ui-console0]idle-timeout 0 0
[sw3-ui-console0]q
[sw3]vl
[sw3]vlan ba
[sw3]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw3]int e0/0/1
[sw3-Ethernet0/0/1]po
[sw3-Ethernet0/0/1]port li
[sw3-Ethernet0/0/1]port link-ty
[sw3-Ethernet0/0/1]port link-type ac
[sw3-Ethernet0/0/1]port link-type access
[sw3-Ethernet0/0/1]po
[sw3-Ethernet0/0/1]port de
[sw3-Ethernet0/0/1]port default vl
[sw3-Ethernet0/0/1]port default vlan 10
[sw3-Ethernet0/0/1]in
[sw3-Ethernet0/0/1]int e0/0/2
[sw3-Ethernet0/0/2]po
[sw3-Ethernet0/0/2]port li
[sw3-Ethernet0/0/2]port link-ty
[sw3-Ethernet0/0/2]port link-type ac
[sw3-Ethernet0/0/2]port link-type access
[sw3-Ethernet0/0/2]po
[sw3-Ethernet0/0/2]port de
[sw3-Ethernet0/0/2]port default vl
[sw3-Ethernet0/0/2]port default vlan 20
[sw3-Ethernet0/0/2]int g0/0/1
[sw3-GigabitEthernet0/0/1]po
[sw3-GigabitEthernet0/0/1]port li
[sw3-GigabitEthernet0/0/1]port link-ty
[sw3-GigabitEthernet0/0/1]port link-type tr
[sw3-GigabitEthernet0/0/1]port link-type trunk
[sw3-GigabitEthernet0/0/1]dis
[sw3-GigabitEthernet0/0/1]display po
[sw3-GigabitEthernet0/0/1]display por
[sw3-GigabitEthernet0/0/1]display port vl
[sw3-GigabitEthernet0/0/1]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1 access 10 -
Ethernet0/0/2 access 20 -
Ethernet0/0/3 hybrid 1 -
Ethernet0/0/4 hybrid 1 -
Ethernet0/0/5 hybrid 1 -
Ethernet0/0/6 hybrid 1 -
Ethernet0/0/7 hybrid 1 -
Ethernet0/0/8 hybrid 1 -
Ethernet0/0/9 hybrid 1 -
Ethernet0/0/10 hybrid 1 -
Ethernet0/0/11 hybrid 1 -
Ethernet0/0/12 hybrid 1 -
Ethernet0/0/13 hybrid 1 -
Ethernet0/0/14 hybrid 1 -
Ethernet0/0/15 hybrid 1 -
Ethernet0/0/16 hybrid 1 -
Ethernet0/0/17 hybrid 1 -
Ethernet0/0/18 hybrid 1 -
Ethernet0/0/19 hybrid 1 -
Ethernet0/0/20 hybrid 1 -
Ethernet0/0/21 hybrid 1 -
Ethernet0/0/22 hybrid 1 -
GigabitEthernet0/0/1 trunk 1 1
GigabitEthernet0/0/2 hybrid 1 -
[sw3-GigabitEthernet0/0/1]po
[sw3-GigabitEthernet0/0/1]port tr
[sw3-GigabitEthernet0/0/1]port trunk al
[sw3-GigabitEthernet0/0/1]port trunk allow-pass vl
[sw3-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[sw3-GigabitEthernet0/0/1]dis
[sw3-GigabitEthernet0/0/1]display por
[sw3-GigabitEthernet0/0/1]display port vl
[sw3-GigabitEthernet0/0/1]display port vlan
Port Link Type PVID Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1 access 10 -
Ethernet0/0/2 access 20 -
Ethernet0/0/3 hybrid 1 -
Ethernet0/0/4 hybrid 1 -
Ethernet0/0/5 hybrid 1 -
Ethernet0/0/6 hybrid 1 -
Ethernet0/0/7 hybrid 1 -
Ethernet0/0/8 hybrid 1 -
Ethernet0/0/9 hybrid 1 -
Ethernet0/0/10 hybrid 1 -
Ethernet0/0/11 hybrid 1 -
Ethernet0/0/12 hybrid 1 -
Ethernet0/0/13 hybrid 1 -
Ethernet0/0/14 hybrid 1 -
Ethernet0/0/15 hybrid 1 -
Ethernet0/0/16 hybrid 1 -
Ethernet0/0/17 hybrid 1 -
Ethernet0/0/18 hybrid 1 -
Ethernet0/0/19 hybrid 1 -
Ethernet0/0/20 hybrid 1 -
Ethernet0/0/21 hybrid 1 -
Ethernet0/0/22 hybrid 1 -
GigabitEthernet0/0/1 trunk 1 1 10 20
GigabitEthernet0/0/2 hybrid 1 -
[sw3-GigabitEthernet0/0/1]
The device is running!
<Huawei>un
<Huawei>undo te
<Huawei>undo terminal mo
<Huawei>undo terminal monitor
Info: Current terminal monitor is off.
<Huawei>sys
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysn
[Huawei]sysname r1
[r1]us
[r1]user-in
[r1]user-interface co
[r1]user-interface console 0
[r1-ui-console0]id
[r1-ui-console0]idle-timeout 0 0
[r1-ui-console0]q
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]un
[r1-GigabitEthernet0/0/0]undo sh
[r1-GigabitEthernet0/0/0]undo shutdown
Info: Interface GigabitEthernet0/0/0 is not shutdown.
[r1-GigabitEthernet0/0/0]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]vla
[r1-GigabitEthernet0/0/0.1]vlan-yt
[r1-GigabitEthernet0/0/0.1]vlan-ty
[r1-GigabitEthernet0/0/0.1]vlan-type do
[r1-GigabitEthernet0/0/0.1]vlan-type dot1q 10 de
[r1-GigabitEthernet0/0/0.1]vlan-type dot1q 10 default
[r1-GigabitEthernet0/0/0.1]ip ad
[r1-GigabitEthernet0/0/0.1]ip address 192.168.10.1 24
[r1-GigabitEthernet0/0/0.1]int g0/0/0.2
[r1-GigabitEthernet0/0/0.2]vl
[r1-GigabitEthernet0/0/0.2]vlan-ty
[r1-GigabitEthernet0/0/0.2]vlan-type do
[r1-GigabitEthernet0/0/0.2]vlan-type dot1q 20 de
[r1-GigabitEthernet0/0/0.2]vlan-type dot1q 20 default
[r1-GigabitEthernet0/0/0.2]ip ad
[r1-GigabitEthernet0/0/0.2]ip address 192.168.20.1 24
[r1-GigabitEthernet0/0/0.2]disp
[r1-GigabitEthernet0/0/0.2]display ip ro
[r1-GigabitEthernet0/0/0.2]display ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 6 Routes : 6
Destination/Mask Proto Pre Cost Flags NextHop Interface
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.10.0/24 Direct 0 0 D 192.168.10.1 GigabitEthernet
0/0/0.1
192.168.10.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0.1
192.168.20.0/24 Direct 0 0 D 192.168.20.1 GigabitEthernet
0/0/0.2
192.168.20.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0.2
[r1-GigabitEthernet0/0/0.2]
7.vlan的标识
有两种封装类型:ISL(Cisco私有标准)
IEEE 802.1q 公有标准(华为、中兴、H3C都可使用)
注:路由器默认接口是关闭的,需要手动开启
开启命令:[ ]undo shutdown
[ ]display ip routing-table 查看路由表
8.三层交换vlan间通信
三层交换机
三层交换机要执行三层信息的硬件交换,路由处理器(三层引擎)必须将有关路由选择等的三层信息下载到硬件中。以便对数据包进行过处理。为完成在硬件中处理数据包的高层信息,会使用传统的MLS和基于CEF的MLS。
传统的MLS:
使用传统的MLS时,交换机将数据流中第一个数据包转发给第三层引擎,后者以软件交换的方式对数报包进行过处理,对数据流中的第一个包进行路由处理后,第三层引擎对硬件交换组织进行编程,使之为后续的数据包选择路由。这个过程被称为“一次路由多次交换”,也就是说交换机的三层引擎只需要处理数据流中的第一个数据包,而后续的数据全部由硬件来执行转发。这样实现了三层交换的线速转发。
CEF的MLS:
写传统MLS不同的是,CEF预先根据路由表学习路由信息后,直接储存在FIB (转发信息库)。REF 顶先根据ARP表生成邻接表,直接由硬件进行转发。 传统MLS至少需要软件查询一次路由表后,建立转发条目,才能使用硬件进行转发。
工作原理:
①主机A给B发送单播数据包
②交换机查找FIB表,找到下一跳地址
③查找下一跳地址对应的邻接关系的2层封装信息
④转发
三层交换技术:使用三层交换技术实现vlan间通信
三层交换=二层交换(二层交换机)+三层转发(三层路由转发)
工作原理:第三层交换工作在OSI七层网络模型中的第三层即网络层,是利用第三层协议中的IP包的包头信息来对后续数据业务流进行标记,具有同一标记的业务流的后续报文被交换到第二层数据链路层,从而打通源IP地址和目的IP地址之间的一条通路。这条通路经过第二层链路层。有了这条通路,三层交换机就没必要每次将接收到的数据包进行拆包来判断路由,而是直接将数据包进行转发,将数据流进行交换。
注:二层交换机是看mac地址,三层交换机则是看IP地址进行高速转发
路由器真正的用途的计算路由,三层交换机是无法取代路由器的,因为路由器更加灵活,自适应性高。
三层交换机配置:
< >undo terminal monitor //关闭弹窗
< >system-view //进入系统模式
[ ]sysname L3sw1 //重命名
[ ]user-interface console 0
[ ]idle-timeout 0 0 //永久不超时
[ ]vlan bat 2 4 //一次性创建vlan2和vlan4
[ ]int g0/0/1 //进入接口g0/0/1
[ ]port link-type access //接口链路类型为access
[ ]port default vlan 2 //将g0/0/1划分进vlan 2
[ ]int vlanif 2 //进入虚拟接口vlanif 2
[ ]ip address 192.168.2.1 24 //设置IP地址和子网掩码长度
[ ]int g0/0/2 //进入接口g0/0/2
[ ]port link-type access //接口链路类型为access
[ ]port default vlanif 4 //进入虚拟接口vlanif 4
[ ]ip address 192.168.4.1 24 //设置IP地址和子网掩码长度
PC机配置:pc1:192.168.2.10 24 指定网关:192.168.2.1
pc2:192.168.4.10 24 指定网关:192.168.4.1
[ ]display fib 查看转换表



<Huawei>un
<Huawei>undo te
<Huawei>undo terminal mo
<Huawei>undo terminal monitor
Info: Current terminal monitor is off.
<Huawei>sys
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysn
[Huawei]sysname l3sw1
[l3sw1]us
[l3sw1]user-in
[l3sw1]user-interface co
[l3sw1]user-interface console 0
[l3sw1-ui-console0]id
[l3sw1-ui-console0]idle-timeout 0 0
[l3sw1-ui-console0]q
[l3sw1]vl
[l3sw1]vlan ba
[l3sw1]vlan batch 2 4
Info: This operation may take a few seconds. Please wait for a moment...done.
[l3sw1]in
[l3sw1]int g0/0/1
[l3sw1-GigabitEthernet0/0/1]po
[l3sw1-GigabitEthernet0/0/1]port li
[l3sw1-GigabitEthernet0/0/1]port link-ty
[l3sw1-GigabitEthernet0/0/1]port link-type ac
[l3sw1-GigabitEthernet0/0/1]port link-type access
[l3sw1-GigabitEthernet0/0/1]po
[l3sw1-GigabitEthernet0/0/1]port de
[l3sw1-GigabitEthernet0/0/1]port default vl
[l3sw1-GigabitEthernet0/0/1]port default vlan 2
[l3sw1-GigabitEthernet0/0/1]int g0/0/2
[l3sw1-GigabitEthernet0/0/2]po
[l3sw1-GigabitEthernet0/0/2]port li
[l3sw1-GigabitEthernet0/0/2]port link-ty
[l3sw1-GigabitEthernet0/0/2]port link-type ac
[l3sw1-GigabitEthernet0/0/2]port link-type access
[l3sw1-GigabitEthernet0/0/2]po
[l3sw1-GigabitEthernet0/0/2]port de
[l3sw1-GigabitEthernet0/0/2]port default vl
[l3sw1-GigabitEthernet0/0/2]port default vlan 4
[l3sw1-GigabitEthernet0/0/2]int vl
[l3sw1-GigabitEthernet0/0/2]int vlanif 2
[l3sw1-Vlanif2]ip ad
[l3sw1-Vlanif2]ip address 192.168.2.1 24
[l3sw1-Vlanif2]int vlanif 4
[l3sw1-Vlanif4]ip ad
[l3sw1-Vlanif4]ip address 192.168.4.1 24
[l3sw1-Vlanif4]dis
[l3sw1-Vlanif4]display ma
[l3sw1-Vlanif4]display mac-ad
[l3sw1-Vlanif4]display mac-address
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-98cb-2d2d 4 - - GE0/0/2 dynamic 0/-
5489-98d4-213f 2 - - GE0/0/1 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2
[l3sw1-Vlanif4]
单臂路由技术:当只有二层交换机时,又要实现不同vlan间通信时,需要用到单臂路由技术
三层交换实现不同vlan间路由:三层交换机可以配置vlanif接口,通过vlanif接口可以配置ip地址,成为不同vlan对应的网关,从而实现不同vlan间路由
总结
vlan是虚拟的局域网
一个vlan=一个广播域=逻辑网段(子网)(广播域越小越好)
vlan管理方式有静态vlan和动态vlan
静态vlan基于端口划分
动态vlan基于mac地址划分
vlan数量一共是4096个
相同vlan间通信分为同一台交换机和跨交换机
不同vlan间通信分为单臂路由和三层交换
本文详细介绍了VLAN的概念,包括其作为逻辑网段和广播域的隔离作用,以及提升网络管理和安全性的优势。讲解了静态VLAN的创建步骤,并探讨了VLAN跨交换机的传输和通信方式,包括三层交换机在VLAN间通信中的作用。最后,总结了VLAN管理的两种主要方式:静态和动态,并指出VLAN总数为4096个。

2464

被折叠的 条评论
为什么被折叠?



