1.vlan综述
vlan实现原理:一个vlan=一个广播域=逻辑网段(子网)
vlan——虚拟局域网
冲突:两个节点同时发送数据的情况
冲突域:产生冲突的范围
集线器/交换机的冲突域:集线器所有接口都处于一个冲突域,交换机一个接口一个冲突域
本网段广播:发送的消息会传达给这个网段的全体成员
广播域:广播扩散的范围
交换机/路由器的广播域:交换机的所有接口处于一个广播域中,路由器一个接口一个广播域
2.vlan的好处
1.隔离了广播域——端口的分隔。即便在同一个交换机上,处于不同vlan的端口也是不能通信的。这样一个物理的交换机可以当作多个逻辑的交换机使用。
2.安全性更好——网络的安全。不同vlan不能直接通信,杜绝了广播信息的不安全性。
3.灵活性——更易管理。更改用户所属的网络不必换端口和连线,只更改软件配置就可以了。
3.vlan管理的方式
1.静态vlan(比较常用,简单经济)
基于端口划分静态vlan
2.动态vlan(复杂成本高不常用)
基于MAC地址划分动态vlan
注:vlan的数量一共是4096ge,其中vlan0,4095系统保留,不可见也不可用,vlan1系统默认vlan,用户可以使用,但不能删除,vlan2-4094,用户可以创建、使用、删除
4.静态vlan的创建
创建步骤:1.三条必打命令
< >undo terminal monitor
< >system-view
[ ]sysname sw1
[ ]user-interface console 0
[ ]idle-timeout 0 0
2.交换机上创建vlan
2.1创建一个vlan
[ ]vlan 2
2.2创建多个不连续的vlan
例:一次性创建vlan3,vlan6,vlan9
[ ]vlan batch 3 6 9
2.3创建多个连续的vlan
例:一次性创建vlan10,vlan11,vlan12,vlan13,vlan14,vlan15
[ ]vlan batch 10 to 15
2.4验证vlan是否创建成功
[ ]display vlan
3.接口划分进对应的vlan
3.1进入接口
[ ]interface vlan 0e/0/1
3.2设置该接口的链路类型
[ ]port link-type access
3.3将该接口划分进对应的vlan
[ ]port default vlan3
补充:交换机根据连接对象的不同,会有不同的链路类型,交换机的连接对象是电脑,那么接口链路类型为access,注意:access这种类型接口只能属于一个vlan。交换机连接的对象是交换机,那么接口链路类型为trunk,注意:trunk不属于任何vlan,它是一条公有链路,用来在单条链路上承载不同的vlan流量,让其通过。
[ ]undo shudown 开启接口
[ ]clear configuration interface e0/0/1 清除接口下所有配置
[ ]display vlan 显示当前vlan
PC机命令
Welcome to use PC Simulator!
PC>ping 192.168.1.20
Ping 192.168.1.20: 32 data bytes, Press Ctrl_C to break
From 192.168.1.20: bytes=32 seq=1 ttl=128 time=63 ms
From 192.168.1.20: bytes=32 seq=2 ttl=128 time=47 ms
From 192.168.1.20: bytes=32 seq=3 ttl=128 time=47 ms
From 192.168.1.20: bytes=32 seq=4 ttl=128 time=47 ms
From 192.168.1.20: bytes=32 seq=5 ttl=128 time=46 ms
--- 192.168.1.20 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 46/50/63 ms
PC>ping 198.1681.30
host 198.1681.30 unreachable
PC>ping 192.168.1.30
Ping 192.168.1.30: 32 data bytes, Press Ctrl_C to break
From 192.168.1.30: bytes=32 seq=1 ttl=128 time=32 ms
From 192.168.1.30: bytes=32 seq=2 ttl=128 time=47 ms
From 192.168.1.30: bytes=32 seq=3 ttl=128 time=47 ms
From 192.168.1.30: bytes=32 seq=4 ttl=128 time=31 ms
From 192.168.1.30: bytes=32 seq=5 ttl=128 time=63 ms
--- 192.168.1.30 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/44/63 ms
PC>display mac-address
Invalid command!
PC>ping 192.168.1.20
Ping 192.168.1.20: 32 data bytes, Press Ctrl_C to break
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
--- 192.168.1.20 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
PC>192.168.1.30
Invalid command!
PC>ping 192.168.1.30
Ping 192.168.1.30: 32 data bytes, Press Ctrl_C to break
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
From 192.168.1.10: Destination host unreachable
--- 192.168.1.30 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
SW交换机命令
Ethernet0/0/2 has been available.
Aug 6 2021 22:54:18-08:00 Huawei %%01PHY/1/PHY(l)[50]: Ethernet0/0/1: change
status to up
Aug 6 2021 22:54:18-08:00 Huawei %%01IFNET/4/IF_STATE(l)[51]:Interface Vlanif1
has turned into UP state.
Aug 6 2021 22:54:18-08:00 Huawei %%01PHY/1/PHY(l)[52]: Ethernet0/0/2: change
status to up
Aug 6 2021 22:54:18-08:00 Huawei %%01PHY/1/PHY(l)[53]: Ethernet0/0/3: change
status to up
<Huawei>
<Huawei>dis
<Huawei>display ma
<Huawei>display mac-ad
<Huawei>display mac-address
<Huawei>un
<Huawei>undo te
<Huawei>undo terminal mo
<Huawei>undo terminal monitor
Info: Current terminal monitor is off.
<Huawei>sy
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sys
[Huawei]sysname sw7
[sw7]ur
[sw7]urus
[sw7]us
[sw7]user-in
[sw7]user-interface co
[sw7]user-interface console 0
[sw7-ui-console0]id
[sw7-ui-console0]idle-timeout 0 0
[sw7-ui-console0]q
[sw7]vl
[sw7]vlan 2 3 5
^
Error:Too many parameters found at '^' position.
[sw7]vlan 2 5 7
^
Error:Too many parameters found at '^' position.
[sw7]vlan ba
[sw7]vlan batch 2 3 5
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw7]DIS
[sw7]display V
[sw7]display vL
[sw7]display vlaN
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:Eth0/0/1(U) Eth0/0/2(U) Eth0/0/3(U) Eth0/0/4(D)
Eth0/0/5(D) Eth0/0/6(D) Eth0/0/7(D) Eth0/0/8(D)
Eth0/0/9(D) Eth0/0/10(D) Eth0/0/11(D) Eth0/0/12(D)
Eth0/0/13(D) Eth0/0/14(D) Eth0/0/15(D) Eth0/0/16(D)
Eth0/0/17(D) Eth0/0/18(D) Eth0/0/19(D) Eth0/0/20(D)
Eth0/0/21(D) Eth0/0/22(D) GE0/0/1(D) GE0/0/2(D)
2 common
3 common
5 common
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
2 enable default enable disable VLAN 0002
3 enable default enable disable VLAN 0003
5 enable default enable disable VLAN 0005
[sw7]di
[sw7]display ma
[sw7]display mac-ad
[sw7]display mac-address
[sw7]dis
[sw7]display ma
[sw7]display mac-ad
[sw7]display mac-address
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-98bc-6861 1 - - Eth0/0/1 dynamic 0/-
5489-9882-7e94 1 - - Eth0/0/2 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2
[sw7]
[sw7]dis
[sw7]display ma
[sw7]display mac-ad
[sw7]display mac-address
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-98bc-6861 1 - - Eth0/0/1 dynamic 0/-
5489-9882-7e94 1 - - Eth0/0/2 dynamic 0/-
5489-9812-4b02 1 - - Eth0/0/3