一、实验拓扑
二、实验要求
1、pc1和pc3所在接口为access; pvlan vlan2;
2、PC2/4/5/6处于同一网段;其中PC2可以访问PC4/5/6;但PC4可以访问PC5, 不能访问PC6;
3、PC5不能访问PC6;
4、PC1/3与PC2/4/5/6不在一个网段;
5、所有PC通过DHCP获取ip地址,且PC1/3可以正常访问
三、实验配置
1、
R1:
[R1]vlan batch 2 to 5
[R1]int g0/0/2
[R1-GigabitEthernet0/0/2]port link-type access
[R1-GigabitEthernet0/0/2]port default vlan 2
[R1-GigabitEthernet0/0/2]int g0/0/3
[R1-GigabitEthernet0/0/3]port hybrid pvid vlan 3
[R1-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 5
[R1-GigabitEthernet0/0/3]int g0/0/4
[R1-GigabitEthernet0/0/4]port link-type trunk
[R1-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 5
[R1-GigabitEthernet0/0/4]int g0/0/1
[R1-GigabitEthernet0/0/1]port hybrid tagged vlan 2
[R1-GigabitEthernet0/0/1]port hybrid untagged vlan 3 to 5
R2:
[R2]vlan batch 2 to 5
[R2]int g0/0/1
[R2-GigabitEthernet0/0/1]port link-type trunk
[R2-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 to 5
[R2-GigabitEthernet0/0/1]int g0/0/2
[R2-GigabitEthernet0/0/2]port link-type access
[R2-GigabitEthernet0/0/2]port default vlan 2
[R2-GigabitEthernet0/0/2]int g0/0/3
[R2-GigabitEthernet0/0/3]port hybrid pvid vlan 4
[R2-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 4
[R2-GigabitEthernet0/0/3]int g0/0/4
[R2-GigabitEthernet0/0/4]port link-type trunk
[R2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 5
R3:
[R3]vlan batch 2 to 5
[R3]int g0/0/1
[R3-GigabitEthernet0/0/1]port link-type trunk
[R3-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 to 5
[R3-GigabitEthernet0/0/1]int g0/0/2
[R3-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[R3-GigabitEthernet0/0/2]port hybrid untagged vlan 3 to 4
[R3-GigabitEthernet0/0/2]int g0/0/3
[R3-GigabitEthernet0/0/3]port hybrid pvid vlan 5
[R3-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 5
2、路由器配置
[R1]dhcp enable
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.1.1 24
[R1-GigabitEthernet0/0/0]dhcp select global
[R1-GigabitEthernet0/0/0]int g0/0/0.1
[R1-GigabitEthernet0/0/0.1]ip add 192.168.2.1 24
[R1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[R1-GigabitEthernet0/0/0.1]arp broadcast enable
[R1-GigabitEthernet0/0/0.1]dhcp select global
[R1]ip pool p1
[R1-ip-pool-p1]network 192.168.1.0 mask 24
[R1-ip-pool-p1]gateway-list 192.168.1.1
[R1-ip-pool-p1]q
[R1]ip pool p2
[R1-ip-pool-p2]network 192.168.2.0 mask 24
[R1-ip-pool-p2]gateway-list 192.168.2.1
ping 4\5\6
PC4能访问PC5不能访问PC6