实验拓扑图
实验要求
要求:
1、PC1和PC3所在的接口为access接口
PC2/4/5/6处于同一网段,其中PC2可以访问PC4/5/6
PC4可以访问PC5,但不能访问PC6
PC5不能访问PC6
2、PC1/3与PC2/4/5/6不在同一网段
3、所有PC通过DHCP获取IP地址,且PC1/3可以正常访问PC2/4/5/6
配置内容
因为配置过程中日志太多,不方便截图,所以只留下了命令行
交换机1
[sw1]vlan batch 2 3 4 5
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 2
[sw1-GigabitEthernet0/0/1]int g 0/0/2
[sw1-GigabitEthernet0/0/2]port link-type hybrid
[sw1-GigabitEthernet0/0/2]port hybrid untagged vlan 2 to 5
[sw1-GigabitEthernet0/0/2]int g 0/0/3
[sw1-GigabitEthernet0/0/3]port link-type trunk
[sw1-GigabitEthernet0/0/3]port trunk allow-pass vlan 2
[sw1-GigabitEthernet0/0/3]int g 0/0/4
[sw1-GigabitEthernet0/0/4]port hybrid tagged vlan 2
[sw1-GigabitEthernet0/0/4]port hybrid untagged vlan 3 to 5
交换机2
[sw2]int g 0/0/1
[sw2-GigabitEthernet0/0/1]port link-type access
[sw2-GigabitEthernet0/0/1]port default vlan 2
[sw2-GigabitEthernet0/0/1]int g 0/0/2
[sw2-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[sw2-GigabitEthernet0/0/2]port hybrid untagged vlan 2 to 5
[sw2-GigabitEthernet0/0/2]int g 0/0/3
[sw2-GigabitEthernet0/0/3]port link-type trunk
[sw2-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 5
[sw2-GigabitEthernet0/0/3]int g 0/0/4
[sw2-GigabitEthernet0/0/4]port hybrid tagged vlan 2 to 5
交换机3
[sw3]int g 0/0/1
[sw3-GigabitEthernet0/0/1]port hybrid pvid vlan 5
[sw3-GigabitEthernet0/0/1]port hybrid untagged vlan 2 3 5
[sw3-GigabitEthernet0/0/1]int g 0/0/2
[sw3-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[sw3-GigabitEthernet0/0/2]port hybrid untagged vlan 2 to 5
[sw3-GigabitEthernet0/0/2]int g 0/0/3
[sw3-GigabitEthernet0/0/3]port link-type trunk
[sw3-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 5
[sw3-GigabitEthernet0/0/3]int g 0/0/4
[sw3-GigabitEthernet0/0/4]port link-type trunk
[sw3-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 5
R1配置DHCP地址池和子接口
接口配置
[r1]int g 0/0/0.1
[r1-GigabitEthernet0/0/0.1]do
[r1-GigabitEthernet0/0/0.1]dot1q t
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]ip add 192.168.2.1 24[r1-GigabitEthernet0/0/0.1]int g 0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.1.1 24
地址池
[r1]ip pool aa -----------------给物理接口0/0/0
Info: It's successful to create an IP address pool.
[r1-ip-pool-aa]network 192.168.1.0 mask 24
[r1-ip-pool-aa]gateway-list 192.168.1.1[r1-ip-pool-aa]q
[r1]int g 0/0/0
[r1-GigabitEthernet0/0/0]dhcp select global
[r1]ip pool bb -----------------给虚拟子接口0/0/0.1(vlan2)
Info: It's successful to create an IP address pool.
[r1-ip-pool-bb]network 192.168.2.0 mask 24
[r1-ip-pool-bb]gateway-list 192.168.2.1[r1-ip-pool-bb]q
[r1]int g 0/0/0.1
[r1-GigabitEthernet0/0/0.1]dhcp select global
PC1
PC2
PC3
PC4
PC5
PC6
PC4 ping PC5
PC5 ping PC6
因为vlan隔离广播域,所以PC5(vlan4)ping不通PC6(vlan5)
PC1 ping PC2/4/5/6
例如PC1pingPC6,能通
PC3 ping PC/2/4/5/6
例如PC3pingPC6,能通
至此,实验完成