VLAN实验
根据题目要求:
pc1和pc3所在接口为access ; pvlan vlan2;
PC2/4/5/6 处于同一网段﹔其中PC2可以访问PC4/5/6;但PC4可以访问PC5,不能访问PC6
PC5不能访问PC6
PC1/3与PC2/4/5/6不在一个网段
所有C通过DHCP获取ip地址,且PC1/3可以正常访问PC2/4/5/6
VLAN:虚拟局域网 二层交换与路由器(三层交换机)逻辑将一个广播域切分为多个;
配置思路:
1、 交换机上创建vlan
2、 交换机上各个接口划分到对应的vlan中
3、 trunk干道
4、 vlan间路由--- 单臂路由(路由器子接口) 三层交换机
那我们来设计:
PC13 VLAN2 自动获取IP 子接口
PC2 VLAN3
PC45 VLAN4
PC6 VLAN5
配置:
sw1
[sw1]vlan batch 2 to 5
[sw1-Ethernet0/0/1]port link-type access
[sw1-Ethernet0/0/1]port default vlan 2
[sw1-Ethernet0/0/2]port link-type hybrid
[sw1-Ethernet0/0/2]port hybrid pvid vlan 3
[sw1-Ethernet0/0/2]port hybrid untagged vlan 3 4 5
[sw1-Ethernet0/0/3]port link-type trunk
[sw1-Ethernet0/0/3]port trunk allow-pass vlan 2 to 5
sw2
[sw2]vlan batch 2 to 5
[sw2-Ethernet0/0/3]port link-type trunk
[sw2-Ethernet0/0/3]port trunk allow-pass vlan 2 to 5
[sw2-Ethernet0/0/1]port link-type access
[sw2-Ethernet0/0/1]port default vlan 2
[sw2-Ethernet0/0/2]port hybrid pvid vlan 4
[sw2-Ethernet0/0/2]port hybrid untagged vlan 3 to 4
[sw2-Ethernet0/0/4]port hybrid tagged vlan 2 to 5
sw3
[sw3]vlan batch 2 to 5
[sw3-Ethernet0/0/3]port hybrid tagged vlan 2 to 5
[sw3-Ethernet0/0/1]port hybrid pvid vlan 4
[sw3-Ethernet0/0/1]port hybrid untagged vlan 3 to 4
[sw3-Ethernet0/0/2]port hybrid pvid vlan 5
[sw3-Ethernet0/0/2]port hybrid untagged vlan 3 5
sw1连路由
[sw1-Ethernet0/0/4]port hybrid tagged vlan 2
[sw1-Ethernet0/0/4]port hybrid untagged vlan 3 to 5
路由器0
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[r1-GigabitEthernet0/0/0]q
[r1]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]ip address 192.168.2.1 24
[r1-GigabitEthernet0/0/0.1]arp broadcast enable
[r1]dhcp enable
[r1]ip pool a
[r1-ip-pool-a]network 192.168.1.0 mask 24
[r1-ip-pool-a]gateway-list 192.168.1.1
[r1]ip pool b
[r1-ip-pool-b]network 192.168.2.0 mask 24
[r1-ip-pool-b]gateway-list 192.168.2.1
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]dhcp select global
[r1]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]dhcp select global
所有PC去DHCP获取IP
PC1 192.168.2.254 VLAN 2
PC2 192.168.1.254 VLAN 3
PC3 192.168.2.253 VLAN 2
PC4 192.168.1.253 VLAN 4
PC5 192.168.1.252 VLAN 4
PC6 192.168.1.251 VLAN 5
PC4不能访问PC6
实验完成
3CYoy-1645166190548)]
实验完成