赞
踩
1 虚拟局域网(VLAN)是一组逻辑上的设备和用户,这些设备和用户并不受物理位置的限制,可以根据功能、部门及应用等因素将它们组织起来,相互之间的通信就好像它们在同一个网段中一样,由此得名虚拟局域网,隔离广播,提升安全.
2 划分VLAN的方式有:基于接口、基于MAC地址、基于子网、基于协议、基于策略(MAC地址、IP地址、接口)
根据交换机的接口来划分VLAN,基于接口划分VLAN,是最简单,最常见的划分方式。网络管理员预先给交换机的每个接口配置不同的PVID,当一个数据帧进入交换机时,如果没有带VLAN标签,该数据帧就会被打上接口指定PVID的Tag。然后数据帧将在指定PVID中传输。
3 实验拓扑
4配置
#sw1
- <Huawei>
- <Huawei>sys
- Enter system view, return user view with Ctrl+Z.
- [Huawei]sysnam
- [Huawei]sysname sw1 //交换机名字
- [sw1]
- [sw1]vlan batch 6 7 8 //批量创建VLAN 6和VLAN 7 ,vlan 8
- [sw1]dis vlan //查看vlan
- [sw1]interface GigabitEthernet 0/0/3
- [sw1-GigabitEthernet0/0/3]port link-type access //和接入设备相连的接口类型必须是access,接口默认类型不是access,需要手动配置为access
- [sw1-GigabitEthernet0/0/3]port default vlan 8 //将接口GE0/0/3加入VLAN 8
- [sw1-GigabitEthernet0/0/3]qu
- [sw1]interface GigabitEthernet 0/0/4
- [sw1-GigabitEthernet0/0/4]port link-type access
- [sw1-GigabitEthernet0/0/4]port default vlan 6
- [sw1-GigabitEthernet0/0/3]qu
- [sw1]interface GigabitEthernet 0/0/5
- [sw1-GigabitEthernet0/0/5]port link-type access
- [sw1-GigabitEthernet0/0/5]port default vlan 7
- [sw1-GigabitEthernet0/0/5]qu
- [sw1]interface Eth-Trunk 1 //创建ID为1的Eth-Trunk接口
- [sw1-Eth-Trunk1]trunkport GigabitEthernet 0/0/1 to 0/0/2 //在Eth-Trunk1接口中加入GE0/0/1到GE0/0/2二个成员接口
- [sw1-Eth-Trunk1]qu
- # 配置Eth-Trunk1接口允许VLAN6和VLAN7,VLAN8通过
- [sw1]interface eth-trunk 1
- [sw1-Eth-Trunk1]port link-type trunk
- [sw1-Eth-Trunk1]port trunk allow-pass vlan 6 7 8
- [sw1-Eth-Trunk1]dis this \\查看配置
- [sw1-Eth-Trunk1]qu
- [sw1]qu
- <sw1>save
#sw2
- [Huawei]sysn
- [Huawei]sysname sw2
- [sw2]
- [sw2]vlan batch 6 7 8
- [sw2]interface GigabitEthernet 0/0/3
- [sw2-GigabitEthernet0/0/3]port link-type access
- [sw2-GigabitEthernet0/0/3]port default vlan 6
- [sw2-GigabitEthernet0/0/3]qu
- [sw2]interface GigabitEthernet 0/0/4
- [sw2-GigabitEthernet0/0/4]port link-type access
- [sw2-GigabitEthernet0/0/4]port default vlan 7
- [sw2-GigabitEthernet0/0/4]qu
- [sw2]interface GigabitEthernet 0/0/5
- [sw2-GigabitEthernet0/0/5]port link-type access
- [sw2-GigabitEthernet0/0/5]port default vlan 7
- [sw2-GigabitEthernet0/0/5]qu
- [sw2]interface Eth-Trunk 1
- [sw2-Eth-Trunk1]trunkport GigabitEthernet 0/0/1 to 0/0/2
- [sw2-Eth-Trunk1]port link-type trunk
- [sw2-Eth-Trunk1]port trunk allow-pass vlan 6 7 8
- [sw2-Eth-Trunk1]qu
- [sw2]qu
- <sw2>save
#pc 和server端配置
5验证配置结果
#在视图下执行display eth-trunk 1命令,检查Eth-Trunk是否创建成功,及成员接口是否正确加入
- [sw1]display eth-trunk 1
- Eth-Trunk1's state information is:
- WorkingMode: NORMAL Hash arithmetic: According to SIP-XOR-DIP
- Least Active-linknumber: 1 Max Bandwidth-affected-linknumber: 8
- Operate status: up Number Of Up Port In Trunk: 2
- --------------------------------------------------------------------------------
- PortName Status Weight
- GigabitEthernet0/0/1 Up 1
- GigabitEthernet0/0/2 Up 1
-
- <sw2>dis eth-trunk 1
- Eth-Trunk1's state information is:
- WorkingMode: NORMAL Hash arithmetic: According to SIP-XOR-DIP
- Least Active-linknumber: 1 Max Bandwidth-affected-linknumber: 8
- Operate status: up Number Of Up Port In Trunk: 2
- --------------------------------------------------------------------------------
- PortName Status Weight
- GigabitEthernet0/0/1 Up 1
- GigabitEthernet0/0/2 Up 1
将pc1和pc3配置在一个网段;将pc2和pc4,pc5配置在一个网段,pc1和pc3能够互相ping通,但是均不能ping通pc2和pc4,pc5。pc2和pc4,pc5能够互相ping通,但是均不能ping通pc1和pc3.
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。