VLAN—交换
VLAN—虚拟局域网—地理覆盖范围较小的网络—虚拟的一个广播域
MLAN—城域网
WLAN—广域网
VLAN的要求—将一个广播域逻辑上拆分为多个虚拟的广播域
1.创建VLAN
<Huawei>display vlan—查看交换机VLAN的情况
VID—IEEE国际公有化组织规范的协议标准—为了标识和区分不同的VLAN
VID是由二进制构成并且是由12位构成(2的12次方4096)—0 -4095—0和4095保留不能去配—能配的范围为1-4094
Ports—接口
[Huawei]vl
[Huawei]vlan ?
INTEGER<1-4094> VLAN ID
batch Batch process
[Huawei]vlan 2—创建单个VLAN
初始情况下交换机默认有一个VLAN1
[Huawei]vlan batch 3 ?
INTEGER<1-4094> VLAN ID
to Range link symbol
<cr>
[Huawei]vlan batch 3 to 100—创建3-100个VLAN
[Huawei]vlan batch 102 103—创建102和103这两个VLAN
[Huawei]undo vlan batch 3 to 102—删除创建的VLAN
2.VLAN的划分方式(划多少个部门创建多少个VLAN):
打开交换机—创建两个VLAN
[Huawei]vlan 2
[Huawei]vlan 3
虽然已经创建了两个VLAN但是没有任何数据此时交换机所有接口还是属于VLAN1所以还是一个广播域
①将交换机的接口划分不同的VLAN—物理VLAN(接口)—一层VLAN
②将MAC地址和VLAN进行映射,从而实现VLAN的划分—二层VLAN
③根据以太网帧中携带的类型字段划分—三层VLAN
类型:IPV4-0100和IPV6-0110
CRC—帧校验的算法
FCS—帧校验
传统的以太网帧结构—untag帧(不携带VLAN标签的数据帧)
802.1Q数据帧—tag帧(携带VLAN标签的数据帧)
3.接口分配链路类型(华为规定交换机下来不携带标签的流量的办法)
将交换机和PC连接链路的接口配置为access
port link-type access—进入接口,一旦接口配置为了access类型,则代表从该接口下发的流量都是不携带VLAN标签的流量
打开交换机
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/1]port default vlan 2
[Huawei-GigabitEthernet0/0/1]q
[Huawei]display vlan
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 2
[Huawei-GigabitEthernet0/0/2]q
[Huawei]interface GigabitEthernet 0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 3
[Huawei-GigabitEthernet0/0/3]q
[Huawei]interface GigabitEthernet 0/0/4
[Huawei-GigabitEthernet0/0/4]port link-type access
[Huawei-GigabitEthernet0/0/4]port default vlan 3
编号一样就属于一个广播域,因此上图有四个广播域
一般将交换机与交换机之间的链路配置为trunk
[Huawei]interface GigabitEthernet 0/0/5
[Huawei-GigabitEthernet0/0/5]port link-type trunk
[Huawei-GigabitEthernet0/0/5]port trunk allow-pass vlan 2 3—允许对应的VLAN流量通过,同时VLAN标签将被保留
上面的配置都是对于交换机1而言的,打开交换机2
<Huawei>sys
[Huawei]sys sw2
[sw2]vlan batch 2 3—创建VLAN
[sw2]interface GigabitEthernet 0/0/2
[sw2-GigabitEthernet0/0/2]port link-type access —分配接口的链路类型
[sw2-GigabitEthernet0/0/2]q
[sw2]interface GigabitEthernet 0/0/3
[sw2-GigabitEthernet0/0/3]port link-type access
[sw2-GigabitEthernet0/0/3]port default vlan 3
[sw2-GigabitEthernet0/0/3]q
[sw2]interface GigabitEthernet 0/0/1
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
这张图不是我们如期的效果
打开R1
<Huawei>sys
[Huawei]sys r1
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.1.1 24
[r1-GigabitEthernet0/0/0]q
[r1]interface GigabitEthernet 0/0/1
[r1-GigabitEthernet0/0/1]ip add 192.168.2.1 24
[r1-GigabitEthernet0/0/1]q
打开交换机1
[Huawei]interface GigabitEthernet 0/0/6
[Huawei-GigabitEthernet0/0/6]port link-type access
[Huawei-GigabitEthernet0/0/6]port default vlan 2
[Huawei-GigabitEthernet0/0/6]q
[Huawei]interface GigabitEthernet 0/0/7
[Huawei-GigabitEthernet0/0/7]port link-type access
[Huawei-GigabitEthernet0/0/7]port default vlan 3
[Huawei-GigabitEthernet0/0/7]q
打开R1(创建虚拟接口)
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]undo ip address
[r1-GigabitEthernet0/0/0]q
[r1]interface GigabitEthernet 0/0/0.1—创建虚拟子接口
[r1-GigabitEthernet0/0/0.1]ip add 192.168.1.1 24—配置IP地址
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2—子接口按照802.1Q标准去执行,并且告诉接口告诉它属于VLAN几去服务VLAN几
打开交换机1
[Huawei]interface GigabitEthernet 0/0/6
[Huawei-GigabitEthernet0/0/6]undo port default vlan
[Huawei-GigabitEthernet0/0/6]undo port link-type
[Huawei-GigabitEthernet0/0/6]port link-type trunk
[Huawei-GigabitEthernet0/0/6]port trunk allow-pass vlan 2 3
[r1-GigabitEthernet0/0/0.1]arp broadcast enable
打开R1
[r1-GigabitEthernet0/0/0.1]q
[r1]interface GigabitEthernet 0/0/0.2
[r1-GigabitEthernet0/0/0.2]q
[r1-GigabitEthernet0/0/1]undo ip add
[r1-GigabitEthernet0/0/1]q
[r1]interface GigabitEthernet 0/0/0.2
[r1-GigabitEthernet0/0/0.2]ip add 192.168.2.1 24
[r1-GigabitEthernet0/0/0.2]dot1q termination vid 3
[r1-GigabitEthernet0/0/0.2]arp broadcast enable
4.接口划分VLAN
[Huawei-GigabitEthernet0/0/1]port default vlan ?
INTEGER<1-4094> VLAN ID
5.跨网段传输—需要借助路由器
[Huawei]interface GigabitEthernet 0/0/0.1
interface GigabitEthernet0/0/0.1 —创建虚拟子接口
dot1q termination vid 2 —子接口按照802.1Q标准去执行,并且告诉接口告诉它属于VLAN几去服务VLAN几
ip address 192.168.1.1 255.255.255.0 —配IP地址
arp broadcast enable—开启arp功能