一.实验拓扑图
二.实验需求
(1)pc1和pc3所在接口为access,属于vlan2;pc2/4/5/6处于同一网段;其中pc2可以访问pc4/5/6;pc4可以访问pc5,但不能访问pc6
(2)pc5不能访问pc6
(3)pc1/3与pc2/4/5/6不在同一网段
(4)所以pc通过DHCP获取ip地址,且pc1/3可以正常访问pc2/4/5/6
三.实验步骤
步骤一:根据实验需求(1),(2)需要对pc1-pc6划分vlan,如拓扑图所示:
步骤二创建vlan,并对pc1-pc6属于vlan,进行划分:
(1)创建vlan
SW1
SW2
SW3
(2)pc1/pc3所在接口类型为access,pc2/4/5/6对应的所在接口为
SW1配置如下:
[SW1]int g 0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 2
[SW1-GigabitEthernet0/0/2]int g 0/0/3
[SW1-GigabitEthernet0/0/3]port hybrid pvid vlan 3
[SW1-GigabitEthernet0/0/3]port hybrid untagged vlan 2 to 5
SW2配置如下:
[SW2]interface GigabitEthernet 0/0/4
[SW2-GigabitEthernet0/0/4]port link-type access
[SW2-GigabitEthernet0/0/4]port default vlan 2
[SW2-GigabitEthernet0/0/4]int g 0/0/3
[SW2-GigabitEthernet0/0/3]port hybrid pvid vlan 4
[SW2-GigabitEthernet0/0/3]port hybrid untagged
[SW2-GigabitEthernet0/0/3]port hybrid untagged vlan 2 3 4
SW3配置如下:
[SW3]int g 0/0/2
[SW3-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[SW3-GigabitEthernet0/0/2]port hybrid untagged vlan 2 to 4
[SW3-GigabitEthernet0/0/2]in
[SW3-GigabitEthernet0/0/2]int g 0/0/3
[SW3-GigabitEthernet0/0/3]port hybrid pvid vlan 5
[SW3-GigabitEthernet0/0/3]port hybrid untagged vlan 2 3 5
(3)trunk干道,接口类型设置为trunk,并且允许所以vlan通过SW1:
SW1:
[SW1]int g 0/0/4
[SW1-GigabitEthernet0/0/4]port link-type trunk
[SW1-GigabitEthernet0/0/4]port trunk allow-pass vlan all
SW2:
[SW2]int g 0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[SW2-GigabitEthernet0/0/1]int g 0/0/2
[SW2-GigabitEthernet0/0/2]port link-type trunk
[SW2-GigabitEthernet0/0/2]port trunk allow-pass vlan all
SW3:
[SW3]int g 0/0/1
[SW3-GigabitEthernet0/0/1]port link-type trunk
[SW3-GigabitEthernet0/0/1]port trunk allow-pass vlan all
步骤三,vlan间路由
(1)SW1让vlan2携带标签发出,vlan3/4/5剥离标签发出
[SW1]int g 0/0/1
[SW1-GigabitEthernet0/0/1]port hybrid untagged vlan 3 4 5
[SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 2
(2)pc1/3和pc2/4/5/6分别属于不同的网段,给pc1/3划分网段为192.168.1.0/24,pc2/4/5/6划分网段为192.168.2.0/24划分接口,配置ip
[R1]int g 0/0/0
[R1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[R1-GigabitEthernet0/0/0]int g 0/0/0.2
[R1-GigabitEthernet0/0/0.2]ip address 192.168.2.1 24
[R1-GigabitEthernet0/0/0.2]dot1q termination vid 2
[R1-GigabitEthernet0/0/0.2]arp broadcast enable
[R1-GigabitEthernet0/0/0.2]dhcp enable
所有pc发布在2个网段,需要创建2个地址池
[R1]ip pool aa
[R1-ip-pool-aa]network 192.168.1.0 mask 24
[R1-ip-pool-aa]gateway-list 192.168.1.1
[R1-ip-pool-aa]dns-list 192.168.1.1
[R1-ip-pool-aa]dns-list 114.114.114.114 8.8.8.8
[R1]ip pool bb
[R1-ip-pool-bb]network 192.168.2.0 mask 24
[R1-ip-pool-bb]gateway-list 192.168.2.1
[R1-ip-pool-bb]dns-list 114.114.114.114 8.8.8.8
进入对应接口,开启dhcp服务
[R1]int g 0/0/0
[R1-GigabitEthernet0/0/0]dhcp select global
[R1]int g 0/0/0.2
[R1-GigabitEthernet0/0/0.2]dhcp select global
步骤四:实验测试
(1)所有pc 选择自动获取DHCP服务
获取的IP地址如下:
(2)pc2可以访问pc4/5/6;pc4可以访问pc5,但不能访问pc6,pc2可以访问pc4/5/6
pc4可以访问pc5,但不能访问pc6
(3)pc5不能访问pc6
(4)pc1/3可以正常访问pc2/4/5/6