VLAN配置实验

实验要求

1、PC1和PC3所在的接口为access,属于 vlan2。

2、PC2、PC4、PC5、PC6处于同一网段;其中PC2可以访问PC4、PC5、PC6;但PC4可以访问PC5,不能访问PC6。

3、PC5不能访问PC6。

4、PC1、PC3与PC2、PC4、PC5、PC6不在同一网段。

5、所有PC通过DHCP获取IP地址,且PC1与PC3可以正常访问PC2、PC4、PC5、PC6。

实验拓扑

实验思路

1、根据实验要求划分出两个不同的网段,192.168.1.0 / 24和192.168.2.0 / 24

2、给交换机的每个接口配置接口类型

PC1和PC3所在的接口配置为access

PC2、PC4、PC5、PC6所在的接口配置为hybird(因为PC2、PC4、PC5、PC6之间需要做策略,PC2的允许列表是VALAN3、VALAN4、VALAN5、VALAN6不带标签的数据流都能够通过,PC4、PC5的允许列表是VALAN3、VALAN4、VALAN5不带标签数据流可以通过,PC6的允许列表是VALN3、VLAN6不带标签的数据流可以通过)

注意:SW1的0/0/4接口的类型需要改为hybird,因为PC2、PC4、PC5、PC6属于不同的VLAN区域,而需要通过DHCP分配IP地址的话,就需要将PC2、PC4、PC5、PC6发送的数据包中不带标签;而PC1和PC3的数据包中需要带标签,原因是 PC1与PC3在同一个VALN中是通过子接口来通过DHCP分配IP地址。从而达到PC2可以访问PC4、PC5、PC6;但PC4可以访问PC5,不能访问PC6;PC5不能访问PC6。

实验步骤

划分网段

将PC1、PC3划分在192.168.1.0 / 24中,PC2、PC4、PC5、PC6划分在192.168.2.0 / 24中

SW1、SW2、SW3配置vlan及各个接口

SW1
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sys SW1
[SW1]vlan batch 2 to 6
[SW1]INT GigabitEthernet 0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access 
[SW1-GigabitEthernet0/0/1]port default vlan 2
[SW1-GigabitEthernet0/0/1]int g 0/0/2
[SW1-GigabitEthernet0/0/2]port hybrid pvid vlan 3
[SW1-GigabitEthernet0/0/2]port hybrid untagged vlan 3 4 5 6
[SW1-GigabitEthernet0/0/2]int g 0/0/3
[SW1-GigabitEthernet0/0/3]port link-type trunk
[SW1-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[SW1-GigabitEthernet0/0/4]port hybrid untagged vlan 3 4 5 6
[SW1-GigabitEthernet0/0/4]port hybrid tagged vlan 2
SW2
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sys SW2
[SW1]vlan batch 2 to 6
[SW2-GigabitEthernet0/0/1]port link-type access 
[SW2-GigabitEthernet0/0/1]port default vlan 2
[SW2-GigabitEthernet0/0/1]int g 0/0/2
[SW2-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[SW2-GigabitEthernet0/0/2]port hybrid untagged vlan 3 4 5
[SW2-GigabitEthernet0/0/2]int g 0/0/3
[SW2-GigabitEthernet0/0/3]port link-type trunk
[SW2-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[SW2-GigabitEthernet0/0/3]int g 0/0/4
[SW2-GigabitEthernet0/0/4]port link-type trunk
[SW2-GigabitEthernet0/0/4]port trunk allow-pass vlan all
SW3
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sys SW3
[SW3]vlan batch 2 to 6
[SW3]int g 0/0/1
[SW3-GigabitEthernet0/0/1]port hybrid pvid vlan 5
[SW3-GigabitEthernet0/0/1]port hybrid untagged vlan 3 4 5
[SW3-GigabitEthernet0/0/2]int g 0/0/2
[SW3-GigabitEthernet0/0/2]port hybrid untagged vlan 3 6
[SW3-GigabitEthernet0/0/1]int g 0/0/3
[SW3-GigabitEthernet0/0/3]port link-type trunk
[SW3-GigabitEthernet0/0/3]port trunk allow-pass vlan all

在R1上配置DHCP及子接口

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sys R1
[R1]int g 0/0/0.1
[R1-GigabitEthernet0/0/0.1]ip address 192.168.1.1 24
[R1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[R1-GigabitEthernet0/0/0.1]arp broadcast enable
[R1-GigabitEthernet0/0/0.1]int g 0/0/0
[R1-GigabitEthernet0/0/0]ip address 192.168.2.1 24
[R1]dhcp enable 
[R1]ip pool dhcp1
Info: It's successful to create an IP address pool. 
[R1-ip-pool-dhcp1]network 192.168.1.0 mask 24
[R1-ip-pool-dhcp1]gateway-list 192.168.1.1
[R1-ip-pool-dhcp1]dns-list 114.114.114.114 8.8.8.8
[R1]ip pool dhcp2
Info: It's successful to create an IP address pool.
[R1-ip-pool-dhcp2]network 192.168.2.0 mask 24
[R1-ip-pool-dhcp2]gateway-list 192.168.2.1
[R1-ip-pool-dhcp2]dns-list 114.114.114.114 8.8.8.8
[R1-GigabitEthernet0/0/0]dhcp select global
[R1-GigabitEthernet0/0/0]int g 0/0/0.1
[R1-GigabitEthernet0/0/0.1]dhcp select global

结果验证

PC>ping 192.168.2.252

Ping 192.168.2.252: 32 data bytes, Press Ctrl_C to break From 192.168.2.252: bytes=32 seq=1 ttl=128 time=78 ms From 192.168.2.252: bytes=32 seq=2 ttl=128 time=62 ms From 192.168.2.252: bytes=32 seq=3 ttl=128 time=63 ms From 192.168.2.252: bytes=32 seq=4 ttl=128 time=62 ms From 192.168.2.252: bytes=32 seq=5 ttl=128 time=79 ms

--- 192.168.2.252 ping statistics --- 5 packet(s) transmitted 5 packet(s) received 0.00% packet loss round-trip min/avg/max = 62/68/79 ms

PC>ping 192.168.2.251

Ping 192.168.2.251: 32 data bytes, Press Ctrl_C to break From 192.168.2.253: Destination host unreachable From 192.168.2.253: Destination host unreachable From 192.168.2.253: Destination host unreachable From 192.168.2.253: Destination host unreachable From 192.168.2.253: Destination host unreachable

--- 192.168.2.251 ping statistics --- 5 packet(s) transmitted 0 packet(s) received 100.00% packet loss

 

  • 26
    点赞
  • 18
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值