需求实现:
1)PC1/2/3/4都属于同一个 VLAN 10
2)IP地址所在网段为 192.168.10.0/24,网关地址为 192.168.10.254
3)PC1/2不能互相访问,但是都可以访问 PC3/4
4)同时,所有的PC都可以访问 Server1
第一步:配置R1和Server1的地址和网关
第二步:配置交换机(SW1)端口隔离
交换机创建vlan并将端口加入vlan
[Huawei]sysname sw1
[sw1]vlan 10
[sw1-vlan10]q
[sw1]port-group group-member g0/0/11 to g0/0/14 g0/0/1
[sw1-port-group]port link-type access
[sw1-GigabitEthernet0/0/11]port link-type access
[sw1-GigabitEthernet0/0/12]port link-type access
[sw1-GigabitEthernet0/0/13]port link-type access
[sw1-GigabitEthernet0/0/14]port link-type access
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-port-group]port default vlan 10
[sw1-GigabitEthernet0/0/11]port default vlan 10
[sw1-GigabitEthernet0/0/12]port default vlan 10
[sw1-GigabitEthernet0/0/13]port default vlan 10
[sw1-GigabitEthernet0/0/14]port default vlan 10
[sw1-GigabitEthernet0/0/1]port default vlan 10
[sw1-port-group]q
启用端口隔离
[sw1]port-group group-member g0/0/11 g0/0/12
[sw1-port-group]port-isolate enable group 1
[sw1-GigabitEthernet0/0/11]port-isolate enable group 1
[sw1-GigabitEthernet0/0/12]port-isolate enable group 1
[sw1-port-group]q