实验拓扑图:
实验配置思路:
1、修改MAC地址优先级防止MAC地址漂移
2、交换机G0/0/2口和G0/0/3口会收到同一个MAC地址,MAC地址表会出现震荡
3、配置MAC地址优先级,让MAC地址优先级高的接口先学习到MAC地址
4、MAC地址优先级较低的端口,只有等优先级较高的端口down,才可以学习到MAC地址
实验摘要重点命令:
[Huawei]int g0/0/2 //进入接口
[Huawei-GigabitEthernet0/0/2]mac-learning priority 1 //配置接口优先级为1
[Huawei-GigabitEthernet0/0/2]quit //退出
[Huawei]
实验详细配置步骤:
PC2——Ping PC1
PC>ping 192.168.1.1 //ping PC1
Ping 192.168.1.1: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: bytes=32 seq=1 ttl=128 time=31 ms
From 192.168.1.1: bytes=32 seq=2 ttl=128 time=47 ms
From 192.168.1.1: bytes=32 seq=3 ttl=128 time=46 ms
From 192.168.1.1: bytes=32 seq=4 ttl=128 time=47 ms
From 192.168.1.1: bytes=32 seq=5 ttl=128 time=31 ms //ping 通
--- 192.168.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/40/47 ms
PC>
SW1——查看MAC地址表项
<Huawei>dis mac-address //查看MAC地址表项
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-983d-5ce0 1 - - GE0/0/2 dynamic 0/- //这个MAC地址是通过G0/0/2口学到的
5489-9820-3850 1 - - GE0/0/1 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2
<Huawei>
PC3——ping PC1
PC>ping 192.168.1.1 //ping PC1
Ping 192.168.1.1: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: bytes=32 seq=1 ttl=128 time=47 ms
From 192.168.1.1: bytes=32 seq=2 ttl=128 time=47 ms
From 192.168.1.1: bytes=32 seq=3 ttl=128 time=31 ms
From 192.168.1.1: bytes=32 seq=4 ttl=128 time=31 ms
From 192.168.1.1: bytes=32 seq=5 ttl=128 time=32 ms //ping 通
--- 192.168.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/37/47 ms
PC>
SW1——查看MAC地址表项
同一个MAC地址通过不同的接口学习到
<Huawei>dis mac-address //查看MAC地址表项
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-983d-5ce0 1 - - GE0/0/3 dynamic 0/- //这个MAC地址是通过G0/0/3口学到的
5489-9820-3850 1 - - GE0/0/1 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2
<Huawei>
SW1——配置MAC学习优先级
防止环路,防MAC仿冒攻击,配置接口MAC地址学习优先级
[Huawei]int g0/0/2 //进入接口
[Huawei-GigabitEthernet0/0/2]mac-learning priority 1 //配置接口优先级为1
[Huawei-GigabitEthernet0/0/2]quit //退出
[Huawei]
PC2——ping PC1
由于PC2连接交换机的接口是G0/0/2口,MAC地址的优先级较高
PC>ping 192.168.1.1 //ping PC1
Ping 192.168.1.1: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: bytes=32 seq=1 ttl=128 time=31 ms
From 192.168.1.1: bytes=32 seq=2 ttl=128 time=31 ms
From 192.168.1.1: bytes=32 seq=3 ttl=128 time=31 ms
From 192.168.1.1: bytes=32 seq=4 ttl=128 time=31 ms
From 192.168.1.1: bytes=32 seq=5 ttl=128 time=47 ms //ping 通
--- 192.168.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/34/47 ms
PC>
PC3—— ping PC1
由于PC3连接交换机的接口是G0/0/3口,MAC地址优先级较低,交换机无法学习到MAC地址,所以无法ping通PC1
PC>ping 192.168.1.1 //ping PC1
Ping 192.168.1.1: 32 data bytes, Press Ctrl_C to break
From 192.168.1.3: Destination host unreachable
From 192.168.1.3: Destination host unreachable
From 192.168.1.3: Destination host unreachable
From 192.168.1.3: Destination host unreachable
From 192.168.1.3: Destination host unreachable //由于交换机学习不到MAC地址
--- 192.168.1.1 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
PC>
SW1——查看MAC地址表项
那个接口的优先级高,学习那个接口的MAC地址
[Huawei]dis mac-address //查看MAC地址表项
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-983d-5ce0 1 - - GE0/0/2 dynamic 0/- //由于G0/0/2口的MAC地址优先级高
5489-9820-3850 1 - - GE0/0/1 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2
[Huawei]
断开连接PC2的线路
PC3——ping PC1
PC>ping 192.168.1.1 //ping PC 1
Ping 192.168.1.1: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: bytes=32 seq=1 ttl=128 time=46 ms
From 192.168.1.1: bytes=32 seq=2 ttl=128 time=15 ms
From 192.168.1.1: bytes=32 seq=3 ttl=128 time=47 ms
From 192.168.1.1: bytes=32 seq=4 ttl=128 time=16 ms
From 192.168.1.1: bytes=32 seq=5 ttl=128 time=47 ms //ping 通
--- 192.168.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 15/34/47 ms
PC>
SW1——查看MAC地址表项
如果G0/0/2口线路断开,G0/0/3的PC是可以ping 通PC1的
[Huawei]dis mac-address //查看MAC地址表项
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-9820-3850 1 - - GE0/0/1 dynamic 0/-
5489-983d-5ce0 1 - - GE0/0/3 dynamic 0/- //由于G0/0/2口断开,没有映射,G0/0/3口的PC是可以ping 通PC1
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2
[Huawei]