实验要求:
1/pc1和pc3所在接口为access; pvlan vlan2;
2/PC2/4/5/6处于同一网段;其中PC2可以访问PC4/5/6;但PC4可以访问PC5, 不能访问PC6
2 pc5不能访问PC6
3、PC1/3与PC2/4/5/6不在 - -个网段
4、所有PC通过DHCP获取ip地址,且PC1/3可以正常访问
SW1配置
[sw1]vlan batch 2 to 5
[sw1]int g0/0/2
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1-GigabitEthernet0/0/2]port default vlan 2
[sw1-GigabitEthernet0/0/2]int g0/0/3
[sw1-GigabitEthernet0/0/3]port hybrid pvid vlan 3
[sw1-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 5
[sw1-GigabitEthernet0/0/3]int g0/0/4
[sw1-GigabitEthernet0/0/4]port link-type trunk
[sw1-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 5
[sw1-GigabitEthernet0/0/4]int g0/0/1
[sw1-GigabitEthernet0/0/1]port hybrid tagged vlan 2
[sw1-GigabitEthernet0/0/1]port hybrid untagged vlan 3 to 5
SW2配置
[sw2]vlan batch 2 to 5
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 to 5
[sw2-GigabitEthernet0/0/1]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link-type access
[sw2-GigabitEthernet0/0/2]port default vlan 2
[sw2-GigabitEthernet0/0/2]int g0/0/3
[sw2-GigabitEthernet0/0/3]port hybrid pvid vlan 4
[sw2-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 4
[sw2-GigabitEthernet0/0/3]int g0/0/4
[sw2-GigabitEthernet0/0/4]port link-type trunk
[sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 5
SW3配置
[sw3]vlan batch 2 to 5
[sw3]int g0/0/1
[sw3-GigabitEthernet0/0/1]port link-type trunk
[sw3-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 to 5
[sw3-GigabitEthernet0/0/1]int g0/0/2
[sw3-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[sw3-GigabitEthernet0/0/2]port hybrid untagged vlan 3 to 4
[sw3-GigabitEthernet0/0/2]int g0/0/3
[sw3-GigabitEthernet0/0/3]port hybrid pvid vlan 5
[sw3-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 5
路由器配置
[r1]dhcp enable
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.1.1 24
[r1-GigabitEthernet0/0/0]dhcp select global
[r1-GigabitEthernet0/0/0]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]ip add 192.168.2.1 24
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]arp broadcast enable
[r1-GigabitEthernet0/0/0.1]dhcp select global
[r1]ip pool p1
[r1-ip-pool-p1]network 192.168.1.0 mask 24
[r1-ip-pool-p1]gateway-list 192.168.1.1
[r1-ip-pool-p1]q
[r1]ip pool p2
[r1-ip-pool-p2]network 192.168.2.0 mask 24
[r1-ip-pool-p2]gateway-list 192.168.2.1
pc1到6获取已经获取到了地址
PC1:192.168.2.254
PC2: 192.168.1.254
PC3:192.168.2.253
PC4:192.168.1.253
PC5:192.168.1.252
PC6:192.168.1.251
PC2可以ping通PC4/5/6
PC4能访问PC5不能访问PC6
实验完成!