<SW1>system-view //进入系统视图
[SW1]interface Vlan 1 //进入VLAN 1
[SW1-Vlanif1]ip address 192.168.10.100 24 //设置VLAN1的IP地址
[SW1-Vlanif1]display ip interface brief //查看接口IP地址
[SW1-Vlanif1]display interface brief //
<SW1>display mac-address
<SW2>display interface vlan 1
[SW1]user-interface vty 0 4 //远程登录交换机设置
[SW1-ui-vty0-4]set authentication password cipher 123456
[SW1]super password cipher 123456
<SW2>telnet 192.168.10.100
路由器设置IP地址
[AR1]int g0/0/1
[AR1-GigabitEthernet0/0/1]ip add 192.168.10.1 24
[AR1-GigabitEthernet0/0/1]int g0/0/2
[AR1-GigabitEthernet0/0/2]ip add 192.168.20.1 24
<AR1>display ip routing-table
实验:划分VLAN
[SW1]vlan bat 10 20
[SW1]display vlan
[SW1]interface e0/0/1
[SW1-Ethernet0/0/1]port link-type access
[SW1-Ethernet0/0/1]port default vlan 10
[SW1-Ethernet0/0/1]int e0/0/2
[SW1-Ethernet0/0/2]port link-type access
[SW1-Ethernet0/0/2]port default vlan 20
[SW2]vlan bat 10 20
[SW2]int e0/0/3
[SW2-Ethernet0/0/3]port link-type access
[SW2-Ethernet0/0/3]port default vlan 10
[SW2-Ethernet0/0/3]int e0/0/4
[SW2-Ethernet0/0/4]port link-type access
[SW2-Ethernet0/0/4]port default vlan 20
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type trunk
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
实验效果:PC1、PC3可以互相PING通,但不能PING通PC2、PC4
PC2、PC4可以互相PING通,但不能PING通PC1、PC3
VLAN三种模式access、trunk、hybrid(tagged打上标签,用在trunk,untagged脱下标签)
[SW1]vlan bat 10 20 30
[SW1]display vlan
[SW1]interface e0/0/1
[SW1-Ethernet0/0/1]port link-type access
[SW1-Ethernet0/0/1]port default vlan 10
[SW1-Ethernet0/0/1]int e0/0/2
[SW1-Ethernet0/0/2]port link-type access
[SW1-Ethernet0/0/2]port default vlan 20
[SW2]vlan bat 10 20 30
[SW2]int e0/0/3
[SW2-Ethernet0/0/3]port link-type access
[SW2-Ethernet0/0/3]port default vlan 10
[SW2-Ethernet0/0/3]int e0/0/4
[SW2-Ethernet0/0/4]port link-type access
[SW2-Ethernet0/0/4]port default vlan 20
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type trunk
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW2]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW1]int e0/0/1
[SW1-Ethernet0/0/1]undo port default vlan
[SW1-Ethernet0/0/1]port link-type hybrid
[SW1-Ethernet0/0/1]port hybrid pvid vlan 10
[SW1-Ethernet0/0/1]port hybrid untagged vlan 10
[SW1-Ethernet0/0/1]int e0/0/2
[SW1-Ethernet0/0/2]undo port default vlan
[SW1-Ethernet0/0/2]port link-type hybrid
[SW1-Ethernet0/0/2]port hybrid pvid vlan 20
[SW1-Ethernet0/0/2]port hybrid untagged vlan 20
[SW2]int e0/0/6
[SW2-Ethernet0/0/6]port link-type hybrid
[SW2-Ethernet0/0/6]port hybrid pvid vlan 30
[SW2-Ethernet0/0/6]port hybrid untagged vlan 30
[SW2]int g0/0/1
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 30
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 30
[SW1-GigabitEthernet0/0/1]int e0/0/1
[SW1-Ethernet0/0/1]port hybrid untagged vlan 30
[SW1]int e0/0/2
[SW1-Ethernet0/0/2]port hybrid untagged vlan 30
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]undo port trunk allow-pass vlan all
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 1
[SW1-GigabitEthernet0/0/1]port link-type hybrid
[SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 10 20 30
单臂路由实现VLAN间通信(此实验在划分VLAN实验的基础上加了路由器)
实验效果:未作单臂路由前,PC1、PC2不能互相PING通。做了单臂路由后,vlan10的PC1能PING通vlan20的PC2。
[AR1]int g0/0/1.10
[AR1-GigabitEthernet0/0/1.10]dot1q termination vid 10 //大概的意思就是将这个接口划进vlan 10
[AR1-GigabitEthernet0/0/1.10]ip add 192.168.10.1 24 //IP地址
[AR1-GigabitEthernet0/0/1.10]int g0/0/1.20
[AR1-GigabitEthernet0/0/1.20]dot1q termination vid 20
[AR1-GigabitEthernet0/0/1.20]ip add 192.168.20.1 24
[AR1-GigabitEthernet0/0/1.20]int g0/0/1.30
[AR1-GigabitEthernet0/0/1.30]dot1q termination vid 30
[AR1-GigabitEthernet0/0/1.30]ip add 192.168.30.1 24
[AR1]int g0/0/1.10
[AR1-GigabitEthernet0/0/1.10]arp broadcast enable //开启arp广播功能
[AR1-GigabitEthernet0/0/1.10]int g0/0/1.20
[AR1-GigabitEthernet0/0/1.20]arp broadcast enable
[AR1-GigabitEthernet0/0/1.20]int g0/0/1.30
[AR1-GigabitEthernet0/0/1.30]arp broadcast enable
[AR1]int g0/0/1.10
[AR1-GigabitEthernet0/0/1.10]dis this
[V200R003C00]
#
interface GigabitEthernet0/0/1.10
dot1q termination vid 10 //第一条
ip address 192.168.10.1 255.255.255.0 //第二条
arp broadcast enable //第三条
#
return
三层交换机实现VLAN间通信
实验效果:未作三层交换机前,PC1、PC2不能互相PING通。做了三层交换机后,vlan10的PC1能PING通vlan20的PC2。
[SW3]vlan bat 10 20 30
[SW3]int vlan 10
[SW3-Vlanif10]ip add 192.168.10.1 24
[SW3-Vlanif10]int vlan 20
[SW3-Vlanif20]ip add 192.168.20.1 24
[SW3-Vlanif20]int vlan 30
[SW3-Vlanif30]ip add 192.168.30.1 24
[SW3]interface g0/0/1
[SW3-GigabitEthernet0/0/1]port link-type trunk
[SW3]vlan 100
[SW3-vlan100]int vlan 100 //交换机不能配IP,所以在vlan上加IP,将端口划到该vlan,也就有IP
[SW3-Vlanif100]ip add 10.10.4.1 24
[SW3-Vlanif100]int g0/0/2
[SW3-GigabitEthernet0/0/2]port link-type access
[SW3-GigabitEthernet0/0/2]port default vlan 100
[SW3]ip route-static 0.0.0.0 0.0.0.0 10.10.4.2
[AR1]ip route-static 0.0.0.0 0.0.0.0 10.10.4.1
[SW3]vlan 40
[SW3-vlan40]int g0/0/4
[SW3-GigabitEthernet0/0/4]port link-type access
[SW3-GigabitEthernet0/0/4]port default vlan 40
[SW3]int vlan 40
[SW3-Vlanif40]ip add 192.168.40.1 24
dhcp
//方法一:基于接口
[SW3]dhcp enable
//这两条命令在网关处配置
[SW3]int vlan 10
[SW3-Vlanif10]dhcp select interface
[SW3-Vlanif10]dhcp server dns-list 2.2.2.2 5.5.5.5
//方法二:基于地址池
[SW3]ip pool v20
[SW3-ip-pool-v20]network 192.168.20.0 mask 24
[SW3-ip-pool-v20]gateway-list 192.168.20.1
[SW3-ip-pool-v20]dns-list 20.20.20.20 6.6.6.6
[SW3-ip-pool-v20]lease day 9
[SW3-ip-pool-v20]int vlan 20
[SW3-Vlanif20]dhcp select global
//SW1
[Huawei]vlan bat 10 20
[Huawei]int e0/0/1
[Huawei-Ethernet0/0/1]port link-type access
[Huawei-Ethernet0/0/1]port default vlan 10
[Huawei-Ethernet0/0/1]int e0/0/2
[Huawei-Ethernet0/0/2]port link-ty