整体拓扑如下:
涉及本节拓扑图如下:
VLAN规划
10、20、30、40、50、60、70、80、1000、4094
涉及网段:192.168.*.0 172.16.1.0 172.16.2.0
有线数据中心VLAN:10、20、30
无线VLAN:40业务1、50业务2、60管理、4094互联
有线用户侧VLAN70、80
互联VLAN:1000
注意:
所有设备间互联链路要配置TRUNK+聚合
配置各VLAN接口的IP作为网关实现路由互通
双链路问题,在默认没有任何配置的情况下,容易产生环路,建议先单链路连接,聚合配置完成后,再进行双链路的连接。
主核心VLAN、网关地址、设备间连接链路聚合+TRUNK配置
无线POE交换机由于计划承载无线和DOT1X有线客户端认证,所以VLAN保持和核心一致,但如果是仅考虑无线环境,则只需要考虑无线的VLAN即可。上联TRUNK+聚合
有线交换机由于只承载有线网络,所以只需要考虑有线VLAN即可。上联TRUNK+聚合
无线控制器由于只做无线使用,所以只需要考虑无线vlan 和互联VLAN即可。
核心交换机S5750(已做VSU)配置
vlan 10
vlan 20
vlan 30
vlan 40
vlan 50
vlan 60
vlan 70
vlan 80
vlan 1000
vlan 4094
inter vlan 1
ip address 192.168.1.254 255.255.255.0
inter vlan 10
ip address 192.168.10.254 255.255.255.0
inter vlan 20
ip address 192.168.20.254 255.255.255.0
inter vlan 30
ip address 192.168.30.254 255.255.255.0
inter vlan 40
ip address 192.168.40.254 255.255.255.0
inter vlan 50
ip address 192.168.50.254 255.255.255.0
inter vlan 60
ip address 192.168.60.254 255.255.255.0
inter vlan 70
ip address 192.168.70.254 255.255.255.0
inter vlan 80
ip address 192.168.80.254 255.255.255.0
inter vlan 1000
ip address 172.16.1.254 255.255.255.0
inter vlan 4094
ip address 172.16.2.254 255.255.255.0
聚合配置
inter G1/0/24
medium-type fiber
port-group 1
inter G2/0/24
medium-type fiber
port-group 1
inter Ag1
switchport mode trunk
switch trunk alled vlan all
switch trunk native vlan 60
telnet配置
line vty 0 4
login local
exit
username admin password ruijie
enable password ruijie
end
办公有线接入交换机配置
vlan 70
vlan 80
inter G0/25
medium-type fiber
port-group 1
inter G0/26
medium-type fiber
port-group 1
inter Ag1
switchport mode trunk
switchport trunk allowed vlan all
inter vlan 1
ip address 192.168.60.253 255.255.255.0
H3C(V5) S5008(无线POE交换机)配置
vlan 40
vlan 50
vlan 60
vlan 70
vlan 80
interface bridge-aggregation 2
port link-type trunk
port trunk permit vlan all
interface range g1/0/7 to g1/0/8
port link-aggregation group 2
inter vlan 1
ip address 192.168.60.252 24
user-interface vty 0 4
authentication-mode scheme
local-user h3c
password simple h3c
service-type telnet
authorization-attribute level 3
H3C(V7) 2540H无线控制器
telnet server enable
local-user h3c
password simple WWW.root123
service-type telnet
authorization-attribute user-role network-admin
quit
user-interface vty 0 4
authentication-mode scheme
user-role network-admin
protocol inbound telnet
idle-timeout 5 0
quit
看大家有一些人对拓扑图比较关注,这里分享2个VISIO版拓扑链接,供大家免费下载使用。
https://download.csdn.net/download/king01299/89755212 中小企业网络综合拓扑图Visio版
https://download.csdn.net/download/king01299/89755214 校园网络综合拓扑图Visio版
喜欢的收藏!还请大家留个好评,关注,收藏,一键三连哦!!!