实验要求:
1、pc1 和 PC3所在接口为access,pvlan vlan2;
pc2/4/5/6处于同一网段;其中pc2可以访问pc4/5/6;
但pc4可以访问pc5,不能访问pc6.
2、pc5不能访问pc6
实验步骤:
- 规划IP地址,PC1和PC3在同一网段:192.168.1.0/24,PC2/4/5/6在同一网段:192.168.2.0/24。由路由器配置DHCP动态分配地址。
- 根据题目要求,将PC划分为4个VLAN
PC1和PC3在VLAN2
PC2在VLAN3
PC4/5在VLAN4
PC6在VLAN5
- 配置
- 路由DHCP池建立,在g0/0/0接口匹配VLAN3/4/5,g0/0/0.1匹配vlan2
- 交换机S1,开启Vlan2/3/4/5。
[s1]vlan batch 2 to 5
G0/0/1更改access模式,匹配VLAN2;
interface GigabitEthernet0/0/1
port link-type access
port default vlan 2
G0/0/2更改hybrid模式,匹配vlan3,更改pvid为vlan3,配置untagged;
interface GigabitEthernet0/0/2
port hybrid pvid vlan 3
port hybrid untagged vlan 3 to 5
G0/0/4更改trunk模式,匹配all;
interface GigabitEthernet0/0/4
port link-type trunk
port trunk allow-pass vlan 2 to 4094
G0/0/3更改hybrid模式,配置tagged匹配vlan2保存标签,配置untagged匹配 vlan3/4/5撕掉标签。
interface GigabitEthernet0/0/3
port hybrid tagged vlan 2
port hybrid untagged vlan 3 to 5
- 交换机S2,开启VLAN2/3/4/5
[s2]vlan batch 2 to 5
G0/0/1更改access模式,匹配vlan2;
interface GigabitEthernet0/0/1
port link-type access
port default vlan 2
G0/0/2更改hybrid模式,匹配vlan4,更改pvid为vlan4,配置untagged匹配vlan3/4无标签;
interface GigabitEthernet0/0/2
port hybrid pvid vlan 4
port hybrid untagged vlan 3 to 4
G0/0/3更改truck模式,匹配all;
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
G0/0/4更改truck模式,匹配all;
interface GigabitEthernet0/0/4
port link-type trunk
port trunk allow-pass vlan 2 to 4094
- 交换机S3,开启VLAN2/3/4/5;
s3]vlan batch 2 to 5
G0/0/1更改hybrid模式,匹配vlan4 ,修改pvid为vlan4,配置untagged匹配vlan3/4撕掉标签;
interface GigabitEthernet0/0/1
port hybrid pvid vlan 4
port hybrid untagged vlan 3 to 4
G0/0/2更改hybrid模式,匹配vlan5,修改pvid为vlan5,配置untagged匹配vlan3/5撕掉标签;
interface GigabitEthernet0/0/2
port hybrid pvid vlan 5
port hybrid untagged vlan 3 5
G/0/0/3更改trunk模式,匹配all;
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
PC2都可访问
PC4可以访问PC5,不能访问PC6
PC5 不能访问PC6