实验要求:
思路
1.根据要求PC13 一个网段 PC2456 一个网段则分别分配 192.168.1.0 24(PC1/3) 192.168.2.0 (pc2456)
2.要求二中,pc2可以访问PC4/5/6;但PC4可以访问Pc5,不能访问PC6 ,PC5不能访问PC6,则需要除VLAN2 为还需3个VLAN 共5 分配如下 pc2 VLAN3 ; pc4/ 5 VLAN4 ;pc6 VLAN5
3.接口分析就要求而言 PC2/4/5/6 之间需要做策略则配置hybird类型,PC1/3为access,三交换机之间配置trunk干道. 单臂路由 连接 sw1 g4/0/0接口配置hybird,满足做策略要求
1.创建VLAN,并改变相连各自PC接口的类型,同时划分VLAN,做策略即保证:pc2可以访问PC4/5/6;但PC4可以访问Pc5,不能访问PC6 ;PC5不能访问PC6
sw1
[sw1]vlan batch 2 to 5 批量创建VLAN
[sw1]int g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 2
[sw1-GigabitEthernet0/0/1]int g0/0/2
[sw1-GigabitEthernet0/0/2]port hybrid pvid vlan 3 修改混杂口的PVID
[sw1-GigabitEthernet0/0/2]port hybrid untagged vlan 2 to 5 修改允许列表,并且出去的
时候不带标签
sw2
[sw2]vlan batch 2 to 5
[sw2-GigabitEthernet0/0/1]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link-type access
[sw2-GigabitEthernet0/0/2]port default vlan 2
[sw2-GigabitEthernet0/0/2]int g0/0/3
[sw2-GigabitEthernet0/0/3]port hybrid pvid vlan 4
[sw2-GigabitEthernet0/0/3]port hybrid untagged vlan 2 to 4
sw3
[sw3]vlan batch 2 to 5
[sw3]int g0/0/1
[sw3-GigabitEthernet0/0/1]port hybrid pvid vlan 4
[sw3-GigabitEthernet0/0/1]port hybrid untagged vlan 2 to 4
[sw3-GigabitEthernet0/0/2]port hybrid pvid vlan 5
[sw3-GigabitEthernet0/0/2]port hybrid untagged vlan 2 3 5
2.根据分析思路配置交换机之间trunk干道,且允许所有
[sw1-GigabitEthernet0/0/2]int g0/0/3
[sw1-GigabitEthernet0/0/3]port link-type trunk
[sw1-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[sw2-GigabitEthernet0/0/3]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[sw2-GigabitEthernet0/0/1]int g0/0/4
[sw2-GigabitEthernet0/0/4]port link-type trunk
[sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan all
[sw3] int g0/0/3
[sw3-GigabitEthernet0/0/3]port link-type trunk
[sw3-GigabitEthernet0/0/3]port trunk allow-pass vlan all
3.r1配置DHCP及子接口
在r1配置子接口,属于VLAN2 所以去往VLAN2 需要带标签
去往VLAN345 的流量可以不带标签。因为交换机默认接口的PVID为1 所以默认为VLAN1的流量 三个接口类型都默认允许通过
sw1
[sw1]int g0/0/4
[sw1-GigabitEthernet0/0/4]port hybrid untagged vlan 3 4 5
[sw1-GigabitEthernet0/0/4]port hybrid tagged vlan 2
r1
[r1]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]ip a 192.168.1.1 24
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]arp broadcast enable
[r1-GigabitEthernet0/0/0.1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip a 192.168.2.1 24
[r1]dhcp enable
创建2个地址池,属于vlan2 h和vlan 345
[r1]ip pool a
[r1-ip-pool-a]net 192.168.1.0 mask 24
[r1-ip-pool-a]gateway-list 192.168.1.1
[r1-ip-pool-a]dns-list 114.114.114.114
[r1-ip-pool-a]q
[r1]ip pool b
[r1-ip-pool-b]network 192.168.2.0 mask 24
[r1-ip-pool-b]gateway-list 192.168.2.1
[r1-ip-pool-b]dns-list 114.114.114.114
[r1-ip-pool-b]int g0/0/0
[r1-GigabitEthernet0/0/0.1]dhcp select global
[r1-GigabitEthernet0/0/0]dhcp select global