二层防环技术

此实验采用的防环技术为MSTP生成实例

组网需求

在满足学生可以与老师通信,学生与老师可以访问校园官网,监控只可以内部互访的基础上,学 校为提升该网络的冗余性,新增了一台汇聚交换机L3_SW2,

组网拓扑如下

 业务访问需求

满足原有业务访问需求——“VLAN间通信(二)”)的基础上, 现需将学生所在网段网关发布在L3_SW1,教师网段网关发布在L3-SW2上。实 现学生和教师网络的冗余性以及业务流量的负载分担。

实验要求

根据现有规划,完成L3_SW1、L3_SW2、L2_SW2、L2_SW3设备的相关 配置,达到业务的访问需求

VLANIP地址段描述
5010.10.10.0/30校园官网服务器所属的VLAN
100192.168.100.0/24学生终端所属的VLAN
200192.168.200.0/24教师终端所属的VLAN
300192.168.30.0/24摄像头所属的VLAN

实验思路

1、实现基本网络通信

2、实现二层防环

L2_SW2配置

[L2_SW2]vlan batch 100 200 300

[L2_SW2]int g0/0/1
[L2_SW2-GigabitEthernet0/0/1]port link-type access
[L2_SW2-GigabitEthernet0/0/1]port default vlan 100
[L2_SW2-GigabitEthernet0/0/1]int g0/0/2

[L2_SW2-GigabitEthernet0/0/2]port link-type access 
[L2_SW2-GigabitEthernet0/0/2]port default vlan 200

[L2_SW2-GigabitEthernet0/0/2]int g0/0/3	
[L2_SW2-GigabitEthernet0/0/3]port link-type access 
[L2_SW2-GigabitEthernet0/0/3]port default vlan 300

[L2_SW2-GigabitEthernet0/0/3]int g0/0/4	
[L2_SW2-GigabitEthernet0/0/4]port hybrid tagged vlan 100  200 300  //此处也可以trunk模式

[L2_SW2-GigabitEthernet0/0/4]int g0/0/5	
[L2_SW2-GigabitEthernet0/0/5]port hybrid tagged vlan 100 200 300

L2_SW3配置

[L2_SW3]vlan batch 100 200 300
[L2_SW3]interface GigabitEthernet0/0/1
[L2_SW3-GigabitEthernet0/0/1] port link-type access
[L2_SW3-GigabitEthernet0/0/1] port default vlan 100

[L2_SW3-GigabitEthernet0/0/1]interface GigabitEthernet0/0/2
[L2_SW3-GigabitEthernet0/0/2] port link-type access
[L2_SW3-GigabitEthernet0/0/2] port default vlan 200

[L2_SW3-GigabitEthernet0/0/2]interface GigabitEthernet0/0/3
[L2_SW3-GigabitEthernet0/0/3] port link-type access
[L2_SW3-GigabitEthernet0/0/3] port default vlan 300

[L2_SW3-GigabitEthernet0/0/3]interface GigabitEthernet0/0/4
[L2_SW3-GigabitEthernet0/0/4] port hybrid tagged vlan 100 200 300  //此处也可用trunk模式

[L2_SW3-GigabitEthernet0/0/4]interface GigabitEthernet0/0/5
[L2_SW3-GigabitEthernet0/0/5] port hybrid tagged vlan 100 200 300

L3_SW1配置

[L3_SW1]vlan batch   50  100  200 300 
[L3_SW1]int g0/0/1	
[L3_SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 100 200 300

[L3_SW1-GigabitEthernet0/0/1]int g0/0/2
[L3_SW1-GigabitEthernet0/0/2]port hybrid tagged vlan 100 200 300

[L3_SW1-GigabitEthernet0/0/2]int g0/0/3
[L3_SW1-GigabitEthernet0/0/3]port hybrid tagged vlan 100 200 300

[L3_SW1-GigabitEthernet0/0/3]int g0/0/4   //对接校园官网接口
[L3_SW1-GigabitEthernet0/0/4]port link-type access 
[L3_SW1-GigabitEthernet0/0/4]port default vlan 50

[L3_SW1]int Vlanif 50   //学校官网服务器vlan
[L3_SW1-Vlanif50]ip address 10.10.10.1  30


[L3_SW1]dhcp enable   //启动DHCP服务,自动给客户端分配IP地址

[L3_SW1]int Vlanif 100  //进入vlan 100
[L3_SW1-Vlanif100]ip address 192.168.100.254  24  //学生IP网关
[L3_SW1-Vlanif100]dhcp select interface  //启动DHCP接口模式为学生客户端分配IP地址  
//此实验未做强制要求,可以单独配客户端的IP地址,不开启DHCP服务,因为本人太懒了,不想一台pc一台pc的配置,就配置了DHCP。
//DHCP还可以采用地址池配DHCP中继或者DHCP全局,我都太懒了,不想在多写地址池,就配了接口模式。可根据自己的需求来配置。

L3_SW2配置

[L3_SW2]interface GigabitEthernet0/0/1
[L3_SW2-GigabitEthernet0/0/1] port hybrid tagged vlan 100 200 300

[L3_SW2-GigabitEthernet0/0/1]interface GigabitEthernet0/0/2
[L3_SW2-GigabitEthernet0/0/2] port hybrid tagged vlan 100 200 300

[L3_SW2-GigabitEthernet0/0/2]interface GigabitEthernet0/0/3
[L3_SW2-GigabitEthernet0/0/3] port hybrid tagged vlan 100 200 300

[L3_SW2]dhcp enable  //启动DHCP服务,自动为客户端分配IP地址
	
[L3_SW2]int Vlanif 200  //进入vlan200
[L3_SW2-Vlanif200]ip address 192.168.200.254  24   //教师IP网关
[L3_SW2-Vlanif200]dhcp select interface   //启动DHCP接口模式为教师客户端分配IP地址


基本通信配置好,现在配置防环机制

L3_SW1

[L3_SW1]stp region-configuration   //进入stp配置	
[L3_SW1-mst-region]region-name shutong  //配置文件命名
[L3_SW1-mst-region]instance 1 vlan 100   //定义instance实例
[L3_SW1-mst-region]instance 2 vlan 200	
[L3_SW1-mst-region]active region-configuration   //激活配置,不激活则配置保存不成功


[L3_SW1]stp root primary 
[L3_SW1]stp instance 1 root primary 
[L3_SW1]stp instance 2 root secondary 

L3_SW2

[L3_SW2]stp region-configuration
[L3_SW2-mst-region] region-name shutong
[L3_SW2-mst-region] instance 1 vlan 100
[L3_SW2-mst-region] instance 2 vlan 200
[L3_SW2-mst-region] active region-configuration

[L3_SW2]stp  root secondary 
[L3_SW2]stp instance 1 root secondary 	
[L3_SW2]stp instance 2 root primary 

L2_SW2

[L2_SW2]stp region-configuration
[L2_SW2-mst-region] region-name shutong
[L2_SW2-mst-region] instance 1 vlan 100
[L2_SW2-mst-region] instance 2 vlan 200
[L2_SW2-mst-region] active region-configuration

L2_SW3

[L2_SW3]stp region-configuration
[L2_SW3-mst-region] region-name shutong
[L2_SW3-mst-region] instance 1 vlan 100
[L2_SW3-mst-region] instance 2 vlan 200
[L2_SW3-mst-region] active region-configuration

至此可以实现客户端访问服务器的需求,学生客户端与教师客户端互访的需求暂未达到

若要实现教师与学生互访,我们需要设置静态路由,但是该组网图中没有路由器,所以我们需要创建一个vlan用来充当路由。

L2_SW2

[L2_SW2]vlan 10
[L2_SW2-vlan10]q
[L2_SW2]int g0/0/4	
[L2_SW2-GigabitEthernet0/0/4]port hybrid tagged vlan 10

[L2_SW2-GigabitEthernet0/0/4]int g0/0/5	
[L2_SW2-GigabitEthernet0/0/5]port hybrid tagged vlan 10

L2_SW3

[L2_SW3]vlan 10
[L2_SW3-vlan10]q
[L2_SW3]interface GigabitEthernet0/0/4
[L2_SW3-GigabitEthernet0/0/4] port hybrid tagged vlan 10 100 200 300

[L2_SW3-GigabitEthernet0/0/4]interface GigabitEthernet0/0/5
[L2_SW3-GigabitEthernet0/0/5] port hybrid tagged vlan 10 100 200 300

L3_SW1

[L3_SW1]vlan 10
[L3_SW1-vlan10]q
[L3_SW1]int g0/0/1
[L3_SW1-GigabitEthernet0/0/1]dis th  //此命令为查看命令
#
interface GigabitEthernet0/0/1
 port hybrid tagged vlan 100 200 300
#
return	
[L3_SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 10

[L3_SW1-GigabitEthernet0/0/1]int g0/0/2
[L3_SW1-GigabitEthernet0/0/2]port hybrid tagged vlan 10

[L3_SW1]int g0/0/3	
[L3_SW1-GigabitEthernet0/0/3]port hybrid tagged vlan 10


//进入vlan10,配置IP地址,因为我配置过了,所以就只查看配置了,可根据的情况来配置vlan10
[L3_SW1]int Vlanif 10
[L3_SW1-Vlanif10]dis th
#
interface Vlanif10
ip address 172.16.0.1 255.255.255.252
#
return

//添加学生到老师的静态路由
[L3_SW1] ip route-static 192.168.200.0 255.255.255.0 172.16.0.2  //目的网段   目的子网掩码   下一跳地址


L3_SW2

[L3_SW2]vlan 10
[L3_SW2-vlan10]q
[L3_SW2]int g0/0/1	
[L3_SW2-GigabitEthernet0/0/1]port hybrid tagged vlan 10
[L3_SW2-GigabitEthernet0/0/1]int g0/0/2
[L3_SW2-GigabitEthernet0/0/2]port hybrid tagged vlan 10

[L3_SW2]int g0/0/3	
[L3_SW2-GigabitEthernet0/0/3]port hybrid tagged vlan 10

//进入vlan10,配置IP地址,因为我配置过了,所以就只查看配置了,可根据的情况来配置vlan10
[L3_SW2]int Vlanif 10
[L3_SW2-Vlanif10]dis th
#
interface Vlanif10
ip address 172.16.0.2 255.255.255.252
#
return
//添加教师端到学生端的静态路由
[L3_SW2] ip route-static 192.168.100.0 255.255.255.0 172.16.0.1

测试

学生端可以ping通服务器和教师端

按照这个配置的路由来看,教师端只可以ping通学生端,无法ping通服务器。所以我们需要修改教师IP网关所在交换机的静态路由。

学生端可以直接访问服务器而教师端不可以,是因为服务器跟学生端的vlanif在一个交换机里配置的,学生端与服务器通过vlanif进行通信。而教师端IP网关所在的交换机没有服务器的vanif,且也没有与服务器直接连接,所以需要单独配置一条路由。

此处有两种配置方法:

方法一:添加一条教师端到服务器的静态路由

[L3_SW2]ip route-static 10.10.10.0  30 172.16.0.1

方法二:删除教师端到学生端的静态路由,直接配置一条缺省路由

[L3_SW2]un ip route-static 192.168.100.0 255.255.255.0 172.16.0.1
[L3_SW2]ip route-static 0.0.0.0  0  172.16.0.1

配置好路由后我们再单独测试一下教师端的通信

可以访问服务器,至此满足所有需求。

  • 4
    点赞
  • 5
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值