此实验采用的防环技术为MSTP生成实例
组网需求
在满足学生可以与老师通信,学生与老师可以访问校园官网,监控只可以内部互访的基础上,学 校为提升该网络的冗余性,新增了一台汇聚交换机L3_SW2,
组网拓扑如下
业务访问需求
满足原有业务访问需求——“VLAN间通信(二)”)的基础上, 现需将学生所在网段网关发布在L3_SW1,教师网段网关发布在L3-SW2上。实 现学生和教师网络的冗余性以及业务流量的负载分担。
实验要求
根据现有规划,完成L3_SW1、L3_SW2、L2_SW2、L2_SW3设备的相关 配置,达到业务的访问需求
VLAN | IP地址段 | 描述 |
50 | 10.10.10.0/30 | 校园官网服务器所属的VLAN |
100 | 192.168.100.0/24 | 学生终端所属的VLAN |
200 | 192.168.200.0/24 | 教师终端所属的VLAN |
300 | 192.168.30.0/24 | 摄像头所属的VLAN |
实验思路
1、实现基本网络通信
2、实现二层防环
L2_SW2配置
[L2_SW2]vlan batch 100 200 300
[L2_SW2]int g0/0/1
[L2_SW2-GigabitEthernet0/0/1]port link-type access
[L2_SW2-GigabitEthernet0/0/1]port default vlan 100
[L2_SW2-GigabitEthernet0/0/1]int g0/0/2
[L2_SW2-GigabitEthernet0/0/2]port link-type access
[L2_SW2-GigabitEthernet0/0/2]port default vlan 200
[L2_SW2-GigabitEthernet0/0/2]int g0/0/3
[L2_SW2-GigabitEthernet0/0/3]port link-type access
[L2_SW2-GigabitEthernet0/0/3]port default vlan 300
[L2_SW2-GigabitEthernet0/0/3]int g0/0/4
[L2_SW2-GigabitEthernet0/0/4]port hybrid tagged vlan 100 200 300 //此处也可以trunk模式
[L2_SW2-GigabitEthernet0/0/4]int g0/0/5
[L2_SW2-GigabitEthernet0/0/5]port hybrid tagged vlan 100 200 300
L2_SW3配置
[L2_SW3]vlan batch 100 200 300
[L2_SW3]interface GigabitEthernet0/0/1
[L2_SW3-GigabitEthernet0/0/1] port link-type access
[L2_SW3-GigabitEthernet0/0/1] port default vlan 100
[L2_SW3-GigabitEthernet0/0/1]interface GigabitEthernet0/0/2
[L2_SW3-GigabitEthernet0/0/2] port link-type access
[L2_SW3-GigabitEthernet0/0/2] port default vlan 200
[L2_SW3-GigabitEthernet0/0/2]interface GigabitEthernet0/0/3
[L2_SW3-GigabitEthernet0/0/3] port link-type access
[L2_SW3-GigabitEthernet0/0/3] port default vlan 300
[L2_SW3-GigabitEthernet0/0/3]interface GigabitEthernet0/0/4
[L2_SW3-GigabitEthernet0/0/4] port hybrid tagged vlan 100 200 300 //此处也可用trunk模式
[L2_SW3-GigabitEthernet0/0/4]interface GigabitEthernet0/0/5
[L2_SW3-GigabitEthernet0/0/5] port hybrid tagged vlan 100 200 300
L3_SW1配置
[L3_SW1]vlan batch 50 100 200 300
[L3_SW1]int g0/0/1
[L3_SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 100 200 300
[L3_SW1-GigabitEthernet0/0/1]int g0/0/2
[L3_SW1-GigabitEthernet0/0/2]port hybrid tagged vlan 100 200 300
[L3_SW1-GigabitEthernet0/0/2]int g0/0/3
[L3_SW1-GigabitEthernet0/0/3]port hybrid tagged vlan 100 200 300
[L3_SW1-GigabitEthernet0/0/3]int g0/0/4 //对接校园官网接口
[L3_SW1-GigabitEthernet0/0/4]port link-type access
[L3_SW1-GigabitEthernet0/0/4]port default vlan 50
[L3_SW1]int Vlanif 50 //学校官网服务器vlan
[L3_SW1-Vlanif50]ip address 10.10.10.1 30
[L3_SW1]dhcp enable //启动DHCP服务,自动给客户端分配IP地址
[L3_SW1]int Vlanif 100 //进入vlan 100
[L3_SW1-Vlanif100]ip address 192.168.100.254 24 //学生IP网关
[L3_SW1-Vlanif100]dhcp select interface //启动DHCP接口模式为学生客户端分配IP地址
//此实验未做强制要求,可以单独配客户端的IP地址,不开启DHCP服务,因为本人太懒了,不想一台pc一台pc的配置,就配置了DHCP。
//DHCP还可以采用地址池配DHCP中继或者DHCP全局,我都太懒了,不想在多写地址池,就配了接口模式。可根据自己的需求来配置。
L3_SW2配置
[L3_SW2]interface GigabitEthernet0/0/1
[L3_SW2-GigabitEthernet0/0/1] port hybrid tagged vlan 100 200 300
[L3_SW2-GigabitEthernet0/0/1]interface GigabitEthernet0/0/2
[L3_SW2-GigabitEthernet0/0/2] port hybrid tagged vlan 100 200 300
[L3_SW2-GigabitEthernet0/0/2]interface GigabitEthernet0/0/3
[L3_SW2-GigabitEthernet0/0/3] port hybrid tagged vlan 100 200 300
[L3_SW2]dhcp enable //启动DHCP服务,自动为客户端分配IP地址
[L3_SW2]int Vlanif 200 //进入vlan200
[L3_SW2-Vlanif200]ip address 192.168.200.254 24 //教师IP网关
[L3_SW2-Vlanif200]dhcp select interface //启动DHCP接口模式为教师客户端分配IP地址
基本通信配置好,现在配置防环机制
L3_SW1
[L3_SW1]stp region-configuration //进入stp配置
[L3_SW1-mst-region]region-name shutong //配置文件命名
[L3_SW1-mst-region]instance 1 vlan 100 //定义instance实例
[L3_SW1-mst-region]instance 2 vlan 200
[L3_SW1-mst-region]active region-configuration //激活配置,不激活则配置保存不成功
[L3_SW1]stp root primary
[L3_SW1]stp instance 1 root primary
[L3_SW1]stp instance 2 root secondary
L3_SW2
[L3_SW2]stp region-configuration
[L3_SW2-mst-region] region-name shutong
[L3_SW2-mst-region] instance 1 vlan 100
[L3_SW2-mst-region] instance 2 vlan 200
[L3_SW2-mst-region] active region-configuration
[L3_SW2]stp root secondary
[L3_SW2]stp instance 1 root secondary
[L3_SW2]stp instance 2 root primary
L2_SW2
[L2_SW2]stp region-configuration
[L2_SW2-mst-region] region-name shutong
[L2_SW2-mst-region] instance 1 vlan 100
[L2_SW2-mst-region] instance 2 vlan 200
[L2_SW2-mst-region] active region-configuration
L2_SW3
[L2_SW3]stp region-configuration
[L2_SW3-mst-region] region-name shutong
[L2_SW3-mst-region] instance 1 vlan 100
[L2_SW3-mst-region] instance 2 vlan 200
[L2_SW3-mst-region] active region-configuration
至此可以实现客户端访问服务器的需求,学生客户端与教师客户端互访的需求暂未达到
若要实现教师与学生互访,我们需要设置静态路由,但是该组网图中没有路由器,所以我们需要创建一个vlan用来充当路由。
L2_SW2
[L2_SW2]vlan 10
[L2_SW2-vlan10]q
[L2_SW2]int g0/0/4
[L2_SW2-GigabitEthernet0/0/4]port hybrid tagged vlan 10
[L2_SW2-GigabitEthernet0/0/4]int g0/0/5
[L2_SW2-GigabitEthernet0/0/5]port hybrid tagged vlan 10
L2_SW3
[L2_SW3]vlan 10
[L2_SW3-vlan10]q
[L2_SW3]interface GigabitEthernet0/0/4
[L2_SW3-GigabitEthernet0/0/4] port hybrid tagged vlan 10 100 200 300
[L2_SW3-GigabitEthernet0/0/4]interface GigabitEthernet0/0/5
[L2_SW3-GigabitEthernet0/0/5] port hybrid tagged vlan 10 100 200 300
L3_SW1
[L3_SW1]vlan 10
[L3_SW1-vlan10]q
[L3_SW1]int g0/0/1
[L3_SW1-GigabitEthernet0/0/1]dis th //此命令为查看命令
#
interface GigabitEthernet0/0/1
port hybrid tagged vlan 100 200 300
#
return
[L3_SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 10
[L3_SW1-GigabitEthernet0/0/1]int g0/0/2
[L3_SW1-GigabitEthernet0/0/2]port hybrid tagged vlan 10
[L3_SW1]int g0/0/3
[L3_SW1-GigabitEthernet0/0/3]port hybrid tagged vlan 10
//进入vlan10,配置IP地址,因为我配置过了,所以就只查看配置了,可根据的情况来配置vlan10
[L3_SW1]int Vlanif 10
[L3_SW1-Vlanif10]dis th
#
interface Vlanif10
ip address 172.16.0.1 255.255.255.252
#
return
//添加学生到老师的静态路由
[L3_SW1] ip route-static 192.168.200.0 255.255.255.0 172.16.0.2 //目的网段 目的子网掩码 下一跳地址
L3_SW2
[L3_SW2]vlan 10
[L3_SW2-vlan10]q
[L3_SW2]int g0/0/1
[L3_SW2-GigabitEthernet0/0/1]port hybrid tagged vlan 10
[L3_SW2-GigabitEthernet0/0/1]int g0/0/2
[L3_SW2-GigabitEthernet0/0/2]port hybrid tagged vlan 10
[L3_SW2]int g0/0/3
[L3_SW2-GigabitEthernet0/0/3]port hybrid tagged vlan 10
//进入vlan10,配置IP地址,因为我配置过了,所以就只查看配置了,可根据的情况来配置vlan10
[L3_SW2]int Vlanif 10
[L3_SW2-Vlanif10]dis th
#
interface Vlanif10
ip address 172.16.0.2 255.255.255.252
#
return
//添加教师端到学生端的静态路由
[L3_SW2] ip route-static 192.168.100.0 255.255.255.0 172.16.0.1
测试
学生端可以ping通服务器和教师端
按照这个配置的路由来看,教师端只可以ping通学生端,无法ping通服务器。所以我们需要修改教师IP网关所在交换机的静态路由。
学生端可以直接访问服务器而教师端不可以,是因为服务器跟学生端的vlanif在一个交换机里配置的,学生端与服务器通过vlanif进行通信。而教师端IP网关所在的交换机没有服务器的vanif,且也没有与服务器直接连接,所以需要单独配置一条路由。
此处有两种配置方法:
方法一:添加一条教师端到服务器的静态路由
[L3_SW2]ip route-static 10.10.10.0 30 172.16.0.1
方法二:删除教师端到学生端的静态路由,直接配置一条缺省路由
[L3_SW2]un ip route-static 192.168.100.0 255.255.255.0 172.16.0.1
[L3_SW2]ip route-static 0.0.0.0 0 172.16.0.1
配置好路由后我们再单独测试一下教师端的通信
可以访问服务器,至此满足所有需求。