VLAN Access:
交换机的 VLAN Access(VLAN 访问)功能可以让交换机上的端口只能使用特定的 VLAN(虚拟局域网)。
VLAN Access 是一种基于交换机端口的 VLAN 实现方式,与 VLAN Trunking(VLAN 干道)不同,它不需要将多个 VLAN 的数据流通过同一个物理端口进行传输。在 VLAN Access 中,每个端口只属于一个 VLAN,所有进入该端口的数据都被默认标记为该 VLAN 的数据。换句话说,该端口只能传输属于该 VLAN 的数据包。
通过配置 VLAN Access,可以将不同的设备或网络段分配到不同的 VLAN 中,以实现虚拟隔离和流量控制。这对于企业或组织内部的网络管理和安全管理非常重要,可以有效地控制不同用户和设备的网络访问和通信。例如,可以将所有 IT 部门的设备分配到一个 VLAN 中,将所有客户端设备分配到另一个 VLAN 中,以此来隔离 IT 部门设备与客户端设备,保证网络安全。
在配置 VLAN Access 时,需要为每个端口指定所属的 VLAN ID,以及 VLAN ID 对应的 VLAN 名称。当有数据包进入该端口时,交换机会将该数据包的 VLAN ID 与端口所属的 VLAN ID 进行比较,如果匹配,则交换机会将数据包转发到相应的 VLAN 中,否则会将数据包丢弃或进行其他处理。
需要注意的是,如果交换机中的某个端口被配置为 VLAN Access,那么该端口只能传输属于该 VLAN 的数据包,而不能传输其他 VLAN 的数据包。如果需要传输多个 VLAN 的数据包,则需要使用 VLAN Trunking 功能。
布置拓扑图:
配置交换机:
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info enable
Info: Information center is disabled.
[Huawei]vlan 10
[Huawei-vlan10]q
[Huawei]vlan 20
[Huawei-vlan20]q
[Huawei]int eth 0/0/1
[Huawei-Ethernet0/0/1]port link-type access
[Huawei-Ethernet0/0/1]port default vlan 10
[Huawei-Ethernet0/0/1]int eth 0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 10
[Huawei-Ethernet0/0/2]int eth 0/0/3
[Huawei-Ethernet0/0/3]port link-type access
[Huawei-Ethernet0/0/3]port default vlan 10
[Huawei-Ethernet0/0/3]int eth 0/0/4
[Huawei-Ethernet0/0/4]port link-type access
[Huawei-Ethernet0/0/4]port default vlan 20
[Huawei-Ethernet0/0/4]int eth 0/0/5
[Huawei-Ethernet0/0/5]port link-type access
[Huawei-Ethernet0/0/5]port default vlan 20
[Huawei-Ethernet0/0/5]int eth 0/0/6
[Huawei-Ethernet0/0/6]port link-type access
[Huawei-Ethernet0/0/6]port default vlan 20
[Huawei-Ethernet0/0/6]display vlan
The total number of vlans is : 3
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:Eth0/0/7(D) Eth0/0/8(D) Eth0/0/9(D) Eth0/0/10(D)
Eth0/0/11(D) Eth0/0/12(D) Eth0/0/13(D) Eth0/0/14(D)
Eth0/0/15(D) Eth0/0/16(D) Eth0/0/17(D) Eth0/0/18(D)
Eth0/0/19(D) Eth0/0/20(D) Eth0/0/21(D) Eth0/0/22(D)
GE0/0/1(D) GE0/0/2(D)
10 common UT:Eth0/0/1(U) Eth0/0/2(U) Eth0/0/3(U)
20 common UT:Eth0/0/4(U) Eth0/0/5(U) Eth0/0/6(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
使用主机pc0(192.168.1.1)-ping-主机pc3(192.168.1.3)
使用wireshark抓包交换机0/0/3接口:
使用wireshark抓包交换机0/0/4接口:
说明VLAN20与VLAN10在同一网段但是无法传输数据
查看交换机路由表:VLAN为10
交换机VLAN Trunking 实验:
布置拓扑图:
LSWE1配置:
- 创建VLAN10和VLAN20
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan batch 10 20
[Huawei]int eth 0/0/1
[Huawei-Ethernet0/0/1]port link-type trunk
[Huawei-Ethernet0/0/1]port trunk allow-pass vlan 10 20
[Huawei-Ethernet0/0/1]undo port trunk allow-pass vlan 1
[Huawei-Ethernet0/0/1]quit
[Huawei]int eth 0/0/2
[Huawei-Ethernet0/0/2]port link-type trunk
[Huawei-Ethernet0/0/2]port trunk allow-pass valn 10 20
^
Error: Unrecognized command found at '^' position.
[Huawei-Ethernet0/0/2]port trunk allow-pass vlan 10 20
[Huawei-Ethernet0/0/2]undo port trunk allow-pass vlan 1
[Huawei-Ethernet0/0/2]quit
[Huawei]quit
Info: This operation may take a few seconds. Please wait for a moment...done.
LAWE2配置:
- 配置0/0/4接口为Trunk模式,允许VLAN10和VLAN20通过,拒绝VLAN1通过
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[Huawei]undo info enable
Info: Information center is disabled.
[Huawei]int eth 0/0/4
[Huawei-Ethernet0/0/4]port link-type trunk
[Huawei-Ethernet0/0/4]port trunk allow-pass vlan 10 20
[Huawei-Ethernet0/0/4]undo port trunk allow-pass vlan 1
[Huawei-Ethernet0/0/4]quit
[Huawei]int eth 0/0/1
[Huawei-Ethernet0/0/1]port link-type access
[Huawei-Ethernet0/0/1]port default vlan 10
[Huawei-Ethernet0/0/1]quit
[Huawei]int eth 0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 10
[Huawei-Ethernet0/0/2]quit
[Huawei]int eth 0/0/3
[Huawei-Ethernet0/0/3]port link-type access
[Huawei-Ethernet0/0/3]port default vlan 20
[Huawei-Ethernet0/0/3]quit
[Huawei]display vlan
The total number of vlans is : 3
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:Eth0/0/5(D) Eth0/0/6(D) Eth0/0/7(D) Eth0/0/8(D)
Eth0/0/9(D) Eth0/0/10(D) Eth0/0/11(D) Eth0/0/12(D)
Eth0/0/13(D) Eth0/0/14(D) Eth0/0/15(D) Eth0/0/16(D)
Eth0/0/17(D) Eth0/0/18(D) Eth0/0/19(D) Eth0/0/20(D)
Eth0/0/21(D) Eth0/0/22(D) GE0/0/1(D) GE0/0/2(D)
10 common UT:Eth0/0/1(U) Eth0/0/2(U)
TG:Eth0/0/4(U)
20 common UT:Eth0/0/3(U)
TG:Eth0/0/4(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
[Huawei]quit
<Huawei>save
The current configuration will be written to the device.
Are you sure to continue?[Y/N]y
Info: Please input the file name ( *.cfg, *.zip ) [vrpcfg.zip]:jiao.cfg
Now saving the current configuration to the slot 0.
Save the configuration successfully.
LAWE3配置
- 配置0/0/4接口为Trunk模式,允许VLAN10和VLAN20通过,拒绝VLAN1通过
<Huawei>sy
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[Huawei]undo info enable
Info: Information center is disabled.
[Huawei]int eth 0/0/4
[Huawei-Ethernet0/0/4]port link-type trunk
[Huawei-Ethernet0/0/4]port trunk allow-pass vlan 10 20
[Huawei-Ethernet0/0/4]undo port trunk allow-pass vlan 1
[Huawei-Ethernet0/0/4]quit
[Huawei]int eth 0/0/1
[Huawei-Ethernet0/0/1]port link-type access
[Huawei-Ethernet0/0/1]port default vlan 10
[Huawei-Ethernet0/0/1]quit
[Huawei]int eth 0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 20
[Huawei-Ethernet0/0/2]quit
[Huawei]int eth 0/0/3
[Huawei-Ethernet0/0/3]port link-type access
[Huawei-Ethernet0/0/3]port default vlan 20
[Huawei-Ethernet0/0/3]quit
[Huawei]display vlan
The total number of vlans is : 3
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:Eth0/0/5(D) Eth0/0/6(D) Eth0/0/7(D) Eth0/0/8(D)
Eth0/0/9(D) Eth0/0/10(D) Eth0/0/11(D) Eth0/0/12(D)
Eth0/0/13(D) Eth0/0/14(D) Eth0/0/15(D) Eth0/0/16(D)
Eth0/0/17(D) Eth0/0/18(D) Eth0/0/19(D) Eth0/0/20(D)
Eth0/0/21(D) Eth0/0/22(D) GE0/0/1(D) GE0/0/2(D)
10 common UT:Eth0/0/1(U)
TG:Eth0/0/4(U)
20 common UT:Eth0/0/2(U) Eth0/0/3(U)
TG:Eth0/0/4(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
[Huawei]quit
<Huawei>save
The current configuration will be written to the device.
Are you sure to continue?[Y/N]y
Info: Please input the file name ( *.cfg, *.zip ) [vrpcfg.zip]:jiao.cfg
Now saving the current configuration to the slot 0.
Save the configuration successfully.