实验要求:
1)PC1/3的接口均为access模式,且属于vlan2 ,在同一网段
2)PC2/4/5/6的IP地址在同一-网段,与PC1/3不在同- -网段
3)PC2可以访问4/5/6 , PC4不能访问5/6 , PC5不能访问PC6
4)所有PC通过DHCP获取ip地址, PC1/3可以访问PC2/4/5/6
实验步骤:
1、IP地址规划及拓扑设计
2、创建VLAN设置VLAN规则(交换机)
1)SW1将Ethernet 0/0/1和 Ethernet 0/0/3 划分为vlan2的access模式
[SW1]vlan batch 2 to 6
[SW1]port-group group-member Ethernet 0/0/1 Ethernet 0/0/3
[SW1-port-group]port link-type access
[SW1-port-group]port default vlan 2
2)SW1将Ethernet 0/0/2的pvid设为vlan3模式设为hybrid允许vlan3-vlan6进入
[SW1]int e0/0/2
[SW1-Ethernet0/0/2]port hybrid pvid vlan 3
[SW1-Ethernet0/0/2]port hybrid untagged vlan 3 to 6
3)SW1将Ethernet 0/0/4的pvid设为vlan4模式设为hybrid允许vlan3-vlan4进入
[SW1]int e0/0/4
[SW1-Ethernet0/0/4]port hybrid pvid vlan 4
[SW1-Ethernet0/0/4]port hybrid untagged vlan 3 to 4
4)SW2将Ethernet 0/0/1的pvid设为vlan5模式设为hybrid允许vlan3和vlan5进入
[SW2]vlan batch 2 to 6
[SW2]int e0/0/1
[SW2-Ethernet0/0/1]port hybrid pvid vlan 5
[SW2-Ethernet0/0/1]port hybrid untagged vlan 3 5
5)SW2将Ethernet 0/0/2的pvid设为vlan6模式设为hybrid允许vlan3和vlan6进入
[SW2]int e0/0/2
[SW2-Ethernet0/0/2]port hybrid pvid vlan 6
[SW2-Ethernet0/0/2]port hybrid untagged vlan 3 6
6)SW1将Ethernet 0/0/5模式设为trunk允许vlan2-vlan6进入;SW2将Ethernet 0/0/3模式设为trunk允许vlan2-vlan6进入
[SW1]int e0/0/5
[SW1-Ethernet0/0/5]port link-type trunk
[SW1-Ethernet0/0/5]port trunk allow-pass vlan 2 to 6
[SW2]int e0/0/3
[SW2-Ethernet0/0/3]port link-type trunk
[SW2-Ethernet0/0/3]port trunk allow-pass vlan 2 to 6
7)SW1将Ethernet 0/0/6模式设为hybrid允许vlan2带标记进入,允许vlan3-vlan6不代标签进入
[SW1]int e0/0/6
[SW1-Ethernet0/0/6]port hybrid tagged vlan 2
[SW1-Ethernet0/0/6]port hybrid untagged vlan 3 to 6
8)配置完成查看在交换机上配置的vlan规则
3、配置路由器
1)配置网关地址
[router]int g0/0/0
[router-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[router-GigabitEthernet0/0/0]q
[router]int g0/0/0.1
[router-GigabitEthernet0/0/0.1]dot1q termination vid 2
[router-GigabitEthernet0/0/0.1]ip address 192.168.2.1 24
2)配置DHCP的ip池塘
[router]dhcp enable
[router]ip pool v2
[router-ip-pool-v2]network 192.168.2.0 mask 24
[router-ip-pool-v2]gateway-list 192.168.2.1
[router]ip pool v3-6
[router-ip-pool-v3-6]network 192.168.1.0 mask 24
[router-ip-pool-v3-6]gateway-list 192.168.1.1
[router-ip-pool-v3-6]q
[router]int g0/0/0.1
[router-GigabitEthernet0/0/0.1]dhcp select global
[router-GigabitEthernet0/0/0.1]arp broadcast enable
[router-GigabitEthernet0/0/0.1]q
[router]int g0/0/0
[router-GigabitEthernet0/0/0]dhcp select global
3)查看各个PC端的IP地址
4)测试:
PC2访问PC4/5/6
PC4不能访问PC5/6
PC5不能访问PC6
PC1/3可以访问PC2//4/5/6