.:
一、实验要求
.:
1、pc1和pc3所在接口为access;属于vlan 2;
pc2/pc4/pc5/pc6处于同一网段;其中pc2可以访问pc4/pc5/pc6;
pc4可以访问pc6; pc5不能访问pc6;
2、pc1/pc3与pc2/pc4/pc5/pc6不在同一网段;
3、所有pc通过DHCP获取IP地址,且pc1/pc3可以正常访问pc2/pc4/pc5/pc6;
.:
三、实验思路
.:
1、pc1和pc3所在接口为access,其他连接主机的接口为hybrid,交换机间的为trunk
2、因为pc1/pc3与pc2/pc4/pc5/pc6不在同一网段(不同网段需要路由器转发)
vlan3/vlan4/vlan5/vlan6访问vlan2通过路由器,所以不需要管vlan2,
3、pc2可以访问pc4/pc5/pc6,因此hybrid接口允许vlan3/vlan4/vlan5/vlan6通过,但必须不带标签
4、pc4可以访问pc6,但pc4也有访问pc2/pc5的需求,因此hybrid接口允许vlan3/vlan4/vlan5/vlan6通过,但必须不带标签
5、pc5不可以访问pc6,但pc5也有访问pc2/pc4的需求,因此hybrid接口允许vlan3/vlan4/vlan5通过,但必须不带标签
6、交换机间的trunk干道放行所有vlan
7、在华为中不带标签的划归物理接口,子接口专门管理带标签的vlan
因此路由器划分子接口专门管理vlan2(携带标签)
物理接口管理vlan3/vlan4/vlan5/vlan6(不携带标签)
所以在SW1的g/0/0/4接口对vlan2带标签通过,对vlan3/vlan4/vlan5/vlan6不带标签通过
8、配置DHCP服务,在子接口和物理接口都开启DHCP
.:
四、实验步骤
1)配置交换机的VLAN
①SW1
.:
[SW1]vlan batch 2 to 6 # 定义vlan
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access # 定义接口类型为access
[SW1-GigabitEthernet0/0/1]port default vlan 2 # 设置接口的vlan
[SW1-GigabitEthernet0/0/1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port hybrid pvid vlan 3 # 设置接口pvid
[SW1-GigabitEthernet0/0/2]port hybrid untagged 3 to 6 # 设置对vlan的放行
[SW1]int g0/0/3
[SW1-GigabitEthernet0/0/3]port link-type trunk
[SW1-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6
[SW1]int g0/0/4
[SW1-GigabitEthernet0/0/4]port hybrid tagged vlan 2
[SW1-GigabitEthernet0/0/4]port hybrid untagged vlan 3 to 6
.:
②SW2
.:
[SW2]vlan batch 2 to 6
[SW2]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type access
[SW2-GigabitEthernet0/0/1]port default vlan 2
[SW2-GigabitEthernet0/0/1]int g0/0/2
[SW2-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[SW2-GigabitEthernet0/0/2]port hybrid untagged vlan 3 to 6
[SW2-GigabitEthernet0/0/2]int g0/0/3
[SW2-GigabitEthernet0/0/3]port link-type trunk
[SW2-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6
[SW2-GigabitEthernet0/0/3]int g0/0/4
[SW2-GigabitEthernet0/0/4]port link-type trunk
[SW2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 6
.:
③SW3
.:
[SW3]vlan batch 2 to 6
[SW3]int g0/0/1
[SW3-GigabitEthernet0/0/1]port hybrid pvid vlan 5
[SW3-GigabitEthernet0/0/1]port hybrid untagged vlan 3 4 5
[SW3-GigabitEthernet0/0/1]int g0/0/2
[SW3-GigabitEthernet0/0/2]port hybrid pvid vlan 6
[SW3-GigabitEthernet0/0/2]port hybrid untagged vlan 2 4 6
[SW3-GigabitEthernet0/0/1]int g0/0/3
[SW3-GigabitEthernet0/0/3]port link-type trunk
[SW3-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6
.:
2、配置路由器的子接口
分析:
.:
由于vlan 2和其他vlan不在同一网段,所以vlan2访问其他vlan是通过路由器进行访问,所以要给vlan2配置一个路由器子接口
由于vlan 3/4/5/6若全带标签发送数据的话,将会被分配到不同的子接口进行管理vlan,所以可在SW1连接路由器的接口上,将vlan3/4/5/6剥离标签,由物理接口同一管理
[R1]int g0/0/0 # 在华为中不带标签的划归物理接口
[R1-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[R1]int g0/0/0.2 # 子接口专门管理带标签的vlan,例如:vlan2
[R1-GigabitEthernet0/0/0.1]ip add 192.168.2.254 24
[R1-GigabitEthernet0/0/0.1]dot1q termination vid 2
.:
3)配置DHCP服务
.:
[R1]ip pool aa
[R1-ip-pool-aa]network 192.168.1.0 mask 24
[R1-ip-pool-aa]gateway-list 192.168.1.254
[R1-ip-pool-aa]dns-list 114.114.114.114
[R1-ip-pool-aa]q
[R1]ip pool bb
[R1-ip-pool-bb]network 192.168.2.0 mask 24
[R1-ip-pool-bb]gateway-list 192.168.2.254
[R1-ip-pool-bb]dns-list 114.114.114.114
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]dhcp select global
[R1-GigabitEthernet0/0/0]int g0/0/0.2
[R1-GigabitEthernet0/0/0.2]dhcp select global