实验图
要求
1、pc3所在接口为access;属于VLAN2
pc2/4/5/6处于同一个网段;其中pc2可以访问pc4/5/6;但pc4可以访问pc5不可访问pc6;
2、pc5不可访问pc6
3、pc1/3与pc2/4/5/6不在同一个网段
4、所有的PC用DHCP获取IP地址,PC1/3可以访问pc2/4/5/6
思路
1、交换机上可以利用混杂口的优势来控制其PC的访问
2、pc1/3同属于一个VLAN且属于同一个网段并用路由器的子接口来分配IP,其他设备属于不同的VLAN可以用路由器的物理接口来分配IP
3、在交换机1中连接路由器的子接口可以让带标签的vlan2通过,其他走路由器的物理接口这样的话刚是两个网段。
配置
交换机
vlan batch 2 to 6 批量创建VLAN
sw1
[sw1]int g0/0/1
[sw1-GigabitEthernet0/0/1]p l a
[sw1-GigabitEthernet0/0/1]p d v 2
[sw1-GigabitEthernet0/0/1]int g0/0/2
[sw1-GigabitEthernet0/0/2]p h p v 3
[sw1-GigabitEthernet0/0/2]p h u v 3 4 5 6
[sw1-GigabitEthernet0/0/2]int g0/0/3
[sw1-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[sw1-GigabitEthernet0/0/3]int g0/0/4
[sw1-GigabitEthernet0/0/4]p h t
[sw1-GigabitEthernet0/0/4]p h t v 2
[sw1-GigabitEthernet0/0/4]p h u v 3 4 5 6
sw2
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]p l a
[sw2-GigabitEthernet0/0/1]p d v 2
[sw2-GigabitEthernet0/0/1]int g0/0/2
[sw2-GigabitEthernet0/0/2]p h p v 4
[sw2-GigabitEthernet0/0/2]p h u v
[sw2-GigabitEthernet0/0/2]int g0/0/3
[sw2-GigabitEthernet0/0/3]p l t
[sw2-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[sw2-GigabitEthernet0/0/3]int g0/0/4
[sw2-GigabitEthernet0/0/4] p l t
[sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan all
sw3
[sw3]int g0/0/3
[sw3-GigabitEthernet0/0/3]p l t
[sw3-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[sw3-GigabitEthernet0/0/2]p h p v 6
[sw3-GigabitEthernet0/0/2]p h u v 3 6
[sw3]int g0/0/1
[sw3-GigabitEthernet0/0/1]p h p v 5
[sw3-GigabitEthernet0/0/1]p h u v 3 4 5
VLAN间路由
[r1]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]ip add 192.168.1.1 24
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]arp broadcast enable
[r1-GigabitEthernet0/0/0.1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.2.1 24
[r1-GigabitEthernet0/0/0]q
[r1]dhcp enable
[r1]ip pool zz
[r1-ip-pool-zz]network 192.168.1.0 mask 24
[r1-ip-pool-zz]gateway-list 192.168.1.1
[r1-ip-pool-zz]q
[r1]ip pool xx
[r1-ip-pool-xx]network 192.168.2.0 mask 24
[r1-ip-pool-xx]gateway-list 192.168.2.1
[r1-ip-pool-xx]q
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]dhcp select global
[r1-GigabitEthernet0/0/0]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]dhcp select global
测试
PC1/3可以访问pc2/4/5/6
其中pc2可以访问pc4/5/6