Super VLAN概念:
用多个VLAN隔离广播域,并将这些VLAN归属到一个逻辑VLAN,这些子VLAN使用同一个IP子网和默认网关,进而达到节约IP地址的目的。
一般使用在用户密集程度高的地方,彼此之间要进行二层隔离,但是又有三层互访需求。用vlan划分广播域提高安全性,可以给多个vlan当网关
拓扑:
PC1:
PC2:
配置:
LSW2:
[Huawei]vlan batch 10 20
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/1]port default vlan 10
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 20
[Huawei-GigabitEthernet0/0/2]int g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type trunk
[Huawei-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
LSW3:
<Huawei>system-view
[Huawei]vlan batch 10 20 99
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20[Huawei]vlan 99
[Huawei-vlan99]aggregate-vlan // 设置 vlan 99 为super vlan
[Huawei-vlan99]access-vlan 10 20 //设置 vlan 10、20 为sub vlan
[Huawei]int Vlanif 99
[Huawei-Vlanif99]ip address 192.168.1.254 24[Huawei-Vlanif99]arp-proxy inter-sub-vlan-proxy enable //开启arp代理
注意:
[Huawei-Vlanif99]arp-proxy ?
enable Enable proxy ARP(Address Resolve Protocol)
inner-sub-vlan-proxy Proxy ARP within a VLAN //一个vlan通信,用于vlan内端口隔离
inter-sub-vlan-proxy Proxy ARP between VLANs //vlan之间的arp代理
效果: