要求:
- PC1和PC3所在接口为access;属于 vlan2;
PC2/4/5/6处于同一网段;其中PC2可以访问PC4/5/6;但PC4可以访问PC5,不能访问PC6- PC5不能访问PC6
- PC1/3与PC2/4/5/6不在同一个网段
- 所有PC通过DHCP获取IP地址,且PC1/3可以正常访问PC2/4/5/6
划分VLAN
[SW1]vlan 2
[SW1]vlan batch 4 5 6
[SW1-vlan2]q
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 2
[SW1]interface GigabitEthernet 0/0/1
[SW1-GigabitEthernet0/0/1]port link-type hybrid
[SW1-GigabitEthernet0/0/1]port hybrid untagged vlan all
[SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 2
[SW1]interface GigabitEthernet 0/0/4
[SW1-GigabitEthernet0/0/4]port hybrid tagged vlan all
[SW2]vlan batch 2 4 5 6
[SW2]interface GigabitEthernet 0/0/3
[SW2-GigabitEthernet0/0/3]port link-type access
[SW2-GigabitEthernet0/0/3]port default vlan 2
[SW2]interface GigabitEthernet 0/0/4
[SW2-GigabitEthernet0/0/4]port hybrid pvid vlan 4
SW2-GigabitEthernet0/0/4]port hybrid untagged vlan all
[SW2]interface GigabitEthernet 0/0/1
[SW2-GigabitEthernet0/0/1]port hybrid tagged vlan all
[SW2]interface GigabitEthernet 0/0/2
[SW2-GigabitEthernet0/0/2]port hybrid tagged vlan all
[SW3]vlan batch 2 4 5 6
[SW3]interface GigabitEthernet 0/0/2
[SW3-GigabitEthernet0/0/2]port hybrid pvid vlan 5
[SW3-GigabitEthernet0/0/2]port hybrid untagged vlan all
[SW3]interface GigabitEthernet 0/0/3
[SW3-GigabitEthernet0/0/3]port hybrid pvid vlan 6
[SW3-GigabitEthernet0/0/3]port hybrid untagged vlan all
[SW3]interface GigabitEthernet 0/0/1
[SW3-GigabitEthernet0/0/1]port hybrid tagged vlan all
使用DHCP分配IP
[R1]dhcp enable
[R1]ip pool v1
[R1-ip-pool-v1]network 192.168.1.0 mask 255.255.255.0
[R1-ip-pool-v1]gateway-list 192.168.1.254 设置网关
[R1-ip-pool-v1]dns-list 114.114.114.114 设置DNS
[R1-ip-pool-v1]q
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ip address 192.168.1.254 24
[R1-GigabitEthernet0/0/0]dhcp select global
[R1]ip pool v2
[R1-ip-pool-v2]network 192.168.2.0 mask 255.255.255.0
[R1-ip-pool-v2]gateway-list 192.168.2.2544
[R1-ip-pool-v2]dns-list 114.114.114.114
[R1-ip-pool-v2]q
[R1]interface GigabitEthernet 0/0/0.2
[R1-GigabitEthernet0/0/0.2]ip address 192.168.2.254 24 设置IP地址
[R1-GigabitEthernet0/0/0.2]dot1q termination vid 2 定义子接口管理的VLAN
[R1-GigabitEthernet0/0/0.2]dhcp select global 开启dhcp功能
[R1-GigabitEthernet0/0/0.2]arp broadcast enable 开启子接口arp广播应答功能,华为子接口默认不响应arp请求
查看ip
PC1
PC2
PC3
PC4
PC5
PC6
测试PC2可以访问PC4/5/6
[SW1]interface GigabitEthernet 0/0/3
[SW1-GigabitEthernet0/0/3]port hybrid untagged vlan all
测试PC4可以访问PC5,测试PC4不可以访问PC6
[SW3]interface GigabitEthernet 0/0/3
[SW3-GigabitEthernet0/0/3]port hybrid tagged vlan 4
PC5不能访问PC6
[SW3]interface GigabitEthernet 0/0/3
[SW3-GigabitEthernet0/0/3]port hybrid tagged vlan 5
且PC1/3可以正常访问PC2/4/5/6