如图所示,某公司网络拓补图如下:
PC1,PC3 同属部门A,PC2,PC4 同属部门B,
PC1和PC2使用同一台交换机接入网络,PC3和PC4使用同一台交换机接入网络。各部门电脑配置的ip同属一个C类地址段,要求实现不同部门之间不能互访,同一部门的电脑之间可以互访。
操作步骤
交换机1
<Huawei>system-view #进入系统视图
[Huawei]sysname Switch1 #配置系统名称位 Switch 1
[Switch1]vlan 10 #创建VLAN 10
[Switch1-vlan10]quit #退出VLAN10
[Switch1]vlan 20 #创建VLAN20
[Switch1-vlan20]quit #退出VLAN20
[Switch1]interface GigabitEthernet 0/0/1 #进入千兆以太网端口 0/0/1
[Switch1-GigabitEthernet0/0/1]port link-type access #配置端口的链路类型为ACCESS
[Switch1-GigabitEthernet0/0/1]port default vlan 10 #配置端口的默认VLAN 为 10
[Switch1-GigabitEthernet0/0/1]quit #退出千兆以太网端口 0/0/1
[Switch1]interface GigabitEthernet 0/0/2 #进入千兆以太网端口 0/0/2
[Switch1-GigabitEthernet0/0/2]port link-type access #配置端口的链路类型为ACCESS
[Switch1-GigabitEthernet0/0/2]port default vlan 20 #配置端口的默认VLAN 为 20
[Switch1-GigabitEthernet0/0/2]quit #退出千兆以太网端口 0/0/2
[Switch1]interface GigabitEthernet 0/0/3 #进入千兆以太网端口 0/0/3
[Switch1-GigabitEthernet0/0/3]port link-type trunk #配置端口的链路类型为TRUNK
[Switch1-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20 #配置端口TRUNK允许通过的VLAN为 10 20
[Switch1-GigabitEthernet0/0/3]quit #退出千兆以太网端口 0/0/2
[Switch1]
交换机2
<Huawei>system-view #进入系统视图
[Huawei]sysname Switch2 #配置系统名称位 Switch 1
[Switch2]vlan 10 #创建VLAN 10
[Switch2-vlan10]quit #退出VLAN10
[Switch2]vlan 20 #创建VLAN20
[Switch2-vlan20]quit #退出VLAN20
[Switch2]interface GigabitEthernet 0/0/1 #进入千兆以太网端口 0/0/1
[Switch2-GigabitEthernet0/0/1]port link-type access #配置端口的链路类型为ACCESS
[Switch2-GigabitEthernet0/0/1]port default vlan 10 #配置端口的默认VLAN 为 10
[Switch2-GigabitEthernet0/0/1]quit #退出千兆以太网端口 0/0/1
[Switch2]interface GigabitEthernet 0/0/2 #进入千兆以太网端口 0/0/2
[Switch2-GigabitEthernet0/0/2]port link-type access #配置端口的链路类型为ACCESS
[Switch2-GigabitEthernet0/0/2]port default vlan 20 #配置端口的默认VLAN 为 20
[Switch2-GigabitEthernet0/0/2]quit #退出千兆以太网端口 0/0/2
[Switch2]interface GigabitEthernet 0/0/3 #进入千兆以太网端口 0/0/3
[Switch2-GigabitEthernet0/0/3]port link-type trunk #配置端口的链路类型为TRUNK
[Switch2-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20 #配置端口TRUNK允许通过的VLAN为 10 20
[Switch2-GigabitEthernet0/0/3]quit #退出千兆以太网端口 0/0/2
[Switch2]
配置验证
将PC1,PC2,PC3,PC4,均配置为同一网段的ip地址
在PC1上PING同部门的电脑PC3的地址192.168.1.3,通了。
PC>ping 192.168.1.3
Ping 192.168.1.3: 32 data bytes, Press Ctrl_C to break
From 192.168.1.3: bytes=32 seq=1 ttl=128 time=78 ms
From 192.168.1.3: bytes=32 seq=2 ttl=128 time=62 ms
From 192.168.1.3: bytes=32 seq=3 ttl=128 time=62 ms
From 192.168.1.3: bytes=32 seq=4 ttl=128 time=62 ms
From 192.168.1.3: bytes=32 seq=5 ttl=128 time=78 ms
--- 192.168.1.3 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 62/68/78 ms
在PC1上PING不同部门的电脑PC2和PC4的地址192.168.1.2和192.168.1.4,不通。
PC>ping 192.168.1.2
Ping 192.168.1.2: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
--- 192.168.1.2 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
PC>ping 192.168.1.4
Ping 192.168.1.4: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
--- 192.168.1.4 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
PC>