一、实验拓扑
二、实验要求
1、pc1和pc3所在接口为access模式,pvlan为VLAN2;
2、Pc2/4/5/6处于同一网段,其中pc2可以访问pc4/5/6,pc4可以访问 pc5,但不能访问pc6,pc5不能访问pc6;
三、实验思路
1、IP地址规划:192.168.1.0 24 VLAN 2
192.168.2.0 24 VLAN 1
使用DHCP,pc自动获取地址
2、VLAN划分
Pc1,pc3处于VLAN2
Pc2处于VLAN3
Pc4,PC 处于VLAN4
Pc6处于VLAN5
四、实验配置
- (1)交换机配置
Sw1:
vlan batch 2 to 5
interface GigabitEthernet0/0/1
port hybrid tagged vlan 2
port hybrid untagged vlan 3 to 5
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 5
interface GigabitEthernet0/0/3
port link-type access
port default vlan 2
interface GigabitEthernet0/0/4
port hybrid pvid vlan 3
port hybrid untagged vlan 3 to 5
Sw2:
vlan batch 2 to 5
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 5
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 5
interface GigabitEthernet0/0/3
port link-type access
port default vlan 2
interface GigabitEthernet0/0/4
port hybrid pvid vlan 4
port hybrid untagged vlan 3 to 4
Sw3:
vlan batch 3 to 5
interface MEth0/0/1
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 3 to 5
interface GigabitEthernet0/0/2
port hybrid pvid vlan 4
port hybrid untagged vlan 3 to 4
interface GigabitEthernet0/0/3
port hybrid pvid vlan 5
port hybrid untagged vlan 3 5
- (二)路由器配置
dhcp enable
ip pool v1
gateway-list 192.168.1.1
network 192.168.1.0 mask 255.255.255.0
dns-list 8.8.8.8
ip pool v2
gateway-list 192.168.2.1
network 192.168.2.0 mask 255.255.255.0
dns-list 8.8.8.8
interface GigabitEthernet0/0/0
ip address 192.168.1.1 255.255.255.0
dhcp select global
interface GigabitEthernet0/0/0.1
dot1q termination vid 2
ip address 192.168.2.1 255.255.255.0
arp broadcast enable
dhcp select global
五、测试
PC1 ping PC3
PC2 ping PC4/5/6
PC4 ping通PC5 但ping不通PC6
PC5 ping不通 PC6