基于mac的vlan
实验拓扑:
SW1:
[AR1]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[AR1]vlan 10
[AR1-vlan10]mac-vlan mac-address 5489-980E-3F60
[AR1]vlan 20
[AR1-vlan20]mac-vlan mac-address 5489-986D-1514
[AR1]int g0/0/1
[AR1-GigabitEthernet0/0/1]port hybrid untagged vlan 10 20
[AR1-GigabitEthernet0/0/1]mac-vlan enable #从1口进入的数据包,检查源mac地址然后匹配相应的vlan
SW2:
[SW2]int g0/0/3
[SW2-GigabitEthernet0/0/3]port link-type access
[SW2-GigabitEthernet0/0/3]port default vlan 20
[SW2-GigabitEthernet0/0/3]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW2-GigabitEthernet0/0/1]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type access
[SW2-GigabitEthernet0/0/2]port default vlan 10
验证: PC1和PC3、PC2和PC4相互通信后
[AR1]dis mac-address
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-98c9-02c2 10 - - GE0/0/2 dynamic 0/-
5489-980e-3f60 10 - - GE0/0/1 dynamic 0/-
5489-986d-1514 20 - - GE0/0/1 dynamic 0/-
5489-988c-79ed 20 - - GE0/0/2 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 4
基于ip子网划分vlan
实验拓扑:
SW1:
vlan batch 10 20
vlan 10
ip-subnet-vlan 1 ip 192.168.10.0 255.255.255.0
vlan 20
ip-subnet-vlan 1 ip 192.168.20.0 255.255.255.0
interface GigabitEthernet0/0/1
port hybrid untagged vlan 10 20
ip-subnet-vlan enable
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 10 20
SW2:
vlan batch 10 20
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 20
#
super vlan
SW1:
[SW1]port-group group-member gi0/0/1 to gi0/0/2
[SW1-port-group]port link-type access
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-port-group]port default vlan 10
[SW1-GigabitEthernet0/0/1]port default vlan 10
[SW1-GigabitEthernet0/0/2]port default vlan 10
[SW1-port-group]qu
[SW1]port-group group-member gi0/0/3 to gi0/0/4
[SW1-port-group]port link-type access
[SW1-GigabitEthernet0/0/3]port link-type access
[SW1-GigabitEthernet0/0/4]port link-type access
[SW1-port-group]port default vlan 20
[SW1-GigabitEthernet0/0/3]port default vlan 20
[SW1-GigabitEthernet0/0/4]port default vlan 20
[SW1-port-group]qu
[SW1]vlan 30
[SW1-vlan30]aggregate-vlan
[SW1-vlan30]access-vlan 10 20
相同vlan隔离端口
实验拓扑:
SW1:
[Huawei]port-group group-member gi0/0/1 to gi0/0/4
[Huawei-port-group]port link-type access
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/4]port link-type access
[Huawei-port-group]port default vlan 10
[Huawei-GigabitEthernet0/0/1]port default vlan 10
[Huawei-GigabitEthernet0/0/2]port default vlan 10
[Huawei-GigabitEthernet0/0/3]port default vlan 10
[Huawei-GigabitEthernet0/0/4]port default vlan 10
[Huawei-port-group]qu
[Huawei]int gi0/0/4
[Huawei-GigabitEthernet0/0/4]port-isolate enable # 将4口设置为隔离端口,并加入隔离组1 (默认都会加入隔离组1)
[Huawei-GigabitEthernet0/0/4]int gi0/0/1
[Huawei-GigabitEthernet0/0/1]port-isolate enable
注:同一台交换机相同隔离组的端口不能互访
vlan的映射
实验拓扑:
SW2:
[SW2-GigabitEthernet0/0/1]dis thi
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 30 to 31
#
return
[SW2-GigabitEthernet0/0/1]int g0/0/2
[SW2-GigabitEthernet0/0/2]dis thi
#
interface GigabitEthernet0/0/2
qinq vlan-translation enable
port link-type trunk
port trunk allow-pass vlan 100
port vlan-mapping vlan 30 to 39 map-vlan 100
[SW2-GigabitEthernet0/0/1]dis thi
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 30 to 31
[SW2-GigabitEthernet0/0/3]dis thi
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 32
注意: 由于模拟器不支持该功能,虽然命令能配上,但是不能生效