目录
题目
需求(所要实现的功能):
(1)PC1和PC2所在接口为ACCESS,属于VLAN2。PC2/4/5/6处于同一网段;其中PC2可以访问PC4/5/6;但PC4可以访问PC5,不能访问PC6
(2)PC5不能访问PC6
(3)PC1/3与PC2/4/5/6不在同一个网段
(4)所有PC通过DHCP获取IP 地址,且PC1/3可以正常访问PC2/4/5/6
需求分析:
(1)有题知 PC1和PC2所在接口为ACCESS ,PC2/4/5/6则用混杂模式
(2)PC1/3划分到一个网段,PC2/4/5/6划分到另一个网段
(3)分析可知 vlan可分到vlan 6
(4)sw1连接到路由的接口定义是否标记
网络部署思路:
1、拓扑设计 -- IP地址规划
PC1/3 属于 192.168.1.0/24网段
PC2/4/5/6 属于 192.168.2.0/24网段
PC1/3 —> vlan2
PC2 —> vlan3
PC4 —> vlan4
PC5 —> vlan5
PC6 —> vlan6
2、实施
【1】拓扑的搭建
【2】配置
「1」交换机配置
sw1
[sw1]vlan batch 2 to 6
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw1]int e0/0/1
[sw1-Ethernet0/0/1]p l a
[sw1-Ethernet0/0/1]p d v 2
[sw1-Ethernet0/0/1]int e0/0/2
[sw1-Ethernet0/0/2]port hybrid pvid vlan 3
[sw1-Ethernet0/0/2]port hybrid untagged vlan 2 to 6
[sw1-Ethernet0/0/2]int e0/0/3
[sw1-Ethernet0/0/3]p l t[sw1-Ethernet0/0/3]p t a v a
查看接口的VLAN转发规则
sw2
[sw2]vlan batch 2 to 6
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw2]int e0/0/1
[sw2-Ethernet0/0/1]p l a
[sw2-Ethernet0/0/1]p d v 2
[sw2-Ethernet0/0/1]int e0/0/2
[sw2-Ethernet0/0/2]port hybrid pvid vlan 4
[sw2-Ethernet0/0/2]port hybrid untagged vlan 2 to 5
[sw2-Ethernet0/0/2]int e0/0/4
[sw2-Ethernet0/0/4]p l t
[sw2-Ethernet0/0/4]p t a v a
[sw2-Ethernet0/0/4]int e0/0/3
[sw2-Ethernet0/0/3]p l t
[sw2-Ethernet0/0/3]p t a v a
查看接口的VLAN转发规则
sw3
[sw3]vlan batch 2 to 6
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw3]int e 0/0/3
[sw3-Ethernet0/0/3]p l t
[sw3-Ethernet0/0/3]p t a v a
[sw3-Ethernet0/0/3]int e0/0/1
[sw3-Ethernet0/0/1]port hybrid pvid vlan 5
[sw3-Ethernet0/0/1]port hybrid untagged vlan 2 to 5
[sw3-Ethernet0/0/1]int e0/0/2
[sw3-Ethernet0/0/2]port hybrid pvid vlan 6
[sw3-Ethernet0/0/2]port hybrid untagged vlan 2 3 6
查看接口的VLAN转发规则
「2」定义是否标记
sw1
[sw1]int e0/0/4
[sw1-Ethernet0/0/4]port hybrid tagged vlan 2
[sw1-Ethernet0/0/4]port hybrid untagged vlan 3 4 5 6
「3」DHCP 池塘配置
AR1
[r1]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]ip add 192.168.1.1 24
[r1-GigabitEthernet0/0/0.1]arp broadcast enable
[r1-GigabitEthernet0/0/0.1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.2.1 24
[r1-GigabitEthernet0/0/0]q
[r1]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[r1]ip pool vlan2
Info: It's successful to create an IP address pool.
[r1-ip-pool-vlan2]network 192.168.1.0 ma 24
[r1-ip-pool-vlan2]gateway-list 192.168.1.1
[r1-ip-pool-vlan2]dns-list 114.114.114.114 8.8.8.8
[r1-ip-pool-vlan2]q
[r1]ip pool aa
Info: It's successful to create an IP address pool.
[r1-ip-pool-aa]network 192.168.2.0 ma 24
[r1-ip-pool-aa]gateway-list 192.168.2.1
[r1-ip-pool-aa]dns-list 114.114.114.114 8.8.8.8
[r1-ip-pool-aa]q
[r1]int g0/0/0.1
[r1-GigabitEthernet0/0/0.1]dhcp select global
[r1-GigabitEthernet0/0/0.1]int g0/0/0
[r1-GigabitEthernet0/0/0]dhcp select global
查看PC的ip
PC1
PC2
PC3
PC4
PC5
PC6
「4」测试
PC2可以访问PC4/5/6
PC4可以访问PC5,不能访问PC6
PC5不能访问PC6
PC1/3可以正常访问PC2/4/5/6