二 、知识点
1,VLAN聚合 —较少IP地址浪费问题
配置思路:
[SW3]vlan 10
[SW3-vlan10]q
[SW3]int g0/0/1
[SW3-GigabitEthernet0/0/1]port link-type access
[SW3-GigabitEthernet0/0/1]port default vlan 10
[SW3-GigabitEthernet0/0/1]q
[SW3]int g0/0/2
[SW3-GigabitEthernet0/0/2]port link-type access
[SW3-GigabitEthernet0/0/2]port default vlan 10
[SW3-GigabitEthernet0/0/2]q
[SW3]int g0/0/3
[SW3-GigabitEthernet0/0/3]port link-type trunk
[SW3-GigabitEthernet0/0/3]port trunk allow-pass vlan 10
[sw2]vlan 20
[sw2-vlan20]q
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type access
[sw2-GigabitEthernet0/0/1]port default vlan 20
[sw2-GigabitEthernet0/0/1]q
[sw2]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link-type access
[sw2-GigabitEthernet0/0/2]port default vlan 20
[sw2-GigabitEthernet0/0/2]q
[sw2]int g0/0/3
[sw2-GigabitEthernet0/0/3]port link-type trunk
[sw2-GigabitEthernet0/0/3]port trunk allow-pass vlan 20
[sw2-GigabitEthernet0/0/3]q
[sw2]
[SW1]vlan batch 100 200 10 20
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 200
[SW1-GigabitEthernet0/0/1]q
[SW1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type trunk
[SW1-GigabitEthernet0/0/2]port trunk allow-pass vlan 10
[SW1-GigabitEthernet0/0/2]q
[SW1]int g0/0/3
[SW1-GigabitEthernet0/0/3]port link-type trunk
[SW1-GigabitEthernet0/0/3]port trunk allow-pass vlan 20
[SW1-GigabitEthernet0/0/3]q
[SW1]int Vlanif 200
[SW1-Vlanif200]ip add 192.168.200.254 24
[SW1-Vlanif200]q
[SW1]int Vlanif 100
[SW1-Vlanif100]ip add 192.168.100.254 24
[SW1-Vlanif100]arp-proxy inter-sub-vlan-proxy enable //配置ARP 代理 ,实现不同子VLAn之间通信
[SW1-Vlanif100]q
[SW1]vlan 100
[SW1-vlan100]aggregate-vlan //配置VLAN100为聚合VLAN
[SW1-vlan100]access-vlan 10 20 //配置VLAN10 、10 为 子VLAN
[SW1-vlan100]q
1,MUX-VLAN —实现资源的访问控制
配置思路:
1,创建VLAN
2,配置主VLAN --服务器所在的VLAN
配置从VLAN
-团体VLAN --部门
-隔离VLAN --访客区
3,验证 团体VLAN 和隔离VLAN 主机都可以访问 主VLAN
团体VLAN内部可以互相通信,互相不能通信
隔离VLAN内部不可以互相通信,和团体VLAN不可以互相通信
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.200.254 24
[R1-GigabitEthernet0/0/0]q
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 192.168.100.254 24
[R1-GigabitEthernet0/0/1]q
[SW1]vlan batch 10 20 30 100
[SW1]port-group group-member g0/0/1 g0/0/2
[SW1-port-group]port link-type access
[SW1-port-group]port default vlan 10
[SW1-port-group]q
[SW1]port-group group-member g0/0/3 g0/0/4
[SW1-port-group]port link-type access
[SW1-port-group]port default vlan 30
[SW1-port-group]q
[SW1]port-group group-member g0/0/5 g0/0/6
[SW1-port-group]port link-type access
[SW1-port-group]port default vlan 20
[SW1-port-group]q
[SW1]int g0/0/7 //与路由器相连的接口 加入VLAN100-主VLAN
[SW1-GigabitEthernet0/0/7]port link-type access
[SW1-GigabitEthernet0/0/7]port default vlan 100
[SW1-GigabitEthernet0/0/7]q
[SW1]vlan 100
[SW1-vlan100]mux-vlan //配置VLAN100 为主VLAN
[SW1-vlan100]subordinate group 10 20 //配置团体VLAN
[SW1-vlan100]subordinate separate 30 //配置隔离VLAN
[SW1-vlan100]q
[SW1]port-group group-member g0/0/1 to g0/0/7
[SW1-port-group]port mux-vlan enable //所有接口开启MUX-VLAN功能
3, QinQ
实验:基本QINQ
配置命令:
[SW1]vlan 100
[SW1-vlan100]q
[SW1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type trunk //ISP 之间配置中继
[SW1-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[SW1-GigabitEthernet0/0/2]q
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type dot1q-tunnel//ISP 入口 与企业端相连的端口配置隧道
[SW1-GigabitEthernet0/0/1]port default vlan 100 //配置隧道口打的公网标签
[SW2]vlan 100
[SW2-vlan100]q
[SW2]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type trunk
[SW2-GigabitEthernet0/0/2]port trunk allow-pass vlan 100
[SW2-GigabitEthernet0/0/2]q
[SW2]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type dot1q-tunnel
[SW2-GigabitEthernet0/0/1]port default vlan 100
[sw3]vlan batch 10 20
[sw3]INT G0/0/1
[sw3-GigabitEthernet0/0/1]port link-type access
[sw3-GigabitEthernet0/0/1]port default vlan 10
[sw3-GigabitEthernet0/0/1]Q
[sw3]INT g0/0/2
[sw3-GigabitEthernet0/0/2]port link-type access
[sw3-GigabitEthernet0/0/2]port default vlan 20
[sw3-GigabitEthernet0/0/2]q
[sw3]int g0/0/3
[sw3-GigabitEthernet0/0/3]port link-type trunk
[sw3-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
[SW4]vlan batch 10 20
[SW4]int g0/0/1
[SW4-GigabitEthernet0/0/1]port link-type access
[SW4-GigabitEthernet0/0/1]port default vlan 10
[SW4-GigabitEthernet0/0/1]q
[SW4]int g0/0/2
[SW4-GigabitEthernet0/0/2]port link-type access
[SW4-GigabitEthernet0/0/2]port default vlan 20
[SW4-GigabitEthernet0/0/2]q
[SW4]int g0/0/3
[SW4-GigabitEthernet0/0/3]port link-type trunk
[SW4-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
抓包验证:
实验:灵活QINQ
配置思路:
1,配置终端
2,配置企业端
3,配置ISP 端-QINQ
4, 测试
内网VLAN10---外网VLAN2
内网VLAN20---外网VLAN3
配置命令:
配置企业总部业务:
[SW3]vlan batch 10 20
[SW3]int g0/0/1
[SW3-GigabitEthernet0/0/1]port link-type trunk
[SW3-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW3-GigabitEthernet0/0/1]q
[SW3]int g0/0/2
[SW3-GigabitEthernet0/0/2]port link-type trunk
[SW3-GigabitEthernet0/0/2]port trunk allow-pass vlan 10 20
[SW3-GigabitEthernet0/0/2]q
[SW3]int g0/0/3
[SW3-GigabitEthernet0/0/3]port link-type trunk
[SW3-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
[SW5]vlan batch 10 20
[SW5]INT G0/0/1
[SW5-GigabitEthernet0/0/1]port link-type trunk
[SW5-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW5-GigabitEthernet0/0/1]q
[SW5]int g0/0/2
[SW5-GigabitEthernet0/0/2]port link-type access
[SW5-GigabitEthernet0/0/2]port default vlan 10
[SW5-GigabitEthernet0/0/2]q
[SW6]vlan batch 10 20
[SW6]int g0/0/1
[SW6-GigabitEthernet0/0/1]port link-type trunk
[SW6-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW6-GigabitEthernet0/0/1]q
[SW6]int g0/0/2
[SW6-GigabitEthernet0/0/2]port link-type access
[SW6-GigabitEthernet0/0/2]port default vlan 20
配置企业分支业务:
[SW4]vlan batch 10 20
[SW4]int g0/0/1
[SW4-GigabitEthernet0/0/1]port link-type trunk
[SW4-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW4-GigabitEthernet0/0/1]q
[SW4]int g0/0/2
[SW4-GigabitEthernet0/0/2]port link-type trunk
[SW4-GigabitEthernet0/0/2]port trunk allow-pass vlan 10 20
[SW4-GigabitEthernet0/0/2]q
[SW4]int g0/0/3
[SW4-GigabitEthernet0/0/3]port link-type trunk
[SW4-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
[SW7]vlan batch 10 20
[SW7]int g0/0/1
[SW7-GigabitEthernet0/0/1]port link-type trunk
[SW7-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW7-GigabitEthernet0/0/1]q
[SW7]int g0/0/2
[SW7-GigabitEthernet0/0/2]port link-type access
[SW7-GigabitEthernet0/0/2]port default vlan 10
[SW7-GigabitEthernet0/0/2]q
[SW8]vlan batch 10 20
[SW8]int g0/0/1
[SW8-GigabitEthernet0/0/1]port link-type trunk
[SW8-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[SW8-GigabitEthernet0/0/1]q
[SW8]int g0/0/2
[SW8-GigabitEthernet0/0/2]port link-type access
[SW8-GigabitEthernet0/0/2]port default vlan 20
配置ISP -SW1
[SW1]vlan batch 2 3 //创建公网封装的VLAN 2/3
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type trunk //与运营商相连接口配置trunk
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3 //允许公网标签通过
[SW1-GigabitEthernet0/0/1]q
[SW1]
[SW1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type hybrid //在ISP 入口配置链路类型为hybrid (必须为hybrid ,如果为trunk 还需要配置对应的PVID)
[SW1-GigabitEthernet0/0/2]port hybrid untagged vlan 2 3 //配置脱掉公网标签
[SW1-GigabitEthernet0/0/2]qinq vlan-translation enable //开启QINQ 标签转换功能
[SW1-GigabitEthernet0/0/2]port vlan-stacking vlan 10 stack-vlan 2 //配置私有标签tag 和公有标签tag 的映射关系
[SW1-GigabitEthernet0/0/2]port vlan-stacking vlan 20 stack-vlan 3//配置私有标签tag 和公有标签tag 的映射关系
配置ISP-SW2
[sw2]vlan batch 2 3
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3
[sw2-GigabitEthernet0/0/1]q
[sw2]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link-type hybrid
[sw2-GigabitEthernet0/0/2]port hybrid untagged vlan 2 3
[sw2-GigabitEthernet0/0/2]qinq vlan-translation enable
[sw2-GigabitEthernet0/0/2]port vlan-stacking vlan 10 stack-vlan 2
[sw2-GigabitEthernet0/0/2]port vlan-stacking vlan 20 stack-vlan 3
[sw2-GigabitEthernet0/0/2]
验证:
在运营商线路上抓包,能抓到双层标签