1、建vlan
vlan data
vlan 10
vlan 20
vlan 30
vlan 40
2、设管理vlan ip
conf t
interface vlan 1
ip address 192.168.1.254 255.255.255.0
no shutdown
3、设置VLAN 10-40的管理IP
interface vlan 10
ip address 192.168.10.254 255.255.255.0
no shutdown
interface vlan 20
ip address 192.168.20.254 255.255.255.0
no shutdown
interface vlan 30
ip address 192.168.30.254 255.255.255.0
no shutdown
interface vlan 30
ip address 192.168.30.254 255.255.255.0
no shutdown
4、标记连线端口为trunk
inter fast 0/1
swit mode trunk
5、启用IP路由
conf t
ip routing
6、在交换机上可以PING其它交换机的管理IP测试其是否已通
至此安装配置完成。
三层交换机未发现有VTP配置命令(因为三层只管VLAN的列表,不具体实现有多少VLAN
(9)配访问控制列表ACL禁VLAN3子网的客户机访问服务器
Switch1#
Switch1#config t
Switch1(config)#access-list 1 deny 192.168.3.0 0.0.0.255
Switch1(config)#access-list 1 permit any
Switch1(config)#interface fastethernet0/13 (此接口接服务器)
Switch1(config-if)#ip access-group 1 out