如有疑问或其他需求可私信联系!
(二)交换配置(本题共 10 分)
1.配置 SW1、SW2、SW3 的 Vlan,二层链路只允许下面 Vlan 通过,不限制 vlan1。
![](https://img-blog.csdnimg.cn/direct/d25ba73981bd40e4b994d91ca4292dd0.png)
![](https://img-blog.csdnimg.cn/direct/91454c604eb64b749be6550c4c48cd7e.png)
SW1:
SW1:
Interface Ethernet1/0/1
switchport access vlan 11
!
Interface Ethernet1/0/2
switchport access vlan 12
!
Interface Ethernet1/0/3
switchport access vlan 13
!
Interface Ethernet1/0/4
switchport access vlan 14
!
Interface Ethernet1/0/5
switchport access vlan 15
!
Interface Ethernet1/0/22
switchport mode trunk
switchport trunk allowed vlan 11-15
!
SW2:
SW2:
Interface Ethernet1/0/1
switchport access vlan 21
!
Interface Ethernet1/0/2
switchport access vlan 22
!
Interface Ethernet1/0/3
switchport access vlan 23
!
Interface Ethernet1/0/4
switchport access vlan 24
!
Interface Ethernet1/0/5
switchport access vlan 25
!
Interface Ethernet1/0/22
switchport mode trunk
switchport trunk allowed vlan 21-25
!
SW3:
1Interface Ethernet1/0/1
switchport access vlan 31
!
Interface Ethernet1/0/2
switchport access vlan 32
!
Interface Ethernet1/0/3
switchport access vlan 33
!
Interface Ethernet1/0/4
switchport access vlan 34
!
Interface Ethernet1/0/11
switchport access vlan 110
!
Interface Ethernet1/0/12
switchport access vlan 120
2.SW1 和 SW2 之间利用三条裸光缆实现互通,其中一条裸光缆承载三层 IP 业务、一条裸光缆承载 VPN 业务、一条裸光缆承载二层业务。用相关技术分别实现财务 1 段、财务 2 段业务路由表与其它业务路由表隔离,财务业务 VPN 实例名称为 Finance,RD 为 1:1。承载二层业务的只有一条裸光缆通道,配置相关技术,方便后续链路扩容与冗余备份,编号为 1,用 LACP 协议,SW1 为 active,SW2 为 passive;采用目的、源 IP 进行实现流量负载分担。
SW1:
SW1:
ip vrf Finance
!
interface Vlan14
ip vrf forwarding Finance
ipv6 address 2001:10:4:14::1/64
ip address 10.4.14.1 255.255.255.0
!
interface Vlan1023
ip vrf forwarding Finance
ip address 10.4.255.1 255.255.255.252
!
port-group 1
!
interface e1/0/22 //建议采用双接口更合适
port-group 1 mode active
!
interface port-channel 1
switchport mode trunk
switchport trunk allowed vlan 11-15
!
load-balance dst-src-ip //缺省情况
!
SW2:
SW2:
ip vrf Finance
!
interface Vlan24
ip vrf forwarding Finance
ipv6 address 2001:10:4:24::1/64
ip address 10.4.24.1 255.255.255.0
!
interface Vlan1023
ip vrf forwarding Finance
ip address 10.4.255.2 255.255.255.252
!
port-group 1
!
interface e1/0/22 //建议采用双接口更合适
port-group 1 mode passive
!
interface port-channel 1
switchport mode trunk
switchport trunk allowed vlan 21-25
!
load-balance dst-src-ip //缺省情况
!
3.为方便后续验证与测试,SW3 的 E1/0/22 连接其他合适设备的一个接口,配置为 trunk,允许 Vlan31-34、110、120 通过。
SW3:
Interface Ethernet1/0/22
switchport mode trunk
switchport trunk allowed vlan 31-34;110;120
4.将 SW3 模拟办事处交换机,实现与集团其它业务路由表隔离,办事处路由表 VPN 实例名称为 Office,RD 为 1:1。将 SW3 模拟为 Internet交换机,实现与集团其它业务路由表隔离,Internet 路由表 VPN 实例名称为 Internet,RD 为 2:2。
SW3:
ip vrf Internet
RD 2:2
!
Vlan 1017;1018
!
Interface Ethernet1/0/17
switchport access vlan 1017
!
interface Vlan1017
ip vrf forwarding Internet
ip address 200.200.200.1 255.255.255.252
!
Interface Ethernet1/0/18
switchport access vlan 1018
!
interface Vlan1018
ip vrf forwarding Internet
ip address 200.200.200.5 255.255.255.252
!
ip vrf Office
RD 1:1
!
Vlan 110;120;1015
!
Interface Ethernet1/0/15
switchport access vlan 1015
!
interface Loopback2
ip vrf forwarding Office
ipv6 address 2001:10:4:3::2/128
ip address 10.4.3.2 255.255.255.255
!
interface Vlan110
ip vrf forwarding Office
ipv6 address 2001:10:4:110::1/64
ip address 10.4.110.1 255.255.255.0
!
interface Vlan120
ip vrf forwarding Office
ipv6 address 2001:10:4:120::1/64
ip address 10.4.120.1 255.255.255.0
!
interface Vlan1015
ip vrf forwarding Office
ip address 10.4.255.30 255.255.255.252
!