MUX VLAN的详解与配置实例
1、实验环境
公司网络分为公司内部部门,访客区、公共服务器三种,现在要求公司内部部门、访客区都可以访问公共服务器,公司内部部门的PC能够互相访问、访客区的PC不能互相访问。可以使用MUX VLAN实现以上需求。配置公共服务器VLAN 100作为主VLAN,公司内部部门为互通型VLAN,访客区为隔离型VLAN。
2、实验拓扑
3、实验步骤
(1)配置VLAN,并配置MUX LAN
<Huawei>sys
[Huawei]un in en
[Huawei]sysname S1
[S1]vlan batch 10 20 100
[S1]vlan 100
[S1-vlan100]mux-vlan //配置 VLAN 100 为主 VLAN
[S1-vlan100]subordinate group 10 //配置 VLAN 10 为互通型 VLAN
[S1-vlan100]subordinate separate 20 //配置 VLAN 20 为隔离型 VLAN
(2)配置接口的链路类型
[S1]int g 0/0/1
[S1-GigabitEthernet0/0/1]p l a
[S1-GigabitEthernet0/0/1]p d v 10
[S1-GigabitEthernet0/0/1]port mux-vlan enable
[S1]int g 0/0/2
[S1-GigabitEthernet0/0/2]p l a
[S1-GigabitEthernet0/0/2]p d v 10
[S1-GigabitEthernet0/0/2]port mux-vlan enable
[S1]int g 0/0/3
[S1-GigabitEthernet0/0/3]p l a
[S1-GigabitEthernet0/0/3]p d v 20
[S1-GigabitEthernet0/0/3]port mux-vlan enable
[S1]int g 0/0/4
[S1-GigabitEthernet0/0/4]p l a
[S1-GigabitEthernet0/0/4]p d v 20
[S1-GigabitEthernet0/0/4]port mux-vlan enable
[S1]int g 0/0/05
[S1-GigabitEthernet0/0/5]p l a
[S1-GigabitEthernet0/0/5]p d v 100
[S1-GigabitEthernet0/0/5]port mux-vlan enable
(3)查看配置结果
[S1]display vlan
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:GE0/0/6(D) GE0/0/7(D) GE0/0/8(D) GE0/0/9(D)
GE0/0/10(D) GE0/0/11(D) GE0/0/12(D) GE0/0/13(D)
GE0/0/14(D) GE0/0/15(D) GE0/0/16(D) GE0/0/17(D)
GE0/0/18(D) GE0/0/19(D) GE0/0/20(D) GE0/0/21(D)
GE0/0/22(D) GE0/0/23(D) GE0/0/24(D)
10 mux-sub UT:GE0/0/1(U) GE0/0/2(U)
20 mux-sub UT:GE0/0/3(U) GE0/0/4(U)
100 mux UT:GE0/0/5(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
100 enable default enable disable VLAN 0100
可以看到VLAN10、VLAN20、为MUX VLAN的从VLAN,VLAN100为MUX VLAN的主VLAN。
(4)测试配置结果,使用PC1访问PC2、PC3、以及PC5。
访问PC2
PC>ping 10.1.1.2
Ping 10.1.1.2: 32 data bytes, Press Ctrl_C to break
From 10.1.1.2: bytes=32 seq=1 ttl=128 time=47 ms
From 10.1.1.2: bytes=32 seq=2 ttl=128 time=94 ms
From 10.1.1.2: bytes=32 seq=3 ttl=128 time=47 ms
From 10.1.1.2: bytes=32 seq=4 ttl=128 time=62 ms
From 10.1.1.2: bytes=32 seq=5 ttl=128 time=63 ms
--- 10.1.1.2 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 47/62/94 ms
访问PC3:
PC>ping 10.1.1.3
Ping 10.1.1.3: 32 data bytes, Press Ctrl_C to break
From 10.1.1.1: Destination host unreachable
From 10.1.1.1: Destination host unreachable
From 10.1.1.1: Destination host unreachable
From 10.1.1.1: Destination host unreachable
From 10.1.1.1: Destination host unreachable
--- 10.1.1.3 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
访问PC5:
PC>ping 10.1.1.100
Ping 10.1.1.100: 32 data bytes, Press Ctrl_C to break
From 10.1.1.100: bytes=32 seq=1 ttl=128 time=47 ms
From 10.1.1.100: bytes=32 seq=2 ttl=128 time=93 ms
From 10.1.1.100: bytes=32 seq=3 ttl=128 time=32 ms
From 10.1.1.100: bytes=32 seq=4 ttl=128 time=31 ms
From 10.1.1.100: bytes=32 seq=5 ttl=128 time=47 ms
--- 10.1.1.100 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/50/93 ms
可以看到VLAN10为互通型VLAN,设置之间可以互通,与VLAN20不能互通,VLAN10也可以访问到VLAN100
(5)使用PC3访问PC4,以及PC5
PC>ping 10.1.1.4
Ping 10.1.1.4: 32 data bytes, Press Ctrl_C to break
From 10.1.1.3: Destination host unreachable
From 10.1.1.3: Destination host unreachable
From 10.1.1.3: Destination host unreachable
From 10.1.1.3: Destination host unreachable
From 10.1.1.3: Destination host unreachable
--- 10.1.1.4 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
可以看到PC3和PC4即使属于同一个VLAN,但是由于配置了VLAN20为隔离型VLAN,它们之间也不能互通。VLAN 20也可以访问到VLAN100.