华为交换机接口允许vlan通过_VLAN工作原理之TRUNK:控制允许通过的VLAN(Allowed List)...

各位大家好,欢迎各位关注我的头条号,本头条号主要分享网络基本原理和测试方法。今天分享的内容是TRUNK工作模式的里的Allowed List。

我们都知道TRUNK端口可以允许不同VLAN的报文通过,这个在交换机内部是如何实现的呢,有没有什么表项可以查?答案是肯定的,交换机是通过Allowed VLAN List来控制是否允许某个VLAN的报文通过TRUNK端口,只有VLAN在List里,才允许通过TRUNK端口。

我们来设计一个用例验证Allowed List的功能,测试拓扑如下

28e5cebbf41efc2fa408a74a9d067188.png

测试拓扑

拓扑说明

  1. 和PC相连的交换机端口都配置为ACCESS模式,PC1、PC3所连端口配置为VLAN 10, PC2、PC4所连端口配置为VLAN 20
  2. 两个交换机之间的端口配置为TRUNK

测试用例

69cdb0eeaeae1523f0db17ed7c366b25.png

测试过程

测试配置

以下是思科、华为、新华三、锐捷交换机的命令大全: 思科交换机命令: 1. 配置主机名:hostname <name> 2. 配置接口VLAN:interface <interface type><interface number>,switchport mode access,switchport access vlan <vlan ID> 3. 配置Trunk口:interface <interface type><interface number>,switchport mode trunk,switchport trunk allowed vlan <vlan ID> 4. 配置默认网关:ip default-gateway <ip address> 5. 配置静态路由:ip route <destination network> <subnet mask> <next hop address> 6. 配置Telnet:line vty <line number>,password <password>,login 7. 配置SSH:ip ssh version <version>,crypto key generate rsa 8. 配置ACL:access-list <number> permit/deny <protocol> <source address> <wildcard mask> [<destination address> <wildcard mask> <operator> <port>] 9. 配置STP:spanning-tree mode <mode>,spanning-tree vlan <vlan ID> root primary/secondary,spanning-tree portfast 华为交换机命令: 1. 配置主机名:sysname <name> 2. 配置接口VLAN:interface <interface type><interface number>,port link-type access,port default vlan <vlan ID> 3. 配置Trunk口:interface <interface type><interface number>,port link-type trunk,port trunk allow-pass vlan <vlan ID> 4. 配置默认网关:ip route-static 0.0.0.0 0.0.0.0 <next hop address> 5. 配置静态路由:ip route-static <destination network> <subnet mask> <next hop address> 6. 配置Telnet:user-interface vty <line number>,authentication-mode password,set authentication password cipher <password> 7. 配置SSH:ssh server enable,user-interface vty <line number>,authentication-mode aaa,protocol inbound ssh,user privilege level 3 8. 配置ACL:acl number <number>,rule <rule number> permit/deny <protocol> source <source address> <wildcard mask> destination <destination address> <wildcard mask> [destination-port <port>] 9. 配置STP:stp mode <mode>,stp priority <priority>,stp enable 新华三交换机命令: 1. 配置主机名:sysname <name> 2. 配置接口VLAN:interface <interface type><interface number>,port link-type access,port default vlan <vlan ID> 3. 配置Trunk口:interface <interface type><interface number>,port link-type trunk,port trunk allow-pass vlan <vlan ID> 4. 配置默认网关:ip route-static 0.0.0.0 0.0.0.0 <next hop address> 5. 配置静态路由:ip route-static <destination network> <subnet mask> <next hop address> 6. 配置Telnet:user-interface vty <line number>,authentication-mode password,set authentication password cipher <password> 7. 配置SSH:ssh server enable,user-interface vty <line number>,authentication-mode aaa,protocol inbound ssh,user privilege level 3 8. 配置ACL:acl number <number>,rule <rule number> permit/deny <protocol> source <source address> <wildcard mask> destination <destination address> <wildcard mask> [destination-port <port>] 9. 配置STP:stp mode <mode>,stp priority <priority>,stp enable 锐捷交换机命令: 1. 配置主机名:system name <name> 2. 配置接口VLAN:interface <interface type><interface number>,port link-type access,port default vlan <vlan ID> 3. 配置Trunk口:interface <interface type><interface number>,port link-type trunk,port trunk allow-pass vlan <vlan ID> 4. 配置默认网关:ip route-static 0.0.0.0 0.0.0.0 <next hop address> 5. 配置静态路由:ip route <destination network> <subnet mask> <next hop address> 6. 配置Telnet:user-interface vty <line number>,authentication-mode password,set authentication password cipher <password> 7. 配置SSH:ssh server enable,user-interface vty <line number>,authentication-mode aaa,protocol inbound ssh,user privilege level 3 8. 配置ACL:acl number <number>,rule <rule number> permit/deny <protocol> source <source address> <wildcard mask> destination <destination address> <wildcard mask> [destination-port <port>] 9. 配置STP:stp enable,stp force-version <version>,stp priority <priority>
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值