前言:关于二层隔离,相信应用最多的技术就是端口隔离和PVLAN(思科)或MUX VLAN(华为)。PVLAN的部署已经有网上已经有大量相关文档支持,而在网上华为MUX VLAN能搜索到的都是单台交换机的隔离。而实际项目中隔离需要跨交换机实现,首先我们来先看看之前在实验中总结出MUX VLAN的相关定义,如下:
①定义:MUX VLAN是一种二层流量隔离机制
②类型:
1.主VLAN(Principal)
2.从VLAN(Subordinate):
2-1.组(group)vlan 可互通
2-2.隔离(Separate)vlan 不可互通
③关键特性:
Group VLAN可有多个,隔离VLAN有且只有一个。
同交换机同一Group VLAN可互通、不同Group VLAN不可互通、隔离VLAN不可互通。
不同交换机同一Group VLAN可互通、不同Group VLAN不可互通、隔离VLAN可互通。
④配置注意事项
·所有主机必须在同一子网
·端口必须为access模式加入vlan
·配置MUX VLAN不能用于VLANIF接口、VLAN Mapping、VLAN Stacking、Super-VLAN、Sub-VLAN的配置
实验:
![在这里插入图片描述](https://i-blog.csdnimg.cn/blog_migrate/91bbffbb6b95b1556aae3328caecde94.png)
配置如下:
SW1:
vlan batch 10 20 30 100
vlan 100
mux-vlan
subordinate separate 30
subordinate group 10 20
interface GigabitEthernet0/0/1
port link-type access
port default vlan 100
port mux-vlan enable
interface GigabitEthernet0/0/4
port link-type trunk
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/5
port link-type trunk
port trunk allow-pass vlan 2 to 4094
------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------
SW2:
vlan batch 10 20 30 100
vlan 100
mux-vlan
subordinate separate 30
subordinate group 10 20
interface Ethernet0/0/1
port link-type access
port default vlan 10
port mux-vlan enable
interface Ethernet0/0/2
port link-type access
port default vlan 10
port mux-vlan enable
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------
SW3:
vlan batch 10 20 30 100
vlan 100
mux-vlan
subordinate separate 30
subordinate group 10 20
interface Ethernet0/0/1
port link-type access
port default vlan 10
port mux-vlan enable
interface Ethernet0/0/2
port link-type access
port default vlan 30
port mux-vlan enable
interface Ethernet0/0/3
port link-type access
port default vlan 30
port mux-vlan enable
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------
SW4
vlan batch 10 20 30 100
vlan 100
mux-vlan
subordinate separate 30
subordinate group 10 20
interface Ethernet0/0/1
port link-type trunk
port trunk pvid vlan 2
port trunk allow-pass vlan 2 to 4094
interface Ethernet0/0/2
port link-type trunk
port trunk pvid vlan 2
port trunk allow-pass vlan 2 to 4094
interface Ethernet0/0/3
port link-type access
port default vlan 20
port mux-vlan enable
port-isolate enable group 1
interface Ethernet0/0/4
port link-type access
port default vlan 20
port mux-vlan enable
port-isolate enable group 1
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------
假如接入交换机之间无通信需求可在核心的下联接口开启端口隔离,接入交换机下联终端端口也可以开启端口隔离即可实现全网二层隔离。