组网拓扑
配置步骤
SW1配置 vlan 20 ! vlan 100 //创建vlan 100 private-vlan primary //定义主级vlan private-vlan association 101-102,109 //关联次级vlan 101,102,109 ! vlan 101 private-vlan community //定义次级vlan101类型为团体VLAN ! vlan 102 private-vlan community //定义次级vlan102类型为团体VLAN ! vlan 109 private-vlan isolated //定义次级vlan109类型为隔离VLAN ! vlan 110,200 ! interface Ethernet0/0 switchport access vlan 110 //网关路由器R11与SW1互联接口,加入vlan110,之后会为vlan110创建SVI 110接口,用于与R11起OSPF动态路由协议,实现全网互通 switchport mode access ! interface Ethernet0/1 //与SW2接入交换机互联,接口类型为Trunk switchport trunk encapsulation dot1q switchport mode trunk ! interface Ethernet0/2 //与SW3接入交换机互联,接口类型为Trunk switchport trunk encapsulation dot1q switchport mode trunk ! interface Ethernet0/3 //连接部门服务器接口 switchport private-vlan mapping 100 101-102,109 //主级VLAN100,关联次级VLAN 101,102,109 switchport mode private-vlan promiscuous //接口定义为混杂模式,该端口能够与主级和次级VLAN内的所有端口建立通信 ! interface Ethernet1/0 //连接公司服务器接口 switchport access vlan 200 //该服务器连接交换机的接口属于普通VLAN 200 switchport mode access ! interface Vlan20 ip address 20.1.1.254 255.255.255.0 ! interface Vlan100 ip address 10.1.1.254 255.255.255.0 private-vlan mapping 101-102,109 //为了实现次级VLAN的流量也能够执行三层转发,需为主级VLAN(SVI)添加私有VLAN的映射 ! interface Vlan110 ip address 172.31.1.110 255.255.255.0 //与网关互联SVI接口 ! interface Vlan200 ip address 200.1.1.254 255.255.255.0 //公司服务器所在VLAN的SVI接口 ! router ospf 110 router-id 89.110.110.110 redistribute connected subnets //重发布直连,可以将所有VLAN子网宣告进OSPF network 172.31.1.110 0.0.0.0 area 0 |
SW2配置 vlan 20 ! vlan 100 private-vlan primary private-vlan association 101-102,109 //所有交换机定义的私有VLAN需保持一致 ! vlan 101 private-vlan community ! vlan 102 private-vlan community ! vlan 109 private-vlan isolated ! vlan 200 ! interface Ethernet0/0 switchport trunk encapsulation dot1q switchport mode trunk //与汇聚交换机互联接口类型还是正常为中继模式 ! interface Ethernet0/1 switchport private-vlan host-association 100 101 //关联接口到正确的主级(VLAN 100)和次级VLAN(VLAN 101 团体VLAN) switchport mode private-vlan host //定义接口模式为主机模式 ! interface Ethernet0/2 switchport private-vlan host-association 100 109 //关联接口到正确的主级(VLAN 100)和次级VLAN(VLAN 109 隔离VLAN) switchport mode private-vlan host //定义接口模式为主机模式 ! interface Ethernet0/3 switchport private-vlan host-association 100 102 //关联接口到正确的主级(VLAN 100)和次级VLAN(VLAN 102 团体VLAN) switchport mode private-vlan host //定义接口模式为主机模式 |
SW3配置 vlan 20 ! vlan 100 private-vlan primary private-vlan association 101-102,109 //所有交换机定义的私有VLAN需保持一致 ! vlan 101 private-vlan community ! vlan 102 private-vlan community ! vlan 109 private-vlan isolated ! vlan 200 ! interface Ethernet0/0 switchport trunk encapsulation dot1q switchport mode trunk //与汇聚交换机互联接口类型还是正常为中继模式 ! interface Ethernet0/1 switchport private-vlan host-association 100 101 switchport mode private-vlan host ! interface Ethernet0/2 switchport private-vlan host-association 100 109 switchport mode private-vlan host ! interface Ethernet0/3 switchport access vlan 20 switchport mode access |
最终实现效果
|