设备调试之PVLAN技术实践

private vlan

1.项目背景

在二层设备上隔离用户或隔离广播,可以将一组设备加入到一个vlan中,但vlan的最大数是4094,所以当需要隔离大量的广播域时会受到vlan个数的限制。通常在服务提供商(SP)网络中,为了隔离不同客户之间的通信而将一个客户作为一个vlan,但是如果客户的数量增大到vlan的最大个数时,服务提供商提供的服务也将受到限制。这种一个客户作为一个vlan的解决方案,服务提供商需要为每一个客户分配一个子网地址,会导致IP地址的浪费。

2.实验原理

PVLAN实验,实现了混杂端口与任意端口的通信,即混杂端口与隔离端口和团体端口的通;隔离端口只能与混杂端口通信,同vlan中不同PC之间的隔离;团体vlan与混杂端口通信,同vlan之间通信,不同vlan之间不能通信。

3.实验拓扑

VLAN 10 Primary vlan | VLAN 20 Community vlan | VLAN 30 Isolated vlan
以下实验采用锐捷设备调试

在这里插入图片描述

4.地址规划

在这里插入图片描述

5.详细配置

S2-1基本配置

Ruijie>ena
Ruijie#con
Enter configuration commands, one per line.  End with CNTL/Z.
s2-1(config)#vlan 10
s2-1(config-vlan)#private-vlan primary 
s2-1(config-vlan)#exit
s2-1(config)#vlan 30
s2-1(config-vlan)#private-vlan isolated 
s2-1(config-vlan)#exit
s2-1(config)#vlan 20
s2-1(config-vlan)#private-vlan community 
s2-1(config-vlan)#exit
s2-1(config)#vlan 10
s2-1(config-vlan)#private-vlan association add 20,30
s2-1(config-vlan)#exit
s2-1(config)#interface range fastEthernet 0/1,0/3
s2-1(config-if-range)#switchport mode private-vlan host
s2-1(config-if-range)#switchport private-vlan host-association 10 30
s2-1(config-if-range)#exit
s2-1(config)#interface aggregateport 1
s2-1(config-if-AggregatePort 1)#switchport mode trunk
s2-1(config-if-AggregatePort 1)#exit
s2-1(config)#interface range fastEthernet 0/23-24
s2-1(config-if-range)#port-group 1
s2-1(config-if-range)#exit   
s2-1(config)#interface fastEthernet 0/5
s2-1(config-if-FastEthernet 0/5)#switchport mode private-vlan promiscuous 
                                                                        
s2-1(config-if-FastEthernet 0/5)#switchport private-vlan mapping 10 add 30   
s2-1(config-if-FastEthernet 0/5)#exit
s2-1(config)#interface vlan 10
2-1(config-if-VLAN 10)#ip address 192.168.10.1 255.255.255.0
s2-1(config-if-VLAN 10)#private-vlan mapping add 30
s2-1(config-if-VLAN 10)#exit

S2-2基本配置

Ruijie>ena
Ruijie#con
Enter configuration commands, one per line.  End with CNTL/Z.
Ruijie(config)#host s2-2
s2-2(config)#vlan 10
s2-2(config-vlan)#private-vlan primary 
s2-2(config-vlan)#exit
s2-2(config)#vlan 20
s2-2(config-vlan)#private-vlan community 
s2-2(config-vlan)#exit
s2-2(config)#vlan 30
s2-2(config-vlan)#private-vlan isolated 
s2-2(config-vlan)#exit
s2-2(config)#vlan 10
s2-2(config-vlan)#private-vlan association add 20,30
s2-2(config-vlan)#exit
s2-2(config)#interface fastEthernet 0/1
s2-2(config-if-FastEthernet 0/1)#switchport mode private-vlan host
s2-2(config-if-FastEthernet 0/1)#switchport private-vlan host-association 10 20            
s2-2(config-if-FastEthernet 0/1)#exit
s2-2(config)#interface aggregateport 1
s2-2(config-if-AggregatePort 1)#switchport mode trunk
s2-2(config-if-AggregatePort 1)#exit
s2-2(config)#interface range fastEthernet 0/23-24
s2-2(config-if-range)#port-group 1
s2-2(config-if-range)#exit        
s2-2(config)#interface fastEthernet 0/3
s2-2(config-if-FastEthernet 0/3)#switchport mode trunk
s2-2(config-if-FastEthernet 0/3)#exit
s2-2(config)#interface vlan 10
s2-2(config-if-VLAN 10)#ip address 192.168.10.1 255.255.255.0
s2-2(config-if-VLAN 10)#exit
s2-2(config)#interface fastEthernet 0/3                                             
s2-2(config-if-FastEthernet 0/3)#switchport mode private-vlan promiscuous
s2-2(config-if-FastEthernet 0/3)#switchport private-vlan mapping 10 add 20
s2-2(config-if-FastEthernet 0/3)#exit
s2-2(config)#exit

6.测试结果

S2-1测试结果
s2-1#ping 192.168.10.1
Sending 5, 100-byte ICMP Echoes to 192.168.10.1, timeout is 2 seconds:
  < press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
s2-1#ping 192.168.10.12
Sending 5, 100-byte ICMP Echoes to 192.168.10.12, timeout is 2 seconds:
  < press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
s2-1#ping 192.168.10.11
Sending 5, 100-byte ICMP Echoes to 192.168.10.14, timeout is 2 seconds:
  < press Ctrl+C to break >
.
Success rate is 0 percent (0/1)

s2-1#ping 192.168.10.14
Sending 5, 100-byte ICMP Echoes to 192.168.10.14, timeout is 2 seconds:
  < press Ctrl+C to break >
.
Success rate is 0 percent (0/1)
s2-1#

S2-1测试结果

s2-2#ping 192.168.10.1
Sending 5, 100-byte ICMP Echoes to 192.168.10.1, timeout is 2 seconds:
  < press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
s2-2#ping 192.168.10.14
Sending 5, 100-byte ICMP Echoes to 192.168.10.14, timeout is 2 seconds:
  < press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
s2-2#ping 192.168.10.11
Sending 5, 100-byte ICMP Echoes to 192.168.10.11, timeout is 2 seconds:
  < press Ctrl+C to break >
.
Success rate is 0 percent (0/1)
s2-2#ping 192.168.10.12
Sending 5, 100-byte ICMP Echoes to 192.168.10.12, timeout is 2 seconds:
  < press Ctrl+C to break >
.
Success rate is 0 percent (0/1)

s2-2#
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

寻址00000001

千里之行,始于“足下”

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值