实验要求:
1 PC1和PC3所在接口为access;属于 vlan2
PC2/4/5/6处于同一网段;其中PC2可以访问PC4/5/6; 但PC4可以访问PC5,不能访问PC6, PC5不能访问PC6
3 PC1/3与PC2/4/5/6不在同一个网段
4 所有PC通过DHCP获取IP地址,且PC1/3可以正常访问PC2/4/5/6
实验拓扑:
实验过程:
1、划分vlan
实验要求说明:当前已有vlan2,包含机器为PC1,PC3
在实验要求第一点中说明,PC2/4/5/6需要配置策略,分析实验要求,PC2可以访问PC4/5/6,PC2可以与PC4/5/6在同一个vlan;PC4可以访问PC2/5,但是不能访问PC6,所以PC4与PC5可以在同一个vlan,但是不能与PC6在同一个vlan;PC5可以访问PC2/4,但是无法访问到PC6;所以我们需要vlan3/4/5,我们也可以直接划分vlan3/4/5/6四个vlan。
2、在交换机进行配置
SW1
首先配置PC1接口,access口配置;然后配置PC2,修改PVID为3,PC3-6都可以访问到PC2
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 2
[SW1]int g0/0/3
[SW1-GigabitEthernet0/0/3]port link-type hybrid
[SW1-GigabitEthernet0/0/3]port hybrid pvid vlan 3
[SW1-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 6
与SW2和R1相连的链路,SW2连接链路配置为trunk,与R1连接链路配置为hybrid,在与R1连接的链路上,因为需要接受PC2/4/5/6四台机器的数据,这四台数据发包到SW1上如果不进行脱标签的情况下,需要在R1上接入四个子接口,但是实验要求我们需要将PC2/4/5/6在同一网段,所以需要对PC2/4/5/6发来的数据包进行脱标签再发送给R1,脱标签后默认带vlan 1的标签
[SW1]int g0/0/4
[SW1-GigabitEthernet0/0/4]port link-type trunk
[SW1-GigabitEthernet0/0/4]port trunk allow-pass vlan all
[SW1-GigabitEthernet0/0/1]port link-type hybrid
[SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 2
[SW1-GigabitEthernet0/0/1]port hybrid untagged vlan 3 to 6
SW2
[Huawei]sysname SW2
[SW2]vlan batch 2 to 6
[SW2]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type access
[SW2-GigabitEthernet0/0/2]port default vlan 2
[SW2]int g0/0/
[SW2-GigabitEthernet0/0/2]port link-type access
[SW2-GigabitEthernet0/0/2]port default vlan 2
[SW2]int g0/0/3
[SW2-GigabitEthernet0/0/3]port link-type hybrid
[SW2-GigabitEthernet0/0/3]port hybrid pvid vlan 4
[SW2-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 5
[SW2-GigabitEthernet0/0/3]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[SW2-GigabitEthernet0/0/1]int g0/0/
[SW2-GigabitEthernet0/0/4]port link-type trunk
[SW2-GigabitEthernet0/0/4]port trunk allow-pass vlan all
SW3
[Huawei]sys SW3
[SW3]vlan batch 2 to 6
[SW3]int g0/0/1
[SW3-GigabitEthernet0/0/1]port link-type trunk
[SW3-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[SW3-GigabitEthernet0/0/1]int g0/0/2
[SW3-GigabitEthernet0/0/2]port link-type hybrid
[SW3-GigabitEthernet0/0/2]port hybrid pvid vlan 5
[SW3]int g0/0/2
[SW3-GigabitEthernet0/0/2]port link-type hybrid
[SW3-GigabitEthernet0/0/2]port hybrid pvid vlan 5
[SW3-GigabitEthernet0/0/2]port hybrid untagged vlan 3 to 5
[SW3]int g0/0/3
[SW3-GigabitEthernet0/0/3]port link-type hybrid
[SW3-GigabitEthernet0/0/3]port hybrid pvid vlan 6
[SW3-GigabitEthernet0/0/3]port hybrid untagged vlan 3 6
3、在R1上配置DHCP分发ip
进入物理接口配置网关信息
[Huawei]sys R1
[R1]dhcp enable
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.2.254 24
子接口配置网关信息,告知子接口需要处理的是带有标签vlan id2的数据,打开广播
[R1-GigabitEthernet0/0/0]int g0/0/0.1
[R1-GigabitEthernet0/0/0.1]ip add 192.168.1.254 24
[R1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[R1-GigabitEthernet0/0/0.1]arp broadcast enable
[R1]ip pool a
[R1-ip-pool-a]network 192.168.1.0 mask 24
[R1-ip-pool-a]gateway-list 192.168.1.254
[R1-ip-pool-a]dns-list 114.114.114.114
[R1]ip pool b
[R1-ip-pool-b]network 192.168.2.0 mask 24
[R1-ip-pool-b]gateway-list 192.168.2.254
[R1-ip-pool-b]dns-list 114.114.114.114
[R1-ip-pool-b]int g0/0/0
[R1-GigabitEthernet0/0/0]dhcp select global
[R1-GigabitEthernet0/0/0]int g0/0/0.1
[R1-GigabitEthernet0/0/0.1]dhcp select global
4、查看各PC的ip配置并测试
PC1
PC2
PC3
PC4
PC5
PC6
使用PC4pingPC6测试
使用PC5pingPC6