实现不同vlan间PC不可互访,而不同vlan的PC均可访问服务器的特殊效果!
*配置命令:
交换机1(左):
[sw1]vlan batch 10 20 30 ------------------------------创建VLAN
[sw1]interface e0/0/1
[sw1-Ethernet0/0/1]port hybrid untagged vlan 10 30 -----------------------------流量通过时,删除VLAN 10 30的标签
[sw1-Ethernet0/0/1]port hybrid pvid vlan 10 ------------------------接口pvid为VLAN 10
[sw1-Ethernet0/0/1]int e0/0/2
[sw1-Ethernet0/0/2]port hybrid untagged vlan 20 30
[sw1-Ethernet0/0/2]port hybrid pvid vlan 20
[sw1-Ethernet0/0/2]int e0/0/3
[sw1-Ethernet0/0/3]port hybrid tagged vlan 10 20 30 -------------------------流量通过时,添加VLAN 10 20 30的标签
交换机2(右):
[sw2]vlan batch 10 20 30 ------------------------------创建VLAN
[sw2]interface e0/0/1
[sw2-Ethernet0/0/1]port hybrid untagged vlan 10 20 30 -----------------------------流量通过时,删除VLAN 10 20 30的标签
[sw2-Ethernet0/0/1]port hybrid pvid vlan 30 ------------------------接口pvid为VLAN 30
[sw2-Ethernet0/0/1]int e0/0/2
[sw2-Ethernet0/0/2]port hybrid tagged vlan 10 20 30 -------------------------流量通过时,添加VLAN 10 20 30的标签
实验结果为:
PC9与PC11可以ping通
PC10与PC11可以ping通
PC9与PC10不通