目录
基础
Vlan、IP规划
PC1:192.168.1.1/24,hybrid pvid vlan 10
PC2:192.168.1.2/24,hybrid pvid vlan 20
PC3:192.168.30.3/24,hybrid pvid vlan 30
PC4:192.168.1.4/24,hybrid pvid vlan 30
PC5:192.168.30.5/24,access vlan 30
SW1:vlan 10、20、30,trunk vlan all
SW2:vlan 10、20、30,trunk vlan all
拓扑连接
目标
目标1:PC1可与同交换机的PC2不能相互访问
目标2:PC1、PC2分别与不同交换机的PC4相互访问
目标3:PC3与PC5跨交换机可相互访问
模拟器实施过程
SW1实施过程
[SW1]vlan 10
[SW1-vlan10]vlan 20
[SW1-vlan20]vlan 30
[SW1-vlan30]qu
[SW1]interface GigabitEthernet 1/0/1
[SW1-GigabitEthernet1/0/1]port link-type hybrid
[SW1-GigabitEthernet1/0/1]port hybrid pvid vlan 10
[SW1-GigabitEthernet1/0/1]port hybrid vlan 10 30 untagged
[SW1-GigabitEthernet1/0/1]undo port hybrid vlan 1
[SW1-GigabitEthernet1/0/1]qu
[SW1]interface GigabitEthernet 1/0/2
[SW1-GigabitEthernet1/0/2]port link-type hybrid
[SW1-GigabitEthernet1/0/2]port hybrid pvid vlan 20
[SW1-GigabitEthernet1/0/2]port hybrid vlan 20 30 untagged
[SW1-GigabitEthernet1/0/2]undo port hybrid vlan 1
[SW1-GigabitEthernet1/0/2]qu
[SW1]interface GigabitEthernet 1/0/3
[SW1-GigabitEthernet1/0/3]port link-type hybrid
[SW1-GigabitEthernet1/0/3]port hybrid pvid vlan 30
[SW1-GigabitEthernet1/0/3]port hybrid vlan 10 20 30 untagged
[SW1-GigabitEthernet1/0/3]undo port hybrid vlan 1
[SW1-GigabitEthernet1/0/3]qu
[SW1]interface GigabitEthernet 1/0/9
[SW1-GigabitEthernet1/0/9]port link-type trunk
[SW1-GigabitEthernet1/0/9]port trunk permit vlan all
[SW1-GigabitEthernet1/0/9]qu
SW2实施过程
[SW2]vlan 10
[SW2-vlan10]vlan 20
[SW2-vlan20]vlan 30
[SW2-vlan30]qu
[SW2]interface GigabitEthernet 1/0/1
[SW2-GigabitEthernet1/0/1]port link-type hybrid
[SW2-GigabitEthernet1/0/1]port hybrid pvid vlan 10
[SW2-GigabitEthernet1/0/1]port hybrid vlan 10 20 30 untagged
[SW2-GigabitEthernet1/0/1]undo port hybrid vlan 1
[SW2-GigabitEthernet1/0/1]qu
[SW2]interface GigabitEthernet 1/0/2
[SW2-GigabitEthernet1/0/2]port link-type access
[SW2-GigabitEthernet1/0/2]port access vlan 30
[SW2-GigabitEthernet1/0/2]qu
[SW2]interface GigabitEthernet 1/0/9
[SW2-GigabitEthernet1/0/9]port link-type trunk
[SW2-GigabitEthernet1/0/9]port trunk permit vlan all
[SW2-GigabitEthernet1/0/9]qu
通断验证
验证目标1
PC1至PC2不通,目标1完成
验证目标2
PC1至PC4通,PC2至PC4通,目标2完成
验证目标3
PC3至PC5通,目标3完成
物理机实施过程的阻碍项
其中
PC1:192.168.100.249,hybrid pvid vlan 100
PC2:192.168.100.115,hybrid pvid vlan 200
交换机:H3C S5560 Series
提前创建号vlan 100、200
验证过程1
两个端口均为hybrid口情况下互通验证
[H3C]int g 1/0/1
[H3C-GigabitEthernet1/0/1]por li hy
[H3C-GigabitEthernet1/0/1]po hy pv vlan 100
[H3C-GigabitEthernet1/0/1]po hy vl 100 200 un
[H3C-GigabitEthernet1/0/1]un po hy vl 1
[H3C-GigabitEthernet1/0/1]qu
[H3C]int g 1/0/2
[H3C-GigabitEthernet1/0/2]po li hy
[H3C-GigabitEthernet1/0/2]po hy pv vl 200
[H3C-GigabitEthernet1/0/2]un po hy vl 1
[H3C-GigabitEthernet1/0/2]po hy vl 100 200 un
[H3C-GigabitEthernet1/0/2]qu
[H3C]
按照这个过程正常应该两个主机就通了,实际不通,后发现对方主机未关闭防火墙,关闭防火墙后可通【就是下方图片里的绿色的那个,也需要关闭掉】
验证过程2
一个为hybrid口、一个为access口情况下互通验证
[H3C]int g 1/0/1
[H3C-GigabitEthernet1/0/1]por li hy
[H3C-GigabitEthernet1/0/1]po hy pv vlan 100
[H3C-GigabitEthernet1/0/1]po hy vl 100 200 un
[H3C-GigabitEthernet1/0/1]un po hy vl 1
[H3C-GigabitEthernet1/0/1]qu
[H3C]int g 1/0/2
[H3C-GigabitEthernet1/0/2]po li ac
[H3C-GigabitEthernet1/0/2]po ac vl 100
[H3C-GigabitEthernet1/0/2]qu
[H3C]
小结
个人记忆方法:
access:只允许一个vlan通过,一般就是接PC或傻瓜交换机
trunk:允许多个vlan通过,接可网管交换机的
hybrid:允许1个或多个vlan通过,跨vlan的同网段PC互通
#
interface GigabitEthernet1/0/1
port link-mode bridge
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 10 30 untagged #此处必须包含自己的vlan ID,另外需要和哪个vlan通就写哪个vlan ID
port hybrid pvid vlan 10 #基于端口的vlan ID
combo enable fiber
#
interface GigabitEthernet1/0/2
port link-mode bridge
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 20 30 untagged
port hybrid pvid vlan 30
combo enable fiber
#
interface GigabitEthernet1/0/3
port link-mode bridge
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 10 20 30 untagged
port hybrid pvid vlan 30
combo enable fiber
#