一:eth-trunk--将g0/0/3 0/0/4划入eth-trunk
二: 配置vlan---三层
[sw4]port-group group-member Eth-Trunk0 g 0/0/5 g 0/0/2
[sw4-port-group]port link-type trunk
[sw4-Eth-Trunk0]port link-type trunk
[sw4-GigabitEthernet0/0/5]port link-type trunk
[sw4-GigabitEthernet0/0/2]port link-type trunk
[sw4-port-group]port trunk allow-pass vlan 2
[sw4-Eth-Trunk0]port trunk allow-pass vlan 2
[sw4-GigabitEthernet0/0/5]port trunk allow-pass vlan 2
[sw4-GigabitEthernet0/0/2]port trunk allow-pass vlan 2
二层:将g1g2改为trunk e1e2改为access
[sw1-GigabitEthernet0/0/1]port link-type trunk
[sw1-GigabitEthernet0/0/2]port link-type trunk
[sw1-port-group]port trunk allow-pass vlan 2
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan 2
[sw1-GigabitEthernet0/0/2]port trunk allow-pass vlan 2
[sw1]int e 0/0/2
[sw1-Ethernet0/0/2]port link-type access
[sw1-Ethernet0/0/2]port default vlan 2
[sw1]int e 0/0/1
[sw1-Ethernet0/0/1]port link-type access
[sw1-Ethernet0/0/1]port default vlan 1
三:stp 生成树 三层二层以一个为例:
[sw4]stp mode mstp
[sw4]stp enable
[sw4]stp region-configuration
[sw4-mst-region]region-name a
[sw4-mst-region]instance 1 vlan 1
[sw4-mst-region]instance 2 vlan 2
[sw4-mst-region]active region-configuration
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw4-mst-region]q
[sw4]stp instance 1 root secondary
[sw4]stp instance 2 root primary
[sw1]stp mode mstp
[sw1]stp enable
[sw1]stp region-configuration
[sw1-mst-region]region-name a
[sw1-mst-region]instance 1 vlan 1
[sw1-mst-region]instance 2 vlan 2
四:配置svi及网关冗余
[sw3]int Vlanif 1
[sw3-Vlanif1]ip add 172.16.1.1 25
[sw3]int Vlanif 2
[sw3-Vlanif2]ip address 172.16.1.129 25
五:dhcp配置 客户端获取ip (dhcp开启 端口开启dhcp)
ip pool p1
gateway-list 172.16.1.10
network 172.16.1.0 mask 255.255.255.128
dns-list 114.114.114.114 8.8.8.8
#
ip pool p2
gateway-list 172.16.1.254
network 172.16.1.128 mask 255.255.255.128
dns-list 114.114.114.114 8.8.8.8
pc 可获取ip
六:路由配置(华为模拟器不支持三层接口 创建vlanif代替 将接口调整为access)并配置路由器ip
[sw3]int Vlanif 100
[sw3-Vlanif100]ip add 172.16.0.1 30
[sw3-Vlanif100]q
[sw3]int g 0/0/1
[sw3-GigabitEthernet0/0/1]port link-type access
[sw3-GigabitEthernet0/0/1]port default v 100
---配置公网ip
设置静态路由 访问sip,配置nat
缺省:[sw4]ip route-static 0.0.0.0 0 172.16.0.6
acl:
[r1]acl 2000
[r1-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r1-GigabitEthernet0/0/0]nat outbound acl 2000
ping 12.1.1.2