vlan隔离,vlan之间相互通信,拓扑图如下:
核心交换机5731负责划分VLAN、配置VLAN地址等,实现VLAN间的通信。5731配置如下:
#
sysname CORE 5731
#
vlan batch 2 to 3
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
dhcp enable
#
diffserv domain default
#
drop-profile default
#
vlan 2
description WorkGroup2
vlan 3
description WorkGroup3
#
ip pool vlan2 #配置ip地址池vlan2,用于vlan2的DHCP
gateway-list 192.168.2.1
network 192.168.2.0 mask 255.255.255.0
dns-list 8.8.8.8 221.7.92.98
#
ip pool vlan3 #配置ip地址池vlan2,用于vlan2的DHCP
gateway-list 192.168.3.1
network 192.168.3.0 mask 255.255.255.0
dns-list 8.8.8.8 221.7.92.98
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif2
ip address 192.168.2.1 255.255.255.0
dhcp select global #开启vlan2 DHCP
#
interface Vlanif3
ip address 192.168.3.1 255.255.255.0
dhcp select global #开启vlan3 DHCP
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094 #允许所有VLAN通过 g0/0/1口
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094 #允许所有VLAN通过 g0/0/1口和g0/0/2口,实现VLAN间互联
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
……
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
port-group truck
#
port-group vlan2
group-member GigabitEthernet0/0/1
group-member GigabitEthernet0/0/2
#
return
S5720-1中除g0/0/1上联到5731,其他电口全部用于接终端(计算机等)。S5720 g0/0/2-g0/0/24全部划分到VLAN2,连接的计算机会自动获取IP地址和DNS,具体是:IP地址:192.168.2.X,子网掩码:24位,网关:192.168.2.1,DNS:8.8.8.8 221.7.92.98。配置代码如下:
#
sysname S5720-1
#
vlan batch 2 to 3 #划分了两个VLAN,VLAN编号必须与5731中的VLAN一致,否则无法自动获取IP地址等
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1 #G0/0/1是上行口,接5731 g0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2 #g0/0/2-24全部用于终端,划入VLAN2
port link-type access
port default vlan 2
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 2
#
interface GigabitEthernet0/0/4
port link-type access
port default vlan 2
#
interface GigabitEthernet0/0/5
port link-type access
port default vlan 2
……
interface GigabitEthernet0/0/24
port link-type access
port default vlan 2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
port-group vlan2 #将g0/0/2-24绑定为一个组,方便设置端口类型、加入VLAN等操作
group-member GigabitEthernet0/0/2
group-member GigabitEthernet0/0/3
group-member GigabitEthernet0/0/4
group-member GigabitEthernet0/0/5
group-member GigabitEthernet0/0/6
group-member GigabitEthernet0/0/7
group-member GigabitEthernet0/0/8
group-member GigabitEthernet0/0/9
group-member GigabitEthernet0/0/10
group-member GigabitEthernet0/0/11
group-member GigabitEthernet0/0/12
group-member GigabitEthernet0/0/13
group-member GigabitEthernet0/0/14
group-member GigabitEthernet0/0/15
group-member GigabitEthernet0/0/16
group-member GigabitEthernet0/0/17
group-member GigabitEthernet0/0/18
group-member GigabitEthernet0/0/19
group-member GigabitEthernet0/0/20
group-member GigabitEthernet0/0/21
group-member GigabitEthernet0/0/22
group-member GigabitEthernet0/0/23
group-member GigabitEthernet0/0/24
#
return
S5720-2将2-24口划分为VLAN3,其他配置同上。
最终效果如下: