- MUX vlan(进行访客区网络资源控制)
- 主vlan+从vlan(隔离vlan+组vlan)
- 实验
- 拓扑
- 相关需求:
- 要求划分企业的部门网络通信
- 设立外来访问区,两个部门,所有主机都可访问服务器进行上网
- 同一部门间可以实现互通
- 不同部门禁止访问
- 外来者仅可访问服务器,各部门禁止外来人员的流量访问
- sw1
- vlan batch 100 20 30 40
- vlan 100 关联主从vlan
- mux-vlan(出现l3报错了用undo删掉接口vlan100再输入mux-vlan)
- subordinate separate 40 隔离
- subordinate group 20 30 组
- interface GigabitEthernet0/0/1
- port link-type access
- port default vlan 100
- port mux-vlan enable
- interface GigabitEthernet0/0/2
- port link-type trunk
- port trunk allow-pass vlan 40 20 30 100
- interface GigabitEthernet0/0/3
- port link-type trunk
- port trunk allow-pass vlan 40 20 30 100
- interface GigabitEthernet0/0/4
- port link-type trunk
- port trunk allow-pass vlan 40 20 30 100
- sw2
- vlan batch 40 20 30 100
- vlan 100 关联主从vlan
- mux-vlan(出现l3报错了用undo删掉接口vlan100再输入mux-vlan)
- subordinate separate 40 隔离
- subordinate group 20 30 组
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk allow-pass vlan 40 20 30 100
- interface GigabitEthernet0/0/2
- port link-type access
- port default vlan 20
- port mux-vlan enable
- interface GigabitEthernet0/0/3
- port link-type access
- port default vlan 20
- port mux-vlan enable
- sw3
- vlan batch 40 20 30 100
- vlan 100 关联主从vlan
- mux-vlan(出现l3报错了用undo删掉接口vlan100再输入mux-vlan)
- subordinate separate 40 隔离
- subordinate group 20 30 组
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk allow-pass vlan 40 20 30 100
- interface GigabitEthernet0/0/2
- port link-type access
- port default vlan 30
- port mux-vlan enable
- interface GigabitEthernet0/0/3
- port link-type access
- port default vlan 30
- port mux-vlan enable
- sw4
- vlan batch 40 20 30 100
- vlan 100 关联主从vlan
- mux-vlan(出现l3报错了用undo删掉接口vlan100再输入mux-vlan)
- subordinate separate 40 隔离
- subordinate group 20 30 组
- interface GigabitEthernet0/0/1
- port link-type trunk
- port trunk allow-pass vlan 40 20 30 100
- interface GigabitEthernet0/0/2
- port link-type access
- port default vlan 40
- port mux-vlan enable
- interface GigabitEthernet0/0/3
- port link-type access
- port default vlan 40
- port mux-vlan enable
07-24
3231
04-18
4698
08-04
08-04
08-04
08-04