一.实验拓扑:
二.实验需求:
1.pc1/pc3与pc2/pc4/pc5/pc6不在同一网段;
2.所有pc通过DHCP获取IP地址,且pc1/pc3可以正常访问pc2/pc4/pc5/pc6.
3.pc1和pc3所在接口为access;属于vlan2;PC2/PC4/PC5/PC6处于同一网段;
其中PC2可以访问PC4/pc5/pc6;PC4可以访问pc6,不能访问pc5;pc5不能访问pc6;
三.实验思路:
1.划分两个网段分配给VLAN 2 :192.168.2.0/24 和VLAN 3/4/5/6 :192.168.1.0
2.为实现控制同一网段下不同vlan之间的通信,可以配置VLAN3/4/5/6接口类型为hybrid 在untagged表中写入可互通的vlan,不能访问的则不写入,交换机之间配置trunk类型,vlan2配置access接口类型。
3.在路由器上配置DHCP服务创建子接口用于给vlan下发ip地址,用物理口给vlan 3/4/5/6下发ip地址(物理口只能识别不带标签的帧,子接口可以识别带标签的帧,同时多个不同的vlan需要划分同一个网段地址,所以需要将不同的vlan标签剥离掉,方便路由器下发同一网段的ip)所以还需要再LSW1上连接路由器的接口设置为hybrid口剥离vlan 3/4/5/6的标签
四,实验过程:
(1)配置vlan(注意因为涉及到所有vlan的流量所以再每个交换机上面都要配置所有vlan):
LSW1:
[LSW1]vlan batch 2 to 6 //批量创建vlan
[LSW1-GigabitEthernet0/0/1]port link-type access //设置vlan接口类型为access
[LSW1-GigabitEthernet0/0/1]port default vlan 2 //将接口划分到vlan2
[LSW1]inter g0/0/2
[LSW1-GigabitEthernet0/0/2]port link-type hybrid //设置vlna接口类型为hybrid
[LSW1-GigabitEthernet0/0/2]port hybrid pvid vlan 3 //设置hybrid接口pvid为vlan 3
[LSW1-GigabitEthernet0/0/2]port hybrid untagged vlan 3 to 6//设置untagged表对vlan3to6的撕标签
[LSW1]inter g0/0/3
[LSW1-GigabitEthernet0/0/3]port link-type trunk //设置vlan接口为trunk
[LSW1-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6 //放通vlan 2 to 6
[LSW1]inter g0/0/4
[LSW1-GigabitEthernet0/0/4]port link-type hybrid
[LSW1-GigabitEthernet0/0/4]port hybrid untagged vlan 3 to 6 //对带有 vlan3 to 6 的标签撕下
LSW2:
[LSW2]vlan batch vlan 2 to 6
[LSW2]inter g0/0/1
[LSW2-GigabitEthernet0/0/1]port link-type access
[LSW2-GigabitEthernet0/0/1]port default vlan 2
[LSW2]inter g0/0/2
[LSW2-GigabitEthernet0/0/2]port link-type hybrid
[LSW2-GigabitEthernet0/0/2]port hybrid pvid vlan 4
[LSW2-GigabitEthernet0/0/2]port hybrid untagged vlan 2 3 4 6
[LSW2]inter g0/0/3
[LSW2-GigabitEthernet0/0/3]port link-type trunk
[LSW2-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 to 6
[LSW2]inter g0/0/4
[LSW2-GigabitEthernet0/0/4]port link-type trunk
[LSW2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 6
LSW3:
[LSW3]inter g0/0/1
[LSW3-GigabitEthernet0/0/1]port link-type hybrid
[LSW3-GigabitEthernet0/0/1]port hybrid pvid vlan 5
[LSW3-GigabitEthernet0/0/1]port hybrid untagged vlan 2 3 5
[LSW3]inter g0/0/2
[LSW3-GigabitEthernet0/0/2]port link-type hybrid
[LSW3-GigabitEthernet0/0/2]port hybrid pvid vlan 6
[LSW3-GigabitEthernet0/0/2]port hybrid untagged vlan 2 3 4 6
[LSW3]inter g0/0/4
[LSW3-GigabitEthernet0/0/4]port link-type trunk
[LSW3-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 6
(2)创建子接口,配置dhcp服务
AR1:
[AR1]inter g0/0/0
[AR1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[AR1-GigabitEthernet0/0/0]inter g0/0/0.1
[AR1-GigabitEthernet0/0/0.1]ip address 192.168.2.1 24
[AR1-GigabitEthernet0/0/0.1]dot1q termination vid 2 //配置子接口可以识别的802.1q的帧
[AR1-GigabitEthernet0/0/0.1]arp broadcast enable //开启ARP的广播功能
[AR1]dhcp enable
[AR1]ip pool aa
[AR1-ip-pool-aa]network 192.168.1.0 mask 24
[AR1-ip-pool-aa]gateway-list 192.168.1.1
[AR1-ip-pool-aa]dns-list 114.114.114.114
[AR1-ip-pool-aa]dns-list 8.8.8.8
[AR1]inter g0/0/0
[AR1-GigabitEthernet0/0/0]dhcp select global
[AR1]ip pool bb
[AR1-ip-pool-bb]network 192.168.2.0 mask 24
[AR1-ip-pool-bb]gateway-list 192.168.2.1
[AR1-ip-pool-bb]dns-list 114.114.114.114
[AR1-ip-pool-bb]dns-list 8.8.8.8
[AR1-GigabitEthernet0/0/0.1]dhcp select global
主机开启DHCP功能: