拓扑 :
代码:
LSW1
创建vlan,分配到PC端
<Huawei>sys
[Huawei]vlan batch 10 20
[Huawei]interface e0/0/1
[Huawei-Ethernet0/0/1]port link-type access //Access模式
[Huawei-Ethernet0/0/1]port default vlan 10
[Huawei]interface e0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 20
[Huawei-Ethernet0/0/2]quit
[Huawei]interface e0/0/3
[Huawei-Ethernet0/0/3]port link-type trunk
[Huawei-Ethernet0/0/3]port trunk allow-pass vlan 10 20
[Huawei-Ethernet0/0/3]quit
LSW2
[Huawei]sysname LSW2
[LSW2]vlan batch 30 40
[LSW2]interface e0/0/1
[LSW2-Ethernet0/0/1]port link-type access
[LSW2-Ethernet0/0/1]port default vlan 30
[LSW2-Ethernet0/0/1]quit
[LSW2]interface e0/0/2
[LSW2-Ethernet0/0/2]port link-type access
[LSW2-Ethernet0/0/2]port default vlan 40
[LSW2-Ethernet0/0/2]quit
[LSW2]interface e0/0/3
[LSW2-Ethernet0/0/3]port link-type trunk
[LSW2-Ethernet0/0/3]port trunk allow-pass vlan 30 40
[LSW2-Ethernet0/0/3]quit
[LSW2]quit
<LSW2>save
LSW3
Dot1q技术接入vlan
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]vlan batch 10 20 30 40
Info: This operation may take a few seconds. Please wait for a moment...done.
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk //trunk模式
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[Huawei-GigabitEthernet0/0/1]quit
[Huawei]interface g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type trunk
[Huawei-GigabitEthernet0/0/2]port trunk allow-pass vlan 30 40
[Huawei-GigabitEthernet0/0/2]quit
创建VLANif 接口
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]ip address 192.168.10.254 255.255.255.0 //网关及子网掩码
[Huawei-Vlanif10]quit
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]ip address 192.168.20.254 255.255.255.0
[Huawei-Vlanif20]quit
[Huawei]interface Vlanif 30
[Huawei-Vlanif30]ip address 192.168.30.254 255.255.255.0
[Huawei-Vlanif30]quit
[Huawei]interface Vlanif 40
[Huawei-Vlanif40]ip address 192.168.40.254 255.255.255.0
[Huawei-Vlanif40]quit
<Huawei>sys
[Huawei]interface g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type trunk
[Huawei-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20 30 40
[Huawei-GigabitEthernet0/0/3]quit
R1
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]sysname R1
[R1]interface g0/0/0
[R1-GigabitEthernet0/0/0]undo shutdown
Info: Interface GigabitEthernet0/0/0 is not shutdown.
[R1-GigabitEthernet0/0/0]quit
[R1]interface g0/0/0.10
[R1-GigabitEthernet0/0/0.10]dot1q termination vid 10
[R1-GigabitEthernet0/0/0.10]ip address 192.168.10.254 24
[R1-GigabitEthernet0/0/0.10]arp broadcast enable
[R1-GigabitEthernet0/0/0.10]quit
[R1]interface g0/0/0.20
[R1-GigabitEthernet0/0/0.20]dot1q termination vid 20
[R1-GigabitEthernet0/0/0.20]ip address 192.168.20.254 24
[R1-GigabitEthernet0/0/0.20]arp broadcast enable
[R1-GigabitEthernet0/0/0.20]quit
[R1]interface g0/0/0.30
[R1-GigabitEthernet0/0/0.30]dot1q termination vid 30
[R1-GigabitEthernet0/0/0.30]ip address 192.168.30.254 24
[R1-GigabitEthernet0/0/0.30]arp broadcast enable
[R1-GigabitEthernet0/0/0.30]quit
[R1]interface g0/0/0.40
[R1-GigabitEthernet0/0/0.40]dot1q termination vid 40
[R1-GigabitEthernet0/0/0.40]ip address 192.168.40.254 24
[R1-GigabitEthernet0/0/0.40]arp broadcast enable
[R1-GigabitEthernet0/0/0.40]quit
PC端ping外网配置
[R1]interface g0/0/0
[R1-GigabitEthernet0/0/0]ip address 100.1.1.254 24
[R1-GigabitEthernet0/0/0]undo shutdown
[R1-GigabitEthernet0/0/0]quit
Nat配外网配置
[R1]interface g0/0/2
[R1-GigabitEthernet0/0/2]ip address 192.168.1.254 24
[R1-GigabitEthernet0/0/2]undo shutdown
[R1-GigabitEthernet0/0/2]quit
[R1]quit
阻止acl ping外网
<R1>sys
Enter system view, return user view with Ctrl+Z.
[R1]nat address-group 1 100.1.1.3 100.1.1.4 //地址池
[R1]acl 2000 //acl 配置
[R1-acl-basic-2000]rule 10 permit source 192.168.1.0 0.0.0.255 //允许网段通过
[R1-acl-basic-2000]quit
[R1]interface g0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 //通过地址
[R1-GigabitEthernet0/0/1]quit
[R1]quit
结果:
自己弄!
效果仅供参考!