-
创建VLAN:在LSW1上创建了两个VLAN,VLAN 10和VLAN 20。这是通过
vlan batch 10 20
命令实现的。 -
配置接口:接下来,配置了三个接口。对于接口g0/0/1和g0/0/2,设置了链路类型为access,并将这两个接口分别加入到VLAN 20和VLAN 10中。这是通过
port link-type access
和port default vlan
命令实现的。对于接口g0/0/3,设置了链路类型为trunk,并允许VLAN 10和VLAN 20通过。这是通过port link-type trunk
和port trunk allow-pass vlan 10 20
命令实现的。 -
应用ACL:在R1上,创建了一个基本访问控制列表(ACL)2000,用于拒绝源地址为192.168.20.0/24的流量。这是通过
acl 2000
和rule 10 deny source 192.168.20.0 0.0.0.255
命令实现的。然后,将这个ACL应用到接口g0/0/1的入站流量上,以限制不符合ACL规则的流量通过。这是通过traffic-filter inbound acl 2000
命令实现的。
配置交换机
<LSW1>sys //进入系统视窗
[LSW1]undo info-center enable //关闭输出信息
[LSW1]vlan batch 10 20 //创建vlan10 20
[LSW1]interface g0/0/1
[LSW1-GigabitEthernet0/0/1]port link-type access
[LSW1-GigabitEthernet0/0/1]port default vlan 20
[LSW1-GigabitEthernet0/0/1]port default vlan 10
[LSW1-GigabitEthernet0/0/1]quit
[LSW1]interface g0/0/2
[LSW1-GigabitEthernet0/0/2]port link-type access
[LSW1-GigabitEthernet0/0/2]port default vlan 20
[LSW1-GigabitEthernet0/0/2]quit
[LSW1]interface g0/0/3
[LSW1-GigabitEthernet0/0/3]port link-type trunk
[LSW1-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
[LSW1-GigabitEthernet0/0/3]quit
配置路由器
<Huawei>sys
[Huawei]undo info-center enable
[Huawei]sysname R1
[R1]interface g0/0/1
[R1-GigabitEthernet0/0/1]undo shutdown
[R1-GigabitEthernet0/0/1]quit
[R1]interface g0/0/1.10
[R1-GigabitEthernet0/0/1.10]dot1q termination vid 10
[R1-GigabitEthernet0/0/1.10]ip address 192.168.10.254 24
[R1-GigabitEthernet0/0/1.10]arp broadcast enable
[R1-GigabitEthernet0/0/1.10]quit
[R1]interface g0/0/1.20
[R1-GigabitEthernet0/0/1.20]dot1q termination vid 20
[R1-GigabitEthernet0/0/1.20]ip address 192.168.20.254 24
[R1-GigabitEthernet0/0/1.20]arp broadcast enable
[R1-GigabitEthernet0/0/1.20]quit
[R1]interface g0/0/0
[R1-GigabitEthernet0/0/0]ip address 10.1.1.254 24
[R1-GigabitEthernet0/0/0]undo shutdown
[R1-GigabitEthernet0/0/0]quit
配置完成后用pc1和pc21去ping server
[R1]acl 2000
[R1-acl-basic-2000]rule 10 deny source 192.168.20.0 0.0.0.255
[R1-acl-basic-2000]quit
[R1]interface g0/0/1
[R1-GigabitEthernet0/0/1]traffic-filter inbound acl 2000
[R1-GigabitEthernet0/0/1]quit
配置好基本ACL在用pc1和pc21去ping server