实验分析:
1.pc1和pc3在同一个vlan(vlan2),因为是access接口模式,那么需和pc2/4/5/6不在同一个网段,则是做路由器的子接口。
2. pc2/4/5/6在同一个网段,且需要实现:访问受限,那么靠接口的混杂模式来实现,划分到不同的vlan中去,进行贴标签限制。基于此划分如图2所示。
在接口上进行允许设置:
v3----√-----v4/v5
v4----×----v5
3.交换机接口,只需要做trunk,允许所有vlan通过即可。
4.在交换机于路由器的接口出做分别对应不同流量的处理。vlan2打标签,去子接口,其余去除标签,去子接口。
一、首先需要在sw1-3上创建vlan2到vlan6
二、先配置SW1 ,SW2,SW3
[sw1]int g0/0/2
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1-GigabitEthernet0/0/2]port default vlan 2
[sw1-GigabitEthernet0/0/2]int g0/0/3
[sw1-GigabitEthernet0/0/3]port hybrid pvid vlan 3
[sw1-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 6
[sw1-GigabitEthernet0/0/3]int g0/0/4
[sw1-GigabitEthernet0/0/4]port link-type trunk
[sw1-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 6
[sw2-GigabitEthernet0/0/1]po
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[sw2-GigabitEthernet0/0/1]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link-type access
[sw2-GigabitEthernet0/0/2]port default vlan 2
[sw2-GigabitEthernet0/0/3]port hybrid untagged vlan 3 to 5
[sw2-GigabitEthernet0/0/3]port hybrid pvid vlan 4
[sw3]int g0/0/1
[sw3-GigabitEthernet0/0/1]p t a v a
[sw3-GigabitEthernet0/0/1]int g0/0/2
[sw3-GigabitEthernet0/0/2]p l h
[sw3-GigabitEthernet0/0/2]p h p v 5
[sw3-GigabitEthernet0/0/2]q
[sw3]int g0/0/2
[sw3-GigabitEthernet0/0/2]p h p v 5
[sw3-GigabitEthernet0/0/2]po h u v 2 to 5
[sw3-GigabitEthernet0/0/2]int g0/0/3
[sw3-GigabitEthernet0/0/3]p h p v 6
接着在配置一下sw1上的 g0/0/1:
[sw1]int g 0/0/1
[sw1-GigabitEthernet0/0/1]p l h
[sw1-GigabitEthernet0/0/1]port hybrid untagged vlan 3 to 6
[sw1-GigabitEthernet0/0/1]port hybrid tagged vlan 2
三、配置DHCP
[r1]dhcp enable
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[r1-GigabitEthernet0/0/0]dhcp select global
[r1]ip pool v1
[r1-ip-pool-v1]gateway-list 192.168.1.1
[r1-ip-pool-v1]network 192.168.1.0 mask 255.255.255.0
[r1-ip-pool-v1]dns-list 8.8.8.8
子接口
[r1]interface GigabitEthernet 0/0/0.1
[r1-GigabitEthernet0/0/0.1]ip address 192.168.2.1 24
[r1-GigabitEthernet0/0/0.1]dhcp select global
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]arp broadcast enable //默认arp功能未开启,需要开启
[r1-GigabitEthernet0/0/0.1]q
[r1]ip pool v2
[r1-ip-pool-v2]gateway-list 192.168.2.1
[r1-ip-pool-v2]network 192.168.2.0 mask 255.255.255.0
[r1-ip-pool-v2]dns-list 8.8.8.8
测试: