Vlan(Virtual Local Area Network)即虚拟局域网。VLAN可以把同一个物理网络划分为多个逻辑网段,因此,Vlan可以抑制网络风暴,增强网络的安全性。
实验拓扑图
创建VLAN
有两种方式创建vlan:
1.全局模式下使用vlan vlanid命令,如:switch(config)# vlan 10
2.在vlan database下创建vlan,如switch(vlan) vlan 20
Switch>en
Switch#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#vlan 10
Switch(config-vlan)#name Math
Switch(config-vlan)#exit
Switch(config)#exit
Switch#
%SYS-5-CONFIG_I: Configured from console by console
Switch#vlan database
% Warning: It is recommended to configure VLAN from config mode,
as VLAN database mode is being deprecated. Please consult user
documentation for configuring VTP/VLAN in config mode.
Switch(vlan)#vlan 20 name Chinese
VLAN 20 added:
Name: Chinese
Switch(vlan)#vlan 30 name Other
VLAN 30 added:
Name: Other
Switch(vlan)#
把端口划分给vlan(基于端口的vlan)
Switch(config)#interface fastethernet0/1 进入端口配置模式
Switch(config-if)#switchport mode access 配置端口为access模式
Switch(config-if)#switchport access vlan 10 把端口划分到vlan 10
Switch(config-if)#interface fa0/2
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 10
如果需要一次将多个端口划分给一个vlan使用可以用 interface range命令。
Switch(config-if)#interface range fa0/3 - 5
Switch(config-if-range)#switchport mode access
Switch(config-if-range)#switchport access vlan 20
Switch(config-if-range)#interface range fa0/6 - 7
Switch(config-if-range)#switchport mode access
Switch(config-if-range)#switchport access vlan 30
查看vlan信息
Switch#show vlan
Switch#sh vlan brief 查看vlan简明信息
Switch#show vlan id 10 查看id为10的vlan
Switch#show vlan name Other 通过vlan的名字查看vlan
删除配置
Switch(config)#interface fa0/8
Switch(config-if)#no switchport access vlan 40 把第0个模块中的第8个端口从vlan 40中删除
Switch#vlan database
% Warning: It is recommended to configure VLAN from config mode,
as VLAN database mode is being deprecated. Please consult user
documentation for configuring VTP/VLAN in config mode.
Switch(vlan)#no vlan 40 删除vlan 40
设置主机ip
注意:设置完主机ip,相同vlan可以互相访问,不同vlan不能直接访问。