VLAN间的相互通信
上图为一个简单的网络结构图,3560为cisco三层交换机,2950为cisco二层交换机,pc0,pc1属于vlan10 ip段为192.133.0.X;pc2,pc3属于vlan 20 ip段为192.134.0.X ;pc4,pc5属于vlan 30 ip段为 192.135.0.x 现想实现 vlan 10和 vlan 20可访问vlan 30但vlan 10和vlan 20之间不能互访。
实现方法:
1> 在三层交换机上设好vtp domain 为com,同时设置3560为vtp server,增加三个vlan 10,20,30,将f0/1 switchport vlan10,f0/2 switchport vlan 20,f0/3 swithcport vlan 30,设置好每个vlan 的ip ,这样三个vlan就是互通了。为了限制vlan10和vlan 20之间互访需要做如下限制
增加两条控制访问列表
2> access-list 101 deny ip 192.133.0.0 0.0.0.255 192.134.0.0 0.0.0.255
access-list 101 permit ip any any
access-list 102 deny ip 192.134.0.0 0.0.0.255 192.133.0.0 0.0.0.255
access-list 102 permit ip any any
同时在vlan 10 中设置ip access-group 101 in, vlan20中设置ip access-group 102 in
这样vlan 10和vlan20之间就不能相互访问了。
这种配置在中小型局域网中非常典型,这样划分vlan在一个中小型网络中有助于防止网络风暴,增强网络安全。下面是这个案例的典型配置:
Current configuration : 1622 bytes
version 12.2
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
hostname Switch
interface FastEthernet0/1
switchport access vlan 10
switchport mode access
interface FastEthernet0/2
switchport access vlan 20
interface FastEthernet0/3
switchport access vlan 30
interface FastEthernet0/4
interface FastEthernet0/5
interface FastEthernet0/6
interface FastEthernet0/7
interface FastEthernet0/8
interface FastEthernet0/9
interface FastEthernet0/10
interface FastEthernet0/11
interface FastEthernet0/12
interface FastEthernet0/13
interface FastEthernet0/14
interface FastEthernet0/15
interface FastEthernet0/16
interface FastEthernet0/17
interface FastEthernet0/18
interface FastEthernet0/19
interface FastEthernet0/20
interface FastEthernet0/21
interface FastEthernet0/22
interface FastEthernet0/23
interface FastEthernet0/24
interface GigabitEthernet0/1
interface GigabitEthernet0/2
interface Vlan1
no ip address
shutdown
interface Vlan10
ip address 192.133.0.10 255.255.255.0
ip access-group 101 in
interface Vlan20
ip address 192.134.0.10 255.255.255.0
ip access-group 102 in
interface Vlan30
ip address 192.135.0.10 255.255.255.0
interface Vlan100
no ip address
router rip
ip classless
access-list 101 deny ip 192.133.0.0 0.0.0.255 192.134.0.0 0.0.0.255
access-list 101 permit ip any any
access-list 102 deny ip 192.134.0.0 0.0.0.255 192.133.0.0 0.0.0.255
access-list 102 permit ip any any
line con 0
line vty 0 4
login
end
DHCP设置方法
1、设置好vlan ip地址 ip address 192.133.0.10 255.255.255.0
2、设置 dhcp pool 名字 ip dhcp pool vlan10
3、设置default router 192.133.0.10
4、设置network network 192.133.0.0 255.255.255.0
5、设置DNS-server dns-server 192.133.0.10
这样DHCP就设好了!
配置如下:
ip dhcp excluded-address 192.133.0.10
!
ip dhcp pool vlan10
network 192.133.0.0 255.255.255.0
default-router 192.133.0.10
dns-server 192.133.0.10