一篇实验文档掌握网工常用的VLAN以及端口类型配置
本文由乾颐堂HCIE讲师白伟鹏提供
1、 实验目的
掌握VLAN的创建方法
掌握Access、Trunk和Hybrid类型接口的配置方法
掌握基于接口划分VLAN的配置方法
2、 实验背景
公司根据业务需求,需要对其二层网络进行VLAN划分。Server地址为10.1.1.100,PC的地址分别为:PC1:10.1.1.10,PC2:10.1.1.20,PC3:10.1.1.30,其他设备类似
如实验拓扑图所示,可以在S1和S2交换机上配置基于接口划分VLAN,把业务相同的用户连接的接口划分到同一VLAN。可以使用Trunk,Access、Hybrid相关技术
1、 实验需求
1) PC1、PC2、PC5、PC6可以互访,PC3、PC4、PC7、PC8可以互访,
2) PC1、PC2、PC3、PC4可以访问Server;
3) PC5、PC6、PC7、PC8不可以访问Server;
4) PC1、PC2、PC5、PC6不能访问PC3、PC4、PC7、PC8;
2、 配置思路
1) 创建VLAN
2) 将相关接口加入相关VLAN
3) 进行测试
3、 配置步骤
步骤1 配置S1,S2和S3的设备名称,并创建相关VLAN
在SW1上执行以下操作
<Huawei>system-view //进入系统视图
[Huawei]sysname SW1 //修改设备名称为SW1
[SW1]vlan batch 10 20 100 //批量创建VLAN 10,20,100
在SW2,SW3执行同样操作
步骤2 配置交换机之间的链路
在SW1设备上执行以下操作
[SW1]interface GigabitEthernet 0/0/1 //进入接口模式
[SW1-GigabitEthernet0/0/1]port link-type hybrid //修改接口类型为Hybrid
[SW1-GigabitEthernet0/0/1]port hybrid tagged vlan 10 20 100 //配置接口允许VLAN 10、20,100通过
在SW2设备执行以下操作
[SW2]interface GigabitEthernet 0/0/1 //进入接口模式
[SW2-GigabitEthernet0/0/1]port link-type hybrid //修改接口类型为Hybrid
[SW2-GigabitEthernet0/0/1]port hybrid tagged vlan 10 20 100 //配置接口允许VLAN 10、20,100通过
[SW2-GigabitEthernet0/0/1]interface g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type trunk //修改接口类型为Trunk
[SW2-GigabitEthernet0/0/2]port trunk allow-pass vlan 10 20 10 //配置接口允许VLAN 10、20,100通过
在SW3上执行以下操作
[SW3]interface g0/0/1
[SW3-GigabitEthernet0/0/1]port link-type trunk //修改接口类型为Trunk
[SW3-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 100 //配置接口允许VLAN 10、20,100
步骤3 配置交换机接入链路
配置SW1接入链路
[SW1]port-group group-member GigabitEthernet 0/0/10 g0/0/11
[SW1-port-group]port link-type hybrid
[SW1-port-group]port hybrid untagged vlan 10 100 //配置接口允许VLAN10 100以untag方式通过
[SW1-GigabitEthernet0/0/10]port hybrid pvid vlan 10 //配置接口的缺省VLAN ID为10
[SW1]port-group group-member g0/0/20 g0/0/21
[SW1-port-group]port link-type hybrid
[SW1-port-group]port hybrid untagged vlan 20 100
[SW1-GigabitEthernet0/0/20]port hybrid pvid vlan 20
配置SW2的接入链路
[SW2]port-group group-member GigabitEthernet 0/0/10 g0/0/11
[SW2-port-group]port link-type access //配置接口的类型为Access
[SW2-port-group]port default vlan 10 //将接口加入VLAN 10
[SW2]port-group group-member GigabitEthernet 0/0/20 g0/0/21
[SW2-port-group]port link-type access
[SW2-port-group]port default vlan 20 //将接口加入VLAN 20
配置SW3的接入链路
[SW3]int GigabitEthernet 0/0/10
[SW3-GigabitEthernet0/0/10]port link-type hybrid
[SW3-GigabitEthernet0/0/10]port hybrid untagged vlan 10 20 100
[SW3-GigabitEthernet0/0/10]port hybrid pvid vlan 100
步骤4 查看配置信息
[SW1]display vlan //查看VLAN的相关信息
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:GE0/0/1(U) GE0/0/2(D) GE0/0/3(D) GE0/0/4(D)
GE0/0/5(D) GE0/0/6(D) GE0/0/7(D) GE0/0/8(D)
GE0/0/9(D) GE0/0/10(U) GE0/0/11(U) GE0/0/12(D)
GE0/0/13(D) GE0/0/14(D) GE0/0/15(D) GE0/0/16(D)
GE0/0/17(D) GE0/0/18(D) GE0/0/19(D) GE0/0/20(U)
GE0/0/21(U) GE0/0/22(D) GE0/0/23(D) GE0/0/24(D)
10 common UT:GE0/0/10(U) GE0/0/11(U)
TG:GE0/0/1(U)
20 common UT:GE0/0/20(U) GE0/0/21(U)
TG:GE0/0/1(U)
100 common UT:GE0/0/10(U) GE0/0/11(U) GE0/0/20(U) GE0/0/21(U)
TG:GE0/0/1(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
100 enable default enable disable VLAN 0100
[SW1]display port vlan active //查看VLAN中包含的接口信息
T=TAG U=UNTAG
-------------------------------------------------------------------------------
Port Link Type PVID VLAN List
-------------------------------------------------------------------------------
GE0/0/1 hybrid 1 U: 1
T: 10 20 100
GE0/0/2 hybrid 1 U: 1
GE0/0/3 hybrid 1 U: 1
GE0/0/4 hybrid 1 U: 1
GE0/0/5 hybrid 1 U: 1
GE0/0/6 hybrid 1 U: 1
GE0/0/7 hybrid 1 U: 1
GE0/0/8 hybrid 1 U: 1
GE0/0/9 hybrid 1 U: 1
GE0/0/10 hybrid 10 U: 1 10 100
GE0/0/11 hybrid 10 U: 1 10 100
GE0/0/12 hybrid 1 U: 1
GE0/0/13 hybrid 1 U: 1
GE0/0/14 hybrid 1 U: 1
GE0/0/15 hybrid 1 U: 1
GE0/0/16 hybrid 1 U: 1
GE0/0/17 hybrid 1 U: 1
GE0/0/18 hybrid 1 U: 1
GE0/0/19 hybrid 1 U: 1
GE0/0/20 hybrid 20 U: 1 20 100
GE0/0/21 hybrid 20 U: 1 20 100
GE0/0/22 hybrid 1 U: 1
GE0/0/23 hybrid 1 U: 1
GE0/0/24 hybrid 1 U: 1
<SW2>display vlan
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:GE0/0/1(U) GE0/0/2(U) GE0/0/3(D) GE0/0/4(D)
GE0/0/5(D) GE0/0/6(D) GE0/0/7(D) GE0/0/8(D)
GE0/0/9(D) GE0/0/12(D) GE0/0/13(D) GE0/0/14(D)
GE0/0/15(D) GE0/0/16(D) GE0/0/17(D) GE0/0/18(D)
GE0/0/19(D) GE0/0/22(D) GE0/0/23(D) GE0/0/24(D)
10 common UT:GE0/0/10(U) GE0/0/11(U)
TG:GE0/0/1(U) GE0/0/2(U)
20 common UT:GE0/0/20(U) GE0/0/21(U)
TG:GE0/0/1(U) GE0/0/2(U)
100 common TG:GE0/0/1(U) GE0/0/2(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
100 enable default enable disable VLAN 0100
<SW2>
<SW2>display port vlan active
T=TAG U=UNTAG
-------------------------------------------------------------------------------
Port Link Type PVID VLAN List
-------------------------------------------------------------------------------
GE0/0/1 hybrid 1 U: 1
T: 10 20 100
GE0/0/2 trunk 1 U: 1
T: 10 20 100
GE0/0/3 hybrid 1 U: 1
GE0/0/4 hybrid 1 U: 1
GE0/0/5 hybrid 1 U: 1
GE0/0/6 hybrid 1 U: 1
GE0/0/7 hybrid 1 U: 1
GE0/0/8 hybrid 1 U: 1
GE0/0/9 hybrid 1 U: 1
GE0/0/10 access 10 U: 10
GE0/0/11 access 10 U: 10
GE0/0/12 hybrid 1 U: 1
GE0/0/13 hybrid 1 U: 1
GE0/0/14 hybrid 1 U: 1
GE0/0/15 hybrid 1 U: 1
GE0/0/16 hybrid 1 U: 1
GE0/0/17 hybrid 1 U: 1
GE0/0/18 hybrid 1 U: 1
GE0/0/19 hybrid 1 U: 1
GE0/0/20 access 20 U: 20
GE0/0/21 access 20 U: 20
GE0/0/22 hybrid 1 U: 1
GE0/0/23 hybrid 1 U: 1
GE0/0/24 hybrid 1 U: 1
<SW2>
[SW3]display vlan
The total number of vlans is : 4
--------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
#: ProtocolTransparent-vlan; *: Management-vlan;
--------------------------------------------------------------------------------
VID Type Ports
--------------------------------------------------------------------------------
1 common UT:GE0/0/1(U) GE0/0/2(D) GE0/0/3(D) GE0/0/4(D)
GE0/0/5(D) GE0/0/6(D) GE0/0/7(D) GE0/0/8(D)
GE0/0/9(D) GE0/0/10(U) GE0/0/11(D) GE0/0/12(D)
GE0/0/13(D) GE0/0/14(D) GE0/0/15(D) GE0/0/16(D)
GE0/0/17(D) GE0/0/18(D) GE0/0/19(D) GE0/0/20(D)
GE0/0/21(D) GE0/0/22(D) GE0/0/23(D) GE0/0/24(D)
10 common UT:GE0/0/10(U)
TG:GE0/0/1(U)
20 common UT:GE0/0/10(U)
TG:GE0/0/1(U)
100 common UT:GE0/0/10(U)
TG:GE0/0/1(U)
VID Status Property MAC-LRN Statistics Description
--------------------------------------------------------------------------------
1 enable default enable disable VLAN 0001
10 enable default enable disable VLAN 0010
20 enable default enable disable VLAN 0020
100 enable default enable disable VLAN 0100
[SW3]display port vlan active
T=TAG U=UNTAG
-------------------------------------------------------------------------------
Port Link Type PVID VLAN List
-------------------------------------------------------------------------------
GE0/0/1 trunk 1 U: 1
T: 10 20 100
GE0/0/2 hybrid 1 U: 1
GE0/0/3 hybrid 1 U: 1
GE0/0/4 hybrid 1 U: 1
GE0/0/5 hybrid 1 U: 1
GE0/0/6 hybrid 1 U: 1
GE0/0/7 hybrid 1 U: 1
GE0/0/8 hybrid 1 U: 1
GE0/0/9 hybrid 1 U: 1
GE0/0/10 hybrid 100 U: 1 10 20 100
GE0/0/11 hybrid 1 U: 1
GE0/0/12 hybrid 1 U: 1
GE0/0/13 hybrid 1 U: 1
GE0/0/14 hybrid 1 U: 1
GE0/0/15 hybrid 1 U: 1
GE0/0/16 hybrid 1 U: 1
GE0/0/17 hybrid 1 U: 1
GE0/0/18 hybrid 1 U: 1
GE0/0/19 hybrid 1 U: 1
GE0/0/20 hybrid 1 U: 1
GE0/0/21 hybrid 1 U: 1
GE0/0/22 hybrid 1 U: 1
GE0/0/23 hybrid 1 U: 1
GE0/0/24 hybrid 1 U: 1
[SW3]
4、 验证配置结果
1) 在PC1上测试PC2,PC5,PC6,PC9可以正常通信
2) 在PC3上测试PC4,PC6,PC7,PC8,PC9可以正常通信
3) 在PC5,PC6,PC7,PC8测试到Server不能通信
4) 在PC5,PC6上测试到PC7,PC8不能通信
1、 配置参考
sysname SW1
#
vlan batch 10 20 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port hybrid tagged vlan 10 20 100
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
port hybrid pvid vlan 10
port hybrid untagged vlan 10 100
#
interface GigabitEthernet0/0/11
port hybrid pvid vlan 10
port hybrid untagged vlan 10 100
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
port hybrid pvid vlan 20
port hybrid untagged vlan 20 100
#
interface GigabitEthernet0/0/21
port hybrid pvid vlan 20
port hybrid untagged vlan 20 100
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return
<SW1>
SW2配置
sysname SW2
#
vlan batch 10 20 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port hybrid tagged vlan 10 20 100
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 10 20 100
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/11
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
port link-type access
port default vlan 20
#
interface GigabitEthernet0/0/21
port link-type access
port default vlan 20
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
Return
SW3配置
sysname SW3
#
vlan batch 10 20 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20 100
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
port hybrid pvid vlan 100
port hybrid untagged vlan 10 20 100
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return
微信:qyt3378266435
客服QQ:3378266435
提供基础课免费资料供大家学习
乾颐堂提供
思科.华为.Python学习
CCNA|CCNP|CCIE|HCIA|HCIP|HCIE
路由交换|安全|DC数据中心|无线|云计算
乾颐堂客服热线:400-618-8070
乾颐堂官网:www.qytang.com
乾颐堂网络实验室 我们为您想的更多
姓名:
Q Q:
电话:
|