實驗拓撲
實驗要求
實驗規劃
實驗配置
實驗測試
實驗要求
- PC1和PC3接口都爲 Access模式,VLAN2
- PC2-PC4-PC5-PC6都爲同一個網段
- PC2可以訪問PC4/5/6
- PC4可以訪問PC5,但不能訪問PC6
- PC5不能訪問PC6
實驗規劃
- 首先我們通過DHCP自動下放IP地址,可以在路由器上配置DHCP地址池,然後做DHCP中繼
- SW1連接PC1和PC3的接口成正常的Access模式,創建並劃入VLAN2
- PC2-PC4-PC5-PC6都在同一個網段,在同一個網段的話,通常情況下屬於同一個VLAN,但是如果是同一個VLAN的話,難以實現PC4不能訪問PC6,PC5不能訪問PC6,那麼此時需要多個VLAN來達成此要求,我們此時可以將PC2劃入VLAN3,PC4劃入VLAN2,PC5劃入VLAN2,PC6劃入VLAN3
- PC2:此時需定義SW1連接PC2的接口定義爲Hybrid,Pvid改爲VLAN 3,但是對於VLAN 2&3流量不打標記 untagged vlan 2 3,通過DHCP下放IP地址
- PC4:定義SW2連接PC4的接口定義爲Hybrid,Pvid改爲vlan 2,對於VLAN 2 & 3流量不打標記 untagged vlan 2 3,而PC4手動配置IP地址,雖然爲VLAN 2,但是我們可以手動配置同VLAN 3同網段的IP地址
- PC5:定義SW3連接PC5的接口爲定義爲Hybrid,Pvid改爲vlan 2,對於VLAN 2&3 流量不打標記 untagged vlan 2 3,PC5手動配置IP地址,配置同VLAN3同網段的IP地址
- PC6:定義SW3連接PC6的接口定義爲Hybrid,Pvid爲vlan 2,但是隻對於VLAN 3的流量不打標記,untagged vlan 3,通過DHCP下IP地址
那麼此時,這樣規劃之後
根據實驗要求
- PC2-PC4-PC5-PC6處於同一個網段,達成
- PC2/4/5所在交換機接口模式都爲Hybrid且都這對於VLAN 2/3流量都不打標記,此時可以正常通信,PC 6所在交換機接口爲Hybrid,針對於VLAN 3流量不打標記,PC 2所在接口Pvid爲vlan 3,此時PC2與PC6可以正常通信,達成
- PC4可以訪問PC5,PC 4和PC 6不能通信,達成
- PC5和PC6不能通信,達成
實驗配置
R1
<Huawei>system-view
[Huawei]sysname R1
[R1]interface e0/0/0
[R1-Ethernet0/0/0]ip address 12.1.1.1 255.255.255.0
[R1-Ethernet0/0/0]quit
[R1]ip pool 1
[R1-ip-pool-1]network 172.16.1.0 mask 255.255.255.0
[R1-ip-pool-1]gateway-list 172.16.1.1
[R1-ip-pool-1]excluded-ip-address 172.16.1.2
[R1-ip-pool-1]excluded-ip-address 172.16.1.3
[R1-ip-pool-1]quit
[R1]ip pool 2
[R1-ip-pool-2]network 172.16.2.0 mask 255.255.255.0
[R1-ip-pool-2]gateway-list 172.16.2.1
[R1-ip-pool-2]excluded-ip-address 172.16.2.2
[R1-ip-pool-2]excluded-ip-address 172.16.2.3
[R1]dhcp enable
[R1]interface e0/0/0
[R1-Ethernet0/0/0]dhcp select global
[R1-Ethernet0/0/0]quit
[R1]ip route-static 0.0.0.0 0.0.0.0 12.1.1.2
SW1
<Huawei>system-view
[Huawei]sysname SW1
[SW1]interface Vlanif 1
[SW1-Vlanif1]ip address 12.1.1.2 255.255.255.0
[SW1-Vlanif1]quit
[SW1]ip route-static 0.0.0.0 0.0.0.0 12.1.1.1
[SW1]dhcp enable
[SW1]vlan 2
[SW1-vlan2]quit
[SW1]vlan 3
[SW1-vlan3]quit
[SW1]interface Vlanif 2
[SW1-Vlanif2]ip address 172.16.1.1 255.255.255.0
[SW1-Vlanif2]dhcp select relay
[SW1-Vlanif2]dhcp relay server-ip 12.1.1.1
[SW1-Vlanif2]quit
[SW1]interface Vlanif 3
[SW1-Vlanif3]ip address 172.16.2.1 255.255.255.0
[SW1-Vlanif3]dhcp select relay
[SW1-Vlanif3]dhcp relay server-ip 12.1.1.1
[SW1-Vlanif3]quit
[SW1]interface g0/0/3
[SW1-GigabitEthernet0/0/3]port link-type access
[SW1-GigabitEthernet0/0/3]port default vlan
[SW1-GigabitEthernet0/0/3]port default vlan 2
[SW1-GigabitEthernet0/0/3]quit
[SW1]interface g0/0/4
[SW1-GigabitEthernet0/0/4]port hybrid pvid vlan 3
[SW1-GigabitEthernet0/0/4]port hybrid untagged vlan 2 to 3
[SW1-GigabitEthernet0/0/4]quit
[SW1]interface g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type trunk
[SW1-GigabitEthernet0/0/2]port trunk allow-pass vlan 2 to 3
[SW1-GigabitEthernet0/0/2]quit
SW2
<Huawei>system-view
[Huawei]sysname SW2
[SW2]dhcp enable
[SW2]vlan 2
[SW2-vlan2]quit
[SW2]vlan 3
[SW2-vlan3]quit
[SW2]dhcp enable
[SW2]interface Vlanif 2
[SW2-Vlanif2]ip address 172.16.1.2 255.255.255.0
[SW2-Vlanif2]dhcp select relay
[SW2-Vlanif2]dhcp relay server-ip 12.1.1.1
[SW2-Vlanif2]quit
[SW2]interface Vlanif 3
[SW2-Vlanif3]ip address 172.16.2.2 255.255.255.0
[SW2-Vlanif3]quit
[SW2]interface g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 to 3
[SW2-GigabitEthernet0/0/1]quit
[SW2]interface g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type trunk
[SW2-GigabitEthernet0/0/2]port trunk allow-pass vlan 2 to 3
[SW2-GigabitEthernet0/0/2]quit
[SW2]interface g0/0/3
[SW2-GigabitEthernet0/0/3]port link-type access
[SW2-GigabitEthernet0/0/3]port default vlan 2
[SW2-GigabitEthernet0/0/3]quit
[SW2]interface g0/0/4
[SW2-GigabitEthernet0/0/4]port hybrid pvid vlan 2
[SW2-GigabitEthernet0/0/4]port hybrid untagged vlan 2 to 3
[SW2-GigabitEthernet0/0/4]quit
SW3
<Huawei>system-view
[Huawei]sysname SW3
[SW3]vlan 2
[SW3-vlan2]quit
[SW3]vlan
[SW3]vlan 3
[SW3-vlan3]quit
[SW3]dhcp enable
[SW3]interface Vlanif 2
[SW3-Vlanif2]ip address 172.16.1.3 255.255.255.0
[SW3-Vlanif2]dhcp select relay
[SW3-Vlanif2]dhcp relay server-ip 12.1.1.1
[SW3-Vlanif2]quit
[SW3]interface Vlanif 3
[SW3-Vlanif3]ip address 172.16.2.3 255.255.255.0
[SW3-Vlanif3]dhcp select relay
[SW3-Vlanif3]dhcp relay server-ip 12.1.1.1
[SW3-Vlanif3]quit
[SW3]interface g0/0/1
[SW3-GigabitEthernet0/0/1]port link-type trunk
[SW3-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 to 3
[SW3-GigabitEthernet0/0/1]quit
[SW3]interface g0/0/2
[SW3-GigabitEthernet0/0/2]port hybrid pvid vlan 2
[SW3-GigabitEthernet0/0/2]port hybrid untagged vlan 2 to 3
[SW3-GigabitEthernet0/0/2]quit
[SW3]interface g0/0/3
[SW3-GigabitEthernet0/0/3]port hybrid pvid vlan 3
[SW3-GigabitEthernet0/0/3]port hybrid untagged vlan 3
[SW3-GigabitEthernet0/0/3]quit
測試
1.PC1和PC3接口都爲 Access模式,VLAN2
2.PC2-PC4-PC5-PC6都爲同一個網段
3.PC2訪問PC4/5/6
4.PC4訪問PC5/6,可以與5通,不可以與6通
PC5與PC6通信