虚拟局域网(VLAN)
1.需求:
IP:192.47.10.0/24
pc1-pc2为财务部划分vlan10 pc3-pc4为市场部划分vlan20
内部vlan可以互相访问但不能跨vlan访问
拓扑图:
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname SW1
[SW1]
[SW1]vlan batch 10 20 # 批量创建vlan10和vlan20
Info: This operation may take a few seconds. Please wait for a moment...done.
# [SW1]vlan batch 10 to 20 批量创建vlan10到20个
[SW1-GigabitEthernet0/0/1]port link-type access # 设置链路类型
[SW1-GigabitEthernet0/0/1]port default vlan 10 # 设置端口默认为vlan10
[SW1-GigabitEthernet0/0/1]quit
[SW1]
[SW1]interface GigabitEthernet 0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 10
[SW1-GigabitEthernet0/0/2]quit
[SW1]
[SW1]port-group group-member g0/0/3 g0/0/4
# [SW1]port-group group-member g0/0/3 to g0/0/10 设置g3到4接口
[SW1-port-group]port link-type access
[SW1-GigabitEthernet0/0/3]port link-type access
[SW1-GigabitEthernet0/0/4]port link-type access
[SW1-port-group]
[SW1-port-group]port default vlan 20
[SW1-GigabitEthernet0/0/3]port default vlan 20
[SW1-GigabitEthernet0/0/4]port default vlan 20
[SW1-port-group]quit
[SW1]
[SW1]display port vlan active # 查看接口配置vlan情况
T=TAG U=UNTAG
-------------------------------------------------------------------------------
Port Link Type PVID VLAN List
-------------------------------------------------------------------------------
GE0/0/1 access 10 U: 10
GE0/0/2 access 10 U: 10
GE0/0/3 access 20 U: 20
GE0/0/4 access 20 U: 20
2.需求:
在上述基础上进行修改
pc3和pc4为20.0网段
新增两台服务器server1为vlan10---server2为vlan20
使得pc1-pc2能够访问server1服务器
pc3-pc4能够访问server2服务器
拓扑图:
<Huawei>system-view
[Huawei]sysname SW2
[SW2]
[SW2]vlan batch 10 20
[SW2]interface GigabitEthernet 0/0/2
[SW2-GigabitEthernet0/0/2]port link-type access
[SW2-GigabitEthernet0/0/2]port default vlan 10
[SW2-GigabitEthernet0/0/2]quit
[SW2]
[SW2]interface GigabitEthernet 0/0/3
[SW2-GigabitEthernet0/0/3]port link-type access
[SW2-GigabitEthernet0/0/3]port default vlan 20
[SW2-GigabitEthernet0/0/3]quit
[SW2]
SW1放行vlan:
[SW1]interface GigabitEthernet 0/0/5
[SW1-GigabitEthernet0/0/5]port link-type trunk
[SW1-GigabitEthernet0/0/5]port trunk allow-pass vlan all # all放行所有也可以指定
[SW1-GigabitEthernet0/0/5]quit
[SW1]
[SW1]display port vlan active
T=TAG U=UNTAG
-------------------------------------------------------------------------------
Port Link Type PVID VLAN List
-------------------------------------------------------------------------------
GE0/0/1 access 10 U: 10
GE0/0/2 access 10 U: 10
GE0/0/3 access 20 U: 20
GE0/0/4 access 20 U: 20
GE0/0/5 trunk 1 U: 1
T: 10 20
GE0/0/6 hybrid 1 U: 1
SW2接受vlan:
[SW2]
[SW2]interface GigabitEthernet 0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[SW2-GigabitEthernet0/0/1]quit
[SW2]
[SW2]display port vlan active
T=TAG U=UNTAG
-------------------------------------------------------------------------------
Port Link Type PVID VLAN List
-------------------------------------------------------------------------------
GE0/0/1 trunk 1 U: 1
T: 10 20
GE0/0/2 access 10 U: 10
GE0/0/3 access 20 U: 20
GE0/0/4 hybrid 1 U: 1
标签:vlan,ensp,VLAN,GigabitEthernet0,华为,SW1,20,SW2,port
From: https://blog.51cto.com/lyx888/6535230