一 組網(wǎng)需求:
1.SwitchA與SwitchB用trunk互連,相同VLAN的PC之間可以互訪(fǎng),不同VLAN的PC之間禁止互訪(fǎng);
2.PC1與PC2之間在不同VLAN,通過(guò)設置上層三層交換機SwitchB的VLAN接口10的IP地址為10.1.1.254/24,VLAN接口20的IP地址為20.1.1.254/24可以實(shí)現VLAN間的互訪(fǎng)。
二 組網(wǎng)圖:
1.VLAN內互訪(fǎng),VLAN間禁訪(fǎng)
1 實(shí)現VLAN內互訪(fǎng)VLAN間禁訪(fǎng)配置過(guò)程
SwitchA相關(guān)配置:
1.創(chuàng )建(進(jìn)入)VLAN10,將E0/1加入到VLAN10
[SwitchA]vlan 10
[SwitchA-vlan10]port Ethernet 0/1
2.創(chuàng )建(進(jìn)入)VLAN20,將E0/2加入到VLAN20
[SwitchA]vlan 20
[SwitchA-vlan20]port Ethernet 0/2
3.將端口G1/1配置為T(mén)runk端口,并允許VLAN10和VLAN20通過(guò)
[SwitchA]interface GigabitEthernet 1/1
[SwitchA-GigabitEthernet1/1]port link-type trunk
[SwitchA-GigabitEthernet1/1]port trunk permit vlan 10 20
SwitchB相關(guān)配置:
1.創(chuàng )建(進(jìn)入)VLAN10,將E0/10加入到VLAN10
[SwitchB]vlan 10
[SwitchB-vlan10]port Ethernet 0/10
2.創(chuàng )建(進(jìn)入)VLAN20,將E0/20加入到VLAN20
[SwitchB]vlan 20
[SwitchB-vlan20]port Ethernet 0/20
3.將端口G1/1配置為T(mén)runk端口,并允許VLAN10和VLAN20通過(guò)
[SwitchB]interface GigabitEthernet 1/1
[SwitchB-GigabitEthernet1/1]port link-type trunk
[SwitchB-GigabitEthernet1/1]port trunk permit vlan 10 20
2.通過(guò)三層交換機實(shí)現VLAN間互訪(fǎng)
2 通過(guò)三層交換機實(shí)現VLAN間互訪(fǎng)的配置
SwitchA相關(guān)配置:
1.創(chuàng )建(進(jìn)入)VLAN10,將E0/1加入到VLAN10
[SwitchA]vlan 10
[SwitchA-vlan10]port Ethernet 0/1
2.創(chuàng )建(進(jìn)入)VLAN20,將E0/2加入到VLAN20
[SwitchA]vlan 20
[SwitchA-vlan20]port Ethernet 0/2
3.將端口G1/1配置為T(mén)runk端口,并允許VLAN10和VLAN20通過(guò)
[SwitchA]interface GigabitEthernet 1/1
[SwitchA-GigabitEthernet1/1]port link-type trunk
[SwitchA-GigabitEthernet1/1]port trunk permit vlan 10 20
SwitchB相關(guān)配置:
1.創(chuàng )建VLAN10
[SwitchB]vlan 10
2.設置VLAN10的虛接口地址
[SwitchB]interface vlan 10
[SwitchB-int-vlan10]ip address 10.1.1.254 255.255.255.0
3.創(chuàng )建VLAN20
[SwitchB]vlan 20
4.設置VLAN20的虛接口地址
[SwitchB]interface vlan 20
[SwitchB-int-vlan20]ip address 20.1.1.254 255.255.255.0
5.將端口G1/1配置為T(mén)runk端口,并允許VLAN10和VLAN20通過(guò)
[SwitchA]interface GigabitEthernet 1/1
[SwitchA-GigabitEthernet1/1]port link-type trunk
[SwitchA-GigabitEthernet1/1]port trunk permit vlan 10 20