二层高级
3次课:
1 MUX VLAN
SWB交换机的配置文件: sysname SWB # vlan batch 10 20 30 40 # vlan 10 description Financial VLAN vlan 20 description Marketing VLAN vlan 30 description Client VLAN vlan 40 //在主VLAN下进行配置MUX VLAN的配置 description Principal VLAN mux-vlan //将VLAN 40设置为Principal VLAN subordinate separate 30 //将VLAN 30设置为Separate VLAN(隔离从vlan) subordinate group 10 20 //将VLAN 10与VLAN 20设置为Group VLAN(互通型vlan) # interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 20 30 40 # interface GigabitEthernet0/0/2 port link-type trunk port trunk allow-pass vlan 10 20 30 40 # interface GigabitEthernet0/0/3 port link-type access port default vlan 40 port mux-vlan enable //在接口下开启MUX VLAN功能 SWC交换机的配置文件 sysname SWC # vlan batch 10 20 30 40 # vlan 10 description Financial VLAN vlan 20 description Marketing VLAN vlan 30 description Cilent VLAN vlan 40 description Principal VLAN mux-vlan subordinate separate 30 subordinate group 10 20 # interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 20 30 40 # interface GigabitEthernet0/0/2 port link-type access port default vlan 10 port mux-vlan enable # interface GigabitEthernet0/0/3 port link-type access port default vlan 10 port mux-vlan enable # interface GigabitEthernet0/0/4 port link-type access port default vlan 20 port mux-vlan enable # interface GigabitEthernet0/0/5 port link-type access port default vlan 20 port mux-vlan enable SWD的配置 sysname SWD # vlan batch 10 20 30 40 # vlan 10 description Financial VLAN vlan 20 description Marketing vlan 30 description Client VLAN vlan 40 description Principal VLAN mux-vlan subordinate separate 30 subordinate group 10 20 # interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 20 30 40 # interface GigabitEthernet0/0/2 port link-type access port default vlan 30 port mux-vlan enable # interface GigabitEthernet0/0/3 port link-type access port default vlan 30 port mux-vlan enable
2 端口隔离:
端口隔离的配置文件 sysname SWC # vlan 10 # interface GigabitEthernet0/0/1 port link-type access port default vlan 10 # interface GigabitEthernet0/0/2 port link-type access port default vlan 10 port-isolate enable # interface GigabitEthernet0/0/3 port link-type access port default vlan 10 port-isolate enable # interface GigabitEthernet0/0/4 port link-type access port default vlan 10 port-isolate enable # interface GigabitEthernet0/0/5 port link-type access port default vlan 10 port-isolate enable # SWD的配置文件 sysname SWD # vlan 10 # interface GigabitEthernet0/0/1 port link-type access port default vlan 10 # interface GigabitEthernet0/0/2 port link-type access port default vlan 10 # interface GigabitEthernet0/0/3 port link-type access port default vlan 10 # interface GigabitEthernet0/0/4 port link-type access port default vlan 10 # interface GigabitEthernet0/0/5 port link-type access port default vlan 10 # SWB的配置文件 sysname SWB # vlan 10 # interface GigabitEthernet0/0/1 port link-type access port default vlan 10 # interface GigabitEthernet0/0/2 port link-type access port default vlan 10 # 查看SWC的端口隔离的链路接口 <SWC>display port-isolate group 1 The ports in isolate group 1: GigabitEthernet0/0/1 GigabitEthernet0/0/2 GigabitEthernet0/0/3 GigabitEthernet0/0/4 如何实现PC2在vlan 10当中 网关是192.168.1.254 PC5在vlan 20当中 网关是192.168.2.254 通过配置二层隔离三层互通模式来实现(默认情况端口隔离是该模式)PC2和PC5之间的互通 port-isolate mode all 该命令的作用就是配置端口隔离的模式为二层和三层都无法通信 PC2访问不了PC5
3 端口安全: