VLAN配置:VLAN配置實(shí)例
【網(wǎng)訊網(wǎng)絡(luò)通信學(xué)院】(1)網(wǎng)絡(luò)基本情況
網(wǎng)絡(luò)拓?fù)浣Y(jié)構(gòu)為:中心交換機(jī)采用cisco catalyst 4006-s3,supervisor engine iii g引擎位于第1插槽,用于實(shí)現(xiàn)三層交換;1塊24口1000base-t模塊位于第2插槽,用于連接網(wǎng)絡(luò)服務(wù)器;1塊6端口1000base-x模塊位于第3插槽,用于連接6臺骨干交換機(jī)。一臺交換機(jī)采用cisco catalyst 3550-24-emi,并安裝1塊1000base-x gbic千兆模塊。一臺交換機(jī)采用cisco catalyst 3550-24-smi,也安裝1塊1000base-x gbic千兆模塊。另外四臺交換機(jī)采用cisco catalyst 2950g-24-smi,安裝1塊1000base-t gbic千兆模塊。
所有服務(wù)器劃分為一個(gè)vlan,即vlan 50。四臺catalyst 2950g-24-smi交換機(jī)也只劃分為一個(gè)vlan,分別為vlan 60、vlan 70、vlan 80和vlan 90。catalyst 3550-24-emi劃分為4個(gè)vlan,分別為vlan 10、vlan 20、vlan 30和vlan 40。catalyst 3550-24-smi劃分2個(gè)vlan,分別為vlan 60和vlan 80,與另外兩臺catalyst 2950g-24-smi交換機(jī)分別位于同一vlan。
(2)實(shí)例分析
由于所有catalyst 2950g交換機(jī)都是一個(gè)獨(dú)立的vlan,因此,必須先在這些交換機(jī)上創(chuàng)建vlan(vlan 60~vlan 90),并將所有端口都指定至該vlan。然后,再在catalyst 4006交換機(jī)相應(yīng)端口上分別創(chuàng)建vlan。catalyst 4006的1000base-x端口分別與各catalyst 2950g的1000base-x端口連接。其中,gigabitethernet3/2端口連接至1號catalyst 2950交換機(jī)(vlan 60),gigabitethernet3/3端口連接至2號catalyst 2950交換機(jī)(vlan 70),gigabitethernet3/4端口連接至3號catalyst 2950交換機(jī)(vlan 80),gigabitethernet3/5端口連接至4號catalyst 2950交換機(jī)(vlan 90),gigabitethernet3/6端口連接至6號樓交換機(jī)(vlan 80)。 內(nèi)容來自www.netdigedu.com
由于在catalyst 3550-24-emi上劃分有4個(gè)vlan(vlan 10~vlan 40),而4個(gè)vlan都需借助于一條1000base-x鏈路實(shí)現(xiàn)與catalyst 4006的gigabitethernet3/1端口連接,因此,必須在catalyst 4006與catalyst 3550-24- emi之間創(chuàng)建一個(gè)trunk。
同樣,在catalyst 3550-24-smi上劃分有2個(gè)vlan(vlan 60和vlan 80),而4個(gè)vlan都需借助于一條1000base-x鏈路實(shí)現(xiàn)與catalyst 4006的gigabitethernet3/6端口連接,因此,必須在catalyst 4006與catalyst 3550-24- emi之間創(chuàng)建一個(gè)trunk。
另外,所有服務(wù)器均連接至catalyst 4006的1000base-t模塊,并單獨(dú)成為一個(gè)vlan(vlan 90),因此,也必須為這些交換機(jī)創(chuàng)建一個(gè)vlan,并將所有端口指定至該vlan。需要注意的是,考慮到網(wǎng)絡(luò)管理的需要,也可以剩余幾個(gè)rj-45端口(如21至24端口)不指定至任何vlan,從而便于連接網(wǎng)絡(luò)管理設(shè)備。默認(rèn)狀態(tài)下,所有端口都屬于vlan1,而且也只有在vlan1中才能實(shí)現(xiàn)對網(wǎng)絡(luò)中所有設(shè)備的管理。
(3)配置清單
●cisco catalyst 4006交換機(jī)配置清單
current configuration : 5594 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service compress-config
!
hostname hsnc
!
boot system bootflash:cat4000-is-mz.121-8a.ew1.bin
no logging console
enable secret level 1 5 $1$rkqw$1hkykdn5f.ri5zxeof8yv/
!
ip subnet-zero
!
!
!
interface gigabitethernet1/1
no snmp trap link-status
!--不為supervisor engine iii g引擎中的1000base-x插槽指定vlan
interface gigabitethernet1/2
no snmp trap link-status
!
!
interface gigabitethernet2/1
switchport access vlan 50
no snmp trap link-status
!--將端口gigabitethernet2/1指定至vlan 50
!
interface gigabitethernet2/2
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/3
switchport access vlan 50 www.netdigedu.com
no snmp trap link-status
!
interface gigabitethernet2/4
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/5
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/6
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/7
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/8
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/9
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/10
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/11
switchport access vlan 50 本文來自網(wǎng)訊網(wǎng)絡(luò)通信學(xué)院
no snmp trap link-status
!
interface gigabitethernet2/12
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/13
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/14
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/15
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/16
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/17
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/18
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/19
switchport access vlan 50 本文來自網(wǎng)訊網(wǎng)絡(luò)通信學(xué)院
no snmp trap link-status
!
interface gigabitethernet2/20
switchport access vlan 50
no snmp trap link-status
!--不將gigabitethernet2/20~24指定至任何vlan
!
interface gigabitethernet3/1
switchport trunk encapsulation dot1q
??!--啟用802.1q trunk封裝協(xié)議,即在該端口創(chuàng)建trunk
switchport trunk allowed vlan 1-80
??!--允許vlan 1-90在該中繼線通訊
?。?-可以拒絕或允許某個(gè)vlan訪問該trunk
?。?-確保未被授權(quán)的vlan通過該trunk,實(shí)現(xiàn)vlan的訪問安全
switchport mode trunk
?。?-將該端口設(shè)置為trunk
description netcenter
no snmp trap link-status
!
interface gigabitethernet3/2
switchport access vlan 60
no snmp trap link-status
!--將端口gigabitethernet3/2指定至vlan 60
!
interface gigabitethernet3/3
switchport access vlan 70
no snmp trap link-status
!--將端口gigabitethernet3/3指定至vlan 70
!
interface gigabitethernet3/4
switchport access vlan 80
no snmp trap link-status
!--將端口gigabitethernet3/4指定至vlan 80
!
interface gigabitethernet3/5
switchport access vlan 90
no snmp trap link-status
!--將端口gigabitethernet3/5指定至vlan 90
!
interface gigabitethernet3/6
switchport trunk encapsulation dot1q
??!--啟用802.1q trunk封裝協(xié)議,即在該端口創(chuàng)建trunk
switchport trunk allowed vlan 1-80
??!--允許vlan 1-90在該中繼線通訊
!--可以拒絕或允許某個(gè)vlan訪問該trunk
??!--從而確保未被授權(quán)的vlan通過該trunk,實(shí)現(xiàn)vlan訪問安全
switchport mode trunk
??!--將該端口設(shè)置為trunk
description netcenter
no snmp trap link-status
!
interface vlan1
description netmanger
no ip address
!
網(wǎng)訊網(wǎng)絡(luò)通信學(xué)院
!--對vlan1進(jìn)行描述
interface vlan10
description network center
no ip address
!--對vlan2進(jìn)行描述
!
interface vlan20
description computer center
no ip address
!
interface vlan30
description network lab
no ip address
!
interface vlan40
description huaxuelou
no ip address
!
interface vlan50
description wulilou
no ip address
!
interface vlan60
description shengwulou
no ip address
!
interface vlan70
description zhongwenxi
no ip address
!
interface vlan80
description tushuguan
no ip address
!
!
line con 0
stopbits 1
line vty 0 4
password aaa
login
!
end
●cisco catalyst 3550-emi配置清單
building configuration...
current configuration : 4055 bytes