三层交换机vlan配置范例_第1页
三层交换机vlan配置范例_第2页
三层交换机vlan配置范例_第3页
三层交换机vlan配置范例_第4页
三层交换机vlan配置范例_第5页
已阅读5页,还剩16页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、这个配置没有任何问题。只要你能看明白,记住关键的命令,相信你已经对三层有更深的认识。*网络基本情况网络拓扑结构为:中心交换机采用Cisco Catalyst 4006-S3,Supervisor Engine III G引擎位于第1插槽,用于实现三层交换;1块24口1000Base-T模块位于第2插槽,用于连接网络服务器;1块6端口1000Base-X模块位于第3插槽,用于连接6台骨干交换机。一台交换机采用Cisco Catalyst 3550-24-EMI,并安装1块1000Base-X GBIC千兆模块。一台交换机采用CiscoCatalyst 3550-24-SMI,也安装1块1000B

2、ase-X GBIC千兆模块。另外四台交换机采用Cisco Catalyst 2950G-24-SMI,安装1块1000Base-T GBIC千兆模块。所有服务器划分为一个VLAN,即VLAN 50。四台Catalyst 2950G-24-SMI交换机也只划分为一个VLAN,分别为VLAN 60、VLAN 70、VLAN 80和VLAN 90。Catalyst 3550-24-EMI划分为4个VLAN,分别为VLAN 10、VLAN 20、VLAN 30和VLAN 40。Catalyst 3550-24-SMI划分2个VLAN,分别为VLAN 60和VLAN 80,与另外两台Catalyst

3、2950G-24-SMI交换机分别位于同一VLAN。*实例分析*由于所有Catalyst 2950G交换机都是一个独立的VLAN,因此,必须先在这些交换机上创建VLAN(VLAN 60VLAN 90,并将所有端口都指定至该VLAN。然后,再在Catalyst 4006交换机相应端口上分别创建VLAN。Catalyst 4006的1000Base-X端口分别与各Catalyst 2950G的1000Base-X端口连接。其中,GigabitEthernet3/2端口连接至1号Catalyst 2950交换机(VLAN 60,GigabitEthernet3/3端口连接至2号Catalyst 29

4、50交换机(VLAN 70,GigabitEthernet3/4端口连接至3号Catalyst 2950交换机(VLAN 80,GigabitEthernet3/5端口连接至4号Catalyst 2950交换机(VLAN 90, GigabitEthernet3/6端口连接至6号楼交换机(VLAN 80。由于在Catalyst 3550-24-EMI上划分有4个VLAN(VLAN 10VLAN 40,而4个VLAN都需借助于一条1000Base-X链路实现与Catalyst 4006的GigabitEthernet3/1端口连接,因此,必须在Catalyst 4006与Catalyst 355

5、0-24- EMI之间创建一个Trunk。同样,在Catalyst 3550-24-SMI上划分有2个VLAN(VLAN 60和VLAN 80,而4个VLAN都需借助于一条1000Base-X链路实现与Catalyst 4006的GigabitEthernet3/6端口连接,因此,必须在Catalyst 4006与Catalyst 3550-24- EMI之间创建一个Trunk。另外,所有服务器均连接至Catalyst 4006的1000Base-T模块,并单独成为一个VLAN(VLAN 90,因此,也必须为这些交换机创建一个VLAN,并将所有端口指定至该VLAN。需要注意的是,考虑到网络管理

6、的需要,也可以剩余几个RJ-45端口(如21至24端口不指定至任何VLAN,从而便于连接网络管理设备。默认状态下,所有端口都属于VLAN1,而且也只有在VLAN1中才能实现对网络中所有设备的管理。*配置清单*Cisco Catalyst 4006交换机配置清单Current configuration : 5594 bytes!version 12.1no service padservice timestamps debug uptimeservice timestamps log uptimeno service password-encryptionservice compress-co

7、nfig!hostname hsnc!no logging consoleenable secret level 1 5 $1$rkQW$1HKyKdN5f.Ri5zxeoF8Yv/!ip subnet-zero!interface GigabitEthernet1/1no snmp trap link-status!-不为Supervisor Engine III G引擎中的1000Base-X插槽指定VLAN interface GigabitEthernet1/2no snmp trap link-status!interface GigabitEthernet2/1switchport

8、 access vlan 50no snmp trap link-status!-将端口GigabitEthernet2/1指定至VLAN 50!interface GigabitEthernet2/2switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/3switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/4switchport access vlan 50no snmp trap link-

9、status!interface GigabitEthernet2/5switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/6switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/7switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/8switchport access vlan 50!inter

10、face GigabitEthernet2/9 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/10 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/11 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/12 switchport access vlan 50no snmp tra

11、p link-status!interface GigabitEthernet2/13 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/14 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/15 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/16 switchport acces

12、s vlan 50no snmp trap link-status!interface GigabitEthernet2/17 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/18 switchport access vlan 50no snmp trap link-status!interface GigabitEthernet2/19 switchport access vlan 50!interface GigabitEthernet2/20switchport access vla

13、n 50no snmp trap link-status!-不将GigabitEthernet2/2024指定至任何VLAN!interface GigabitEthernet3/1switchport trunk encapsulation dot1q!-启用802.1Q Trunk封装协议,即在该端口创建Trunk switchport trunk allowed vlan 1-80!-允许vlan 1-90在该中继线通讯!-可以拒绝或允许某个VLAN访问该Trunk!-确保未被授权的VLAN通过该Trunk,实现VLAN的访问安全switchport mode trunk!-将该端口设置

14、为Trunkdescription netcenterno snmp trap link-status!interface GigabitEthernet3/2switchport access vlan 60no snmp trap link-status!-将端口GigabitEthernet3/2指定至VLAN 60!interface GigabitEthernet3/3switchport access vlan 70no snmp trap link-status!-将端口GigabitEthernet3/3指定至VLAN 70!interface GigabitEthernet3

15、/4switchport access vlan 80no snmp trap link-status!-将端口GigabitEthernet3/4指定至VLAN 80!interface GigabitEthernet3/5switchport access vlan 90no snmp trap link-status!-将端口GigabitEthernet3/5指定至VLAN 90!interface GigabitEthernet3/6switchport trunk encapsulation dot1q!-启用802.1Q Trunk封装协议,即在该端口创建Trunk switch

16、port trunk allowed vlan 1-80!-允许vlan 1-90在该中继线通讯!-可以拒绝或允许某个VLAN访问该Trunk!-从而确保未被授权的VLAN通过该Trunk,实现VLAN访问安全switchport mode trunk!-将该端口设置为Trunkdescription netcenterno snmp trap link-status!interface Vlan1description netmangerno ip address!-对VLAN1进行描述interface Vlan10description network centerno ip addre

17、ss!-对VLAN2进行描述!interface Vlan20description computer centerno ip address!interface Vlan30description network labno ip address!interface Vlan40description huaxuelouno ip address!interface Vlan50description wulilouno ip address!interface Vlan60description shengwulouno ip address!interface Vlan70descrip

18、tion zhongwenxino ip address!interface Vlan80description tushuguanno ip address!line con 0stopbits 1line vty 0 4password aaalogin!endCisco Catalyst 3550-EMI配置清单Building configuration.Current configuration : 4055 bytes!version 12.1no service padservice timestamps debug uptimeservice timestamps log up

19、timeno service password-encryption!hostname office!enable secret 5 $1$p0fU$J eyPOM0RuL.Fqfe71efHF1 !ip subnet-zero!spanning-tree extend system-id!interface FastEthernet0/1switchport access vlan 10!-将端口FastEthernet0/1指定至VLAN 10no ip address!interface FastEthernet0/2switchport access vlan 10no ip addr

20、ess!interface FastEthernet0/3switchport access vlan 10no ip addressinterface FastEthernet0/4switchport access vlan 10no ip address!interface FastEthernet0/5switchport access vlan 10no ip address!interface FastEthernet0/6switchport access vlan 20no ip address!-将端口FastEthernet0/6指定至VLAN 20 !interface

21、FastEthernet0/7switchport access vlan 20no ip address!interface FastEthernet0/8switchport access vlan 20no ip address!interface FastEthernet0/9switchport access vlan 20no ip address!interface FastEthernet0/10switchport access vlan 20no ip address!interface FastEthernet0/11switchport access vlan 30no

22、 ip address!-将端口FastEthernet0/6指定至VLAN 30 !interface FastEthernet0/12switchport access vlan 30no ip address!interface FastEthernet0/13switchport access vlan 30no ip address!interface FastEthernet0/14switchport access vlan 30no ip address!interface FastEthernet0/15switchport access vlan 30no ip addre

23、ss!interface FastEthernet0/16switchport access vlan 30no ip address!interface FastEthernet0/17switchport access vlan 30no ip address!interface FastEthernet0/18switchport access vlan 30no ip address!interface FastEthernet0/19switchport access vlan 40no ip address!-将端口FastEthernet0/6指定至VLAN 40 !interf

24、ace FastEthernet0/20switchport access vlan 40no ip address!interface FastEthernet0/21switchport access vlan 40no ip address!interface FastEthernet0/22switchport access vlan 30no ip address!interface FastEthernet0/23switchport access vlan 40no ip address!interface FastEthernet0/24switchport access vl

25、an 40no ip address!interface GigabitEthernet0/1switchport trunk encapsulation dot1q!-启用802.1Q Trunk封装协议,即在该端口创建Trunk switchport trunk allowed vlan 1-80!-允许vlan 1-80在该中继线通讯switchport mode trunk!-将该端口设置为Trunkno ip address!interface GigabitEthernet0/2no ip address!interface Vlan1!-LAN1指定IP地址no ip route

26、-cacheno ip mroute-cache!ip classlessip http server!line con 0line vty 0 4password aaaloginline vty 5 15login!endCisco Catalyst 3550-SMI配置清单Building configuration.Current configuration : 4055 bytes!version 12.1no service padservice timestamps debug uptimeservice timestamps log uptimeno service passw

27、ord-encryption!hostname office! enable secret 5 $1$p0fU$JeyPOM0RuL.Fqfe71efHF1 ! ip subnet-zero ! ! spanning-tree extend system-id ! ! ! interface FastEthernet0/1 switchport access vlan 60 !-将端口 FastEthernet0/1 指定至 VLAN 60 no ip address ! interface FastEthernet0/2 switchport access vlan 60 no ip add

28、ress ! interface FastEthernet0/3 switchport access vlan 60 no ip address ! interface FastEthernet0/4 switchport access vlan 60 no ip address ! interface FastEthernet0/5 switchport access vlan 60 no ip address ! interface FastEthernet0/6 switchport access vlan 20 no ip address !-将端口 FastEthernet0/6 指定至 VLAN 20 ! interface FastEthernet0/7 switchport access vlan 20 no ip

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

最新文档

评论

0/150

提交评论