找回密码
 立即注册
搜索
查看: 36|回复: 0

企业网络-戚员网络企业-网络企业有哪些

[复制链接]

6455

主题

0

回帖

1万

积分

管理员

积分
19437
发表于 2025-4-21 00:05:51 | 显示全部楼层 |阅读模式
[id_[id_15[id_[]6[]]]]]

实验要求

① 设置合理的STP优先级、边缘端口、Eth-trunk

环路会引起广播风暴,设置STP可二层防环,STP是破环协议

企业内网划分出多个不同的 vlan 。这样做能够减小广播域的大小。从而提高网络的稳定性。

③ 所有设备,在任何位置都可以远程管理

④ 出口配置NAT

[]

企业将内网(web)服务器的 80 端口进行映射使其对外网开放,从而允许外网用户进行访问。

设备选型方面,需考虑光口和电口的交换机,同时要注意对设备进行利旧。



二、技术需求

二层中,STP Eth-trunk 属于冗余技术,它能够将接入层到核心层的两条线路捆绑为一条线路。

让交换机运行快速生成树,核心交换机的优先级要调最低。

②vlan、trunk

vlan 是虚拟局域网。它可以隔离广播域,这样能提升网络的稳定性和安全性。并且,它还方便对这个网络进行管理和控制,能够满足特殊网络的访问控制要求。

一个vlan 对应一个网段 对应一个广播域

Trunk 能够提升 vlan 的功能,它允许多个 VLAN 进行通信,接入交换机和核心交换机是通过 trunk 来实现连接的。

专门单独设置一个管理VLAN,用作远程管理

③网关、SVI配置

④DHCP配置

第一种方式:DHCP是在核心交换机上做的,启用DHCP功能

若通过找 DHCP 服务器进行分配,那么就需要在核心交换机上实施 DHCP 中继。

配置DHCP地址池,网关DNS

⑤出口NAT配置

NAT 指的是网络地址翻译,它的作用是把内网私网地址转换为公网地址。在进行出口操作时,会将内网私网地址转换成公网地址。

⑥服务器端口映射

把内网中某一台服务器的某一个端口映射至公网,以便外网能够直接对某台设备和服务进行访问。

⑦ACL配置

控制部门之间的互访

[]

⑧远程管理配置

远程登录,方便运维

⑨vlan修剪配置

通过进一步缩小广播域,进一步提升网络的稳定性和安全性

trunk 只允许特定划分的 vlan 通过,并非所有 vlan 都能通过。这样就使得广播的范围变小了。

三、详细配置 STP Eth-trunk

STP Eth-trunk 设定了合理的优先级,其优先级越小就越优先,并且还设置了边缘端口。

设置边缘端口的好处:可以提高网络的收敛速度,增加稳定性

千兆口连接上行,百兆口连接下行用户

<p><pre>    <code class="prism language-python"><span class="token number">1.</span>STP
核心:sw1
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>stp root primary   <span class="token operator">//</span>成为主根桥
接入:sw2 sw3 sw4 sw5
<span class="token punctuation">[</span>sw2<span class="token punctuation">]</span>port<span class="token operator">-</span>g group<span class="token operator">-</span>member e0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">1</span> to e0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">22</span>   <span class="token operator">//</span>g是group
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>port<span class="token operator">-</span>group<span class="token punctuation">]</span>stp edged<span class="token operator">-</span>port enable
<span class="token number">2.</span>Eth<span class="token operator">-</span>trunk,将两条链路捆绑起来
sw1:
<span class="token builtin">int</span> eth<span class="token operator">-</span>trunk <span class="token number">2</span>
mode lacp<span class="token operator">-</span>static
trunkport gi <span class="token number">0</span><span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">1</span>
trunkport gi <span class="token number">0</span><span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">4</span>
<span class="token builtin">int</span> eth<span class="token operator">-</span>trunk <span class="token number">2</span>
stp cost <span class="token number">10000</span>
sw2:
interface eth<span class="token operator">-</span>trunk <span class="token number">2</span>
mode lacp<span class="token operator">-</span>static
trunkport gi <span class="token number">0</span><span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">1</span>
trunkport gi <span class="token number">0</span><span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">2</span>
<span class="token builtin">int</span> eth<span class="token operator">-</span>trunk <span class="token number">2</span>
stp cost <span class="token number">10000</span>  <span class="token operator">//</span>强制这个 stp 口的开销,这样做可以优化网络,使 STP 更稳定。若一条链路断开,stp 会重新收敛。为避免这种重新收敛的情况,将其捆绑后设定一个固定 cost。

dis eth<span class="token operator">-</span>trunk <span class="token number">2</span>
省略其他交换机的配置,都是类似的
sw3<span class="token operator">-</span><span class="token operator">-</span>sw1   eth<span class="token operator">-</span>trunk3
sw4<span class="token operator">-</span><span class="token operator">-</span>sw1   eth<span class="token operator">-</span>trunk4
sw5<span class="token operator">-</span><span class="token operator">-</span>sw1   eth<span class="token operator">-</span>trunk5
</code></pre></p>
VLAN

②vlan trunk

<p><pre>    <code class="prism language-python">接入 SW2,然后接入 SW3,接着接入 SW4,再接入 SW5。创建 vlan,把相关接口划分到 vlan 中。
<span class="token punctuation">[</span>sw2<span class="token punctuation">]</span>vlan <span class="token number">10</span>
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>vlan10<span class="token punctuation">]</span>vlan <span class="token number">20</span>
<span class="token punctuation">[</span>sw2<span class="token punctuation">]</span><span class="token builtin">int</span> eth<span class="token operator">-</span>trunk2
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>Eth<span class="token operator">-</span>Trunk2<span class="token punctuation">]</span>port link<span class="token operator">-</span><span class="token builtin">type</span> trunk
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>Eth<span class="token operator">-</span>Trunk2<span class="token punctuation">]</span>port trunk allow<span class="token operator">-</span><span class="token keyword">pass</span> vlan <span class="token builtin">all</span>   <span class="token operator">//</span><span class="token builtin">all</span>的范围就是 <span class="token number">2</span> to <span class="token number">4094</span>,因此这种也要修剪
<span class="token punctuation">[</span>sw2<span class="token punctuation">]</span><span class="token builtin">int</span> e0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">2</span>
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>Ethernet0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">2</span><span class="token punctuation">]</span>port link<span class="token operator">-</span><span class="token builtin">type</span> access
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>Ethernet0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">2</span><span class="token punctuation">]</span>port default vlan <span class="token number">10</span>
<span class="token punctuation">[</span>sw2<span class="token punctuation">]</span><span class="token builtin">int</span> e0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">3</span>
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>Ethernet0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">3</span><span class="token punctuation">]</span>port link<span class="token operator">-</span><span class="token builtin">type</span> access
<span class="token punctuation">[</span>sw2<span class="token operator">-</span>Ethernet0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">3</span><span class="token punctuation">]</span>port default vlan <span class="token number">20</span>
针对交换机下很多PC,直接按组配置
<span class="token punctuation">[</span>sw3<span class="token punctuation">]</span>vlan <span class="token number">20</span>


<span class="token punctuation">[</span>sw3<span class="token punctuation">]</span><span class="token builtin">int</span> eth<span class="token operator">-</span>trunk3
<span class="token punctuation">[</span>sw3<span class="token operator">-</span>Eth<span class="token operator">-</span>Trunk3<span class="token punctuation">]</span>port link<span class="token operator">-</span><span class="token builtin">type</span> trunk
<span class="token punctuation">[</span>sw3<span class="token operator">-</span>Eth<span class="token operator">-</span>Trunk3<span class="token punctuation">]</span>port trunk allow<span class="token operator">-</span><span class="token keyword">pass</span> vlan <span class="token builtin">all</span>
<span class="token punctuation">[</span>sw3<span class="token punctuation">]</span>port<span class="token operator">-</span>g g Ethernet <span class="token number">0</span><span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">3</span> to Ethernet <span class="token number">0</span><span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">22</span>
<span class="token punctuation">[</span>sw3<span class="token operator">-</span>port<span class="token operator">-</span>group<span class="token punctuation">]</span>port link<span class="token operator">-</span><span class="token builtin">type</span> access
<span class="token punctuation">[</span>sw3<span class="token operator">-</span>port<span class="token operator">-</span>group<span class="token punctuation">]</span>port default vlan <span class="token number">3</span> <span class="token number">0</span>
sw4 sw5 配置略
<span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span><span class="token punctuation">.</span>
核心SW1,修剪
接入交换机有的VLAN,也要在核心交换机上一并创建
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>vlan <span class="token number">10</span>
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>vlan <span class="token number">20</span>
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span><span class="token builtin">int</span> eth<span class="token operator">-</span>trunk <span class="token number">2</span>
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>Eth<span class="token operator">-</span>Trunk2<span class="token punctuation">]</span>port link<span class="token operator">-</span><span class="token builtin">type</span> trunk
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>Eth<span class="token operator">-</span>Trunk2<span class="token punctuation">]</span>port trunk allow<span class="token operator">-</span><span class="token keyword">pass</span> vlan <span class="token number">10</span> <span class="token number">20</span> <span class="token number">999</span>
这种就是VLAN修剪,原因:
如果是trunk <span class="token builtin">all</span>它的广播域会比较大,因为整个 trunk 链路都属于广播域,这会导致网络不稳定。
用户发送的广播报文带有 vlan10 的标签,这种广播会被发送到所有的 trunk 中,所以所有的交换机都会收到。即便之后其他交换机收到了,也不会将其发到 PC 上。
直接一次性按组配置,这种就全是<span class="token builtin">all</span>,后期要修剪比较好
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>vlan batch <span class="token number">10</span> <span class="token number">20</span> <span class="token number">30</span> <span class="token number">40</span> <span class="token number">200</span>
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>port<span class="token operator">-</span>g g Eth<span class="token operator">-</span>Trunk <span class="token number">2</span> to Eth<span class="token operator">-</span>Trunk <span class="token number">5</span>
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>port<span class="token operator">-</span>group<span class="token punctuation">]</span>port link <span class="token builtin">type</span> turnk
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>port<span class="token operator">-</span>group<span class="token punctuation">]</span>port turnk allow<span class="token operator">-</span><span class="token keyword">pass</span> vlan <span class="token builtin">all</span>
</code></pre></p>
网关 SVI

③网关 SVI SVI就是VLAN IF接口

<p><pre>    <code class="prism language-python">DHCP自动获取IP地址,就是通过网关来获取的
这里先配置接口
sw1<span class="token punctuation">:</span>   交换机虚拟接口
<span class="token builtin">int</span> vlanif10
ip add <span class="token number">192.168</span><span class="token number">.10</span><span class="token number">.1</span> <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
<span class="token builtin">int</span> vlanif20
ip add <span class="token number">192.168</span><span class="token number">.20</span><span class="token number">.1</span> <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
<span class="token builtin">int</span> vlanif30
ip add <span class="token number">192.168</span><span class="token number">.30</span><span class="token number">.1</span> <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
<span class="token builtin">int</span> vlanif40
ip add <span class="token number">192.168</span><span class="token number">.40</span><span class="token number">.1</span> <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
<span class="token builtin">int</span> vlanif200
ip add <span class="token number">192.168</span><span class="token number">.200</span><span class="token number">.1</span> <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
</code></pre></p>
[]

交换机接口通常情况下是不能配置 IP 地址的。因此,在这种情况下会使用 vlan if 接口来进行对接。

然后给交换机 800 配置 192.168.254.2

出口R1的ge0/0/0 配置 192.168.254.1

SW1的具体配置

<p><pre>    <code class="prism language-python">sw1:
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>vlan <span class="token number">800</span>
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span><span class="token builtin">int</span> g <span class="token number">0</span><span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">24</span>
port link<span class="token operator">-</span><span class="token builtin">type</span> access  <span class="token operator">//</span>配置成access,别配置成trunk
port default vlan <span class="token number">800</span>
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span><span class="token builtin">int</span> vlanif <span class="token number">800</span>
ip add <span class="token number">192.168</span><span class="token number">.254</span><span class="token number">.2</span> <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
</code></pre></p>
DHCP

④DHCP配置 服务器地址是静态配置

<p><pre>    <code class="prism language-python">sw1:
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>dhcp enable
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>ip pool caiwu
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>ip<span class="token operator">-</span>pool<span class="token operator">-</span>caiwu<span class="token punctuation">]</span>gateway<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">192.168</span><span class="token number">.30</span><span class="token number">.1</span>
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>ip<span class="token operator">-</span>pool<span class="token operator">-</span>caiwu<span class="token punctuation">]</span>network <span class="token number">192.168</span><span class="token number">.30</span><span class="token number">.0</span> mask <span class="token number">24</span>
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>ip<span class="token operator">-</span>pool<span class="token operator">-</span>caiwu<span class="token punctuation">]</span>dns<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">114.114</span><span class="token number">.114</span><span class="token number">.114</span> <span class="token number">8.8</span><span class="token number">.8</span><span class="token number">.8</span>
<span class="token comment">#</span>
ip pool jishu
gateway<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">192.168</span><span class="token number">.40</span><span class="token number">.1</span>
network <span class="token number">192.168</span><span class="token number">.40</span><span class="token number">.0</span> mask <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
dns<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">114.114</span><span class="token number">.144</span><span class="token number">.114</span> <span class="token number">8.8</span><span class="token number">.8</span><span class="token number">.8</span>
<span class="token comment">#</span>
ip pool xiaoshou_1
gateway<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">192.168</span><span class="token number">.10</span><span class="token number">.1</span>
network <span class="token number">192.168</span><span class="token number">.10</span><span class="token number">.0</span> mask <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
dns<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">114.114</span><span class="token number">.144</span><span class="token number">.114</span> <span class="token number">8.8</span><span class="token number">.8</span><span class="token number">.8</span>
<span class="token comment">#</span>
ip pool xiaoshou_2
gateway<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">192.168</span><span class="token number">.20</span><span class="token number">.1</span>
network <span class="token number">192.168</span><span class="token number">.20</span><span class="token number">.0</span> mask <span class="token number">255.255</span><span class="token number">.255</span><span class="token number">.0</span>
dns<span class="token operator">-</span><span class="token builtin">list</span> <span class="token number">114.114</span><span class="token number">.144</span><span class="token number">.114</span> <span class="token number">8.8</span><span class="token number">.8</span><span class="token number">.8</span>
<span class="token comment">#</span>
<span class="token comment">交换机查看用户请求报文,查看用户是否来自 VLAN 10。接着会查看路由表的 VLAN IF 10 上所配置的地址网段是否为 192.168.10.0 网段。之后会让用户到全局去获取地址池。</span>
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span><span class="token builtin">int</span> vlanif <span class="token number">10</span>
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>vlanif10<span class="token punctuation">]</span>dhcp select <span class="token keyword">global</span>
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span><span class="token builtin">int</span> vlanif <span class="token number">20</span>
<span class="token punctuation">[</span>sw1<span class="token operator">-</span>vlanif20<span class="token punctuation">]</span>dhcp select <span class="token keyword">global</span>      
<span class="token number">30</span> <span class="token number">40</span> <span class="token number">50</span> 略
</code></pre></p>
出口路由 NAT

⑤出口路由 NAT



<p><pre>    <code class="prism language-python">核心sw1上设置缺省路由 指向出口路由器
<span class="token punctuation">[</span>sw1<span class="token punctuation">]</span>ip route<span class="token operator">-</span>static <span class="token number">0.0</span><span class="token number">.0</span><span class="token number">.0</span> <span class="token number">0</span> <span class="token number">192.168</span><span class="token number">.254</span><span class="token number">.1</span>
出口路由器上设置缺省路由  指向运营商
<span class="token punctuation">[</span>R1<span class="token punctuation">]</span>ip route<span class="token operator">-</span>static <span class="token number">0.0</span><span class="token number">.0</span><span class="token number">.0</span> <span class="token number">0</span> <span class="token number">12.1</span><span class="token number">.1</span><span class="token number">.6</span>
出去后 要回来
路由器要根据路由表回去
<span class="token punctuation">[</span>R1<span class="token punctuation">]</span>ip route<span class="token operator">-</span>static <span class="token number">192.168</span><span class="token number">.0</span><span class="token number">.0</span> <span class="token number">16</span> <span class="token number">192.168</span><span class="token number">.254</span><span class="token number">.2</span>
</code></pre></p>
NAT

⑥NAT

<p><pre>    <code class="prism language-python">acl <span class="token number">2000</span>
rule <span class="token number">5</span> permit source <span class="token number">192.168</span><span class="token number">.0</span><span class="token number">.0</span> <span class="token number">0.0</span><span class="token number">.255</span><span class="token number">.255</span>
<span class="token punctuation">[</span>R1<span class="token punctuation">]</span><span class="token builtin">int</span> g0<span class="token operator">/</span><span class="token number">1</span>
<span class="token punctuation">[</span> <span class="token punctuation">]</span>nat outbound <span class="token number">2000</span>
</code></pre></p>
端口映射

⑦服务器端口映射

<p><pre>    <code class="prism language-python">R1<span class="token punctuation">:</span>
<span class="token builtin">int</span> g0<span class="token operator">/</span><span class="token number">0</span><span class="token operator">/</span><span class="token number">1</span>
nat server protocol tcp <span class="token keyword">global</span> <span class="token number">12.1</span><span class="token number">.1</span><span class="token number">.2</span> <span class="token number">80</span> inside <span class="token number">192.168</span><span class="token number">.200</span><span class="token number">.10</span> <span class="token number">80</span>
</code></pre></p>
ACL

⑧ACL配置 只有财务部可以访问财务服务器

<p><pre>    <code class="prism language-python">sw1<span class="token punctuation">:</span>
acl number <span class="token number">3000</span>
rule <span class="token number">5</span> permit ip source <span class="token number">192.168</span><span class="token number">.30</span><span class="token number">.0</span> <span class="token number">0.0</span><span class="token number">.0</span><span class="token number">.255</span> destination <span class="token number">192.168</span><span class="token number">.200</span><span class="token number">.20</span> <span class="token number">0</span>
rule <span class="token number">10</span> deny ip destination <span class="token number">192.168</span><span class="token number">.200</span><span class="token number">.20</span> <span class="token number">0</span>
<span class="token builtin">int</span> eth<span class="token operator">-</span>trunk5
traffic<span class="token operator">-</span><span class="token builtin">filter</span> outbound acl <span class="token number">3000</span>

</code></pre></p>
⑨配置

<p><pre>    <code class="prism language-python">所有设备(路由 交换机)都需如下配置
telnet server enable
aaa
local<span class="token operator">-</span>user aa privilege level <span class="token number">3</span> password cipher <span class="token number">123</span>
local<span class="token operator">-</span>user aa service<span class="token operator">-</span><span class="token builtin">type</span> telnet
user<span class="token operator">-</span>interface vty <span class="token number">0</span> <span class="token number">4</span>
authentication<span class="token operator">-</span>mode aaa
</code></pre></p>
接入交换机(二层交换机)需要配置管理地址,只有交换机有了管理地址,才能够进行后续的管理操作。

使用专门的方式来管理 vlan 999 所承载的管理流量,建议把管理 IP 地址配置在一个特定的网段内,这样就可以满足需求。

管理vlan:vlan 999

管理网段:192.168.253.0/24

<p><pre>    <code class="prism language-python">sw1:
vlan <span class="token number">999</span>
<span class="token builtin">int</span> vlanif <span class="token number">999</span>
ip add <span class="token number">192.168</span><span class="token number">.253</span><span class="token number">.1</span> <span class="token number">24</span>
sw2   
vlan <span class="token number">999</span>   <span class="token operator">//</span>创建vlan
<span class="token builtin">int</span> vlanif <span class="token number">999</span>  <span class="token operator">//</span>配置vlan 管理地址
ip add <span class="token number">192.168</span><span class="token number">.253</span><span class="token number">.2</span> <span class="token number">24</span>
sw3 的配置略,只需将其 ip 地址的最后一位进行更改;sw4 的配置略,只需将其 ip 地址的最后一位进行更改;sw5 的配置略,只需将其 ip 地址的最后一位进行更改。
下面该缺省路由的作用是管理流量回包。每个接入层交换机都需要进行配置。
因为这里管理和业务是分开的。
<span class="token punctuation">[</span>sw2<span class="token punctuation">]</span>ip route<span class="token operator">-</span>s <span class="token number">0.0</span><span class="token number">.0</span><span class="token number">.0</span> <span class="token number">0</span> <span class="token number">192.168</span><span class="token number">.253</span><span class="token number">.1</span>  <span class="token operator">//</span>sw2配置缺省路由 回到核心交换机
sw3  sw4  sw5 配置略,一模一样的
</code></pre></p>
VLAN 修剪

⑨VLAN修剪

为了能让 trunk 链路上广播报文的发送范围进一步减少,广播域进一步缩小,就在 trunk 链路上进行了 VLAN 的配置过滤。

<p><pre>    <code class="prism language-python">sw2
<span class="token builtin">int</span> eth<span class="token operator">-</span>trunk <span class="token number">2</span>
port link<span class="token operator">-</span><span class="token builtin">type</span> trunk
port trunk allow<span class="token operator">-</span><span class="token keyword">pass</span> vlan <span class="token number">10</span> <span class="token number">20</span> <span class="token number">999</span>
sw3 sw4 也是类似这样配置。修剪
sw1
<span class="token builtin">int</span> eth<span class="token operator">-</span>trunk <span class="token number">2</span>
port link<span class="token operator">-</span><span class="token builtin">type</span> trunk
port trunk allow<span class="token operator">-</span><span class="token keyword">pass</span> vlan <span class="token number">10</span> <span class="token number">20</span> <span class="token number">999</span>
</code></pre></p>
补充知识点

拓扑配置文件

附上网络配置(积分可以去淘宝搜一下CSDN):
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|手机版|小黑屋|【远见科技】 ( 京ICP备20013102号-58 )

GMT+8, 2025-5-18 14:53 , Processed in 0.146548 second(s), 20 queries .

Powered by Discuz! X3.5

© 2001-2024 Discuz! Team.

快速回复 返回顶部 返回列表