1、三层交换机A配置了vlan1(10.10.10.1)、vlan10(192.168.0.254)、vlan70(192.168.7.254)等;
2、通过trunk口与二层交换机B连接,二层交换机中设置了管理vlan1的ip地址(10.10.10.2),划分了vlan70(1-7口),8口为trunk口;
3、当前电脑连接在二层交换机B中,接在5口,地址为192.168.7.100,当前电脑能上网,能ping通10.10.10.1,但不能ping通10.10.10.2。
二层交换机如下配置
#
version 7.1.070, Release 6113
#
sysname H3C
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
lldp global enable
#
password-recovery enable
#
vlan 1
#
vlan 10
#
stp global enable
#
interface NULL0
#
interface Vlan-interface1
ip address 10.10.10.2 255.255.255.0
#
interface Vlan-interface70
#
interface Ethernet1/0/1
port access vlan 70
#
interface Ethernet1/0/2
port access vlan 70
#
interface Ethernet1/0/3
port access vlan 70
#
interface Ethernet1/0/4
port access vlan 70
#
interface GigabitEthernet1/0/5
port access vlan 70
#
interface GigabitEthernet1/0/6
port access vlan 70
#
interface GigabitEthernet1/0/7
port access vlan 70
#
interface GigabitEthernet1/0/8
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/9
#
interface GigabitEthernet1/0/10
#
scheduler logfile size 16
#
line class aux
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line vty 0
authentication-mode none
user-role network-operator
#
line vty 1 63
user-role network-operator
#
radius scheme system
user-name-format without-domain
#
domain system
#
domain default enable system
#
user-group system
#
local-user huawei class manage
password hash $h$6$VcxpyybHnIhJ+hTS$B0BzC5HTAzBWXAh7JdgLj50l2ckJoHF4k1Vu56fogBO2cJMaQ9JSGExF0kWUZ3Uau0lzzE49TNDxm7Ud8XJFhw==
service-type telnet
authorization-attribute user-role network-operator
#
return
三层交换机主要配置如下:
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
lldp global enable
#
password-recovery enable
pex working-mode switch slot 1
#
vlan 1
#
vlan 10
#
vlan 20
#
vlan 30
#
vlan 50
#
vlan 60
#
vlan 70
#
vlan 80
#
stp global enable
#
interface NULL0
#
interface Vlan-interface1
ip address 10.10.10.1 255.255.255.0
#
interface Vlan-interface10
ip address 192.168.0.254 255.255.255.0
#
interface Vlan-interface50
ip address 192.168.5.254 255.255.255.0
#
interface Vlan-interface60
ip address 192.168.6.254 255.255.255.0
#
interface Vlan-interface70
ip address 192.168.7.254 255.255.255.0
#
interface Vlan-interface80
ip address 192.168.8.254 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/2
port link-mode bridge
port access vlan 60
#
interface GigabitEthernet1/0/3
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/4
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/5
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/6
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/7
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/8
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/9
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/10
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/11
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/12
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/13
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/14
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/15
port link-mode bridge
port access vlan 60
#
interface GigabitEthernet1/0/16
port link-mode bridge
port access vlan 60
#
interface GigabitEthernet1/0/17
port link-mode bridge
port access vlan 70
#
interface GigabitEthernet1/0/18
port link-mode bridge
port access vlan 10
#
interface GigabitEthernet1/0/19
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/20
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/21
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/22
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/23
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/24
port link-mode bridge
port link-type trunk
port trunk permit vlan all
#
scheduler logfile size 16
#
line class aux
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role network-operator
#
ip route-static 0.0.0.0 0 xx.xx.xx.xx
#
snmp-agent
snmp-agent local-engineid 800063A28084D93116A3F400000001
snmp-agent community read private
snmp-agent community read public
snmp-agent sys-info version all
#
radius scheme system
user-name-format without-domain
#
domain system
#
domain default enable system
#
user-group system
#
local-user anser class manage
password hash lklalOPs1Om+kCfcIEaeakW/$Sk8z
+vj3jkWeMR6U17aNVxNYjholDmcjesasdjflkajslkjaskfjklsadf
tfbWPBaMzmYGRri4ptiR1Q==
service-type telnet http https
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
ip http enable
ip https enable
#
return
(0)
最佳答案
PC的网关在三层交换机上,pc ping 10.10.10.1时,实际上是先从vlan 70到三层交换机上,由于10.10.10.1是设备上本身的地址,所以可以ping通;
而PC ping 10.10.10.2时,报文也是要先到三层交换机上,建议:
1、先看看三层交换机上有没有10.10.10.2的arp,应该是有的,因为是直连;
2、看看二层交换机上有没有到PC网段的路由,即二层交换机回复的ping request报文得有回程路由,看配置是没有的,建议配一条静态。(但实际组网中管理网和PC互通没有意义)
(0)
您好,请知:
vlan 1不通,以下是排查要点,请参考:
1、检查vlan 1是否有在物理端口透传。
2、其次在交换机上配置默认路由指向到上行设备的vlan 1
3、确保上行设备有将vlan 1在路由内进行发布。
(1)
1、你说的二层交换机,其实也是一个三层交换机
2、你在“二层交换机”上,缺少一个默认路由:
ip route-static 0.0.0.0 0 10.10.10.1
因为就象二楼说的一样,“而PC ping 10.10.10.2时,报文也是要先到三层交换机上“,然后再到10.10.10.2上,由于你没有配路由,所以数据找不到路由回来。
(1)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
另外,网络设备方面我是二把刀,求问那里能找到组建管理网的资料或案例