我有一台华三的ER8300G2和一台S5120V2交换机 需要划3个VLAN 相互之间不能互相访问 但是均可上网 请问如何配置 谢谢
(0)
最佳答案
如果是同子网下不能互访,跨子网也不不能互访。
交换机上做二层 起3个vlan 路由器做网关
1.在交换机配置vlan、配置2层隔离
2.在路由器配置acl 应用在网关下面。
如果是同子网下可以互访,跨子网不能互访
1.在交换机配置vlan 不做2层隔离
2.直接在路由器上配置acl 应用在网关下面
(0)
1、网络都放在路由器上
2、互联交换机配置vlan,互联口配置trunk
3、路由器配置vlan间隔离就行了
(0)
这个是交换机的配置文件 麻烦帮我看看 谢谢
我在路由器上已经做好啦 交换机上也划分好啦VLAN 也对应的把端口划进VLAN啦 那个24口设置成trunk口 在24口上我这样设置的port hybrid vlan 10 20 30 untagged 现在是获取不到路由器分配的地址
[H3C]dis cu # version 7.1.070, Release 6126P20 # sysname H3C # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # lldp global enable # password-recovery enable # vlan 1 # vlan 10 # vlan 20 # vlan 30 # vlan 40 # vlan 50 # stp global enable # interface NULL0 # interface GigabitEthernet1/0/1 port access vlan 10 # interface GigabitEthernet1/0/2 port access vlan 10 # interface GigabitEthernet1/0/3 port access vlan 10 # interface GigabitEthernet1/0/4 port access vlan 10 # interface GigabitEthernet1/0/5 port access vlan 20 # interface GigabitEthernet1/0/6 port access vlan 20 # interface GigabitEthernet1/0/7 port access vlan 20 # interface GigabitEthernet1/0/8 port access vlan 20 # interface GigabitEthernet1/0/9 port access vlan 30 # interface GigabitEthernet1/0/10 port access vlan 30 # interface GigabitEthernet1/0/11 port access vlan 30 # interface GigabitEthernet1/0/12 port access vlan 30 # interface GigabitEthernet1/0/13 port access vlan 30 # interface GigabitEthernet1/0/14 port access vlan 30 # interface GigabitEthernet1/0/15 port access vlan 30 # interface GigabitEthernet1/0/16 port access vlan 40 # interface GigabitEthernet1/0/17 port access vlan 40 # interface GigabitEthernet1/0/18 port access vlan 40 # interface GigabitEthernet1/0/19 port access vlan 40 # interface GigabitEthernet1/0/20 port access vlan 50 # interface GigabitEthernet1/0/21 port access vlan 50 # interface GigabitEthernet1/0/22 port access vlan 50 # interface GigabitEthernet1/0/23 port access vlan 50 # interface GigabitEthernet1/0/24 port link-type trunk port trunk permit vlan 1 port trunk pvid vlan 50 # interface GigabitEthernet1/0/25 # interface GigabitEthernet1/0/26 # interface GigabitEthernet1/0/27 # interface GigabitEthernet1/0/28 # scheduler logfile size 16 # line class aux user-role network-admin # line class vty user-role network-operator # line aux 0 user-role network-admin # line vty 0 63 user-role network-operator # radius scheme system user-name-format without-domain # domain system # domain default enable system # role name level-0 description Predefined level-0 role # role name level-1 description Predefined level-1 role # role name level-2 description Predefined level-2 role # role name level-3 description Predefined level-3 role # role name level-4 description Predefined level-4 role # role name level-5 description Predefined level-5 role # role name level-6 description Predefined level-6 role # role name level-7 description Predefined level-7 role # role name level-8 description Predefined level-8 role # role name level-9 description Predefined level-9 role # role name level-10 description Predefined level-10 role # role name level-11 description Predefined level-11 role # role name level-12 description Predefined level-12 role # role name level-13 description Predefined level-13 role # role name level-14 description Predefined level-14 role # user-group system # return [H3C] [H3C] [H3C] [H3C] [H3C] [H3C]%Sep 12 04:10:35:390 2015 H3C IFNET/3/PHY_UPDOWN: Physical state on the int erface GigabitEthernet1/0/2 changed to up. %Sep 12 04:10:35:391 2015 H3C IFNET/5/LINK_UPDOWN: Line protocol state on the in terface GigabitEthernet1/0/2 changed to up. %Sep 12 04:10:35:460 2015 H3C LLDP/6/LLDP_CREATE_NEIGHBOR: Nearest bridge agent neighbor created on port GigabitEthernet1/0/2 (IfIndex 2), neighbor's chassis ID is 28d2-4466-febd, port ID is 28d2-4466-febd. %Sep 12 04:10:56:679 2015 H3C LLDP/6/LLDP_DELETE_NEIGHBOR: Nearest bridge agent neighbor deleted on port GigabitEthernet1/0/2 (IfIndex 2), neighbor's chassis ID is 28d2-4466-febd, port ID is 28d2-4466-febd. %Sep 12 04:10:56:813 2015 H3C IFNET/3/PHY_UPDOWN: Physical state on the interfac e GigabitEthernet1/0/2 changed to down. %Sep 12 04:10:56:818 2015 H3C IFNET/5/LINK_UPDOWN: Line protocol state on the in terface GigabitEthernet1/0/2 changed to down. %Sep 12 04:11:01:142 2015 H3C IFNET/3/PHY_UPDOWN: Physical state on the interfac e GigabitEthernet1/0/2 changed to up. %Sep 12 04:11:01:146 2015 H3C IFNET/5/LINK_UPDOWN: Line protocol state on the in terface GigabitEthernet1/0/2 changed to up. %Sep 12 04:11:06:418 2015 H3C LLDP/6/LLDP_CREATE_NEIGHBOR: Nearest bridge agent neighbor created on port GigabitEthernet1/0/2 (IfIndex 2), neighbor's chassis ID is 28d2-4466-febd, port ID is 28d2-4466-febd. %Sep 12 04:11:31:846 2015 H3C STP/6/STP_DETECTED_TC: Instance 0's port GigabitEt hernet1/0/2 detected a topology change. [H3C] [H3C]%Sep 12 04:12:39:076 2015 H3C IFNET/3/PHY_UPDOWN: Physical state on the int erface GigabitEthernet1/0/2 changed to down. %Sep 12 04:12:39:087 2015 H3C IFNET/5/LINK_UPDOWN: Line protocol state on the in terface GigabitEthernet1/0/2 changed to down. Inactive timeout reached, logging out. ****************************************************************************** * Copyright (c) 2004-2018 New H3C Technologies Co., Ltd. All rights reserved.* * Without the owner's prior written consent, * * no decompiling or reverse-engineering shall be allowed. * ****************************************************************************** Line aux0 is available. Press ENTER to get started. <H3C>%Sep 12 04:22:13:752 2015 H3C SHELL/5/SHELL_LOGIN: TTY logged in from aux0. <H3C>sys System View: return to User View with Ctrl+Z. [H3C]vlan 10 [H3C-vlan10]port gig 1/0/1 [H3C-vlan10]port gig 1/0/2 [H3C-vlan10]port gig 1/0/3 [H3C-vlan10]port gig 1/0/4 [H3C-vlan10]qu [H3C]vlan 20 [H3C-vlan20]port gig 1/0/5 [H3C-vlan20]port gig 1/0/6 [H3C-vlan20]port gig 1/0/7 [H3C-vlan20]port gig 1/0/8 [H3C-vlan20]qu [H3C]vlan 30 [H3C-vlan30]port gig 1/0/9 [H3C-vlan30]port gig 1/0/10 [H3C-vlan30]port gig 1/0/11 [H3C-vlan30]port gig 1/0/12 [H3C-vlan30]port gig 1/0/13 [H3C-vlan30]port gig 1/0/14 [H3C-vlan30]port gig 1/0/15 [H3C-vlan30]qu [H3C]vlan 40 [H3C-vlan40]port gig 1/0/16 [H3C-vlan40]port gig 1/0/17 [H3C-vlan40]port gig 1/0/18 [H3C-vlan40]port gig 1/0/19 [H3C-vlan40]qu [H3C]vlan 50 [H3C-vlan50]port gig 1/0/20 [H3C-vlan50]port gig 1/0/21 [H3C-vlan50]port gig 1/0/22 [H3C-vlan50]port gig 1/0/23 [H3C-vlan50]qu [H3C]int gig 1/0/24 [H3C-GigabitEthernet1/0/24]port link [H3C-GigabitEthernet1/0/24]port link- [H3C-GigabitEthernet1/0/24]port link-aggregation [H3C-GigabitEthernet1/0/24]port link-type tr [H3C-GigabitEthernet1/0/24]port link-type trunk [H3C-GigabitEthernet1/0/24]port tr [H3C-GigabitEthernet1/0/24]port trunk pe [H3C-GigabitEthernet1/0/24]port trunk permit vlan all [H3C-GigabitEthernet1/0/24]qu [H3C]qu <H3C>%Sep 12 04:25:09:751 2015 H3C CFGMAN/5/CFGMAN_EXIT_FROM_CONFIGURE: -Line=au x0-IPAddr=**-User=**; Exit from the system view or a feature view to the user vi ew. sa The current configuration will be written to the device. Are you sure? [Y/N]:y Please input the file name(*.cfg)[flash:/startup.cfg] (To leave the existing filename unchanged, press the enter key):admin The file name is invalid(does not end with .cfg). <H3C> <H3C>dis cu # version 7.1.070, Release 6126P20 # sysname H3C # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # lldp global enable # password-recovery enable # vlan 1 # vlan 10 # vlan 20 # vlan 30 # vlan 40 # vlan 50 # stp global enable # interface NULL0 # interface GigabitEthernet1/0/1 port access vlan 10 # interface GigabitEthernet1/0/2 port access vlan 10 # interface GigabitEthernet1/0/3 port access vlan 10 # interface GigabitEthernet1/0/4 port access vlan 10 # interface GigabitEthernet1/0/5 port access vlan 20 # interface GigabitEthernet1/0/6 port access vlan 20 # interface GigabitEthernet1/0/7 port access vlan 20 # interface GigabitEthernet1/0/8 port access vlan 20 # interface GigabitEthernet1/0/9 port access vlan 30 # interface GigabitEthernet1/0/10 port access vlan 30 # interface GigabitEthernet1/0/11 port access vlan 30 # interface GigabitEthernet1/0/12 port access vlan 30 # interface GigabitEthernet1/0/13 port access vlan 30 # interface GigabitEthernet1/0/14 port access vlan 30 # interface GigabitEthernet1/0/15 port access vlan 30 # interface GigabitEthernet1/0/16 port access vlan 40 # interface GigabitEthernet1/0/17 port access vlan 40 # interface GigabitEthernet1/0/18 port access vlan 40 # interface GigabitEthernet1/0/19 port access vlan 40 # interface GigabitEthernet1/0/20 port access vlan 50 # interface GigabitEthernet1/0/21 port access vlan 50 # interface GigabitEthernet1/0/22 port access vlan 50 # interface GigabitEthernet1/0/23 port access vlan 50 # interface GigabitEthernet1/0/24 port link-type trunk port trunk permit vlan all port trunk pvid vlan 50 # interface GigabitEthernet1/0/25 # interface GigabitEthernet1/0/26 # interface GigabitEthernet1/0/27 # interface GigabitEthernet1/0/28 # scheduler logfile size 16 # line class aux user-role network-admin # line class vty user-role network-operator # line aux 0 user-role network-admin # line vty 0 63 user-role network-operator # radius scheme system user-name-format without-domain # domain system # domain default enable system # role name level-0 description Predefined level-0 role # role name level-1 description Predefined level-1 role # role name level-2 description Predefined level-2 role # role name level-3 description Predefined level-3 role # role name level-4 description Predefined level-4 role # role name level-5 description Predefined level-5 role # role name level-6 description Predefined level-6 role # role name level-7 description Predefined level-7 role # role name level-8 description Predefined level-8 role # role name level-9 description Predefined level-9 role # role name level-10 description Predefined level-10 role # role name level-11 description Predefined level-11 role # role name level-12 description Predefined level-12 role # role name level-13 description Predefined level-13 role # role name level-14 description Predefined level-14 role # user-group system #
这个是交换机的配置文件 麻烦帮我看看 谢谢
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明