案例1 精确一点
system-view
#
vlan 100 to 300
vlan 1156
#
inter gig1/0/1
port link-type trunk
undo port trunk permit vlan1
port trunk permit vlan 100 to 1200
案例2一把写完
system-view
#
vlan 2 to 4094
#
inter gig1/0/1
port link-type trunk
undo port trunk permit vlan1
port trunk permit vlan 2 to 4094
请问这两种模式有啥问题?
vlan 100 to 300 和 vlan 1156),并在上行口仅放通这些特定的 VLAN。vlan 2 to 4094 或 port trunk permit vlan all,会导致 AP 只能成功创建前 256 个 VLAN。对于编号大于 256 的业务 VLAN,将无法在 AP 中创建,最终导致连接该 SSID 的无线终端无法获取 IP 地址或无法注册。system-view
vlan 100-102 300-304 200-202
quit
interface GigabitEthernet1/0/1
port link-type trunk
port trunk permit vlan 100-102 300-304 200-202
quit
vlan 100 to 300 + 端口允许 vlan 100 to 1200vlan 1156 单独写,和区间100-300割裂,后期维护、扩容、排查 VLAN 时容易遗漏。vlan 2 to 4094 + 端口允许 vlan 2 to 4094undo port trunk permit vlan 1system-view
# 只创建实际在用VLAN,不多创建
vlan 100 to 300
vlan 1156
#
interface GigabitEthernet 1/0/1
port link-type trunk
# 保留VLAN1做管理,不删除(重点)
port trunk permit vlan 1 100 to 300 1156
#
system-view
vlan 100 to 800
#
interface GigabitEthernet 1/0/1
port link-type trunk
port trunk permit vlan 1 100 to 800
#
undo port trunk permit vlan 1)system-view
# 管理VLAN + 业务VLAN统一创建
vlan 99
vlan 100 to 300
vlan 1156
#
interface GigabitEthernet 1/0/1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 99 100 to 300 1156
#
全局创建的VLAN ⊇ Trunk端口允许的VLAN,二者范围必须匹配。
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
在POE交换机那一层做对应的vlan限制,也可以