版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
任務(wù)1:配置和管理Trunk鏈 任務(wù)2:配置和管理VTP和vlan數(shù)據(jù) 任務(wù)3:配置和實(shí)施 實(shí)驗(yàn)2:配置和實(shí)施私有 任務(wù)1:建立邏輯拓 任務(wù)2:配置Protected- 步驟3:配置團(tuán)體 任務(wù)4:配置混雜端 任務(wù)5:配置 任務(wù)1:配置快速生成 任務(wù)2:配置多生成樹(shù) 任務(wù)3:配置和實(shí)施生成樹(shù)高級(jí)特 任務(wù)1:配置單臂路由實(shí)施基本的vlan間通信功 任務(wù)2:配置多層交換機(jī)的路由功能來(lái)實(shí)施vlan間通 任務(wù)3:配置和實(shí)施多層交換機(jī)的路由接 任務(wù)4:配置多層交換機(jī)的路由功 任務(wù)5:在多層交換機(jī)上配置 攻城 #^_^# 歸原作者所 任務(wù)2:配置和檢查HSRP基本參 任務(wù)3:調(diào)整和優(yōu)化 任務(wù)1:配置和實(shí)施端口安 任務(wù)2:實(shí)施 任務(wù)3:實(shí)施DHCPSnoo.....................................任務(wù)4:實(shí)施動(dòng)態(tài)ARP檢測(cè) 1vlan1TrunkSW1SW2Fa0/23Fa0/242Trunkvlan100nativeSW1SW3Fa0/19Fa0/202Trunkvlan1nativevlan99和vlan199vlanSW2SW3Fa0/21Fa0/222Trunkvlan1native步驟 Erasingthenvramfilesystemwillremoveallconfigurationfiles!Continue?[confirm]//按下回車Eraseofnvram:SW1#deletevlan.dat //刪除vlan數(shù)據(jù)庫(kù)Deletefilename[vlan.dat]? Deleteflash:vlan.dat?[confirm]//按下回車SystemconfigurationhasbeenmodifiedSave?yes/nonoProceedwithreload?[confirm] Erasingthenvramfilesystemwillremoveallconfigurationfiles!Continue?[confirm]//按下回車XXXX#reload//SystemconfigurationhasbeenmodifiedSave?yes/nonoProceedwithreload?[confirm]//按下回車3SW1和SW2--SW3(config)#interfacerangefastEthe-4SW1和SW2的Fa0/23和Fa0/24DTP、nativeSW1(config)#interfacerangefastEthe 0/23-24SW1(config-if-range)#switchporttrunkencapsulationdot1qSW1(config-if-range)#switchportmodedynamicdesirableSW1(config-if-range)#switchporttrunknativevlan100SW1(config-if-range)#switchporttrunkallowedvlan10,20,100SW1(config-if-range)#noshutdownSW2(config)#interfacerangefastEthe 0/23-24SW2(config-if-range)#switchporttrunkencapsulationdot1qSW2(config-if-range)#switchportmodedynamicautoSW2(config-if-range)#switchporttrunknativevlan100SW2(config-if-range)#switchporttrunkallowedvlan10,20,100SW2(config-if-range)#noshutdown5SW1和SW2的TrunkFa0/23和Fa0/24都是Trunk6SW1的Fa0/23DTP模式為desirable802.1q,nativevlan100,允許的vlan是vlan10、vlan20和SW1#showinterfacesfastEthe 0/23switchportName:Fa0/23OperationalMode:AdministrativeTrunkingEncapsulation:dot1qOperationalTrunkingEncapsulation:dot1qNegotiationofTrunking:OnAccessModeVLAN:1TrunkingNativeModeVLAN:100(Inactive)AdministrativeNativeVLANtagging:enabledVoiceVLAN:noneAdministrativeprivate-vlanhost-association:noneAdministrativeprivate-vlanmap:noneAdministrativeprivate-vlantrunknativeVLAN:noneAdministrativeprivate-vlantrunkNativeVLANtagging:enabledAdministrativeprivate-vlantrunkencapsulation:dot1qAdministrativeprivate-vlantrunknormalVLANs:noneAdministrativeprivate-vlantrunkassociations:noneAdministrativeprivate-vlantrunkmaps:noneOperationalprivate-vlan:nonePruningVLANsEnabled:2-1001CaptureModeDisabledCaptureVLANsAllowed:ALLProtected:falseUnknownunicastblocked:disabledUnknownmulticastblocked:disabledAppliancetrust:none7SW1和SW3的Fa0/19和Fa0/20SW1(config)#interfacerangefastEthe 0/19-20SW1(config-if-range)#switchporttrunkencapsulationdot1qSW1(config-if-range)#switchportmodetrunkSW1(config-if-range)#switchportnonegotiateSW1(config-if-range)#switchporttrunknativevlan1SW1(config-if-range)#switchporttrunkallowedvlanexcept99,199SW1(config-if-range)#noshutdown攻城 #^_^# 歸原作者所 SW3(config)#interfacerangefastEthe 0/19-20SW3(config-if-range)#switchporttrunkencapsulationdot1qSW3(config-if-range)#switchportmodetrunkSW3(config-if-range)#switchportnonegotiateSW3(config-if-range)#switchporttrunknativevlan1SW3(config-if-range)#switchporttrunkallowedvlanexcept99,199SW3(config-if-range)#noshutdown8SW1和SW3的Trunk接口,確認(rèn)Fa0/19和Fa0/20為T(mén)runking狀9vlan是vlan1SW1#showinterfacesfastEthe0/19switchportName:Fa0/19Switchport:EnabledAdministrativeMode:trunkOperationalMode:trunkAdministrativeTrunkingEncapsulation:dot1qOperationalTrunkingEncapsulation:dot1qNegotiationofTrunking:OffAccessModeVLAN:1TrunkingNativeModeVLAN:1(Inactive)AdministrativeNativeVLANtagging:enabledVoiceVLAN:noneAdministrativeprivate-vlanhost-association:noneAdministrativeprivate-vlanmap:noneAdministrativeprivate-vlantrunknativeVLAN:noneAdministrativeprivate-vlantrunkNativeVLANtagging:enabledAdministrativeprivate-vlantrunkencapsulation:dot1qAdministrativeprivate-vlantrunknormalVLANs:noneAdministrativeprivate-vlantrunkassociations:noneAdministrativeprivate-vlantrunkmaps:nonePruningVLANsEnabled:2-1001CaptureModeDisabledCaptureVLANsAllowed:ALLProtected:falseUnknownunicastblocked:disabledUnknownmulticastblocked:disabledAppliancetrust:none10SW2和SW3的Fa0/21和Fa0/22trunkSW2(config)#interfacerangefastEthe 0/21-22SW2(config-if-range)#switchporttrunkencapsulationdot1qSW2(config-if-range)#switchportmodetrunkSW2(config-if-range)#switchportnonegotiateSW2(config-if-range)#switchporttrunknativevlan1SW2(config-if-range)#switchporttrunkallowedvlanexcept199-299SW2(config-if-range)#noshutdownSW3(config)#interfacerangefastEthe 0/21-22SW3(config-if-range)#switchporttrunkencapsulationdot1qSW3(config-if-range)#switchportmodetrunkSW3(config-if-range)#switchportnonegotiateSW3(config-if-range)#switchporttrunknativevlan1SW3(config-if-range)#switchporttrunkallowedexceptvlan199-299SW3(config-if-range)#noshutdown11SW2和SW3的Trunk2VTPvlanSW1SW2的VTP VTP定義為VTP定義為SW1SW2的vlanTrunkVTP定義為VTP定義為SW1SW2之間鏈路丟失的情況下,SW1SW2可以通過(guò)SW3vlan數(shù)據(jù)庫(kù),但SW3的vlan數(shù)據(jù)庫(kù)是獨(dú)立的SW1vlan10、vlan20和vlan100SW1SW23SW3vlan10、vlan20、vlan100SW1的Fa0/1和SW2的Fa0/2vlan10的AccessR1和R2的IP21.12.0.1/1621.12.0.2/16R1R2步驟1:配置SW1和SW2交換機(jī)的VTP,指定版本、、和模式,SW1是server模式、SW2是 SW1(config)#vtpversion2SW1(config)#vtpyangbangSW1(config)#vtppassword123SW1(config)#vtpmodeserverSW2(config)#vtpversion2SW2(config)#vtpyangbangSW2(config)#vtppassword123SW2(config)#vtpmode2SW1vlan10、vlan20和vlan100vlanSW1(config)#vlan10SW1(config)#vlan20SW1(config)#vlan1004SW2的vlanVTP和SW1同步vlan步驟6:配置SW3,指定VTP模式為透明模式,并指定和SW1、SW2相同的和密SW3(config)#vtpyangbangSW3(config)#vtppassword123SW3(config)#vtpmodetransparent7SW3的vtp狀態(tài),確認(rèn)SW3的模式為8SW1的Fa0/23和Fa0/24都關(guān)閉,模擬SW1丟失和SW2的直連鏈路的SW1(config)#interfacerangefastEthe 0/23-249SW1SW1(config)#vlan200攻城 #^_^# 歸原作者所 10SW2的vlanvlan200SW1能SW3的轉(zhuǎn)發(fā),讓SW2獲得vlan數(shù)據(jù)庫(kù)的信息11SW3的vlan數(shù)據(jù)庫(kù),發(fā)現(xiàn)現(xiàn)在SW1只有vlan1SW3并沒(méi)有同步到SW1的vlan數(shù)據(jù)庫(kù)信息12:在SW1vlan200,并恢復(fù)Fa0/23和Fa0/24SW1(config)#novlanSW1(config)#interfacerangefastEthe 0/23-24SW1(config-if-range)#noshutdown13SW3vlan10、vlan、vlan100和SW3(config)#vlan10SW3(config)#vlan20SW3(config)#vlan100SW3(config)#vlan200SW3(config-vlan)#nameLocal14SW1的Fa0/1和SW2的Fa0/2vlan10的AccessSW1(config)#interfacefastEthe SW1(config-if)#switchportmodeaccessSW1(config-if)#switchportaccessvlan10SW1(config-if)#noshutdownSW2(config)#interfacefastEthe SW2(config-if)#switchportmodeaccessSW2(config-if)#switchportaccessvlan10SW2(config-if)#noshutdown15SW1和SW2的vlan數(shù)據(jù)庫(kù),確認(rèn)Fa0/1和Fa0/216R1的Fa0/0R2的Fa0/1口,指定IP21.12.0.1/1621.12.0.2/16R1R2視作vlan10 R1(config-if)#ipaddress21.12.0.1255.255.0.0R1(config-if)#noshutdownR2(config)#interfacefastEthe R2(config-if)#ipaddress21.12.0.2255.255.0.0R2(config-if)#noshutdown步驟17:在R1或R2上使用測(cè)試,確認(rèn)R1和R2能互相通TypeescapesequencetoSending5,100-byteICMPEchosto21.12.0.2,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/1ms3將SW1和SW2之間的Fa0/23和Fa0/24為EtherChannel,具體要求如下SW1和SW2TrunkNativevlan將SW1和SW3之間的Fa0/19和Fa0/20為EtherChannel,具體要求如下將SW2和SW3之間的Fa0/21和Fa0/22為EtherChannel,具體要求如下1:配置SW1和SW2的Fa0/23和Fa0/24口,將212,并指定模式為onSW1(config)#interfacerangefastEthe 0/23-24SW1(config-if-range)#channel-group12modeonCreatingaport-channelinterfacePort-channel12SW2(config)#interfacerangefastEthe 0/23-24SW2(config-if-range)#channel-group12modeonCreatingaport-channelinterfacePort-channel12表二層功能,U代表正在工作3SW1或SW2的Port-channel接口,看到Po124:SW1或SW2的Fa0/24on、加入的組是5SW1和SW2的Port-channel12接口,指定trunk的nativeSW1(config)#interfaceport-channel12SW1(config-if)#switchporttrunknativevlan10SW2(config)#interfaceport-channel12SW2(config-if)#switchporttrunknativevlan10步驟6:檢查SW1或SW2的配置文件,會(huì)看到步驟5的配置也被到了Fa0/237SW1或SW2的TrunkFa0/23和Fa0/24,而是出現(xiàn)了一個(gè)新的接口Po12接口,狀態(tài)是Trunking8SW1和SW3的Fa0/19PAgP,SW1desirable,SW3的模式為AutoPort-SW1(config)#interfacerangefastEthe 0/19-20SW1(config-if-range)#channel-protocolpagpSW1(config-if-range)#channel-group13modedesirableCreatingaport-channelinterfacePort-channel13SW3(config)#interfacerangefastEthe 0/19-20SW3(config-if-range)#channel-protocolpagpSW3(config-if-range)#channel-group13modeautoCreatingaport-channelinterfacePort-channel13攻城 #^_^# 歸原作者所 10SW1或SW3的trunkFa0/19和Fa0/20不再出現(xiàn),而出現(xiàn)了一個(gè)新的Trunk接口Po1311SW2和SW3的Fa0/21和Fa0/22LACP,SW2Active,SW3的模式為PassivePort-SW2(config)#interfacerangefastEthe 0/21-22SW2(config-if-range)#channel-protocollacpSW2(config-if-range)#channel-group23modeactiveCreatingaport-channelinterfacePort-channel23SW3(config)#interfacerangefastEthe 0/21-22SW3(config-if-range)#channel-protocollacpSW3(config-if-range)#channel-group23modepassiveCreatingaport-channelinterfacePort-channel2312SW2或SW3的TrunkFa0/21和Fa0/22不再出現(xiàn),出現(xiàn)了一個(gè)新的Trunk接口Po23SW1(config)#port-channelload-balancesrc-macSW2(config)#port-channelload-balancesrc-macSW3(config)#port-channelload-balancesrc-mac21SW1的Fa0/1和Fa0/19vlan101AccessR1的Fa0/0SW1的Fa0/2和Fa0/20vlan101AccessR2SW2的Fa0/3和Fa0/21vlan103AccessR3SW2的Fa0/4和Fa0/22vlan104AccessR4步驟 Erasingthenvramfilesystemwillremoveallconfigurationfiles!Continue?[confirm]//按下回車Eraseofnvram:SW1#deletevlan.dat //刪除vlan數(shù)據(jù)庫(kù)Deletefilename[vlan.dat]? Deleteflash:vlan.dat?[confirm]//按下回車SystemconfigurationhasbeenmodifiedSave?yes/nonoProceedwithreload?[confirm] Erasingthenvramfilesystemwillremoveallconfigurationfiles!Continue?[confirm]//按下回車XXXX#reload//SystemconfigurationhasbeenmodifiedSave?yes/nonoProceedwithreload?[confirm]//按下回車3SW1和SW2--SW3(config)#interfacerangefastEthe-4SW1的VTP模式調(diào)整為T(mén)ransparentvlan101、SW1(config)#vtpmodetransparentSettingdevicetoVTPTRANSPARENTmode.SW1(config)#vlan101SW1(config)#vlan1025SW1的Fa0/1、Fa0/19vlan101的Access接口,將Fa0/2Fa0/20口配置為vlan102的AccessSW1(config)#interfaceranfa0/1,fa0/19SW1(config-if-range)#switchportmodeaccessSW1(config-if-range)#switchportaccessvlan101SW1(config-if-range)#noshutdownSW1(config)#interfacerangefa0/2,fa0/20SW1(config-if-range)#switchportmodeaccessSW1(config-if-range)#switchportaccessvlan102SW1(config-if-range)#noshutdownSW2(config)#vtpmodetransparentSettingdevicetoVTPTRANSPARENTmode.SW2(config)#vlan103SW2(config)#vlan1047Fa0/3、Fa0/21配置為vlan103的AccessFa0/4、配置為vlan104的AccessSW2(config)#interfacerangefa0/3,fa0/21SW2(config-if-range)#switchportmodeaccessSW2(config-if-range)#switchportaccessvlan103SW2(config-if-range)#noshutdownSW2(config)#interfacerangefa0/4,fa0/22SW2(config-if-range)#switchportmodeaccessSW2(config-if-range)#switchportaccessvlan104SW2(config-if-range)#noshutdown8:將SW3的Fa0/19到Fa0/224accessSW3(config)#interfacerangefastEthe 0/19-22SW3(config-if-range)#switchportmodeaccessSW3(config-if-range)#noshutdown9SW3和SW1、SW2之間的接口加入了不同的vlan,CDP協(xié)議會(huì)提示,不用理會(huì)CDP的警告信息,將CDP關(guān)閉即可*Mar100:47:18.897:%CDP-4-NATIVE_VLAN_MISMATCH:NativeVLANdiscoveredon 0/19(1),withSW1 0/19SW3(config)#nocdp10SW1的vlan數(shù)據(jù)庫(kù),確認(rèn)vlan101和vlan102以及它們的Access11SW2的vlan數(shù)據(jù)庫(kù),確認(rèn)vlan103和vlan104以及它們的Access12R1和R2的Fa0/0R3和R4的Fa0/1,4臺(tái)路由器模擬為同網(wǎng)R1(config)#interfacefastEthe R1(config-if)#noshutdownR2(config)#interfacefastEthe R2(config-if)#noshutdownR3(config)#interfacefastEthe R3(config-if)#noshutdownR4(config)#interfacefastEthe R4(config-if)#noshutdownTypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.2,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/1TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/1TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/4ms2Protected-R1和R2R3、R4R3和R4R3能和R1、R2R4能和R1、R2TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/4ms2SW3的F0/21和F0/22是否開(kāi)啟了Protected功能,確認(rèn)默認(rèn)該功SW3#showinterfacesf0/21switchport|ludeProtectedProtected:falseSW3#showinterfacesf0/22switchport|ludeProtectedProtected:false3SW3的F0/21和F0/22為ProtectedSW3(config)#interfacerangef0/21-224:再檢查SW3的F0/21和F0/22是否開(kāi)啟了Protected功能,確認(rèn)現(xiàn)在已SW3#showinterfacesf0/21switchport|ludeProtectedProtected:trueSW3#showinterfacesf0/22switchport|ludeProtectedProtected:trueTypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.2,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/1msR1#192.168.1.3TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/1msR1#192.168.1.4TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/4msTypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.1,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/1msR2#192.168.1.3TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/1msR2#192.168.1.4TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis80percent(4/5),round-tripmin/avg/max=1/1/4ms7R3和R4TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis0percent3vlan20和vlan30vlanvlanvlan10,為主vlanvlan20R1R2vlan20的主機(jī)、R3R4是vlan3012中關(guān)于Protect-PortsSW3(config)#interfacerangef0/21-22SW3(config-if-range)#noswitchportprotectedSW3#showinterfacesf0/21switchport|ludeProtectedProtected:falseSW3#showinterfacesf0/22switchport|ludeProtectedProtected:true3SW3的VTP模式配置為T(mén)ransparentvlan20和vlan30作為輔助vlan,兩個(gè)vlan均為團(tuán)體vlanSW3(config)#vtpmodetransparentSW3(config)#vlan20SW3(config)#vlanSW3(config-vlan)#private-vlan4vlan20、vlan30是否已經(jīng)是團(tuán)體SW3#showvlanprivate-PrimarySecondary SW3(config)#vlanSW3(config-vlan)#private-vlanprimarySW3(config-vlan)#private-vlanassociation20,306vlan10vlan20和SW3#showvlanprivate-PrimarySecondary SW3#showvlanprivate-vlantypeVlanType1020308:R1R2是vlan20的主機(jī)、R3R4是vlan30SW3(config)#interfacerangef0/19-SW3(config-if-range)#switchportmodeprivate-vlanSW3(config-if-range)#switchportprivate-vlanhost-association10SW3(config)#interfacerangef0/21-SW3(config-if-range)#switchportmodeprivate-vlanSW3(config-if-range)#switchportprivate-vlanhost-association10SW3#showvlanprivate-PrimarySecondary Fa0/19,Fa0/21,SW3#showinterfacesf0/19switchport|ludeprivate-vlanAdministrativeMode:private-vlanhostOperationalMode:private-vlanAdministrativeprivate-vlanmap:noneAdministrativeprivate-vlantrunknativeVLAN:noneAdministrativeprivate-vlantrunkNativeVLANtagging:enabledAdministrativeprivate-vlantrunkencapsulation:dot1qAdministrativeprivate-vlantrunknormalVLANs:noneAdministrativeprivate-vlantrunkassociations:noneAdministrativeprivate-vlantrunkmaps:noneOperationalprivate-SW3#showinterfacesf0/20switchport|ludeprivate-vlanAdministrativeMode:private-vlanhostOperationalMode:private-vlanAdministrativeprivate-vlanmap:noneAdministrativeprivate-vlantrunknativeVLAN:noneAdministrativeprivate-vlantrunkNativeVLANtagging:enabledAdministrativeprivate-vlantrunkencapsulation:dot1qAdministrativeprivate-vlantrunknormalVLANs:noneAdministrativeprivate-vlantrunkassociations:noneAdministrativeprivate-vlantrunkmaps:noneOperationalprivate-SW3#showinterfacesf0/21switchport|ludeprivate-vlanAdministrativeMode:private-vlanhostOperationalMode:private-vlanAdministrativeprivate-vlanmap:noneAdministrativeprivate-vlantrunknativeVLAN:noneAdministrativeprivate-vlantrunkNativeVLANtagging:enabledAdministrativeprivate-vlantrunkencapsulation:dot1qAdministrativeprivate-vlantrunknormalVLANs:noneAdministrativeprivate-vlantrunkassociations:noneAdministrativeprivate-vlantrunkmaps:noneOperationalprivate-SW3#showinterfacesf0/22switchport|ludeprivate-vlanAdministrativeMode:private-vlanhostOperationalMode:private-vlanAdministrativeprivate-vlanmap:noneAdministrativeprivate-vlantrunknativeVLAN:noneAdministrativeprivate-vlantrunkNativeVLANtagging:enabledAdministrativeprivate-vlantrunkencapsulation:dot1qAdministrativeprivate-vlantrunknormalVLANs:noneAdministrativeprivate-vlantrunkassociations:noneAdministrativeprivate-vlantrunkmaps:noneOperationalprivate-R4通訊R1#192.168.1.2//R1能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.2,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/4R1#192.168.1.3//R1不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis0percentR1#192.168.1.4//R1不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis0percentR2#192.168.1.1//R2能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.1,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/4R2#192.168.1.3//R2不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis0percentR2#192.168.1.4//R2不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis0percentR3#192.168.1.4//R3能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/2/4R3#192.168.1.1//R3不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.1,timeoutis2Successrateis0percentR3#192.168.1.2//R3不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.2,timeoutis2Successrateis0percent4R2為vlan20(vlan)R1R2、R3、R4互相通信;R3和R4之間能互相通信;R2只能與R1通信(不能和其他輔助vlan的主機(jī)通信)SW3(config)#interfaceSW3(config-if)#switchportmodeprivate-vlanpromiscuousSW3(config-if)#switchportprivate-vlanmap102SW3連接R1SW3#showinterfacesf0/19switchport|ludeprivate-vlanAdministrativeMode:private-vlanpromiscuousOperationalMode:private-vlanpromiscuousAdministrativeprivate-vlanhost-association:noneAdministrativeprivate-vlanmap Administrativeprivate-vlantrunknativeVLAN:noneAdministrativeprivate-vlantrunkNativeVLANtagging:enabledAdministrativeprivate-vlantrunkencapsulation:dot1qAdministrativeprivate-vlantrunknormalVLANs:noneAdministrativeprivate-vlantrunkassociations:noneAdministrativeprivate-vlantrunkmaps:noneOperationalprivate-攻城 #^_^# 歸原作者所 3R1R2、R3、R4互相通信;R3和R4之間能互相通信;R2R1#192.168.1.2//R1能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.2,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/1R1#192.168.1.3//R1能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/4R1#192.168.1.4//R1能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/2/4R2#192.168.1.1//R2能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.1,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/4R2#192.168.1.3//R2不能通R3和TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis0percentR2#TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis0percentR3#192.168.1.4//R3能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/2/4任務(wù)5:配置vlanR3和R4vlan40完成本配置后,R3和R4之間都不能通信,它們只能和混雜端口的主機(jī)(R1)2R1所在的混雜端口也關(guān)聯(lián)新添加的SW3#showvlanprivate-PrimarySecondary Fa0/19,Fa0/19,Fa0/21,SW3#showvlanprivate-vlantypeVlanType102030404R3R4配置為vlan40SW3#showvlanprivate-PrimarySecondary Fa0/19,Fa0/19,Fa0/21,6:測(cè)試,R3和R4R1R2R3#192.168.1.1//R3能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.1,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/1/4R3#192.168.1.2//R3不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.2,timeoutis2Successrateis0percentR3#192.168.1.4//R3不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.4,timeoutis2Successrateis0percentR4#192.168.1.1//R4能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.1,timeoutis2Successrateis100percent(5/5),round-tripmin/avg/max=1/2/4R4#192.168.1.2//R4不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.2,timeoutis2Successrateis0percentR4#192.168.1.3//R4不能通TypeescapesequencetoSending5,100-byteICMPEchosto192.168.1.3,timeoutis2Successrateis0percent將SW2和SW3之間的Fa0/21和Fa0/22到EtherChannel中,具體要求如下SW3vlan1vlan2的主根橋,SW2vlan1和vlan2SW2vlan3vlan4的主根橋,SW3vlan3和vlan4CostSW1的Fa0/20口是vlan1vlan2SW1的Fa0/1和Fa0/2vlan1Access1SW2和SW3的Sw2(config-if-range)#channel-group23modedesirableCreatingaport-channelinterfacePort-channel23Sw3(config)#interfacerangef0/21-22Sw3(config-if-range)#channel-group23modeautoCreatingaport-channelinterfacePort-channel2SW2和SW3的EtherChannelSw2#showinterfacesport-channelPort-channel23isup,lineprotocolisupHardwareisEtherChannel,addressis000c.859d.ae95(bia000c.859d.ae95)MTU1500bytes,BW200000Kbit,DLY100usec,reliability255/255,txload1/255,rxload1/255EncapsulationARPA,loopbacknotsetKeepaliveset(10Full-duplex,100Mb/s,mediatypeisSw3#showinterfacesport-channelPort-channel23isup,lineprotocolisupHardwareisEtherChannel,addressis0019.aa86.d197(bia0019.aa86.d197)MTU1500bytes,BW200000Kbit/sec,DLY100usec,reliability255/255,txload1/255,rxload1/255EncapsulationARPA,loopbacknotsetKeepaliveset(10Full-duplex,100Mb/s,linktypeisauto,mediatypeisunknowninputflow-controlisoff,outputflow-controlisunsupportedSw2#showetherchannelFlags:D-down P-bundledinport-channelI-stand-alones-suspendedH-Hot-standby(LACPonly)R-Layer3 S-Layer2U-in f-failedtoallocateM-notinuse,minimumlinksnotmetu-unsuitableforbundlingw-waitingtobeaggregatedd-defaultportNumberofchannel-groupsinuse:1Numberofaggregators: GroupPort-channel Fa0/21(P)Sw3#showetherchannelFlags:D-down P-bundledinport-channelI-stand-alones-suspendedH-Hot-standby(LACPonly)R-Layer3 S-Layer2U-in f-failedtoallocateM-notinuse,minimumlinksnotmetu-unsuitableforbundlingw-waitingtobeaggregatedd-defaultportNumberofchannel-groupsinuse:1Numberofaggregators: GroupPort-channel Fa0/21(P)Sw1(config-if-range)#switchporttrunkencapsulationdot1qSw1(config-if-range)#switchportmodetrunkSw2(config-if-range)#switchporttrunkencapsulationdot1qSw2(config-if-range)#switchportmodetrunkSw3(config-if-range)#switchporttrunkencapsulationdot1qSw3(config-if-range)#switchportmodetrunk43臺(tái)交換機(jī)的trunk53臺(tái)交換機(jī)VTPvlan2、3、Sw1(config)#vtpmodetransparentSw2(config)#vlan2-4Sw2(config)#vtpmodetransparentSw2(config)#vlan2-4Sw3(config)#vtpmodetransparentSw3(config)#vlan2-46SW2和SW3,確保SW3是vlan1和vlan2的主根橋,SW2是vlan1Sw3(config)#spanning-treevlan1-2rootprimarySw3(config)#spanning-treevlan3-4rootsecondarySw2(config)#spanning-treevlan3-4rootprimarySw2(config)#spanning-treevlan1-2rootsecondarySw1(config)#spanning-treemoderapid-pvstSw2(config)#spanning-treemoderapid-pvstSw3(config)#spanning-treemoderapid-pvst12:更改Cost值,確保SW1的Fa0/20口是vlan1和vlan2Sw1(config-if)#spanning-treevlan1-2cost13:再檢查SW1的F0/20口的在vlan1和vlan2Fa0/20是根14:檢查SW1的Fa0/24口在vlan3和vlan4Fa0/2415SW2的Fa0/23接口的Port-IDSW1的Fa0/24口是和vlan416:再檢查SW1的F0/24口的在vlan3和vlan4的狀態(tài),是根端口,狀態(tài)是17SW1的Fa0/1和Fa0/2vlan1的AccessSw1(config)#interfacerangef0/1-2Sw1(config-if-range)#switchportmodeaccessSw1(config-if-range)#noshutdown18:確認(rèn)SW1的Fa0/1和Fa0/2portfastSw1#showspanning-treeinterfacef0/1portfast Sw1#showspanning-treeinterfacef0/2portfast 19Trunk接口配置為PortFast%Warning:thiscommandenablesportfastbydefaultonallinterfaces.Youshouldnowdisableportfastexplicitlyonswitchedportsleadingtohubs,switchesandbridgesastheymaycreatetemporarybridgingloops.20:再次檢查SW1的Fa0/1和Fa0/2這兩個(gè)非trunk接口是否是portfast接口,發(fā)現(xiàn)現(xiàn)在已開(kāi)啟了PortFast功能Sw1#showspanning-treeinterfacef0/1portfast Sw1#showspanning-treeinterfacef0/2portfast 21:檢查SW1的trunk接口,確認(rèn)所有Trunk接口都不會(huì)開(kāi)啟2區(qū)改為vlan屬于默認(rèn)實(shí)例Sw1(config)#spanning-treemodemstSw1(config)#spanning-treemstconfigurationSw1(config-mst)#nameyangbangSw1(config-mst)#revisionSw1(config-mst)#instance1vlan1-Sw1(config-mst)#instance2vlan3-4Sw2(config)#spanning-treemodemstSw2(config)#spanning-treemstconfigurationSw2(config-mst)#nameyangbangSw2(config-mst)#revisionSw2(config-mst)#instance1vlan1-Sw2(config-mst)#instance2vlan3-4Sw3(config)#spanning-treemodemstSw3(config)#spanning-treemstconfigurationSw3(config-mst)#nameyangbangSw3(config-mst)#revisionSw3(config-mst)#instance1vlan1-Sw3(config-mst)#instance2vlan3-43SW2SW3SW31的主根橋,SW22的備份根橋,指定SW2為實(shí)例1的備份根橋,SW3為實(shí)例2的主根橋Sw3(config)#spanning-treemst1rootprimarySw3(config)#spanning-treemst2rootSw2(config)#spanning-treemst1rootsecondarySw2(config)#spanning-treemst2rootprimary4SW3和SW2SW3是instance1的根橋,SW2是instance2的到BPDU,立即將該接口置為err-diasbled狀態(tài)SW1Fa0/2BPDUFilter,并使用showSW2和SW3Port-channelUDLD1SW1Fa0/1口開(kāi)啟BPDUGuard,并使用show命名檢查。確保該接口如果收到BPDU,立即將該接口置為err-diasbled狀態(tài)Sw1(config)#interfaceSw1(config-if)#spanning-treebpduguard2SW1的F0/1口是否開(kāi)啟了BPDUguardSw1#showspanning-treeinterfacef0/1detail|ludeBpduguardBpduguardisenabledBpduguardis3SW1Fa0/2口開(kāi)啟Sw1(config)#interfaceSw1(config-if)#spanning-treebpdufilter4:檢查SW1的F0/2口是否開(kāi)啟了Sw1#showspanning-treeinterfacef0/2detail|ludeBpduBpdufilterisenabledBpdufilteris5SW1Fa0/1和Fa0/2Sw1(config)#interfacerangef0/1-2Sw1(config-if-range)#spanning-treeguardroot6SW1上的F0/1和F0/2口的rootguardSw1#showspanning-treeinterfacef0/1detail|ludeRootguardRootguardisenabledontheportRootguardisenabledontheportSw1#showspanning-treeinterfacef0/2detail|ludeRootguardRootguardisenabledontheportRootguardisenabledonthe7SW1上,開(kāi)啟LoopGuardSw1(config)#spanning-treeloopguard8SW2和SW3上,針對(duì)Port-channel接口開(kāi)啟UDLD積極模式,不能直接對(duì)EtherChannel做UDLD,要在物理接口做Sw2(config)#intrangef0/21-22Sw2(config-if-range)#udldportaggressiveSw3(config)#intrangef0/21-22Sw3(config-if-range)#udldportaggressive,SW2是3560交換機(jī)Sw2#showudldInterfacePortenableadministrativeconfigurationsetting:Enabled/inaggressivemodePortenableoperationalstate:Enabled/inaggressivemodeCurrentbidirectionalstate:UnknownCurrentoperationalstate:AdvertisementMessageinterval:7Timeoutinterval:NoneighborcacheinformationstoredSw2#showudldInterfacePortenableadministrativeconfigurationsetting:Enabled/inaggressivemodePortenableoperationalstate:Enabled/inaggressivemodeCurrentbidirectionalstate:UnknownCurrentoperationalstate:AdvertisementMessageinterval:7Timeoutinterval:NoneighborcacheinformationSw3#showudldf0/21InterfaceFa0/21Portenableadministrativeconfigurationsetting:Enabled/inaggressivemodePortenableoperationalstate:Enabled/inaggressivemodeCurrentbidirectionalstate:BidirectionalCurrentoperationalstate:DetectionMessageinterval:7Timeoutinterval:EntryExpirationtime:DeviceID:Currentneighborstate:UnknownDevicename:CAT0714X1X7PortID:Neighborecho1device:CAT1040RJ35Neighborecho1port:Fa0/21Messageinterval:7Timeoutinterval:5CDPDevicename:攻城 #^_^# 歸原作者所 1vlanSW1vlan10和vlan20,將R1vlan10的主機(jī),R2R1的Fa0/0IP192.168.10.1/24,網(wǎng)關(guān)(默認(rèn)路由)指定為R2的Fa0/0IP192.168.20.1/24,網(wǎng)關(guān)(默認(rèn)路由)指定為SW1Fa0/3配置為T(mén)runkDTPvlan10vlan20通過(guò)最后做測(cè)試,確保R1和R2能互相通1:3臺(tái)交換機(jī)的VTP模式指定為Sw1(config)#vtpmodetransparentSw2(config)#vtpmodetransparentSw3(config)#vtpmodetransparent2SW1vlan10和vlan20,將R1配置為vlan10的主機(jī),R2配置為vlan20的主機(jī)Sw1(config)#vlan10Sw1(config-if)#switchportmodeaccessSw1(config-if)#switchporta
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025版學(xué)生兼職人才輸送與培訓(xùn)服務(wù)合同3篇
- 二零二五年金融衍生品交易合同履行及風(fēng)險(xiǎn)擔(dān)保合同3篇
- 2025版高端酒店客房裝修與設(shè)施更新合同4篇
- 2025年度商業(yè)綜合體地下車位租賃及買(mǎi)賣(mài)合同
- 2025年度藝人廣告代言經(jīng)紀(jì)合同及勞動(dòng)合同
- 2025年度二零二五餐飲行業(yè)高級(jí)廚師雇傭合同協(xié)議書(shū)
- 二零二五年度酒店會(huì)議室租賃合同(含互動(dòng)游戲)
- 2025年度叉車租賃與租賃物使用培訓(xùn)及操作手冊(cè)合同
- 2025年度足浴中心加盟體系與營(yíng)銷策略轉(zhuǎn)讓合同
- 2025年度燃?xì)庑袠I(yè)市場(chǎng)拓展與品牌合作合同模板
- 2025年上半年江蘇連云港灌云縣招聘“鄉(xiāng)村振興專干”16人易考易錯(cuò)模擬試題(共500題)試卷后附參考答案
- DB3301T 0382-2022 公共資源交易開(kāi)評(píng)標(biāo)數(shù)字見(jiàn)證服務(wù)規(guī)范
- 人教版2024-2025學(xué)年八年級(jí)上學(xué)期數(shù)學(xué)期末壓軸題練習(xí)
- 江蘇省無(wú)錫市2023-2024學(xué)年八年級(jí)上學(xué)期期末數(shù)學(xué)試題(原卷版)
- 俄語(yǔ)版:中國(guó)文化概論之中國(guó)的傳統(tǒng)節(jié)日
- 2022年湖南省公務(wù)員錄用考試《申論》真題(縣鄉(xiāng)卷)及答案解析
- 婦科一病一品護(hù)理匯報(bào)
- 2024年全國(guó)統(tǒng)一高考數(shù)學(xué)試卷(新高考Ⅱ)含答案
- 移動(dòng)商務(wù)內(nèi)容運(yùn)營(yíng)(吳洪貴)任務(wù)四 引起受眾傳播內(nèi)容要素的掌控
- 繪本《汪汪的生日派對(duì)》
- 助產(chǎn)護(hù)理畢業(yè)論文
評(píng)論
0/150
提交評(píng)論