------1---
1台核心交换时s5700
2台汇聚交换机S3700
6台PC
-----2------
创建vlan 10 20 30
s3700下PC1,PC2,PC3
S3700下PC4,PC5,PC6
VLAN10 PC1,PC2
VLAN20 PC3,PC4
VLAN30 PC5,PC6
-------3-----
要求实现:
PC1,PC2互通;
PC3,PC4互通;
PC5,PC6互通;
------------4-----s5700配置----
<s5700-Core>undo terminal monitor //关闭终端模拟
<s5700-Core>dis cur //查看配置
#
sysname s5700-Core //重命名
#
vlan batch 10 to 30 //批量创建vlan
#
#
dhcp enable //启用dhcp
#
#
ip pool 10 //配置地址池
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
lease day 5 hour 0 minute 0
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10 //进入vlan 10
ip address 192.168.10.1 255.255.255.0 //设置网关 掩码
dhcp select global
#
interface Vlanif20
ip address 192.168.20.1 255.255.255.0
#
interface Vlanif30
ip address 192.168.30.1 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1 //进入接口
port link-type trunk //设置端口访问模式
port trunk allow-pass vlan 10 20 //允许vlan 10 20 通过
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 20 30
#
#
user-interface con 0
user-interface vty 0 4
#
return
----------s3700-h2------配置telnet------
1.使能服务器功能。
<s3700-h2>system-view //进入用户视图模式
[s3700-h2]telnet server enable //使能telnet
Info: The Telnet server has been enabled.
[s3700-h2]
2•配置VTY用户界面的认证方式为AAA:
选择AAA认证,需要配置AAA用户的认证信息、接入类型和用户级别。
[s3700-h2]aaa //进入3a模式
[s3700-h2-aaa]local-user huawei password simple huawei123 //设置明文用户名、密码
Info: Add a new user.
[s3700-h2-aaa]local-user huawei privilege level 15 //设置用户权限
[s3700-h2-aaa]local-user huawei service-type telnet //设置用户访问类型
[s3700-h2-aaa]q
[s3700-h2]
3.配置VTY用户界面的认证方式和用户级别。配置VTY用户界面的支持协议类型。
[s3700-h2]user-interface vty 0 4
[s3700-h2-ui-vty0-4]authentication-mode aaa //配置认证方式为AAA
[s3700-h2-ui-vty0-4]protocol inbound telnet //指定VTY用户界面所支持的协议为Telnet
[s3700-h2-ui-vty0-4]q
[s3700-h2]
4.管理地址配置
[s3700-h2]vlan 100 //创建vlan100
[s3700-h2]interface Vlanif 100 //进入vlan100逻辑接口
[s3700-h2-Vlanif100]ip address 10.10.100.3 24 //配置该虚接口下的ip\掩码
[s3700-h2-Vlanif100]q
[s3700-h2]interface GigabitEthernet 0/0/1
[s3700-h2-GigabitEthernet0/0/1]dis this
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 20 30
[s3700-h2-GigabitEthernet0/0/1]port trunk allow-pass vlan 20 30 100
[s3700-h2-GigabitEthernet0/0/1]
-----------s5700----配置trunk--
<s5700-Core>system-view
[s5700-Core]interface GigabitEthernet 0/0/2 //进入2接口
[s5700-Core-GigabitEthernet0/0/2]dis this //查看接口配置
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 20 30
#
[s5700-Core-GigabitEthernet0/0/2]port trunk allow-pass vlan 20 30 100 //允许vlan通过
[s5700-Core-GigabitEthernet0/0/2]q
[s5700-Core]ping 10.10.100.3 //ping 通测试;
PING 10.10.100.3: 56 data bytes, press CTRL_C to break
Reply from 10.10.100.3: bytes=56 Sequence=1 ttl=255 time=100 ms
Reply from 10.10.100.3: bytes=56 Sequence=2 ttl=255 time=10 ms
Reply from 10.10.100.3: bytes=56 Sequence=3 ttl=255 time=50 ms
Reply from 10.10.100.3: bytes=56 Sequence=4 ttl=255 time=50 ms
Reply from 10.10.100.3: bytes=56 Sequence=5 ttl=255 time=30 ms
--- 10.10.100.3 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 10/48/100 ms
<s5700-Core>telnet 10.10.100.3 //telnet 测试
Trying 10.10.100.3 ...
Press CTRL+K to abort
Connected to 10.10.100.3 ...
Login authentication
Username:
附件:三台交换机具体配置如下:
#
sysname s5700-Core
#
vlan batch 10 to 30 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
dhcp enable
#
diffserv domain default
#
drop-profile default
#
ip pool 10
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
lease day 5 hour 0 minute 0
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
local-user huawei password cipher -J&7(SW'E2AI>,Z,88J\:Q!!
local-user huawei privilege level 15
local-user huawei service-type telnet
#
interface Vlanif1
#
interface Vlanif10
ip address 192.168.10.1 255.255.255.0
dhcp select global
#
interface Vlanif20
ip address 192.168.20.1 255.255.255.0
#
interface Vlanif30
ip address 192.168.30.1 255.255.255.0
#
interface Vlanif100
ip address 10.10.100.1 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20 100
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 20 30 100
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
authentication-mode aaa
#
return
#
sysname s3700-h1
#
vlan batch 10 20 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
local-user huawei password simple huawei123
local-user huawei privilege level 15
local-user huawei service-type telnet
#
interface Vlanif1
#
interface Vlanif100
ip address 10.10.100.2 255.255.255.0
#
interface MEth0/0/1
#
interface Ethernet0/0/1
#
interface Ethernet0/0/2
port link-type access
port default vlan 10
#
interface Ethernet0/0/3
port link-type access
port default vlan 10
#
interface Ethernet0/0/4
port link-type access
port default vlan 20
#
interface Ethernet0/0/5
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20 100
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 10.10.100.1
#
user-interface con 0
user-interface vty 0 4
authentication-mode aaa
#
return
#
sysname s3700-h2
#
vlan batch 20 to 30 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
local-user huawei password simple huawei123
local-user huawei privilege level 15
local-user huawei service-type telnet
#
interface Vlanif1
#
interface Vlanif100
ip address 10.10.100.3 255.255.255.0
#
interface MEth0/0/1
#
interface Ethernet0/0/1
#
interface Ethernet0/0/2
port link-type access
port default vlan 20
#
interface Ethernet0/0/3
port link-type access
port default vlan 30
#
interface Ethernet0/0/4
port link-type access
port default vlan 30
#
interface Ethernet0/0/5
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 20 30 100
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
authentication-mode aaa
#
return