VLAN间通信之VLANIF虚接口
说明:想要实现VLAN间互访有很多解决方案:
1)VLAN终结--也称单臂路由
2)VLANIF虚接口---最受欢迎的解决方案
1、VLANIF虚接口
1)VLANIF接口是一种三层虚拟接口,可以实现VLAN间的三层互通。
2)VANIF配置简单,是实现VLAN间互访最常用的一种技术
3)每个VLAN需要配置一个VLANIF,给VLANIF配置接口IP地址,并指定一个IP子网网段,作为VLAN内主机的网关
2、VLANIF虚接口实验
1)拓扑
2)需求:让所有vlan内的所有pc主机都可以互通
3)配置步骤
-配置PC的IP地址和掩码、网关
-交换机SW2/SW3 上创建VLAN,配置接口接口加入VLAN
-在SW1上创建VLAN,并且给VLANIF 虚拟接口配置IP地址
4)配置命令
SW1配置:
[SW1]vlan batch 10 20 30 40
[SW1]port-group group-member g0/0/1 g0/0/2
[SW1-port-group]port link-type trunk
[SW1-port-group]port trunk allow-pass vlan all
[SW1-port-group]quit
[SW1]interface vlanif 10
[SW1-vlanif10] ip address 192.168.10.254 24
[SW1-vlanif10]interface vlanif 20
[SW1-vlanif20]ip address 192.168.20.254 24
[SW1-vlanif20]interface vlanif 30
[SW1-vlanif30]ip address 192.168.30.254 24
[SW1-vlanif30]interface vlanif 40
[SW1-vlanif40]ip address 192.168.40.254 24
SW2配置:
[SW2]vlan batch 10 20 30 40
[SW2]interface g0/0/1
[SW2-g0/0/1]port link-type trunk
[SW2-g0/0/1]port trunk allow-pass vlan all
[SW2-g0/0/1]interface g0/0/2
[SW2-g0/0/2]port link-type access
[SW2-g0/0/2]port default vlan 10
[SW2-g0/0/2]interface g0/0/3
[SW2-g0/0/3]port link-type access
[SW2-g0/0/3]port default vlan 20
SW3配置:
[SW3]vlan batch 10 20 30 40
[SW3]interface g0/0/1
[SW3-g0/0/1]port link-type trunk
[SW3-g0/0/1]port trunk allow-pass vlan all
[SW3-g0/0/1]interface g0/0/2
[SW3-g0/0/2]port link-type access
[SW3-g0/0/2]port default vlan 30
[SW3-g0/0/2]interface g0/0/3
[SW3-g0/0/3]port link-type access
[SW3-g0/0/3]port default vlan 40
测试与验证:
PC11 ping PC12/13/14 都可以互通
```
3、VLANIF虚接口案例实践
1)拓扑
2)需求:
-所有PC能够ping通自己的网关
-实现vlan间互通,实现所有的PC互通
3)配置步骤:
第一步:给pc配置IP地址
第二步:交换机创建vlan,做access和trunk
-所有的交换机都配置vlan10/20/30/40
-交换机与pc互联的接口做access ,并加vlan
- 交换机与交换机互联做trunk,允许vlan通过
第三步:配置vlanif虚接口IP地址,做vlan内主机的网关,并实现直连路由
前面这3步做完之后,可以实现PC能ping通自己的网关
第四步:配置静态路由,实现所有PC之间的互通(vlan间通信)
第五步:测试与验证
4)配置命令:
第一步:给pc配置IP地址
第二步:交换机创建vlan,做access和trunk
SW1配置:
[SW1]vlan batch 10 20 30 40
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 10
[SW1-GigabitEthernet0/0/1]quit
[SW1]port-group group-member g0/0/12 g0/0/21
[SW1-port-group]port link-type trunk
[SW1-port-group]port trunk allow-pass vlan all
SW2配置:
[SW2]vlan batch 10 20 30 40
[SW2]port-group group-member g0/0/12 g0/0/21 to g0/0/23
[SW2-port-group]port link-type trunk
[SW2-port-group]port trunk allow-pass vlan all
SW3配置:
[SW3]vlan batch 10 20 30 40
[SW3]int g0/0/5
[SW3-GigabitEthernet0/0/5]port link-type access
[SW3-GigabitEthernet0/0/5]port default vlan 40
[SW3-GigabitEthernet0/0/5]int g0/0/23
[SW3-GigabitEthernet0/0/23]port link-type trunk
[SW3-GigabitEthernet0/0/23]port trunk allow-pass vlan all
SW4配置:
[SW4]vlan batch 10 20 30 40 12 23
[SW4]int e0/0/2
[SW4-Ethernet0/0/2]port link-type access
[SW4-Ethernet0/0/2]port default vlan 20
[SW4-Ethernet0/0/2]int e0/0/3
[SW4-Ethernet0/0/3]port link-type access
[SW4-Ethernet0/0/3]port default vlan 10
[SW4-Ethernet0/0/3]quit
[SW4]port-group group-member g0/0/1 g0/0/2 e0/0/22
[SW4-port-group]port link-type trunk
[SW4-Ethernet0/0/22]port link-type trunk
[SW4-port-group]port trunk allow-pass vlan all
[SW4-Ethernet0/0/22]port trunk allow-pass vlan all
SW5配置:
[SW5]vlan batch 10 20 30 40 12 23
[SW5]int e0/0/4
[SW5-Ethernet0/0/4]port link-type access
[SW5-Ethernet0/0/4]port default vlan 30
[SW5-Ethernet0/0/4]quit
[SW5]port-group group-member g0/0/1 e0/0/22
[SW5-port-group]port link-type trunk
[SW5-port-group]port trunk allow-pass vlan all
第三步:配置vlanif虚接口IP地址,做vlan内主机的网关,并实现直连路由
SW1配置:
[SW1]int vlanif 10
[SW1-Vlanif10]ip address 192.168.10.254 24
SW2配置:
[SW2]int vlanif 20
[SW2-Vlanif20]ip address 192.168.20.254 24
SW3配置:
[SW3]int vlanif 30
[SW3-Vlanif30]ip address 192.168.30.254 24
[SW3-Vlanif30]int vlanif 40
[SW3-Vlanif40]ip address 192.168.40.254 24
第四步:配置静态路由,实现所有PC之间的互通(vlan间通信)
SW1配置:
[sw1]vlan batch 12 23
[sw1]interface vlanif 12
[sw1-vlanif12]ip address 192.168.12.1 24
[sw1-vlanif12]quit
[sw1]ip route-static 192.168.20.0 24 192.168.12.2
[sw1]ip route-static 192.168.30.0 24 192.168.12.2
[sw1]ip route-static 192.168.40.0 24 192.168.12.2
SW2配置:
[sw2]vlan batch 12 23
[sw2]interface vlanif 12
[sw2-vlanif12]ip address 192.168.12.2 24
[sw2]interface vlanif 23
[sw2-vlanif23]ip address 192.168.23.2 24
[sw2-vlanif23]quit
[sw2]ip route-static 192.168.10.0 24 192.168.12.1
[sw2]ip route-static 192.168.30.0 24 192.168.23.3
[sw2]ip route-static 192.168.40.0 24 192.168.23.3
SW3配置:
[sw3]vlan batch 12 23
[sw3]interface vlanif 23
[sw3-vlanif23]ip address 192.168.23.3 24
[sw3-vlanif23]quit
[sw3]ip route-static 192.168.10.0 24 192.168.23.2
[sw3]ip route-static 192.168.20.0 24 192.168.23.2
SW4配置:(保证6个vlan10/20/30/40/12/23在每一个交换机都存在)
[sw4]vlan batch 12 23
SW5配置:(保证6个vlan10/20/30/40/12/23在每一个交换机都存在)
[sw5]vlan batch 12 23
备注:
保证这6个vlan10/20/30/40/12/23在每一个交换机都存在
做trunk的接口都允许所有vlan通过 port trunk allow-pass vlan all
第五步:测试与验证:
PC1 ping PC2/3/4/5 都可用互通
PC2 ping PC1/3/4/5 都可用互通
```