Cisco 的基本配置实例之四----vlan的规划及配置(接入交换机)

Posted 狙击手 ▄︻┻═┳一

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了Cisco 的基本配置实例之四----vlan的规划及配置(接入交换机)相关的知识,希望对你有一定的参考价值。

4.2 接入交换机的相关配置

## 在此例中,我们联入的是一台接入交换机,此交换机的gi0/1口上联至核心交换机。也就意味着我们需要配置gi0/1为trunk口。具体的配置如下:

D-2960-3(config)#int gi0/1

D-2960-3(config-if)#sw

D-2960-3(config-if)#switchport mo

D-2960-3(config-if)#switchport mode ?

  access   Set trunking mode to ACCESS unconditionally

  dynamic  Set trunking mode to dynamically negotiate access or trunk mode

  trunk    Set trunking mode to TRUNK unconditionally

D-2960-3(config-if)#switchport mode trunk      

## 配置此接口的模式为trunk,在cisoc2960交换机中,配置完接口模式为trunk后就可以了,不需要进一步配置此trunk口的封装状态,因为其默认的也是唯一的封装类型就是dot1q,并且此系列交换机并没有专门的封装配置命令。

 

D-2960-3(config-if)#exit

D-2960-3(config)#exit

D-2960-3#sh int tru                     # 退至特权配置模式验证一下刚才的配置

 

Port        Mode         Encapsulation  Status        Native vlan

Gi0/1       auto         802.1q         trunking      1                   

# 这个端口已经配置成trunk模式,并且封装成802.1q了

Port        Vlans allowed on trunk

Gi0/1       1-4094

 

Port        Vlans allowed and active in management domain

Gi0/1       1-2,10,20,30,40,50,60,70,80,100,110,120,150,160

 

Port        Vlans in spanning tree forwarding state and not pruned

Gi0/1       1-2,10,20,30,40,50,60,70,80,100,110,120,150,160

 

D-2960-3#conf t                                                     # 进入到全局配置模式

 

D-2960-3(config)#vtp mode client            

# 配置vtp模式为client,与核心交换机的server模式相呼应。

D-2960-3(config)#vtp domain pjoe            

# 配置vtp域为pjoe,只有一个域中的交换机才能互传vlan信息。

D-2960-3(config)#vtp password pjoeserver                # 配置vtp密码

D-2960-3(config)#end

 

D-2960-3#sh vtp status                              # 退出到特权模式验证一下刚才的有关vtp的配置

VTP Version                       : 2

Configuration Revision                : 23

Maximum VLANs supported locally    : 255

Number of existing VLANs           : 19

VTP Operating Mode              : Client            # 模式已经设置成client

VTP Domain Name                 : pjoe             # 域名已经设置成pjoe

VTP Pruning Mode                : Disabled

VTP V2 Mode                     : Disabled

VTP Traps Generation                : Disabled

MD5 digest                      : 0xEC 0x30 0xEF 0x6F 0xA5 0x9A 0x39 0x7B

# 密码已经配置完毕,但是被加密显示了

Configuration last modified by 192.168.113.254 at 12-3-07 22:58:54

 

##稍等一会后,验证一下是否学习到了核心交换机的vlan信息,它的学习有一小段的过程30秒的样子。

 

D-2960-3#sh vlan                                                    # 验证一下vlan信息是否全部学到。

 

VLAN Name                             Status    Ports

---- -------------------------------- --------- -------------------------------

1    default                                active    Fa0/1, Fa0/2, Fa0/3, Fa0/4, Fa0/5, Fa0/6, Fa0/7, Fa0/8, Fa0/9, Fa0/10, Fa0/11,Fa0/12, Fa0/13, Fa0/14, Fa0/15, Fa0/16, Fa0/17, Fa0/18, Fa0/19, Fa0/20, Fa0/21,Fa0/22, Fa0/23, Fa0/24, Fa0/25, Fa0/26, Fa0/27, Fa0/28, Fa0/29, Fa0/30, Fa0/31,Fa0/32, Fa0/33, Fa0/34, Fa0/35, Fa0/36, Fa0/37, Fa0/38, Fa0/39, Fa0/40, Fa0/41,a0/42, Fa0/43, Fa0/44, Fa0/45, Fa0/46, Fa0/47, Fa0/48, Gi0/2

2    firewall                                active   

# ok,核心交换机上配置好的vlan信息已经被这台交换机学习到了,剩下的工作仅需要将相应的端口添加到相应的vlan中就可以了,此处不赘述。   

10   Engineering                            active     

20   Procurement                           active   

30   QAQC                             active   

40   Operation                             active   

50   Yard                                 active   

60   BM                                 active   

70   HRAD                             active   

80   Facility                                active   

100  Finance                               active   

110  GO                                 active   

120  Wlan                                active   

150  Server                                active   

160  Client                                 active   

1002 fddi-default                              act/unsup

1003 token-ring-default                         act/unsup

1004 fddinet-default                            act/unsup

1005 trnet-default                              act/unsup

 

VLAN Type  SAID       MTU   Parent RingNo BridgeNo Stp  BrdgMode Trans1 Trans2

---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------

1    enet  100001     1500  -      -      -        -    -        0      0  

2    enet  100002     1500  -      -      -        -    -        0      0  

10   enet  100010     1500  -      -      -        -    -        0      0  

20   enet  100020     1500  -      -      -        -    -        0      0  

30   enet  100030     1500  -      -      -        -    -        0      0  

40   enet  100040     1500  -      -      -        -    -        0      0  

50   enet  100050     1500  -      -      -        -    -        0      0  

60   enet  100060     1500  -      -      -        -    -        0      0  

70   enet  100070     1500  -      -      -        -    -        0      0  

80   enet  100080     1500  -      -      -        -    -        0      0  

100  enet  100100     1500  -      -      -        -    -        0      0  

110  enet  100110     1500  -      -      -        -    -        0      0  

120  enet  100120     1500  -      -      -        -    -        0      0  

150  enet  100150     1500  -      -      -        -    -        0      0  

160  enet  100160     1500  -      -      -        -    -        0      0  

1002 fddi  101002     1500  -      -      -        -    -        0      0

D-2960-3#

# 配置这台交换机的管理IP

D-2960-3(config)#int vlan 1                                            # 管理ip地址我们配置在vlan1上

D-2960-3(config-if)#ip address 192.168.113.222 255.255.255.0 # 设置实际的ip地址

D-2960-3(config-if)#exit

D-2960-3(config)#ip default-gateway 192.168.113.254     

# 设置这台交换机的网关,此地址即为核心交换机vlan1的地址。

 

D-2960-3(config)#end

D-2960-3#sh run                  # 验证一下完整的配置。

Building configuration...

 

Current configuration : 2087 bytes

!

version 12.2

no service pad

service timestamps debug uptime

service timestamps log uptime

service password-encryption

!

hostname D-2960-3

!

enable password 7 12090F18170805172924

!

no aaa new-model

system mtu routing 1500

ip subnet-zero

!

no file verify auto

spanning-tree mode pvst

spanning-tree extend system-id

!

vlan internal allocation policy ascending

!

interface FastEthernet0/1

!

interface FastEthernet0/2

!

interface FastEthernet0/3

!

(省略… …)

interface FastEthernet0/45

!

interface FastEthernet0/46

!

interface FastEthernet0/47

!

interface FastEthernet0/48

!

interface GigabitEthernet0/1

!

interface GigabitEthernet0/2

!

interface Vlan1

 ip address 192.168.113.222 255.255.255.0

 no ip route-cache

!

ip default-gateway 192.168.113.254

ip http server

!

control-plane

!

!

line con 0

 password 7 12090F18170805172924

line vty 0 4

 password 7 12090F18170805172924

 login

line vty 5 15

 login

!

end

D-2960-3#  

以上是关于Cisco 的基本配置实例之四----vlan的规划及配置(接入交换机)的主要内容,如果未能解决你的问题,请参考以下文章

Cisco交换机VLAN与TRUNK链路配置命令

Cisco3550配置作为DHCP服务器工程实例

Cisco dhcp snooping实例1-单交换机(DHCP服务器和DHCP客户端位于同一VLAN)

Cisco dhcp snooping实例3-多交换机环境(DHCP服务器和DHCP客户端位于同VLAN)

Cisco dhcp snooping实例3-多交换机环境(DHCP服务器和DHCP客户端位于同VLAN)

Cisco dhcp snooping实例2-多交换机环境(DHCP服务器和DHCP客户端位于不同VLAN)