HCNP-路由交换:交换机基础

1. 基本配置

A. 查看MAC表

<Huawei>dis mac-address
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address    VLAN/       PEVLAN CEVLAN Port            Type      LSP/LSR-ID  
               VSI/SI                                              MAC-Tunnel  
-------------------------------------------------------------------------------
5489-982e-0171 1           -      -      Eth0/0/2        dynamic   0/-         
5489-986c-4022 1           -      -      Eth0/0/1        dynamic   0/-         
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 2

B. 设置ARP表老化时间

<Huawei>sys
//设置arp老化时间为200秒
[Huawei]mac-address aging-time 200

C. 配置端口的速率和工作模式

[Huawei]int e0/0/1
//关闭端口自动协商	
[Huawei-Ethernet0/0/1]undo negotiation auto
//设定端口速率为10M
[Huawei-Ethernet0/0/1]speed 10
//设定端口速率为100M
[Huawei-Ethernet0/0/1]speed 100
//设置端口工作模式为全双工
[Huawei-Ethernet0/0/1]duplex full
//设置端口工作模式为半双工
[Huawei-Ethernet0/0/1]duplex half

D. 设置端口描述

[Huawei]int eth0/0/1
//描述的内容为“TO-SW2-E0/0/1”
[Huawei-Ethernet0/0/1]description TO-SW2-E0/0/1

E. 清空端口配置

[Huawei]clear configuration int eth0/0/1
Warning: All configurations of the interface will be cleared, and its state will
 be shutdown. Continue? [Y/N] :y
Info: Total execute 2 command(s), 2 successful, 0 failed.

2. VLAN

A. 配置单个VLAN

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
//创建vlan 10
[Huawei]vlan 10
//设置描述为“财务”	
[Huawei-vlan10]description caiwu
//创建vlan 20
[Huawei-vlan10]vlan 20
//设置描述为“销售”	
[Huawei-vlan20]description xiaoshou

B. 批量配置vlan

[Huawei]vlan batch 30 to 35 40 to 43
Info: This operation may take a few seconds. Please wait for a moment...done.
//查看vlan
[Huawei]dis vlan 
The total number of vlans is : 13
--------------------------------------------------------------------------------
U: Up;         D: Down;         TG: Tagged;         UT: Untagged;
MP: Vlan-mapping;               ST: Vlan-stacking;
#: ProtocolTransparent-vlan;    *: Management-vlan;
--------------------------------------------------------------------------------

VID  Type    Ports                                                          
--------------------------------------------------------------------------------
1    common  UT:Eth0/0/1(U)     Eth0/0/2(U)     Eth0/0/3(U)     Eth0/0/4(D)     
                Eth0/0/5(D)     Eth0/0/6(D)     Eth0/0/7(D)     Eth0/0/8(D)     
                Eth0/0/9(D)     Eth0/0/10(D)    Eth0/0/11(D)    Eth0/0/12(D)    
                Eth0/0/13(D)    Eth0/0/14(D)    Eth0/0/15(D)    Eth0/0/16(D)    
                Eth0/0/17(D)    Eth0/0/18(D)    Eth0/0/19(D)    Eth0/0/20(D)    
                Eth0/0/21(D)    Eth0/0/22(D)    GE0/0/1(D)      GE0/0/2(D)      

10   common  
20   common  
30   common  
31   common  
32   common  
33   common  
34   common  
35   common  
40   common  
41   common  
42   common  
43   common  

VID  Status  Property      MAC-LRN Statistics Description      
--------------------------------------------------------------------------------

1    enable  default       enable  disable    VLAN 0001                         
10   enable  default       enable  disable    caiwu                             
20   enable  default       enable  disable    xiaoshou                          
30   enable  default       enable  disable    VLAN 0030                         
31   enable  default       enable  disable    VLAN 0031                         
32   enable  default       enable  disable    VLAN 0032                         
33   enable  default       enable  disable    VLAN 0033                         
34   enable  default       enable  disable    VLAN 0034                         
35   enable  default       enable  disable    VLAN 0035                         
40   enable  default       enable  disable    VLAN 0040                         
41   enable  default       enable  disable    VLAN 0041                         
42   enable  default       enable  disable    VLAN 0042                         
43   enable  default       enable  disable    VLAN 0043
//删除vlan
[Huawei]undo vlan batch 40 to 43
Warning: The configurations of the VLAN will be deleted. Continue?[Y/N]:Y
Info: This operation may take a few seconds. Please wait for a moment...done.

3. 链路类型

A. acess:接入模式。主要时交换机连接终端设备的接口。只能允许唯一的vlan ID通过本接口。
access端口收发数据帧的原则:
收——如果该端口收到对端发送的不带标签的帧,交换机会加上端口所处的PVID。如果该端口收到对端发送的带标签的帧,则会检查该标签的VLAN ID,当该VLAN ID与该端口的PVID相同,则接收该帧;否则丢弃该帧。
发——判断是否和自己的VLAN ID相同,若相同则剥离VLAN ID标签,再重新发送。
access端口发往对端的以太网帧,永远是不带标签的帧。

//进入eth0/0/1端口
[Huawei]int eth0/0/1
//设置链路类型为 access
[Huawei-Ethernet0/0/1]port link-type access 
//设置允许的 vlan 为10
[Huawei-Ethernet0/0/1]port default vlan 10
//查看端口对应的vlan
[Huawei]dis port vlan
Port                    Link Type    PVID  Trunk VLAN List
-------------------------------------------------------------------------------
Ethernet0/0/1           access       10    -

B. Trunk:干道链路。交换机与交换机之间连接的接口。允许多个vlan(带tag帧)通过本接口。
Trunk端口收发数据帧的原则:
收——当接收到对端设备发送的不带标签的数据帧,交换机会加上该端口所处的PVID,如果该PVID在端口允许通过的VLAN ID列表中,则接收该报文,否则丢弃该报文。当接收到对端设备发送的带标签的数据帧,检查VLAN ID是否在允许通过的VLAN ID列表中,若在则接收该帧,否则丢弃该帧。
发——当VLAN ID与端口的PVID相同,且在允许通过的VLAN ID列表中,则剥离去掉VLAN ID。当VLAN ID 与端口的PVID不同,但在允许通过的VLAN ID列表中,则保持原有的VLAN ID,发送该帧。

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int e0/0/3
//将端口类型改为Trunk
[Huawei-Ethernet0/0/3]port link-type trunk 
//允许Trunk 端口通过的VLAN。
[Huawei-Ethernet0/0/3]port trunk allow-pass vlan 2 to 4094
//安全起见,禁用默认的VLAN 1
[Huawei-Ethernet0/0/3]undo port trunk allow-pass vlan 1

本征VLAN——本征VLAN在Trunk链路上不带标记,交换机收到不带标记的帧的时候,将会发到本帧VLAN

//先要创建vlan
[Huawei]vlan batch 90 to 100
[Huawei]int e0/0/3
//设置Trunk端口的本征vlan
[Huawei-Ethernet0/0/3]port trunk pvid vlan 100

推荐:把Trunk的本征VLAN设置不常用的VLAN;把交换机上不常用的端口设置不常用的VLAN且把端口shutdown。Trunk链路最好只允许相对应的vlan。
C. Hybrid:既可以连接终端又可以连接交换机。

Hybrid端口收发规则:
收——当接收到对端设备发送的不带标签的数据帧时,会添加端口的PVID,如果PVID在允许通过的列表中,则接收该报文,否则丢弃该报文。当接收到对端设备发送的带标签的数据帧时,检查VLAN ID是否在允许通过的列表中,若在接收该报文,否则丢弃该报文。
发——Hybrid端口发送数据帧时,检查该端口是否允许该VLAN通过,如果允许通过则通过命令设置是否携带标签。

a. 配置port hybrid tagged vlan vlan_id 命令后,接口发送该vlan_id数据帧后,不剥离帧中的vlan标签,直接发送。该命令一般配置在连接交换机的端口上。

b. 配置port hybrid untagged vlan vlan_id 命令后,接口发送该vlan_id数据帧后,会将vlan标签剥离后再发送。该命令一般配置在连接终端的端口上。
SW1的配置:

<Huawei>sys
[Huawei]sysname sw1
//创建vlan 2和 vlan 3
[sw1]vlan batch 2 to 3
[sw1]clear configuration int e0/0/1
[sw1]clear configuration int e0/0/2
[sw1]clear configuration int e0/0/3
//设置e0/0/1端口
[sw1]int e0/0/1
//设置端口类型为Hybrid
[sw1-Ethernet0/0/1]undo shutdown
[sw1-Ethernet0/0/1]port link-type hybrid 
//将端口划到vlan 2
[sw1-Ethernet0/0/1]port hybrid pvid vlan 2
//设置给帧剥离vlan 2的标签
[sw1-port-group-hybrid]port hybrid untagged vlan 2
[sw1-port-group-hybrid]q
//配置e0/0/2端口
[sw1]int e0/0/2
[sw1-Ethernet0/0/2]undo shutdown
//设置端口类型为Hybrid
[sw1-Ethernet0/0/2]port link-type hybrid 
//将端口划到vlan 3	
[sw1-Ethernet0/0/2]port hybrid pvid vlan 3
//设置给帧剥离vlan 3的标签
[sw1-Ethernet0/0/2]port hybrid untagged vlan 3
[sw1-Ethernet0/0/2]q
//配置端口e0/0/3
[sw1]int e0/0/3
[sw1-Ethernet0/0/3]undo shutdown
//设置端口类型为Hybrid
[sw1-Ethernet0/0/3]port link-type hybrid 
//设置帧不剥离vlan 2的标签和vlan 3的标签
[sw1-Ethernet0/0/3]port hybrid tagged vlan 2
[sw1-Ethernet0/0/3]port hybrid tagged vlan 3

SW2配置:

<Huawei>sys
[Huawei]clear configuration int e0/0/1
[Huawei]clear configuration int e0/0/2
[Huawei]clear configuration int e0/0/3
[Huawei]sysname sw2
[sw2]vlan batch 2 to 3
//配置端口e0/0/1
[sw2]int e0/0/1
[sw2-Ethernet0/0/1]undo shutdown
[sw2-Ethernet0/0/1]port link-type hybrid
[sw2-Ethernet0/0/1]port hybrid pvid vlan 2
[sw2-Ethernet0/0/1]port hybrid untagged vlan 2
//配置端口e0/0/2
[sw2-Ethernet0/0/1]int e0/0/2
[sw2-Ethernet0/0/2]undo shutdown
[sw2-Ethernet0/0/2]port link-type hybrid
[sw2-Ethernet0/0/2]port hybrid pvid vlan 3
[sw2-Ethernet0/0/2]port hybrid untagged vlan 3
//配置端口e0/0/3
[sw2-Ethernet0/0/2]int e0/0/3
[sw2-Ethernet0/0/2]undo shutdown
[sw2-Ethernet0/0/3]port link-type hybrid
[sw2-Ethernet0/0/3]port hybrid tagged vlan 2
[sw2-Ethernet0/0/3]port hybrid tagged vlan 3

用PC1测试:

PC>ping 192.168.1.2

Ping 192.168.1.2: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable

--- 192.168.1.2 ping statistics ---
  5 packet(s) transmitted
  0 packet(s) received
  100.00% packet loss

PC>ping 192.168.1.3

Ping 192.168.1.3: 32 data bytes, Press Ctrl_C to break
From 192.168.1.3: bytes=32 seq=1 ttl=128 time=62 ms
From 192.168.1.3: bytes=32 seq=2 ttl=128 time=78 ms
From 192.168.1.3: bytes=32 seq=3 ttl=128 time=94 ms
From 192.168.1.3: bytes=32 seq=4 ttl=128 time=94 ms
From 192.168.1.3: bytes=32 seq=5 ttl=128 time=62 ms

--- 192.168.1.3 ping statistics ---
  5 packet(s) transmitted
  5 packet(s) received
  0.00% packet loss
  round-trip min/avg/max = 62/78/94 ms

PC>ping 192.168.1.4

Ping 192.168.1.4: 32 data bytes, Press Ctrl_C to break
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable
From 192.168.1.1: Destination host unreachable

--- 192.168.1.4 ping statistics ---
  5 packet(s) transmitted
  0 packet(s) received
  100.00% packet loss

你可能感兴趣的:(路由交换)