思科三层交换配置清单与案例


网络基本情况
网络拓扑结构为:中心交换机采用cisco catalyst 4006-s3,supervisor engine iii g引擎位于第1插槽,用于实现三层交换;1块24口1000base-t模块位于第2插槽,用于连接网络服务器;1块6端口1000base-x模块位于第3插槽,用于连接6台骨干交换机。一台交换机采用cisco catalyst 3550-24-emi,并安装1块1000base-x gbic千兆模块。一台交换机采用cisco catalyst 3550-24-smi,也安装1块1000base-x gbic千兆模块。另外四台交换机采用cisco catalyst 2950g-24-smi,安装1块1000base-t gbic千兆模块。所有服务器划分为一个vlan,即vlan 50。四台catalyst 2950g-24-smi交换机也只划分为一个vlan,分别为vlan 60、vlan 70、vlan 80和vlan 90。

catalyst 3550-24-emi划分为4个vlan,分别为vlan 10、vlan 20、vlan 30和vlan 40。catalyst 3550-24-smi划分2个vlan,分别为vlan 60和vlan 80,与另外两台catalyst 2950g-24-smi交换机分别位于同一vlan。

实例分析

由于所有catalyst 2950g交换机都是一个独立的vlan,因此,必须先在这些交换机上创建vlan(vlan 60~vlan 90),并将所有端口都指定至该vlan。然后,再在catalyst 4006交换机相应端口上分别创建vlan。catalyst 4006的1000base-x端口分别与各catalyst 2950g的1000base-x端口连接。其中,

gigabitethernet3/2端口连接至1号catalyst 2950交换机(vlan 60),gigabitethernet3/3端口连接至2号catalyst 2950交换机(vlan 70),gigabitethernet3/4端口连接至3号catalyst 2950交换机(vlan 80),gigabitethernet3/5端口连接至4号catalyst 2950交换机(vlan 90),gigabitethernet3/6端口连接至6号楼交换机(vlan 80)。由于在catalyst 3550-24-emi上划分有4个vlan(vlan 10~vlan 40),而4个vlan都需借助于一条1000base-x链路实现与catalyst 4006的gigabitethernet3/1端口连接,因此,必须在catalyst 4006与catalyst 3550-24- emi之间创建一个trunk。

同样,在catalyst 3550-24-smi上划分有2个vlan(vlan 60和vlan 80),而4个vlan都需借助于一条1000base-x链路实现与catalyst 4006的gigabitethernet3/6端口连接,因此,必须在catalyst 4006与catalyst 3550-24- emi之间创建一个trunk。

另外,所有服务器均连接至catalyst 4006的1000base-t模块,并单独成为一个vlan(vlan 90),因此,也必须为这些交换机创建一个vlan,并将所有端口指定至该vlan。需要注意的是,考虑到网络管理的需要,也可以剩余几个rj-45端口 (如21至24端口)不指定至任何vlan,从而便于连接网络管理设备。默认状态下,所有端口都属于vlan1,而且也只有在vlan1中才能实现对网络中所有设备的管理。

配置清单

●cisco catalyst 4006交换机配置清单


current c : 5594 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service compress-c
!
hostname hsnc
!
boot system bootflash:cat4000-is-mz.121-8a.ew1.bin
no logging c
enable secret level 1 5 $1$rkqw$1hkykdn5f.ri5zxeof8yv/
!
ip subnet-zero
!
!
!
interface gigabitethernet1/1
no snmp trap link-status
!--不为supervisor engine iii g引擎中的1000base-x插槽指定vlan
interface gigabitethernet1/2
no snmp trap link-status
!
!
interface gigabitethernet2/1
switchport access vlan 50
no snmp trap link-status
!--将端口gigabitethernet2/1指定至vlan 50
!
interface gigabitethernet2/2
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/3
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/4
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/5
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/6
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/7
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/8
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/9
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/10
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/11
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/12
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/13
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/14
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/15
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/16
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/17
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/18
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/19
switchport access vlan 50
no snmp trap link-status
!
interface gigabitethernet2/20
switchport access vlan 50
no snmp trap link-status
!--不将gigabitethernet2/20~24指定至任何vlan
!interface gigabitethernet3/1
switchport trunk encapsulation dot1q
!--启用802.1q trunk封装协议,即在该端口创建trunk
switchport trunk allowed vlan 1-80
!--允许vlan 1-90在该中继线通讯
!--可以拒绝或允许某个vlan访问该trunk
!--确保未被授权的vlan通过该trunk,实现vlan的访问安全
switchport mode trunk
!--将该端口设置为trunk
description netcenter
no snmp trap link-status
!
interface gigabitethernet3/2
switchport access vlan 60
no snmp trap link-status
!--将端口gigabitethernet3/2指定至vlan 60
!
interface gigabitethernet3/3
switchport access vlan 70
no snmp trap link-status
!--将端口gigabitethernet3/3指定至vlan 70
!
interface gigabitethernet3/4
switchport access vlan 80
no snmp trap link-status
!--将端口gigabitethernet3/4指定至vlan 80
!
interface gigabitethernet3/5
switchport access vlan 90
no snmp trap link-status
!--将端口gigabitethernet3/5指定至vlan 90
!
interface gigabitethernet3/6
switchport trunk encapsulation dot1q
!--启用802.1q trunk封装协议,即在该端口创建trunk
switchport trunk allowed vlan 1-80
!--允许vlan 1-90在该中继线通讯
!--可以拒绝或允许某个vlan访问该trunk
!--从而确保未被授权的vlan通过该trunk,实现vlan访问安全
switchport mode trunk
!--将该端口设置为trunk
description netcenter
no snmp trap link-status
!
interface vlan1
description netmanger
no ip address
!
!--对vlan1进行描述
interface vlan10
description network center
no ip address
!--对vlan2进行描述
!
interface vlan20
description computer center
no ip address
!
interface vlan30
description network lab
no ip address
!
interface vlan40
description huaxuelou
no ip address
!
interface vlan50
description wulilou
no ip address
!
interface vlan60
description shengwulou
no ip address
!interface vlan70
description zh
no ip address
!
interface vlan80
description tushuguan
no ip address
!
!
line con 0
stopbits 1
line vty 0 4
password aaa
login
!
end

cisco catalyst 3550-emi配置清单



building configuration...
current c : 4055 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname office
!
enable secret 5 $1$p0fu$jeypom0rul.fqfe71efhf1
!
ip subnet-zero
!
!
spanning-tree extend system-id
!
!
!
interface fastethernet0/1
switchport access vlan 10
!--将端口fastethernet0/1指定至vlan 10
no ip address
!
interface fastethernet0/2
switchport access vlan 10
no ip address
!
interface fastethernet0/3
switchport access vlan 10
no ip address
!
interface fastethernet0/4
switchport access vlan 10
no ip address
!
interface fastethernet0/5
switchport access vlan 10
no ip address
!
interface fastethernet0/6
switchport access vlan 20
no ip address
!--将端口fastethernet0/6指定至vlan 20
!interface fastethernet0/7
switchport access vlan 20
no ip address
!
interface fastethernet0/8
switchport access vlan 20
no ip address
!
interface fastethernet0/9
switchport access vlan 20
no ip address
!
interface fastethernet0/10
switchport access vlan 20
no ip address
!
interface fastethernet0/11
switchport access vlan 30
no ip address
!--将端口fastethernet0/6指定至vlan 30
!
interface fastethernet0/12
switchport access vlan 30
no ip address
!
interface fastethernet0/13
switchport access vlan 30
no ip address
!
interface fastethernet0/14
switchport access vlan 30
no ip address
!
nterface fastethernet0/15
switchport access vlan 30
no ip address
!
interface fastethernet0/16
switchport access vlan 30
no ip address
!
interface fastethernet0/17
switchport access vlan 30
no ip address
!
interface fastethernet0/18
switchport access vlan 30
no ip address
!
interface fastethernet0/19
switchport access vlan 40
ip address
!--将端口fastethernet0/6指定至vlan 40
!interface fastethernet0/20
witchport access vlan 40
no ip address
!
interface fastethernet0/21
switchport access vlan 40
no ip address
!
interface fastethernet0/22
switchport access vlan 30
no ip address
!
interface fastethernet0/23
switchport access vlan 40
no ip address
!
interface fastethernet0/24
switchport access vlan 40
no ip address
!
interface gigabitethernet0/1
switchport trunk encapsulation dot1q
!--启用802.1q trunk封装协议,即在该端口创建trunk
switchport trunk allowed vlan 1-80
!--允许vlan 1-80在该中继线通讯
itchport mode trunk
!--将该端口设置为trunk
no ip address
!
interface gigabitethernet0/2
no ip address
!
interface vlan1
ip address 172.16.100.12 255.255.255.0
!--lan1指定ip地址
no ip route-cache
no ip mroute-cache
!
ip classless
ip http server
!
!
!
!
line con 0
line vty 0 4
password aaa
login
line vty 5 15
login
!
end
cisco catalyst 3550-smi配置清单



building configuration...
current c : 4055 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname office
!
enable secret 5 $1$p0fu$jeypom0rul.fqfe71efhf1
!
ip subnet-zero
!
!
spanning-tree extend system-id
!
!
!
interface fastethernet0/1
switchport access vlan 60
!--将端口fastethernet0/1指定至vlan 60
no ip address
!
interface fastethernet0/2
switchport access vlan 60
no ip address
!
interface fastethernet0/3
switchport access vlan 60
no ip address
!
interface fastethernet0/4
switchport access vlan 60
no ip address
!
interface fastethernet0/5
switchport access vlan 60
no ip address
!
interface fastethernet0/6
switchport access vlan 20
no ip address
!--将端口fastethernet0/6指定至vlan 20
!interface fastethernet0/7
switchport access vlan 20
no ip address
!
interface fastethernet0/8
switchport access vlan 20
no ip address
!
interface fastethernet0/9
switchport access vlan 20
no ip address
!
interface fastethernet0/10
switchport access vlan 20
no ip address
!
interface fastethernet0/11
switchport access vlan 80
no ip address
!--将端口fastethernet0/6指定至vlan 80
!
interface fastethernet0/12
switchport access vlan 80
no ip address
!
interface fastethernet0/13
switchport access vlan 80
no ip address
!
interface fastethernet0/14
switchport access vlan 80
no ip address
!
interface fastethernet0/15
switchport access vlan 80
no ip address
interface fastethernet0/16
switchport access vlan 80
no ip address
!
interface fastethernet0/17
switchport access vlan 80
no ip address
!
interface fastethernet0/18
switchport access vlan 80
no ip address
!
interface fastethernet0/19
switchport access vlan 80
no ip address
!--将端口fastethernet0/6指定至vlan 80
!interface fastethernet0/20
switchport access vlan 80
no ip address
!
interface fastethernet0/21
switchport access vlan 80
no ip address
!
interface fastethernet0/22
switchport access vlan 80
no ip address
!
interface fastethernet0/23
switchport access vlan 80
no ip address
!
interface fastethernet0/24
switchport access vlan 80
no ip address
!
interface gigabitethernet0/1
switchport trunk encapsulation dot1q
!--启用802.1q trunk封装协议,即在该端口创建trunk
switchport trunk allowed vlan 1-80
!--允许vlan 1-80在该中继线通讯
switchport mode trunk
!--从将该端口设置为trunk
no ip address
!
interface gigabitethernet0/2
no ip address
!
interface vlan1
ip address 172.16.100.13 255.255.255.0
!--为lan1指定ip地址
no ip route-cache
no ip mroute-cache
!
ip classless
ip http server
!
!
!
!
line con 0
line vty 0 4
password aaa
login
line vty 5 15
login
!
end

cisco catalyst 2950g配置清单
四台cisco catalyst 2950g的配置基本相同,下面仅列出vlan 60的配置情况。




building configuration...
current c : 2143 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname msl
!
enable password aaa
!
ip subnet-zero
!
!
spanning-tree extend system-id
!
!
interface fastethernet0/1
switchport access vlan 60
no ip address
!
interface fastethernet0/2
switchport access vlan 60
no ip address
!
interface fastethernet0/3
switchport access vlan 60
no ip address
!
interface fastethernet0/4
switchport access vlan 60
no ip address
!
interface fastethernet0/5
switchport access vlan 60
no ip address
!
interface fastethernet0/6
switchport access vlan 60
no ip address
!
interface fastethernet0/7
switchport access vlan 60
no ip address
!
interface fastethernet0/8
switchport access vlan 60
no ip address
!
interface fastethernet0/9
switchport access vlan 60
no ip address
!
interface fastethernet0/10
switchport access vlan 60
no ip address
!
interface fastethernet0/11
switchport access vlan 60
no ip address
!interface fastethernet0/12
switchport access vlan 60
no ip address
!
interface fastethernet0/13
switchport access vlan 60
no ip address
!
interface fastethernet0/14
switchport access vlan 60
no ip address
!
interface fastethernet0/15
switchport access vlan 60
no ip address
!
interface fastethernet0/16
switchport access vlan 60
no ip address
!
interface fastethernet0/17
switchport access vlan 60
no ip address
!
interface fastethernet0/18
switchport access vlan 60
no ip address
!
interface fastethernet0/19
switchport access vlan 60
no ip address
!
interface fastethernet0/20
switchport access vlan 60
no ip address
!
interface fastethernet0/21
switchport access vlan 60
no ip address
!
interface fastethernet0/22
switchport access vlan 60
no ip address
!
interface fastethernet0/23
switchport access vlan 60
no ip address
!
interface fastethernet0/24
switchport access vlan 60
no ip address
!
interface gigabitethernet0/1
no ip address
!
interface gigabitethernet0/2
no ip address
!
interface vlan1
ip address 172.16.100.10 255.255.255.0
!
ip classless
ip http server
!
!
!
!
line con 0
line vty 0 4
password aaa
login
line vty 5 15
login
!
end
以下内容 ancy 由撰写

经典的三层网络案例分析。改进中。。。新加很多先进技术噢!新增路由器的配置。

经典的三层网络案例分析。

目的:让不同的vlan 之间可以互相通讯。

ip规划

vlna id ip网段 vlan网关




vlan 1 172.16.1.0/24 172.16.1.7-9
vlan 2 172.16.2.0/24 172.16.2.252-254
vlan 3 172.16.3.0/24 172.16.3.252-254
vlan 4 172.16.4.0/24 172.16.4.252-254
vlan 5 172.16.5.0/24 172.16.5.252-254
vlan 6 172.16.6.0/24 172.16.6.252-254
vlan 7 172.16.7.0/24 172.16.7.252-254
vlan 8 172.16.8.0/24 172.16.8.252-254
vlan 9 172.16.9.0/24 172.16.9.252-254

拓朴图见最后面

器配置

cisco路由器配置:


enable
c terminal
service password-encryption
hostname cisco1721
enable secret 654321
enable password 123456
ip subnet-zero
ip name-server 202.96.134.133 202.96.172.218
interface fastethernet 0
ip address 61.142.221.5 255.255.255.240
speed auto
no shutdown
interface serial 0
ip unnumbered fastethernet 0
encapsulation ppp
no fair-queue
bandwidth 2048
no shutdown
exit
ip classless
ip route 0.0.0.0 0.0.0.0 serial 0
no ip http server
line con 0
line aux 0
line vty 0 4
password 12345678
login
no scheduler allocate
end


请注意nat等是在防火墙设置的.
交换机配置

一、catalyst 4006-s3交换机配置:




enable
c terminal
service pad
service password-encryption
hostname c4006-s3
enable password 123456.
enable secret 654321
ip subnet-zero
ip name-server 172.16.8.1 172.16.8.2
ip routing
exit
vlan database
vtp mode server
vtp domain centervtp
vlan 2 name vlan2
vlan 3 name vlan3
vlan 4 name vlan4
vlan 5 name vlan5
vlan 6 name vlan6
vlan 7 name vlan7
vlan 8 name vlan8
vlan 9 name vlan9
exit
c terminal
interface port-channel 1
interface gigabitethernet 2/1
channel-group 1
interface gigabitethernet 2/2
channel-group 1
interface gigabitethernet 2/1
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigabitethernet 2/3
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigabitethernet 2/4
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigbitethernet 2/5
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigbitethernet 2/6
switchport mode trunk
switchport trunk encapsulation dotlq
switchprot trunk allowed vlan all
interface gigbitethernet 2/7
switchport access vlan 9
no shutdown
interface range gigabitethernet 2/8 �c 20
switchport mode access
switchport access vlan 8
no shutdown
spanning-tree portfast
interface gigabitethernet 3/1
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigabitethernet 3/2
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
spanning-tree vlan 1-9 root primary
spanning-tree backb
interface vlan 1
ip address 172.16.1.7 255.255.255.0
no shutdown
standby 1 ip 172.16.1.9
standby 1 priority 110 preempt
interface vlan 2
ip address 172.16.2.252 255.255.255.0
no shutdown
standby 2 ip 172.16.2.254
standby 2 priority 110 preempt
interface vlan 3
ip address 172.16.3.252 255.255.255.0
no shutdown
standby 3 ip 172.16.3.254
standby 3 priority 110 preempt
interface vlan 4
ip address 172.16.4.252 255.255.255.0
no shutdown
standby 4 ip 172.16.4.254
standby 4 priority 110 preempt
interface vlan 5
ip address 172.16.5.252 255.255.255.0
no shutdown
standby 5 ip 172.16.5.254
standby 5 priority 110 preempt
interface vlan 6
ip address 172.16.6.252 255.255.255.0
no shutdown
standby 6 ip 172.16.6.254
standby 6 priority 110 preempt
interface vlan 7
ip address 172.16.7.252 255.255.255.0
no shutdown
standby 7 ip 172.16.7.254
standby 7 priority 110 preempt
interface vlan 8
ip address 172.16.8.252 255.255.255.0
no shutdown
standby 8 ip 172.16.8.254
standby 8 priority 110 preempt
interface vlan 9
ip address 172.16.9.252 255.255.255.0
no shutdown
standby 9 ip 172.16.9.254
standby 9 priority 110 preempt
exit
ip classless
ip route 0.0.0.0 0.0.0.0 172.16.9.250
line con 0
line aux 0
line vty 0 15
password 12345678
login
end
二、catalyst 3550-12t交换机配置:





enable
c terminal
service pad
service password-encryption
hostname c3550-12t
enable password 123456
enable secret 654321
ip subnet-zero
ip name-server 172.16.8.1. 172.16.8.2
ip routing
exit
vlan database
vtp mode server
vtp domain centervtp
vlan 2 name vlan2
vlan 3 name vlan3
vlan 4 name vlan4
vlan 5 name vlan5
vlan 6 name vlan6
vlan 7 name vlan7
vlan 8 name vlan8
vlan 9 name vlan9
exit
c terminal
interface port-channel 1
interface gigabitethernet 0/1
channel-group 1
interface gigabitethernet 0/2
channel-group 1
exit
interface gigabitethernet 0/1
switchport mode trunk
switchport encapsulation dotlq
swithchport trunk allowed vlan all
interface gigabitethernet 0/3
switchport mode trunk
switchport trunk encapsulation dotlq
swithcport trunk allowed vlan all
interface gigabitethernet 0/4
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigabitethernet 0/5
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigabitethernet 0/6
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
interface gigabitethernet 0/7
switchport access vlan 9
no shutdown
interface range gigabitethernet 0/8 �c 10
switchport mode access
switchport access vlan 8
no shutdown
spanning-tree portfast
interface gigabitethernet 0/11
switchport mode trunk
switchport trunk encapsulation dotlq
swithcprot trunk allowed vlan all
interface gigabitethernet 0/12
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
spanning-tree vlan 1-9 root sec
spanning-tree backb
interface vlan 1
ip address 172.16.1.8 255.255.255.0
no shutdown
standby 1 ip 172.16.1.9
standby 1 priority 100 preempt
interface vlan 2
ip address 172.16.2.253 255.255.255.0
no shutdown
standby 2 ip 172.16.2.254
standby 2 priority 100 preempt
interface vlan 3
ip address 172.16.3.253 255.255.255.0
not shutdown
standby 3 ip 172.16.3.254
standby 3 priority 100 preempt
interface vlan 4
ip address 172.16.4.253 255.255.255.0
no shutdown
standby 4 ip 172.16.4.254
standby 4 priority 100 preempt
interface vlan 5
ip addess 172.16.5.253 255.255.255.0
no shutdown
standby 5 ip 172.16.5.253
standby 5 priority 100 preempt
interface vlan 6
ip address 172.16.6.253 255.255.255.0
no shutdown
standby 6 ip 172.16.6.254
standby 6 priority 100 preempt
interface vlan 7
ip address 172.16.7.253 255.255.255.0
no shutdown
standby 7 ip 172.16.7.254
standby 7 priority 100 preempt
interface vlan 8
ip address 172.16.8.253 255.255.255.0
no shutdown
standby 8 ip 172.16.8.254
standby 8 priority 100 preempt
interface vlan 9
ip address 172.16.9.253 255.255.255.0
no shutdown
standby 9 ip 172.16.9.254
standby 9 priority 100 preempt
exit
ip classless
ip route 0.0.0.0 0.0.0.0 172.16.9.250
ip http server
line con 0
line aux 0
line vty 0 15
password 12345678
login
end
三、catalyst 2950-24 vlan2 交换机配置:





enable
c terminal
service pad
service password-encryption
hostname c2950-241
enable password 123456
enable secret 654321
ip subnet-zero
interface vlan 1
ip address 172.16.1.1 255.255.255.0
management
no shutdown
ip default-gateway 172.16.1.9
ip name-server 172.16.8.1 172.16.8.2
exit
vlan database
vtp mode client
vtp domain centervtp
exit
c terminal
interface range fastethernet 0/1 �c 20
switchport mode access
switchport accesss vlan 2
no shutdown
spanning-tree portfast
spanning-tree uplinkfast
spanning-tree backb
interface gigabitethernet 0/1
switchport mode trunk
switchport trunk encapculation dotlq
switchport trunk allowed vlan all
spanning-tree cost 10
interface gigabitethernet 0/2
switchport mode trunk
switchport trunk encapculation dotlq
switchport trunk allowed vlan all
spanning-tree cost 20
exit
line con 0
line aux 0
line vty 0 15
password 12345678
login
end
四、catalyst 2950-24 vlan 3 交换机配置:





enable
c terminal
service pad
service password-encryption
hostname c2950-242
enable password 123456
enable secret 654321
ip subnet-zero
interface vlan 1
ip address 172.16.1.2 255.255.255.0
management
no shutdown
ip default-gateway 172.16.1.9
ip name-server 172.16.8.1 172.16.8.2
exit
vlan database
vtp domain centervtp
vtp mode client
exit
c terminal
interface range fastethernet 0/1 �c 20
switchport mode access
switchport access vlan 3
no shutdown
spanning-tree portfast
spanning-tree uplinefast
spanning-tree backb
interface gigabitethernet 0/1
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
spanning-tree cost 10
interface gigabitethernet 0/2
switchport mode trunk
switchport trunk encapsulation dotlq
switchport trunk allowed vlan all
spanning-tree cost 20
exit
line con 0
line aux 0
line vty 0 15
password 12345678
login
end
copy running-c startup-c
reload

其它交换机配置类似

你可能感兴趣的:(配置,案例,休闲,思科,交换)