实验要求:实现不同vlan间PC不可互访,而不同vlan的PC均可访问服务器的特殊效果;
实验拓扑图:
实验步骤:1、在交换机中创建相关vlan;
--SW1 vlan batch 5 10 50;
--SW2 vlan batch 5 10 50;
2、修改端口模式与PVID;
[SW]interface GigabitEthernet 0/0/1;
[SW-GigabitEthernet0/0/1]port hybrid pvid vlan 5;
............
3、修改端口允许通过的数据帧;
[SW-GigabitEthernet0/0/1]port hybrid untagged vlan 5
[SW-GigabitEthernet0/0/24]port hybrid tagged vlan 5
..............
4、结果验证,vlan5与vlan10的PC不可以互通,但他们均可以与服务器互通。
PC>ping 192.168.1.50
Ping 192.168.1.50: 32 data bytes, Press Ctrl_C to break
From 192.168.1.50: bytes=32 seq=1 ttl=128 time=47 ms
From 192.168.1.50: bytes=32 seq=2 ttl=128 time=62 ms
From 192.168.1.50: bytes=32 seq=3 ttl=128 time=63 ms
From 192.168.1.50: bytes=32 seq=4 ttl=128 time=62 ms
From 192.168.1.50: bytes=32 seq=5 ttl=128 time=63 ms
--- 192.168.1.50 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 47/59/63 ms
原文地址:http://blog.51cto.com/14091631/2351285