• 软件测试技术
  • 软件测试博客
  • 软件测试视频
  • 开源软件测试技术
  • 软件测试论坛
  • 软件测试沙龙
  • 软件测试资料下载
  • 软件测试杂志
  • 软件测试人才招聘
    暂时没有公告

字号: | 推荐给好友 上一篇 | 下一篇

privatevlan在智能化小区中的应用

发布: 2007-6-20 23:14 | 作者:   | 来源:   | 查看: 20次 | 进入软件测试论坛讨论

领测软件测试网

   
  目的:希望实现每个客户之间不通讯,但同时利用一个网关连接到INTERNET.
  
  3550-emi 配置
  interface FastEthe.net0/1
  switchport access vlan 1
  switchport protected
  no ip address
  !

  interface FastEthernet0/2
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/3
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/4
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/5
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/6
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/7
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/8
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/9
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/10
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/11
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/12
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/13
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/14
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/15
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/16
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/17
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/18
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/19
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/20
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/21
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/22
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/23
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface FastEthernet0/24
  switchport access vlan 2
  switchport protected
  no ip address
  !
  interface GigabitEthernet0/1
  switchport trunk encapsulation dot1q
  no ip address
  !
  interface GigabitEthernet0/2
  no ip address
  !
  interface Vlan1
  ip address 172.16.1.1 255.255.0.0
  shutdown
  !
  interface Vlan2
  ip address 10.1.1.1 255.255.0.0
  ip access-group 1 in
  !
  interface Vlan3
  ip address 10.2.1.1 255.255.0.0
  ip access-group 2 in
  !
  ip route 0.0.0.0 0.0.0.0 Vlan1
  !
  ip classless
  ip http server
  
  2950G配置:
  interface FastEthernet0/1
  switchport access vlan 3
  no ip address
  !
  interface FastEthernet0/2
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/3
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/4
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/5
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/6
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/7
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/8
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/9
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/10
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/11
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/12
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/13
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/14
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/15
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/16
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/17
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/18
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/19
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/20
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/21
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/22
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/23
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface FastEthernet0/24
  switchport access vlan 3
  switchport protected
  no ip address
  !
  interface GigabitEthernet0/1
  switchport trunk encapsulation dot1q
  no ip address
  !
  interface GigabitEthernet0/2
  no ip address
  !
  interface Vlan1
  no ip address
  
  FW:领导,这个例子不能称之为PVLAN吧。
  PVLAN的简介如下:PVLAN技术
  现在有了一种新的VLAN机制,服务器同在一个子网中,但服务器只能与自己的缺省网关通信。这一新的VLAN特性就是专用VLAN(private VLAN, pVLAN)。专用VLAN是第2层的机制,在同一个2层域中有两类不同安全级别的访问端口。与服务器连接的端口称作专用端口(Private port),一个专用端口限定在第2层,它只能发送流量到混杂端口,也只能检测从混杂端口来的流量。混杂端口(Promioscuous port)没有专用端口的限定,它与路由器或第3层交换机接口相连。简单地说,在一个专用VLAN内,专用端口收到的流量只能发往混杂端口,混杂端口收到的流量可以发往所有端口(混杂端口和专用端口)。
  
  专 用 VLAN 的 应 用 对于保证城域接入网络的数据通讯的安全性 是 非 常 有 效的用户只需与自己的缺省网关连接,一个专用VLAN不需要多个VLAN 和IP 子 网 就 提 供 了 具备第二层数据通讯安全性的连接,所有的用户都接入专用 VLAN,从而实现了所有用户与缺省网关的连接,而与专用VLAN内的其他用户没

文章来源于领测软件测试网 https://www.ltesting.net/


关于领测软件测试网 | 领测软件测试网合作伙伴 | 广告服务 | 投稿指南 | 联系我们 | 网站地图 | 友情链接
版权所有(C) 2003-2010 TestAge(领测软件测试网)|领测国际科技(北京)有限公司|软件测试工程师培训网 All Rights Reserved
北京市海淀区中关村南大街9号北京理工科技大厦1402室 京ICP备10010545号-5
技术支持和业务联系:info@testage.com.cn 电话:010-51297073

软件测试 | 领测国际ISTQBISTQB官网TMMiTMMi认证国际软件测试工程师认证领测软件测试网