这个还是具体要根据贵公司的网络规模而定的,下面通过一个案例来看看吧。
组网需求如下图所示,接入交换机是二层交换机,使用汇聚交换机(三层交换机)作为用户的网关。PC1和PC2分别属于VLAN 2和VLAN 3,通过接入交换机SW2接入汇聚交换机。PC3和PC4属于VLAN 4,通过SW3接入汇聚交换机。汇聚交换机作为PC1、PC2、PC3和PC4的网关,实现用户PC间的互访以及Internet访问。内网VLAN 2的网段为192.168.2.0/24,VLAN 3的网段为192.168.3.0/24,VLAN 4的网段为192.168.4.0/24。
配置思路配置接入交换机,基于接口划分VLAN,实现二层互通。配置汇聚交换机作为用户的网关并启用DHCP功能,实现三层互通并为用户自动分配IP。配置汇聚交换机与AR相连的接口及默认路由,实现与AR的对接。配置AR与汇聚交换机相连的接口及到内网网段的路由,实现与汇聚交换机的对接。配置AR的上网功能。配置NAT实现内网访问互联网配置步骤1、配置接入交换机
SW2 system-view
[SW2] vlan batch 2 3
[SW2] interface gigabitethernet 0/0/1
[SW2-GigabitEthernet0/0/1] port link-type access
[SW2-GigabitEthernet0/0/1] port default vlan 2
[SW2-GigabitEthernet0/0/1] quit
[SW2] interface gigabitethernet 0/0/3
[SW2-GigabitEthernet0/0/3] port link-type access
[SW2-GigabitEthernet0/0/3] port default vlan 3
[SW2-GigabitEthernet0/0/3] qui
t[SW2] interface gigabitethernet 0/0/2
[SW2-GigabitEthernet0/0/2] port link-type trunk
[SW2-GigabitEthernet0/0/2] port trunk allow-pass vlan 2 3
SW3也类似
2、配置汇聚交换机
将互联接口加入相应VLAN
SW1 system-view
[SW1] vlan batch 2 3 4
[SW1] interface gigabitethernet 0/0/2
[SW1-GigabitEthernet0/0/2] port link-type trunk
[SW1-GigabitEthernet0/0/2] port trunk allow-pass vlan 2 3
[SW1-GigabitEthernet0/0/2] quit[SW1] interface gigabitethernet 0/0/3
[SW1-GigabitEthernet0/0/3] port link-type access
[SW1-GigabitEthernet0/0/3] port default vlan 4 [SW1-GigabitEthernet0/0/3] quit
配置VLANIF接口和DHCP服务器
[SW1] dhcp enable
[SW1] interface vlanif 2
[SW1-Vlanif2] ip address 192.168.2.1 255.255.255.0
[SW1-Vlanif2] dhcp select interface
[SW1-Vlanif2] dhcp server dns-list 114.114.114.114
[SW1-Vlanif2] quit
[SW1] interface vlanif 3
[SW1-Vlanif3] ip address 192.168.3.1 255.255.255.0
[SW1-Vlanif3] dhcp select interface
[SW1-Vlanif3] dhcp server dns-list 114.114.114.114
[SW1-Vlanif3] quit[SW1] interface vlanif 4
[SW1-Vlanif4] ip address 192.168.4.1 255.255.255.0
[SW1-Vlanif4] dhcp select interface
[SW1-Vlanif4] dhcp server dns-list 114.114.114.114
[SW1-Vlanif4] quit
配置核心交换机与路由器对接
[SW1] vlan batch 100
[SW1] interface gigabitethernet 0/0/01
[SW1-GigabitEthernet0/0/1] port link-type access
[SW1-GigabitEthernet0/0/1] port default vlan 100
[SW1-GigabitEthernet0/0/1] quit
[SW1] interface vlanif 100
[SW1-Vlanif100] ip address 192.168.1.2 255.255.255.0
[SW1-Vlanif100] quit[SW1] ip route-static 0.0.0.0 0.0.0.0 192.168.1.1
配置NAT实现内网访问互联网
[AR2]nat address-group 1 192.168.35.100 192.168.35.101
[AR2]acl 2000
[AR2-acl-basic-2000]rule 5 permit source 192.168.0.0 0.0.255.255
[AR2-acl-basic-2000]q
[AR2]interface GigabitEthernet 0/0/1
[AR2-GigabitEthernet0/0/1]nat outbound 2000 address-group 1
希望以上的回答对您有所帮助,更多关于华为数通的知识请关注头条号。