H3C交换机vlan配置

我的想法是将1至7口划为到vlan4,并让这个vlan中的电脑可以通过防火墙访问外网。
具体配置是:
我要将1至7号口划为vlan 4
将连接防火墙的24号口划为vlan trunk
我的配置命令是:
[H3C]vlan 4
[H3C-vlan4]quit
[H3C]int gig1/0/1
[H3C-gigabitethernet1/0/1]port access vlan 4
2-7号端口配置一样
然后我再将24口进行如入配置
[H3C-gigabitethernet1/0/24]port link-type trunk
[H3C-gigabitethernet1/0/1]port trunk permit vlan 4
可是这样配置后,1至7号端口无法通过防火墙,不知道哪里还没有配置呢?

应该单独设置一个可以访问外网的vlan,比如vlan 1000 trunk里面设置只允许你的vlan4和vlan1000通过追问

默认的vlan 1设置trunk不行吗?

追答

你正确分配端口也是可以的,但是不建议使用,vlan1是一个默认的vlan,通常不做太多使用。

温馨提示:答案为网友推荐,仅供参考
第1个回答  2011-05-20
给你一个H3C-S3600交换机例子:
sysname S3600
#
radius scheme system
#
domain system
#
acl number 2001
#
acl number 3001
#
acl number 4000
rule 0 permit
acl number 4001
#
vlan 1
#
vlan 100 to 102
#
vlan 106
#
vlan 118

vlan 120
#
vlan 123
#
vlan 2000
#
vlan 4000
#
interface Vlan-interface2000
ip address 192.168.1.6 255.255.255.0
#
#
interface Aux1/0/0
#
interface Ethernet1/0/1
port access vlan 100
#
interface Ethernet1/0/2
port access vlan 118
#
interface Ethernet1/0/3
port access vlan 118
#
interface Ethernet1/0/4
port access vlan 118
line-rate outbound 2048
#
interface Ethernet1/0/5
port access vlan 118
line-rate outbound 2048
#
interface Ethernet1/0/6
port access vlan 100
#
interface Ethernet1/0/7
port access vlan 100
#
interface Ethernet1/0/8
port access vlan 102
#
interface Ethernet1/0/9
port access vlan 101
#
interface Ethernet1/0/10
port access vlan 102
#
interface Ethernet1/0/11
port access vlan 102
#
interface Ethernet1/0/12
port access vlan 101
#
interface Ethernet1/0/13
port access vlan 102
#
interface Ethernet1/0/14
port access vlan 100
#
interface Ethernet1/0/15
port access vlan 100
#
interface Ethernet1/0/16
port access vlan 101
interface Ethernet1/0/17
port access vlan 101
#
interface Ethernet1/0/18
port access vlan 101
#
interface Ethernet1/0/19
port access vlan 101
#
interface Ethernet1/0/20
port access vlan 100
#
interface Ethernet1/0/21
port access vlan 101
#
interface Ethernet1/0/22
port access vlan 102
#
interface Ethernet1/0/23
port access vlan 101
#
interface Ethernet1/0/24
port access vlan 102
#
interface GigabitEthernet1/1/1
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/1/2
#
interface GigabitEthernet1/1/3
#
interface GigabitEthernet1/1/4
#
undo irf-fabric authentication-mode
#
interface NULL0
#
management-vlan 4000
#
voice vlan mac-address 0001-e300-0000 mask ffff-ff00-0000
#
ip route-static 0.0.0.0 0.0.0.0 192.168.1.1 preference 60
#
snmp-agent
snmp-agent local-engineid 800007DB000FE29D44626877
snmp-agent community read public
snmp-agent community write private
snmp-agent sys-info contact ggg
snmp-agent sys-info location ggg
snmp-agent sys-info version v2c v3
snmp-agent target-host trap address udp-domain 192.168.1.65 udp-port 5000 params securityname public v2c
#
user-interface aux 0 7
user-interface vty 0 4
set authentication password cipher
#
return
第2个回答  2011-05-26
问题解决
相似回答