Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Table of Contents
Table of Contents
Chapter 1 VLAN Configuration .................................................................................................... 1-1 1.1 VLAN Overview.................................................................................................................. 1-1 1.2 Configuring VLAN .............................................................................................................. 1-1 1.2.1 Creating/Deleting a VLAN ....................................................................................... 1-2 1.2.2 Specifying a Description for a VLAN or VLAN interface ......................................... 1-2 1.2.3 Naming the Current VLAN ...................................................................................... 1-3 1.2.4 Shutting down/Bringing up a VLAN Interface.......................................................... 1-3 1.2.5 Configuring Port-Based VLAN ................................................................................ 1-3 1.3 Displaying and Maintaining VLAN ..................................................................................... 1-4 1.4 Overview of Protocol-Based VLAN and IP Subnet-Based VLAN...................................... 1-4 1.4.1 Brief Introduction ..................................................................................................... 1-4 1.5 Configuring Protocol-Based VLAN .................................................................................... 1-5 1.5.1 Configuration Task List ........................................................................................... 1-5 1.5.2 Configuring a Protocol VLAN .................................................................................. 1-5 1.5.3 Applying a Protocol-Based VLAN to a Port............................................................. 1-6 1.6 Displaying Protocol-Based VLAN Configuration................................................................ 1-6 1.7 Configuring an IP Subnet-Based VLAN............................................................................. 1-6 1.7.1 Configuration Task List ........................................................................................... 1-6 1.7.2 Configuring an IP Subnet-Based VLAN .................................................................. 1-7 1.7.3 Applying an IP Subnet-Based VLAN to a Port ........................................................ 1-7 1.8 Displaying and Maintaining IP Subnet-Based VLAN Configuration .................................. 1-8 1.9 VLAN Configuration Examples .......................................................................................... 1-8 1.9.1 VLAN Configuration Example ................................................................................. 1-8 1.9.2 Protocol-Based VLAN and IP Subnet-Based VLAN Configuration Example.......... 1-9 Chapter 2 Super VLAN Configuration ......................................................................................... 2-1 2.1 Super VLAN Overview....................................................................................................... 2-1 2.2 Configuring a Super VLAN ................................................................................................ 2-1 2.3 Super VLAN Configuration Example ................................................................................. 2-3 Chapter 3 Isolate-User-VLAN Configuration .............................................................................. 3-1 3.1 Isolate-User-VLAN Overview............................................................................................. 3-1 3.2 Configuring Isolate-User-VLAN ......................................................................................... 3-2 3.2.1 Configuration Task List ........................................................................................... 3-2 3.2.2 Configuring an Isolate-User-VLAN.......................................................................... 3-2 3.2.3 Configuring a Secondary VLAN .............................................................................. 3-2 3.2.4 Mapping an Isolate-User-VLAN to Secondary VLANs............................................ 3-3 3.3 Displaying and Maintaining Isolate-User-VLANs............................................................... 3-4 3.4 Isolate-User-VLAN Configuration Example ....................................................................... 3-4
Caution: VLAN 1 is the system-default VLAN and cannot be removed. VLANs with their ports being VLAN VPN-enabled cannot be removed. Guest VLANs cannot be deleted. Protocol-enabled VLANs cannot be deleted. Dynamic VLANs cannot be deleted, and the system does not play the prompt when you attempt to delete dynamic VLAN(s).
undo description
By default, the description of a VLAN is the VLAN ID of the VLAN, such as VLAN 0001. The description of a VLAN interface is the VLAN interface name, such as Vlan-interface1 Interface.
Shutting down or bringing up a VLAN interface has no effect on the status of any Ethernet port in this VLAN. By default, when all the Ethernet ports in a VLAN are in the Down state, this VLAN interface is also Down. When there are one or more Ethernet ports in the Up state, this VLAN interface is also Up.
By default, the system adds all the ports to a default VLAN whose ID is 1. Note that you can add/remove the trunk and Hybrid ports to/from a VLAN with the port/undo port command in Ethernet port view, but not in VLAN view.
applied to the port. If the matching is successful, the packet will be forwarded in the VLANs to which the matched protocols belong. If the protocol-based VLAN function is disabled on the port or the matching fails, the packet will be forwarded in the default VLAN of the port.
Required
Caution: You cannot configure the same protocol under a VLAN twice while you can configure the same protocol in different VLANs. If a protocol is configured in a VLAN, you cannot remove the VLAN. If a protocol has been applied to a port, you cannot remove the protocol.
Caution: The port must be of Hybrid type and belong to the protocol-based VLAN to be applied. The same protocol configured in different VLANs cannot be applied to the same port. If a protocol-based VLAN has been applied to a port, the port cannot exit the VLAN.
Caution: An IP subnet can be assigned only to one VLAN. If an IP subnet is configured in a VLAN, you cannot remove the VLAN. If an IP subnet is applied to a port, you cannot remove the IP subnet.
Caution: The port must be of Hybrid type and belong to the IP subnet-based VLAN to be applied. If an IP subnet-based VLAN is applied to a port, the port cannot exit the VLAN.
Eth3/1/1
Eth4/1/1 Eth3/1/2
Eth4/1/2
VLAN2
VLAN3
E2/1/48
E2/1/1 E2/1/3
E2/1/5
Figure 1-2 Network diagram for protocol-based VLAN and IP subnet-based VLAN
[Quidway-Ethernet2/1/48] port hybrid vlan 10 20 30 untag [Quidway-Ethernet2/1/48] port hybrid pvid vlan 30
Note: You can configure multiple super VLANs for a switch. Configuring the VLAN interface and IP address for a super VLAN is the same as that for a common VLAN. Configuring sub VLANs is the same as configuring a common VLAN. This section only provides the configuration steps. For detailed information, refer to VLAN Configuration.
Follow these steps to configure a super VLAN: To do Enter system view Enter VLAN view Set the VLAN type to super VLAN Exit Super VLAN view Create a sub VLAN and enter sub VLAN view Add Ethernet ports to sub a VLAN Exit sub VLAN view Enter Super VLAN view Configure the mapping between the super VLAN and the sub VLANs Enter sub VLAN view Use the command system-view vlan vlan-id Required Required supervlan The VLAN-ID is the configured VLAN ID in the range 1 to 4094. Required Optional Required Optional Enable proxy ARP for the sub VLAN arp proxy enable This command is necessary for multiple sub VLANs to communicate with one another. Optional Display configuration information display super vlan [ supervlan-id ] You can execute the display super vlan command in any view. Remarks
quit vlan vlan-id port interface-list quit vlan vlan-id subvlan sub-vlan-list vlan vlan-id
Caution: A Super VLAN cannot contain ports. After you set the VLAN type to super VLAN, proxy ARP is automatically enabled on the VLAN interface. The default VLAN cannot be set to a super VLAN. You can add multiple ports (non-uplink ports) to a sub VLAN. You cannot configure a virtual VLAN interface for a sub VLAN. If no VLAN ID is specified in the undo subvlan command, the mappings between all sub VLANs and the specified super VLAN is removed; if VLAN ID(s) are specified, only the mappings between the specified sub VLANs and the specified super VLAN is removed. In a super VLAN, do not enable multicast VLAN and IGMP-snooping. Super VLAN does not support VRRP.
[Quidway-vlan5] port ethernet3/1/5 ethernet3/1/6 [Quidway-vlan5] vlan 10 [Quidway-vlan10] subvlan 2 3 5 [Quidway-vlan10] interface vlan 10 [Quidway-Vlan-interface10] ip address 10.110.1.1 255.255.255.0 [Quidway-vlan2]arp proxy enable [Quidway-vlan3]arp proxy enable [Quidway-vlan5]arp proxy enable
VLAN 5 Isolate-user-VLAN
VLAN 6 Isolate-user-VLAN
port interface-list
Note: An Isolate-user-VLAN can correspond to up to 64 Secondary VLANs. You can configure up to 32 Isolate-user-VLANs for a system. You can configure up to 1,024 Secondary VLANs for a system. You cannot configure the same MAC address for the Secondary VLANs corresponding to an Isolate-user-VLAN. You cannot configure a VLAN interface for an Isolate-user-VLAN or Secondary VLAN; neither can you configure a VLAN with a VLAN interface as an Isolate-user-VLAN or Secondary VLAN.
Note: You cannot directly set an Isolate-user-VLAN or Secondary VLAN as other type of VLAN than common VLAN, such as multicast VLAN, Super/Sub VLAN, Guest VLAN or VLAN running L2VPN services. When you set a common VLAN as an Isolate-user-VLAN or Secondary VLAN, the VLAN cannot contain trunk ports.
VLAN 5 is an Isolate-user-VLAN, including an upstream port (Ethernet 2/1/1) and two Secondary VLANs, VLAN 2 and VLAN 3. VLAN 2 includes Ethernet 2/1/2 and VLAN 3 includes Ethernet 2/1/3. 2) On Switch C
VLAN 6 is an Isolate-user-VLAN including an upstream port (Ethernet 2/1/1) and two Secondary VLANs: VLAN 3 and VLAN 4. VLAN 3 includes Ethernet 2/1/3 and VLAN 4 includes Ethernet2/1/4. Seen from Switch A, either Switch B or Switch C carries one VLAN, VLAN 5 and VLAN 6 respectively.
Huawei Technologies Proprietary 3-4
# Configure an Isolate-user-VLAN.
<Quidway> system-view [Quidway] vlan 5 [Quidway-vlan5] isolate-user-vlan enable [Quidway-vlan5] port ethernet2/1/1
# Configure the mapping between the Isolate-user-VLAN and the Secondary VLANs.
[Quidway-vlan2] quit [Quidway] isolate-user-vlan 5 secondary 2 to 3
2)
Configuration on Switch C
# Configure an Isolate-user-VLAN.
<Quidway> system-view [Quidway] vlan 6 [Quidway-vlan6] isolate-user-vlan enable [Quidway-vlan6] port ethernet2/1/1
# Configure the mapping relationship between the Isolate-user-VLAN and the Secondary VLANs.
[Quidway-vlan4] quit [Quidway] isolate-user-vlan 6 secondary 3 to 4