专用 vlan 配置 - 连接问题

网络工程 思科 转变 私有VLAN 第五
2021-07-19 23:27:25

我有一个与私有 VLAN 相关的问题。我有光纤调制解调器,但它们无法访问 DHCP/TFTP 以进行设置。我怀疑来自专用 VLAN 的配置。你能回顾一下吗?我的疑惑主要是在千兆端口的接入交换机和中继配置上。

简而言之,当调制解调器启动时,它们试图通过 DHCP 获取 IP,发送一个未标记的帧到达接入交换机 4506 并且应该在 vlan 11 上处理,因为它们是未标记的私有 vlan。广播发现 DHCP 应通过 vlan 10 转到聚合器交换机。在聚合器交换机 4500x 上,有一个 SVI vlan 10,带有提供服务器的 ip helper-address,该服务器向他发送单播数据包。

pvlan 拓扑

接入交换机 4506 上的配置:

vlan 10
name vlan_10
 private-vlan primary
!
vlan 20
name vlan_20
 private-vlan primary
!
vlan 30
name vlan_30
 private-vlan primary
!
! Isolated VLAN: Connects all CPE hosts to Switch 
!
vlan 11
name Pvlan_11
 private-vlan isolated
!
vlan 21
name Pvlan_21
 private-vlan isolated
!
vlan 31
name Pvlan_31
 private-vlan isolated
!
!  Associating
!
vlan 10
 private-vlan assoc 11
!
vlan 20
 private-vlan assoc 21
!
vlan 30
 private-vlan assoc 31
!
! Isolated port (Can only communicate with Primary port)
!
interface giX/Y
switchport mode private-vlan trunk promiscuous
switchport private-vlan trunk native vlan 11
switchport private-vlan trunk allowed vlan 11,21,31
switchport private-vlan mapping trunk 10 11
switchport private-vlan mapping trunk 20 21
switchport private-vlan mapping trunk 30 31
1个回答

经过几次测试,我找到了解决方案并且可以正常工作。我的第一个配置不完整。

模式

配置生成器

这是一个工作配置:

vlan 10
name vlan_10
 private-vlan primary
!
vlan 20
name vlan_20
 private-vlan primary
!
vlan 30
name vlan_30
 private-vlan primary
!
! Isolated VLAN: Connects all CPE hosts to Switch 
!
vlan 11
name Pvlan_11
 private-vlan isolated
!
vlan 21
name Pvlan_21
 private-vlan isolated
!
vlan 31
name Pvlan_31
 private-vlan isolated
!
!  Associating
!
vlan 10
 private-vlan assoc 11
!
vlan 20
 private-vlan assoc 21
!
vlan 30
 private-vlan assoc 31
!
! Isolated/Access port
!
interface GigabitEthernet1/1
switchport private-vlan trunk native vlan 11
switchport private-vlan trunk allowed vlan 11,21,31
switchport private-vlan association trunk 10 11
switchport private-vlan association trunk 20 21
switchport private-vlan association trunk 30 31
switchport mode private-vlan trunk secondary
!
! Promiscuous port (interconnect switchs) 
!
interface TenGigabitEthernet1/1
switchport private-vlan trunk native vlan 10
switchport private-vlan mapping trunk 10 11
switchport private-vlan mapping trunk 20 21
switchport private-vlan mapping trunk 30 31
switchport mode private-vlan trunk promiscuous