BÀI LAB SWITCH Người Thực hiện : Đào Thanh Quý # Cấu hình VTP SW1#vlan database SW1(vlan)#vtp domain 16084861_TQuy SW1(vlan)#vtp server Device mode already VTP SERVER. SW1(vlan)#vtp v2-mode V2 mode enabled. SW1(vlan)#exit SW1# SW1#vlan da
SW1(vlan)#vlan 2 VLAN 2 added: Name: VLAN0002 SW1(vlan)#vlan 3 VLAN 3 added: Name: VLAN0003 SW1(vlan)#vlan 4 VLAN 4 added: Name: VLAN0004 SW1(vlan)#vlan 5 VLAN 5 added: Name: VLAN0005 SW1(vlan)#vlan 6 VLAN 6 added: Name: VLAN0006 SW1#show vlan-switch VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Fa1/0, Fa1/1, Fa1/2, Fa1/3 Fa1/4, Fa1/5, Fa1/6, Fa1/7 Fa1/8, Fa1/9, Fa1/10, Fa1/11 Fa1/12, Fa1/13, Fa1/14, Fa1/15 2 VLAN0002 active 3 VLAN0003 active
4 VLAN0004 active 5 VLAN0005 active 6 VLAN0006 active SW1#conf t Enter configuration commands, one per line. End with CNTL/Z. SW1(config)#int SW1(config)#interface vlan 2 SW1(config-if)#ip add 192.168.2.1 255.255.255.224 SW1(config-if)#no sh SW1(config-if)#exit SW1(config)#int vlan 3 SW1(config-if)#ip add 192.168.3.1 255.255.255.192 SW1(config-if)#no sh SW1(config-if)#exit SW1(config)#int vlan 4 SW1(config-if)#ip add 192.168.4.1 255.255.255.128 SW1(config-if)#no sh SW1(config-if)#exit SW1(config)#int vlan 5 SW1(config-if)#ip add 192.168.5.1 255.255.255.248 SW1(config-if)#no sh SW1(config-if)#exit SW1(config)#int vlan 6
SW1(config-if)#ip add 192.168.6.1 255.255.255.240 SW1(config-if)#no sh SW1(config-if)#exit SW1(config)#end SW1#co *Mar 1 00:25:28.703: %SYS-5-CONFIG_I: Configured from console by console SW1#copy run start # ------------SW2---------------- SW2(vlan)#vtp dom SW2(vlan)#vtp domain 16084861_TQuy Domain name already set to 16084861_TQuy. SW2(vlan)#vtp cle SW2(vlan)#vtp cli SW2(vlan)#vtp client Setting device to VTP CLIENT mode. SW2(vlan)#vtp v2 SW2(vlan)#vtp v2-mode V2 mode enabled. SW2(vlan)#vtp tr SW2(vlan)#vtp transparent Setting device to VTP TRANSPARENT mode. SW2(config)#int f1/1 SW2(config-if)#switchport mode tr
SW2(config-if)#switchport trunk encapsulation dot1q SW2(config-if)#int f1/2 SW2(config-if)#switchport mode access SW2(config-if)#switchport access vlan 5 SW2(config-if)#int f1/3 SW2(config-if)#switchport mode access SW2(config-if)#switchport access vlan 6 SW2(config-if)# SW2(config)#int f1/1 SW2(config-if)#switchport mode tr SW2(config-if)#sw SW2(config-if)#switchport trunk encapsulation dot1q SW2(config-if)#int f1/2 SW2(config-if)#switchport mode access SW2(config-if)#sw SW2(config-if)#switchport access vlan 5 SW2(config-if)#int f1/3 SW2(config-if)#sw
SW2(config-if)#switchport mode access SW2(config-if)#sw SW2(config-if)#switchport access vlan 6 # ------------SW3---------------- SW3# vlan database SW3(vlan)#vtp do 16084861_TQuy SW3(vlan)#vtp domain 16084861_TQuy Domain name already set to 16084861_TQuy. SW3(vlan)#vtp server SW3(vlan)#vtp server Device mode already VTP SERVER. SW3(vlan)#vtp v2 SW3(vlan)#vtp v2-mode V2 mode enabled. SW3(vlan)#vtp tr SW3(vlan)#vtp transparent Setting device to VTP TRANSPARENT mode. SW3(vlan)#vtp pr SW3(vlan)#vtp pruning Pruning switched ON SW3(vlan)#exit APPLY completed. Exiting...
SW3(config)#int f1/1 SW3(config-if)#switchport mode trunk SW3(config-if)# *Mar 1 00:39:49.987: %DTP-5-TRUNKPORTON: Port Fa1/1 has become dot1q trunk SW3(config-if)#sw SW3(config-if)#switchport trunk encapsulation dot1q SW3(config-if)#no sh SW3(config-if)#exit SW3(config)#int f1/1 SW3(config-if)#sw SW3(config-if)#switchport mode trunk SW3(config-if)#sw SW3(config-if)#switchport trunk encapsulation dot1q SW3(config-if)#no sh SW3(config-if)#int f1/2 SW3(config-if)#switchport mode access SW3(config-if)#sw SW3(config-if)#switchport access vlan 2 SW3(config-if)#no sh SW3(config-if)#int f1/3 SW3(config-if)#switchport mode access SW3(config-if)#switchport access vlan 3 SW3(config-if)#no sh
SW3(config-if)#int f1/4 SW3(config-if)#switchport mode access SW3(config-if)#switchport access vlan 4 SW3(config-if)#no sh SW3(config-if)#end # ------------R1---------------- R1#conf t Enter configuration commands, one per line. End with CNTL/Z. R1(config)#int f0/0 R1(config-if)#ip add 192.168.1.1 255.255.255.224 R1(config-if)#no sh R1(config-if)#exit R1(config)# R1(config)#int f0/0.2 R1(config-subif)#encapsulation dot1q 2 R1(config-subif)#ip R1(config-subif)#ip address 192.168.2.2 255.255.255.224 R1(config-subif)#no sh R1(config-subif)#exit R1(config)#int f0/0.3 R1(config-subif)#encapsulation dot1q 3 R1(config-subif)#ip add 192.168.3.2 255.255.255.192 R1(config-subif)#no sh R1(config-subif)#exit
R1(config)#int f0/0.4 R1(config-subif)#en R1(config-subif)#encapsulation dot1q 4 R1(config-subif)#ip add 192.168.4.2 255.255.255.128 R1(config-subif)#no sh R1(config-subif)#exit R1(config)#int f0/0.5 R1(config-subif)#en R1(config-subif)#encapsulation dot1q 5 R1(config-subif)#ip add 192.168.5.2 255.255.255.248 R1(config-subif)#no sh R1(config-subif)#exit R1(config)#int f0/0.6 R1(config-subif)#en R1(config-subif)#encapsulation dot1q 6 R1(config-subif)#ip add 192.168.6.2 255.255.255.240 R1(config-subif)#no sh R1(config-subif)#exit R1(config)# R1(config)#access-list 100 permit tcp host 192.168.3.3 any eq 20 R1(config)#access-list 100 permit ip any any R1(config)#access-list 100 permit tcp host 192.168.3.3 any eq 21 R1(config)#access-list 100 permit ip any any R1(config)#access-list 101 permit tcp host 192.168.5.5 any eq 20 R1(config)#access-list 101 permit ip any any
R1(config)#access-list 101 permit tcp host 192.168.5.5 any eq 21 R1(config)#access-list 101 permit ip any any R1(config)# ip access-group 100 in ip access-group 101 in