要求:
- 按照图示配置IP地址,所有接口均为trunk且只允许放行vlan10、20
- MSTP做双实例,SW1作为实例1的根网桥,SW2作为实例2的根网桥,且互相备份
- VRRP,SW1作为vlan10的master,SW2作为vlan20的master,高优先级为120,低优先级默认为100。虚拟网关为192.168.1.254与192.168.2.254
基础配置:
SW1
vlan range 10,20 #创建vlan10与20
!
interface GigabitEthernet 0/0
switchport mode trunk #将端口设置为trunk
switchport trunk allowed vlan only 10,20 #配置trunk仅允许vlan10与vlan20通过
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk allowed vlan only 10,20!
interface VLAN 10
ip address 192.168.1.252 255.255.255.0
!
interface VLAN 20
ip address 192.168.2.252 255.255.255.0
SW2
vlan range 10,20
!
interface GigabitEthernet 0/0
switchport mode trunk
switchport trunk allowed vlan only 10,20
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk allowed vlan only 10,20!
interface VLAN 10
ip address 192.168.1.253 255.255.255.0
!
interface VLAN 20
ip address 192.168.2.253 255.255.255.0
SW3
vlan range 10,20
!
interface GigabitEthernet 0/0
switchport mode trunk
switchport trunk allowed vlan only 10,20
!
interface GigabitEthernet 0/1
switchport mode trunk
switchport trunk allowed vlan only 10,20
MSTP配置:
SW1
spanning-tree #开启生成树协议
!
spanning-tree mst configuration #进入mstp生成树配置
instance 1 vlan 10 #实例1绑定vlan10
instance 2 vlan 20 #实例2绑定vlan20
!
spanning-tree mst 1 priority 4096 #设置实例1的生成树优先级为4096
spanning-tree mst 2 priority 8192 #设置实例1的生成树优先级为4096
SW2
spanning-tree
!
spanning-tree mst configuration
instance 1 vlan 10
instance 2 vlan 20
!spanning-tree mst 1 priority 8192
spanning-tree mst 2 priority 4096
SW3
spanning-tree
!
spanning-tree mst configuration
instance 1 vlan 10
instance 2 vlan 20
测试:在SW3上执行命令show spanning-tree summary,可以发现实例1与实例2分别阻塞不同的接口
VRRP配置
SW1
interface VLAN 10
ip address 192.168.1.252 255.255.255.0
vrrp 10 ip 192.168.1.254 #配置序号10的vrrp的虚拟ip为192.168.1.254
vrrp 10 priority 120 #配置优先级为120
!
interface VLAN 20
ip address 192.168.2.252 255.255.255.0
vrrp 20 ip 192.168.2.254
SW2
interface VLAN 10
ip address 192.168.1.253 255.255.255.0
vrrp 10 ip 192.168.1.254
!
interface VLAN 20
ip address 192.168.2.253 255.255.255.0
vrrp 20 ip 192.168.2.254
vrrp 20 priority 120
测试:
在SW1上执行命令show vrrp brief ,可以看到在vlan10中vrrp状态为master,vlan20中状态为backup
在SW2上执行命令show vrrp brief ,可以看到在vlan10中vrrp状态为backup,vlan20中状态为master