Схема тестового стенда:
[PC1] -- (1/0/1[DXS-3600]1/0/3) -- [PC2]
PC1: 192.168.1.15/24 & 192.168.0.15/24
PC2: eth0.200 192.168.10.30/24
Настраиваю DXS-3600-32S:
Код:
con t
int m 0
ip add 172.16.0.1 255.255.255.0
ex
int vlan 1
ip add 192.168.1.1 255.255.255.0
ip add 192.168.0.1 255.255.255.0 secondary
ex
ip access-list mgmt
10 permit 192.168.1.0 0.0.0.255
ex
username admin pri 15 pass 0 123456
line telnet
login local
access-class mgmt
end
Проверяем с PC1 доступ к интерфейсам коммутатора:
Первый:
Код:
D:\>ping 192.168.1.1 -n 4
This is hrPING v2.26 by cFos Software GmbH -- http://www.cfos.de
Pinging 192.168.1.1
with 64 bytes data (92 bytes IP):
Reply from 192.168.1.1: seq=0000 time=0.660ms TTL=255 ID=cf45
Reply from 192.168.1.1: seq=0001 time=0.659ms TTL=255 ID=cf46
Reply from 192.168.1.1: seq=0002 time=0.638ms TTL=255 ID=cf4b
Reply from 192.168.1.1: seq=0003 time=1.627ms TTL=255 ID=cf4c
Statistics for 192.168.1.1:
Packets: sent=4, rcvd=4, error=0, lost=0 (0% loss) in 1.501638 sec
RTTs of replies in ms: min/avg/max: 0.638 / 0.896 / 1.627
Второй:
Код:
D:\>ping 192.168.0.1 -n 4
This is hrPING v2.26 by cFos Software GmbH -- http://www.cfos.de
Pinging 192.168.0.1
with 64 bytes data (92 bytes IP):
Reply from 192.168.0.1: seq=0000 time=2.860ms TTL=255 ID=cf57
Reply from 192.168.0.1: seq=0001 time=2.092ms TTL=255 ID=cf58
Reply from 192.168.0.1: seq=0002 time=2.910ms TTL=255 ID=cf59
Reply from 192.168.0.1: seq=0003 time=8.758ms TTL=255 ID=cf5e
Statistics for 192.168.0.1:
Packets: sent=4, rcvd=4, error=0, lost=0 (0% loss) in 1.508765 sec
RTTs of replies in ms: min/avg/max: 2.092 / 4.155 / 8.758
D:\>
Оба интерфейса отвечают.
Далее проверяет доступ по Telnet:
Первый:
Код:
D:\>telnet 192.168.1.1
DXS-3600-32S TenGigabit Ethernet Switch
Command Line Interface
Firmware: Build 2.31.B060
Copyright(C) 2013 D-Link Corporation. All rights reserved.
User Access Verification
Username:admin
Password:******
DXS-3600-32S#logout
D:\>
Доступ есть.
Второй:
Код:
D:\>telnet 192.168.0.1
D:\>
Доступа нет. Всё правильно и согласно конфигурации.
Добавляем в конфигурацию фильтрацию ICMP пакетов:
Код:
con t
ip access-list extended deny_icmp 2000
10 permit icmp 192.168.1.0 0.0.0.255 any echo
20 deny icmp 192.168.0.0 0.0.0.255 any echo
ex
int eth 1/0/1
ip access-group deny_icmp in
end
Проверяем:
Первый:
Код:
D:\>ping 192.168.1.1 -n 4
This is hrPING v2.26 by cFos Software GmbH -- http://www.cfos.de
Pinging 192.168.1.1
with 64 bytes data (92 bytes IP):
Reply from 192.168.1.1: seq=0000 time=0.640ms TTL=255 ID=dbfb
Reply from 192.168.1.1: seq=0001 time=0.720ms TTL=255 ID=dbfc
Reply from 192.168.1.1: seq=0002 time=0.931ms TTL=255 ID=dbfd
Reply from 192.168.1.1: seq=0003 time=1.693ms TTL=255 ID=dbfe
Statistics for 192.168.1.1:
Packets: sent=4, rcvd=4, error=0, lost=0 (0% loss) in 1.502086 sec
RTTs of replies in ms: min/avg/max: 0.640 / 0.996 / 1.693
Отвечает. Всё правильно.
Второй:
Код:
D:\>ping 192.168.0.1 -n 4
This is hrPING v2.26 by cFos Software GmbH -- http://www.cfos.de
Pinging 192.168.0.1
with 64 bytes data (92 bytes IP):
4 Requests timed out.
Statistics for 192.168.0.1:
Packets: sent=4, rcvd=0, error=0, lost=4 (100% loss) in 0.000000 sec
D:\>
Не отвечает. Всё правильно.
Добавляем ещё в конфигурацию фильтрацию с привязкой к VLAN:
Код:
con t
vlan 200
ex
int vlan 200
ip add 192.168.10.1 255.255.255.0
ex
int eth 1/0/3
switchport mode trunk
switchport trunk native vlan 1
switchport trunk allowed vlan rem 2-199,201-4094
ex
ip access-list extended permit_traffic 2221
10 permit 192.168.10.0 0.0.0.255 192.168.1.0 0.0.0.255
ex
ip access-list extended deny_traffic 2222
10 permit 192.168.10.0 0.0.0.255 192.168.0.0 0.0.0.255
exit
vlan access-map forward_traffic 10
match ip address 2221
action forward
exit
vlan access-map forward_traffic 20
match ip address 2222
action drop
exit
vlan filter forward_traffic vlan-list 200
end
Проверяем с PC2:
Настройка интерфейса:
Код:
root@kenger:/etc/tacacs+# ping 192.168.1.15 -c 4
PING 192.168.1.15 (192.168.1.15) 56(84) bytes of data.
64 bytes from 192.168.1.15root@kenger:/etc/tacacs+# ifconfig
eth0 Link encap:Ethernet HWaddr 00:15:e9:af:fa:4d
inet addr:192.168.20.1 Bcast:192.168.20.255 Mask:255.255.255.0
inet6 addr: fe80::215:e9ff:feaf:fa4d/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:2849 errors:0 dropped:0 overruns:0 frame:0
TX packets:2571 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:318522 (311.0 KiB) TX bytes:248941 (243.1 KiB)
Interrupt:19
eth1 ...
eth0.200 Link encap:Ethernet HWaddr 00:15:e9:af:fa:4d
inet addr:192.168.10.30 Bcast:192.168.10.255 Mask:255.255.255.0
inet6 addr: fe80::215:e9ff:feaf:fa4d/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1484 errors:0 dropped:0 overruns:0 frame:0
TX packets:1450 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:136260 (133.0 KiB) TX bytes:153545 (149.9 KiB)
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:58563 errors:0 dropped:0 overruns:0 frame:0
TX packets:58563 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:5529672 (5.2 MiB) TX bytes:5529672 (5.2 MiB)
Проверяем связь с primary интерфейсом коммутатора:
Код:
root@kenger:/etc/tacacs+# ping 192.168.1.1 -c 4
PING 192.168.1.1 (192.168.1.1) 56(84) bytes of data.
64 bytes from 192.168.1.1: icmp_req=1 ttl=255 time=0.499 ms
64 bytes from 192.168.1.1: icmp_req=2 ttl=255 time=0.486 ms
64 bytes from 192.168.1.1: icmp_req=3 ttl=255 time=0.496 ms
64 bytes from 192.168.1.1: icmp_req=4 ttl=255 time=0.596 ms
--- 192.168.1.1 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 2999ms
rtt min/avg/max/mdev = 0.486/0.519/0.596/0.047 ms
Связь есть. Всё правильно.
Проверяем связь с secondary интерфейсом коммутатора:
Код:
root@kenger:/etc/tacacs+# ping 192.168.1.15 -c 4
PING 192.168.1.15 (192.168.1.15) 56(84) bytes of data.
64 bytes from 192.168.1.15: icmp_req=1 ttl=127 time=0.226 ms
64 bytes from 192.168.1.15: icmp_req=2 ttl=127 time=0.222 ms
64 bytes from 192.168.1.15: icmp_req=3 ttl=127 time=0.216 ms
64 bytes from 192.168.1.15: icmp_req=4 ttl=127 time=0.216 ms
--- 192.168.1.15 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 2999ms
rtt min/avg/max/mdev = 0.216/0.220/0.226/0.004 ms
Связь есть. Всё правильно.
Проверяем связь с 192.168.1.15 интерфейсом PC1:
Код:
root@kenger:/etc/tacacs+# ping 192.168.0.1 -c 4
PING 192.168.0.1 (192.168.0.1) 56(84) bytes of data.
--- 192.168.0.1 ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 2999ms
Связи нет. Всё правильно.
Проверяем связь с 192.168.0.15 интерфейсом PC1:
Код:
root@kenger:/etc/tacacs+# ping 192.168.0.15 -c 4
PING 192.168.0.15 (192.168.0.15) 56(84) bytes of data.
--- 192.168.0.15 ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 3024ms
Связи нет. Всё правильно.