1760上可以实现不同vlan的不同DHCP地址范围吗
如题!!
网友1:
可以,做两个ip pool就可以
楼主问:
然后如何把 这两个IP pool 映射到各自的VLAN呢?
网友2:
这是在用的3550的原配置:
Building configuration...
Current configuration : 46931 bytes
!
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname *******
!
logging buffered 200000 debugging
enable secret 5 $1$ql31$aUv35hIDmNlYNU6urlXkA0
enable password 7 06161B2F495A1E16171C
!
ip subnet-zero
ip routing
no ip domain-lookup
ip dhcp excluded-address 192.168.10.1 192.168.10.29
ip dhcp excluded-address 192.168.20.1 192.168.20.29
ip dhcp excluded-address 192.168.30.1 192.168.30.29
ip dhcp excluded-address 192.168.40.1 192.168.40.29
ip dhcp excluded-address 192.168.50.1 192.168.50.29
--More-- ip dhcp excluded-address 192.168.100.1 192.168.100.29
ip dhcp excluded-address 192.168.110.1 192.168.110.29
ip dhcp excluded-address 192.168.120.1 192.168.120.29
ip dhcp excluded-address 192.168.130.1 192.168.130.29
ip dhcp excluded-address 192.168.140.1 192.168.140.29
ip dhcp excluded-address 192.168.150.1 192.168.150.29
!
ip dhcp pool *_SBGL
network 192.168.10.0 255.255.255.0
default-router 192.168.10.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_GSLD
network 192.168.20.0 255.255.255.0
default-router 192.168.20.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_ZNBM
network 192.168.30.0 255.255.255.0
default-router 192.168.30.1
dns-server 202.101.103.55 202.101.107.55
--More-- lease 8
!
ip dhcp pool *_XTJCB
network 192.168.40.0 255.255.255.0
default-router 192.168.40.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_DXSYB
network 192.168.50.0 255.255.255.0
default-router 192.168.50.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_SCB
network 192.168.100.0 255.255.255.0
default-router 192.168.100.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_FWQ
network 192.168.110.0 255.255.255.0
default-router 192.168.110.1
--More-- dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_WBJR
network 192.168.120.0 255.255.255.0
default-router 192.168.120.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_SYS
network 192.168.140.0 255.255.255.0
default-router 192.168.140.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool *_IDC
network 192.168.130.0 255.255.255.0
default-router 192.168.130.1
dns-server 202.101.103.55 202.101.107.55
lease 8
!
ip dhcp pool ZHEKJ_SBGL
!
--More-- ip dhcp-server 192.168.10.1
ip accounting-threshold 1000
ip accounting-list 0.0.0.0 255.255.255.0
ip accounting-transits 3000
!
!
spanning-tree mode pvst
spanning-tree extend system-id
spanning-tree vlan 1 priority 24576
spanning-tree vlan 2 priority 24576
spanning-tree vlan 1024 priority 24576
!
!
!
--More-- interface FastEthernet0/1
description connect to F5 3550 Fa0/2
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
!
interface FastEthernet0/2
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
!
interface FastEthernet0/3
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
duplex full
speed 100
!
interface FastEthernet0/4
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
!
--More-- interface FastEthernet0/5
no ip address
!
interface FastEthernet0/6
no ip address
!
interface FastEthernet0/7
no ip address
!
interface FastEthernet0/8
no ip address
!
interface FastEthernet0/9
no ip address
!
interface FastEthernet0/10
switchport access vlan 80
switchport mode access
no ip address
!
interface FastEthernet0/11
switchport access vlan 90
switchport mode access
--More-- no ip address
!
interface FastEthernet0/12
switchport access vlan 60
switchport mode access
no ip address
!
interface FastEthernet0/13
switchport access vlan 120
no ip address
!
interface FastEthernet0/14
switchport access vlan 10
no ip address
!
interface FastEthernet0/15
switchport access vlan 80
switchport mode access
no ip address
!
interface FastEthernet0/16
no ip address
!
--More-- interface FastEthernet0/17
no ip address
!
interface FastEthernet0/18
no ip address
!
interface FastEthernet0/19
no ip address
!
interface FastEthernet0/20
no ip address
!
interface FastEthernet0/21
no ip address
!
interface FastEthernet0/22
no ip address
!
interface FastEthernet0/23
switchport access vlan 20
no ip address
!
interface FastEthernet0/24
--More-- no ip address
!
interface GigabitEthernet0/1
no ip address
!
interface GigabitEthernet0/2
no ip address
!
interface Vlan1
ip address 192.168.168.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan10
ip address 192.168.10.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan20
ip address 192.168.20.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan30
ip address 192.168.30.1 255.255.255.0
ip verify unicast source reachable-via rx
--More-- !
interface Vlan40
ip address 192.168.40.1 255.255.255.0
!
interface Vlan50
ip address 192.168.50.1 255.255.255.0
ip verify unicast source reachable-via rx
no ip proxy-arp
ip accounting output-packets
!
interface Vlan60
ip address 192.168.60.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan70
no ip address
ip verify unicast source reachable-via rx
!
interface Vlan80
ip address 192.168.80.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan90
--More-- ip address 202.109.251.1 255.255.255.192
ip verify unicast source reachable-via rx
!
interface Vlan100
ip address 192.168.100.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan110
ip address 192.168.110.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan120
ip address 192.168.120.1 255.255.255.0
ip access-group 120 in
ip access-group 115 out
ip verify unicast source reachable-via rx
ip accounting output-packets
ip accounting mac-address input
ip accounting mac-address output
ip accounting precedence output
priority-group 1
!
interface Vlan130
--More-- ip address 192.168.130.1 255.255.255.0
ip verify unicast source reachable-via rx
!
interface Vlan140
ip address 192.168.140.1 255.255.255.0
ip verify unicast source reachable-via rx
!
router ospf 100
log-adjacency-changes
network 192.168.120.1 0.0.0.0 area 0
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.120.2
ip http server
!
ip access-list extended denyicmp
deny icmp any any
permit ip any any
!
!
logging 192.168.168.172
access-list 1 deny 192.168.40.55 log
access-list 1 deny 192.168.40.57 log
--More-- access-list 1 deny 192.168.40.59 log
access-list 1 permit any
access-list 10 permit 192.168.50.18
access-list 10 permit 192.168.20.0 0.0.0.255
access-list 115 deny udp any any eq tftp
access-list 115 deny tcp any any eq 135
access-list 115 deny udp any any eq 135
access-list 115 deny udp any any eq netbios-ns
access-list 115 deny udp any any eq netbios-dgm
access-list 115 deny tcp any any eq 139
access-list 115 deny udp any any eq netbios-ss
access-list 115 deny tcp any any eq 445
access-list 115 deny tcp any any eq 593
access-list 115 deny tcp any any eq 4444
access-list 115 permit ip any any
access-list 120 permit ip any 192.168.120.0 0.0.0.255 log
access-list 120 permit ip any 192.168.110.0 0.0.0.255 log
access-list 120 permit ip any 192.168.100.0 0.0.0.255 log
access-list 120 permit ip any 192.168.90.0 0.0.0.255 log
access-list 120 permit ip any 192.168.80.0 0.0.0.255 log
access-list 120 permit ip any 192.168.70.0 0.0.0.255 log
access-list 120 permit ip any 192.168.60.0 0.0.0.255 log
access-list 120 permit ip any 192.168.50.0 0.0.0.255 log
--More-- access-list 120 permit ip any 192.168.40.0 0.0.0.255 log
access-list 120 permit ip any 192.168.30.0 0.0.0.255 log
access-list 120 permit ip any 192.168.20.0 0.0.0.255 log
access-list 120 permit ip any any
priority-list 1 protocol ip high list 150
priority-list 1 protocol ip high list 10
arp 192.168.50.168 0003.0d03.bb83 ARPA
snmp-server community * RO
snmp-server community public RO
snmp-server host 192.168.50.3 *
!
line con 0
privilege level 15
password 7 00140708014F1C091D2A
line vty 0 4
password 7 0103120A5E1F11003347
login
line vty 5 15
password 7 044B1F080A355B411B12
login
!
end
网友3:
俺想知道如何使各vlan的地址不会混
是因为vlan的原因吗?
网友4:
这个问题,我现在还不是太清楚
在上面的配置中,感觉应该是比如switch发现该端口属于vlan50后,因为配了
interface Vlan50
ip address 192.168.50.1 255.255.255.0
所以switch知道该vlan的ip应该是50段的,所以自动到50段的ip pool
ip dhcp pool *_DXSYB
network 192.168.50.0 255.255.255.0
default-router 192.168.50.1
dns-server 202.101.103.55 202.101.107.55
lease 8
里面选取一个50.×的ip分配给客户端
纯属推测
不一定准确