动态VLAN详细配置实例
作者 佚名技术
来源 网络技术
浏览
发布时间 2012-07-01
ether. You use these VLAN groups when defining VLAN port policies. Define the VLAN group name; then list each VLAN name you want to include in the VLAN group. You can enter a maximum of 256 VLANS in a VMPS database file for the Catalyst 2948G switch. The example at the end of this section has the VLAN group Engineering, which consists of the VLANs hardware and software. Section 5, VLAN port policies, lists the VLAN port policies, which use the port groups and VLAN groups to further restrict access to the network. You can configure a restricted access using MAC addresses and the port groups or VLAN groups. The example at the end of this section has three VLAN port policies specified. In the first VLAN port policy, the VLAN hardware or software is restricted to port 3/2 on the VMPS client 198.92.30.32 and port 2/8 on the VMPS client 172.20.23.141. In the second VLAN port policy, the devices specified in VLAN Green can connect only to port 4/8 on the VMPS client 198.92.30.32. In the third VLAN port policy, the devices specified in VLAN Purple can connect to only port 1/2 on the VMPS client 198.4.254.22 and the ports specified in the port group Executive Row. The following example shows a sample VMPS database configuration file. !Section 1: GLOBAL SETTINGS !VMPS File Format, version 1.1 ! Always begin the configuration file with ! the word "VMPS" ! !vmps domain <domain-name> ! The VMPS domain must be defined. !vmps mode {open | secure} ! The default mode is open. !vmps fallback <vlan-name> !vmps no-domain-req { allow | deny } ! ! The default value is allow. vmps domain WBU vmps mode open vmps fallback default vmps no-domain-req deny ! !Section 2: MAC ADDRESSES !MAC Addresses vmps-mac-addrs ! ! address <addr> vlan-name <vlan_name> ! address 0012.2233.4455 vlan-name hardware address 0000.6509.a080 vlan-name hardware address aabb.ccdd.eeff vlan-name Green address 1223.5678.9abc vlan-name ExecStaff address fedc.ba98.7654 vlan-name --NONE-- address fedc.ba23.1245 vlan-name Purple ! !Section 3: PORT GROUPS !Port Groups !vmps-port-group <group-name> ! device <device-id> { port <port-name> | all-ports } ! vmps-port-group WiringCloset1 device 198.92.30.32 port 3/2 device 172.20.26.141 port 2/8 vmps-port-group "Executive Row" device 198.4.254.222 port 1/2 device 198.4.254.222 port 1/3 device 198.4.254.223 all-ports ! !Section 4: VLAN GROUPS !VLAN groups ! !vmps-vlan-group <group-name> ! vlan-name <vlan-name> ! vmps-vlan-group Engineering vlan-name hardware vlan-name software ! !Section 5: VLAN PORT POLICIES !VLAN port Policies ! !vmps-port-policies {vlan-name <vlan_name> | vlan-group <group-name> } ! { port-group <group-name> | device <device-id> port <port-name> } ! vmps-port-policies vlan-group Engineering port-group WiringCloset1 vmps-port-policies vlan-name Green device 198.92.30.32 port 4/8 vmps-port-policies vlan-name Purple device 198.4.254.22 port 1/2 port-group "Executive Row" |
凌众科技专业提供服务器租用、服务器托管、企业邮局、虚拟主机等服务,公司网站:http://www.lingzhong.cn 为了给广大客户了解更多的技术信息,本技术文章收集来源于网络,凌众科技尊重文章作者的版权,如果有涉及你的版权有必要删除你的文章,请和我们联系。以上信息与文章正文是不可分割的一部分,如果您要转载本文章,请保留以上信息,谢谢! |
你可能对下面的文章感兴趣
上一篇: 二层交换机,三层交换机,四层交换机的区别下一篇: 三层交换主宰局域网
关于动态VLAN详细配置实例的所有评论