Bao Cao Vlan

Embed Size (px)

Citation preview

  • 8/13/2019 Bao Cao Vlan

    1/50

    Ging vin hng dn: Hu Thu

    hm thc hin: guyn m(1111020080)

    guyn nh Thin (1111020174)

    p: 11CTH01

    TP. H Ch inh, 2013

    B GIO DC V O TO

    R .

  • 8/13/2019 Bao Cao Vlan

    2/50

    2

    LI C

    Em xin gi li cm n chn thnh v stri n su sc i vi cc thy c ca trng i hc

    Cng NghTP.HCh inh, c bit l cc thy c khoa Cng NghThng Tin ca trng

    hng dn v gip em. V em cng xin chn thnh cm n c Hu Thu nhit tnh

    hng dn hng dn em hon thnh tt bi lap.

    Trong qu trnh hc tp, cng nh l trong qu trnh lm bi lap, kh trnh khi sai st, rt

    mong cc Thy, C bqua. Em rt mong nhn c kin ng gp Thy, C em hc

    thm c nhiu kinh nghim v shon thnh tt hn bi bo co tt nghip sp ti.

    Em xin chn thnh cm n !

  • 8/13/2019 Bao Cao Vlan

    3/50

    3

    L

    1. L UY .......................................................................................... 41.1 Tng qut v VLAN........................................................................................ 4

    1.1.1 Gii thiu ................................................................................................... 51.1.2 hi nim V ...................................................................................... 61.1.3 Cu hnh V ........................................................................................ 6

    1.2 VLAN Trunking Protocol (VTP)................................................................ 121.2.1 Gii thiu v VTP ................................................................................... 121.2.2 i t ca VTP ........................................................................................ 131.2.3 in VTP VTP domain)...................................................................... 131.2.4 Cc ch VTP...................................................................................... 14

    1.3 EtherChanels .................................................................................................. 141.3.1

    Tm hiu v EtherChanel ......................................................................... 141.3.1.1 Tng qut v EtherChanel.............................................................. 14

    1.3.1.2 Cc interface Port-Chanel ............................................................... 141.3.1.3 Port Aggregation Protocol(PAgP) .................................................. 15

    1.3.1.3.1 PAgP Modes .......................................................................... 171.3.1.3.2 t s tnh nng khc ca PgP........................................... 18

    1.3.1.4 Link Aggregation Control Protocol (LACP) ................................. 181.3.2 Cu hnh EtherChanel ............................................................................. 18

    1.3.2.1 Cu hnh EtherChanel mc nh ..................................................... 191.3.2.2 Cuhnh EtherChanel theo hng dn .......................................... 191.3.2.3 Cu hnh layer 2 EtherChanel ......................................................... 201.4 HSRP ............................................................................................................... 21

    1.4.1 S dng Default Gateway ....................................................................... 211.4.2 Proxy ARP ............................................................................................... 221.4.3 Router Redundancy ................................................................................. 301.4.4 Cu hnh layer 3 Redundancy vi giao thc HSRP ............................... 281.4.5 Qu trnh hot ng ca HSRP ............................................................... 29

    2. ....................................................................................... 332.1 hnh thc hnh ........................................................................................... 452.2 Thc hin cu hnh .......................................................................................... 452.3 t un .......................................................................................................... 56

  • 8/13/2019 Bao Cao Vlan

    4/50

    4

    1. L UYT

    1.1Tng Quan vVLAN1.1.1

    Gii thiung l mt mng cc bvit tc ca ocal rea etwork), c nh

    ngha l tt c cc my tnh trong cng mt min qung b broadcast domain). Cn

    nh rng cc router b nh tuyn) chn bn tin qung b, trong khi switch b

    chuyn mch) ch chuyn tip chng.

    ng c nhiu quy m v mc phc tp khc nhau, n c th ch lin kt

    vi ba my tnh c nhn v dng chung mt thit b ngoi vi t tin nh my in

    lazer chng hn. Cc h thng phc tp hn th c my tnh trung tm y chServer) cho php nhng ngi dng trao i thng tin vi nhau v thm nhp vo

    cc c s d liu dng chung.

    Phm vi ng dng ca mng - ng thng c s dng kt ni cc

    my tnh trong gia nh, trong mt phng Game, phng ET, trong mt to nh

    ca C quan, Trng hc.- Cly ca mng gii hn trong phm vi c bn

    knh khong 100m- Cc my tnh c c ly xa hn thng thng ngi ta s dng

    mng Internet trao i thng tin.

    hnh mng khng c V l mt mng phng flat network) v n hot ng

    chuyn mch p 2. t mng phng l mt nim qung b broadcast), mi gi

    qung b t mt host no u n c cc host cn li trong mng. i cng

    trong switch l mt min ng collision), v vy ngi ta s dng switch

    chia nh min collision, nhng n khng ngn c min qung b.

    V bg tg: trong mt s trng hp mt mng Campus lp 2 cth m thm mt s ta nh cao tng na, hay mt s ngi dng tng ln

    th nhu cu s dng bng thng cng tng, do kh nng thc thi ca

    mng cng gim.

    V bo mt: mi ngi dng no cng c th thy cc ngi dngkhc trong cng mt mng phng flat network), do rt kh bo mt.

    V v bg ti: trong mng phng ta khng th thc hin truyntrn nhiu ng i, v lc mng d b vng lp, to nn cn bo qung

  • 8/13/2019 Bao Cao Vlan

    5/50

    5

    b broardcast storm) nh hng n bng thng ca ng truyn. Do

    khng th chia ti cn gi l cn bng ti).

    gii quyt vn trn, ta a ra gii php V. V Virtual ocal rea

    etwork) c nh ngha l mt nhm logic cc thit b mng, v c thit lp

    da trn cc yu t nh chc nng, b phn, ng dngca cng ty. i V l

    mt mng con logic c to ra trn switch, cn gi l on hay min qung b

    (broadcast).

    V Virtual ocal rea etwork) c nh ngha l mt nhm logic cc thit

    b mng, v c thit lp da trn cc yu t nh chc nng, b phn, ng

    dngca cng ty. i V l mt mng con logic c to ra trn switch, cngi l on hay min qung b broadcast).

    V l mt mng o. V mt k thut, V l mt min qung b c

    to bi cc switch. Bnh thng th router ng vai to ra min qung b. i

    V th c th to ra min qung b.V l mt k thut kt hp chuyn mch

    lp 2 v nh tuyn lp 3 gii hn min ng v min qung b. V cn

    c s dng bo mt gia cc nhm V theo chc nng mi nhm.

    V vi cch phn ngun ti nguyn v user theo logic lm tng hiu qu

    hot ng ca ton h thng mng. Cc cng ty, t chc thng s dng V

    phn nhm user theo logic m khng cn quan tm n v tr vt l ca h.

    Vi V, mng c kh nng pht trin, bo mt v qun l tt hn v router

    trong cu V c th ngn gi qung b, bo mt v qun l dng lu lng

    mng.

    Hnh2.1: M hnh mng LAN o

  • 8/13/2019 Bao Cao Vlan

    6/50

    6

    1.1.2hi i v

    VLAN l mt nhm cc thit b mng khng gii hn theo v tr vt l hoctheo LAN switch m chng kt ni vo.

    VLAN l mt segment mng theo logic da trn chc nng, i nhm, hoc ngdng ca mt tchc chkhng phthuc vo v tr vt l hay kt ni vt ltrong mng. Tt c cc trm v server c s dng bi cng mt nhm lmvic sc t trong cng VLAN bt kvtr hay kt ni vt l ca chng.

    Mi cng vic cu hnh VLAN hoc thay i cu hnh V iu c thchin trn phn mm m khng cn thay i cp v thit bvt l.

    Mt my trm trong mt VLAN ch c lin lc vi file server trong cngVLAN vi n. V c nhm theo chc nng logic v mi VLAN l mtmin qung b, do gi dliu chc chuyn mch trong cng mt VLAN.

    VLAN c khnng mrng, bo mt v qun l mng tt hn. Router trong cutrc VLAN thc hin ngn chn qung b, bo mt v qun l ngun giao thngmng. Switch khng th chuyn mch giao thng gia cc VLAN khc nhau.Giao thng gia cc VLAN phi c nh tuyn qua router.

    1.1.2.1Mi qug b vi v routert V l mt nim qung b c to nn mt hay nhiu switch.

    Hnh2.2: M in qung b trn 3 swi tch khc nhau

    Trong hnh 2.9 cho thy to 3 min qung b ring bit trn ba switch nh th no.

    nh tuyn p 3 cho php router chuyn gi gia cc min qung b vi nhau.

  • 8/13/2019 Bao Cao Vlan

    7/50

    7

    Hnh2.3: M in qung b trn mt switch

    Trong hnh 2.10 chng ta thy 3 V tc l 3 min qung b khc nhau c to

    ra trn mt switch v mt router. Router s s dng nh tuyn p 3 chuyn

    giao thng gia 3 V.

    Switch trong hnh trn s truyn frame ln cng giao tip ca router khi:

    Gi d liu l gi qung b. Gi d liu c a ch C ch l mt trong cc a ch C ca router.

    u my trm 1 trong V thut mun gi d liu cho my trm 2 trong V

    Bn hng, hai my ny nm trong 2 min qung b khc nhau, thuc hai mng khc

    nhau, do a ch C ch trong gi d liu s a ch C ca default gateway

    ca my trm 1. V vy a ch C ch ca gi d liu s l a C ca tng

    Fa0/0 trn router. Gi d liu c chuyn n router, bng nh tuyn IP, router s

    chuyn gi ng V Bn hng.

    u my trm 1 trong V thut mun gi gi d liu cho my trm 2 trong

    cng mt V th a ch C ch ca gi d liu s chnh l a ch C ca

    my trm 2.

    Tm li, switch s x l chuyn mch gi d liu khi c chia V nh sau:

    i vi mi V switch c mt bng chuyn mch ring tng ng.

  • 8/13/2019 Bao Cao Vlan

    8/50

    8

    u switch nhn c gi d liu t mt port nm trong V 1 chng hn, th switch s tm a ch C ch trong bng chuyn mch ca V m

    thi.

    ng thi switch s hc a ch C ngun trong gi d liu v ghi vobng chuyn mch ca V 1 nu a ch ny cha c bit.

    Sau switch quyn nh chuyn gi d liu. Switch nhn frame vo t V no th switch ch hc a ch ngun ca

    frame v tm a ch ch cho frame trong mt bng chuyn mch tng ng

    vi V .

    1.1.1.1Hot ng ca VLANi port trn switch c th gn cho mt V khc nhau. Cc port nm trong cng

    mt V s chia s gi qung b vi nhau. Cc port khng nm trong cng V

    s khng chia s gi qung b vi nhau. h mng hot ng hiu qu hn.

    Hnh2.4: VLAN cnh

    Thnh vin c nh ca V c xc nh theo port. hi thit b kt ni vo mt

    port ca switch, tu theo port thuc loi V no th thit b s nm trong V

    .

    c nh, tt c cc port trn mt switch u nm trong V qun l. V qun

    l lun lun l V 1 v chng ta khng th xo V ny c.

  • 8/13/2019 Bao Cao Vlan

    9/50

    9

    Sau chng ta c th cu hnh gn port vo cc V khc. V cung cp bng

    thng tin nhiu hn cho user so vi mng chia s. Trong mng chia s, cc user cng

    chia s mt bng thng trong mng , cng nhiu user trong mt mng chia s th

    lng bng thng cng thp hn v hiu sut hot ng cng gim i.

    Thnh vin ng ca V c cu hnh bng phn mm qun l mng. Bn c th

    s dng CiscoWorks 2000 hoc CiscoWorks for Switch Internetworks to V

    ng. V ng cho php cc nh thnh vin da theo a ch C ca thit b kt

    ni vo switch ch khng cn xc nh theo port na. hi thit b kt ni vo switch,

    switch s tm trong c s d liu ca n xc nh thit b ny thuc loi V no.

    Hnh2.5: VLAN ng

    Cu hnh V bng cc phn mm V qun l tp trung.C C th chia V theo a ch C, a ch lgic hoc theo loi giao thc. hng cn qun l nhiu cc t ni dy na v thit b kt ni vo mng

    thuc V no l tu theo a ch ca thit b c gn vo V.

    C kh nng thng bo cho qun tr mng khi c mt user l, khng c trongc s d liu kt ni vo mng.

    Xc nh thnh vin V theo port tc l port c gn vo V no th thit

    b kt ni vo port thuc V , khng ph thuc vo thit b kt ni l thit b

    g, a ch bao nhiu. Vi cch chia V theo port nh vy, tt c cc user kt ni

    vo cng mt port s nm trong cng mt V. t user haynhiu user c th kt

    ni vo mt port v s khng nhn thy l c s tn ti ca V. Cch chia V

  • 8/13/2019 Bao Cao Vlan

    10/50

    10

    ny gip vic qun l n gin hn v khng cn tm trong c s d liu phc tp

    xc nh thnh vin ca mi V.

    gi qun tr mng c trch nhim cu hnh V bng tay v c nh.

    i mt port trn switch cng hot ng ging nh mt port trn bridge. Bridge s

    chn lung lu lng nu n khng cn thit phi i ra ngoi segment. u gi d liu

    cn phi chuyn qua bridge v switch khng bit a ch ch hoc gi nhn c l

    gi qung b th mi chuyn ra tt c cc port nm trong cng min qung b vi port

    nhn gi d liu vo.

    Hnh2.6: Chia VLAN theo port

    u i ca :

    i ch ca V l cho php ngi qun tr mng t chc mng theo logic chc

    khng theo vt l na. h nhng cng vic sau thc hin d dng hn:

    C tnh linh ng cao: di chuyn my trm trong d dng. Thm my trm vo d dng: Trn mt switch nhiu cng, c th c th

    cu hnh V khc nhau cho tng cng, do d dng kt ni thm cc my

    tnh vi cc V.

    Thay i cu hnh d dng. im sot giao thng mng d dng.

  • 8/13/2019 Bao Cao Vlan

    11/50

    11

    Gia tng bo mt: Cc V khc nhau khng truy cp c vo nhau tr khic khai bo nh tuyn).

    Tit kim bng thng ca mng: do V c th chia nh thnh cc onl mt vng qung b). hi mt gi tin qung b, n s c truyn i ch

    trong mt V duy nht, khng khng truyn i cc V khc nn gim

    lu lng qung b, tit kim bng thng ng truyn.

    C th to ra mng o, to ra cc nhm lm vic khng ph thuc vovtr ca thit b, chng hn, nhng ngi thuc cng nhm nghin cu khng cn

    ngi cng mt phng hay cng mt tng trong to nh m vn l cc thnh vin

    trong mt mng o.

    1.1.1.2u hh u hh theo vt l:

    V t u cui - n - u cui cho php phn nhm ngun ti nguyn s dng, v

    d nh phn nhm user theo server s dng, nhm d n v theo phng ban... c

    tiu ca V t u n cui - n - u cui l gi 80% giao thng trong ni b

    ca V.

    Chnh v xu hng s dng v phn b ti nguyn mng khc i nn hin nay V

    thng c to ra theo gii hn ca a l.

    Phm vi a l c th ln bng c mt to nh hoc cng c th ch nh vi mt

    switch. Trong cu trc V ny. T l lu lng s l 20/80, 20% giao thng trong

    ni b V v 80% giao thng i ra ngoi V.

    im ny c ngha l lu lng phi i qua thit b lp 3 mi n c 80% ngun ti

    nguyn. iu thit k ny cho php vic truy cp ngun ti nguyn c thng nhtu hh c h:

    V c nh l V c c hnh theo port trn switch bng cc phn mm qun

    l hoc cu hnh trc tip trn switch. Cc port c gn vo V no th n s

    gi nguyn cuhnh V cho n khi thay i bng lnh. y l cu trc V

    theo a l, cc user phi i qua thit b lp 3 mi truy cp 80% ti nguyn mng. oi

    V c nh hot ng tt trong nhng mng c c im sau:

    S di chuyn trong mng c qun l v kim sot.

  • 8/13/2019 Bao Cao Vlan

    12/50

    12

    C phn mm qun l V mnh cu hnh port trn switch. hng dnh nhiu ti cho hot ng duy tr a ch C ca thit b

    u cui v iu cnh bng a ch.

    1.2VLAN Trunking Protocol (VTP)1.2.1ii thiu v

    VTP l giao thc hot ng lp 2 trong m hnh OSI. VTP gip cho vic cu hnh

    V lun hot ng ng nht khi thm, xa, sa thng tin v V trong h

    thng mng.

    Trong khun kh mi trng chuyn mch V. t ng Trunk l mt ng

    kt ni point - to-point h tr cc V trn cc switch lin kt vi nhau. t

    ng cu hnh Trunk s gp nhiu ng lin kt o trn mt ng lin kt vt l

    chuy tn hiu t cc V trn cc switch vi nhau da trn mt ng cp vt l.

    Vai tr ca VTP l duy tr cu hnh V thng qua admin domain ca mng. VTP

    p 2 mt giao thc p 2 s dng cc Trunk Frame qun l vic thm bt, xa v

    i tn cc V trn mt domain. Thm na, VTP cho php tp trung cc thay iti tt c cc switch trong mng.

    Thng ip VTP c nggi trong mt chun CISCO l giao thc IS hoc IEEE

    802.1q v sau i qua cc lin kt Trunk ti cc thit b khc.

    1.2.2i t ca VTP c th cu hnh khng ng, khi s thay i to ra. Cc cu hnh khng ng c

    th tng hp trong trng hp thngk cc vi phm nguyn tc bo mt. bi v cc k

    ni V b chng cho khi cc V b t trng tn. Cc cu hnh khng ng

    ny c th b ct kt ni khi chng c nh x t mt kiu ti mt kiu

    khc. VTP cung cp cc li ch sau:

    Cu hnh ng cc V qua mng. H thng nh x cho php 1 V c trunk qua cc mi trng truyn

    hn hp. Ging nh nh x cc V Enthernet ti cc ng truyn tc

    cao nh T, E, hoc FDDI.

  • 8/13/2019 Bao Cao Vlan

    13/50

    13

    Theo di chnh xc kim tra V Bo ng v vic thm vo ccVLAN. D dng thm mi V

    Trc khi thit lp cc V, ta phi thit lp mt min qun l management

    domain) trong phm vi nhng th m ta kim tra cc V trong mng. Cc switch

    trong cng mt min qun l chia s thng tin V vi cc V khc vmt s

    switch c th tham gia vo ch mt min qun l VTP. Cc switch khc min khng

    chia s thng tin VTP.

    Cc switch s dng giao thc VTP th trn mi cng trunk ca n c:

    in qun lmanagment domain) S cu hnh Bit c V v cc thng s c th.1.2.3Mi doai

    t min VTP VTP domain) c to ra mt hay nhiu cc thit b a kt ni chia

    s trn cng mt tn min VTP. i switch ch c th c mt min VTP. hi mt

    thng ip VTP truyn ti cc switch trong mng, th tn min phi chnh xc thng

    tin truyn qua.

    ng gi VTP vi IS Frame:

    VTP header c nhiu kiu trn mt thng ip VTP, c 4 kiu thng c tm thy

    trn tt c cc thng ip VTP:

    Phin bn giao thc VTP 1 hoc 2 iu thng ip VTP 1 trong 4 kiu di tn ca min qun l Tn min qun l

    VTP flood thng ip qung b advertisement) qua VTP domain 5 pht mt ln, hoc

    c s thay i xy ra trong cu hnh V. t VTP advertisement bao gm c

    revisionnumber, tn V vlan name), s hiu V(vlan number), v thng tin

    v cc switch c port gn vi mi V. Bng s cu hnh VTP Server v vic truyn

  • 8/13/2019 Bao Cao Vlan

    14/50

    14

    b thng tin thng qua advertisement , tt c cc switch u bit v tn V v s

    hiu ca V ca tt c cc V.

    t trong nhng thnh phn quan trng ca VTP advertisement l tham s revision

    number. i ln VTP Server iu chnh thng s V, n tng revision number

    ln 1, ri sau VTP Server mi gi VTP advertisement i. hi mt switch nhn mt

    VTP advertisement vi revision number ln hn, n s cp nht cu hnh V.

    1.2.4c ch VTP hot ng mt trong 3 ch :

    -Server-Client-Transparent

    u mt Switch ch VTP server c th to, chnh sa, xa V. VTP server

    lu cu hnh V trong VR ca n. VTP servergi thng ip ra tt c cc

    port trunk ca n.

    Switch ch VTP Client khng to, chnh sa v xa thng tin. VTP Client c

    chc nng p ng theo mi s thay i ca V t server v gi thng ip ra ttc cc port trunk ca n.

    VTP Client khng lu cu hnh trong VR m ch t trn R v n th c hc

    cu hnh V t server. Do ch client rt hu dng khi switch khng b

    nh lu mt lng ln thng tin V.

    Switch ch transparent s nhn v chuyn tip forward) cc VTP update do cc

    switch do cc switch khc gi n m khng quan tm n ni dung ca cc thng

    ip ny. u transparent switch nhn thng tin cp nht VTP n cng khng cp nht

    vo c s ca n, ng thi nu cu hnh V ca n c g thay i, n cng khng

    gi thng tin cp nht cho cc switch khc. Trn transparent switch ch c mt vic

    duy nht l chuyn tip thng ip VTP. Switch hot ng ch transprarent -

    mode ch c th to ra V cc b. Cc vlan ny s khng qung b n cc switch

    khc.

    1.3Etherchannels1.3.1 hiu v therchannels

  • 8/13/2019 Bao Cao Vlan

    15/50

    15

    Trong phn ny s bao gm mt s ch sau:

    + Tng quan v EtherChannel.

    + Giao din Port-Channel

    + Giao thc Port ggregation

    + Giao thc iu khin ink ggregation.

    + Cc mode EtherChannel.

    + Cc phng thc chuyn d liu v chia ti d liu

    1.3.1.1g qua v therhaelt EtherChannel bao gm nhiu ng vt l fast ethernet Fa 10/100bps) hoc

    gigabit ethernet 10/100/1000 bps) c gp thnh mt kt ni logical.EtherChannel c khnng cho php cc port dng kt ni hot ng ch Full-

    duplex. V bng thng trn mi mt kt ni vt l c th t ti tc l 800 bps

    i vi kt ni Fast Ethernet Fast EtherChannel), i vi kt ni gigabit ethernet th

    tc ca mi ngvt l c th t mc ti a l 8 Gbps Gigabit EtherChannel)

    i EtherChannel c th gp ti a l 8 ng Ethernet port, tt c cc port trong

    EtherChannel s phi cu hnh nh mt ayer 2 port.

    S EtherChannel c th cu hnh ti a trn Switch c gii hn l 6.

    Bn c th cu hnh cc port EtherChannel hot ng vi nhng ch sau:

    Port Aggregation Protocol (PAgP) Link Aggregation Control Protocol (LACP) On

    Cu hnh c 2 port u cui ca EtherChannel hot ng cng mt ch :

    hi bn cu hnh 1 port u cui ca EtherChannel hot ng c 2 ch : PgP

    hoc CP, h thng s t ng iu chnh vi port u cui cn li ca EtherChannel

    xc nh ch no s c hot ng. hi qu trnh t ng iu chnh khng

    thnh cng th nhng port s hot ng vi trng thi suspended i vi cc IOS

    12.2 tr v trc). Bt u t Cisco IOS Release 12.235) SE th thay v cc port

    hot ng vi trng thi suspended th nhng port local s hot ng trng thi

    independent v vn c kh nng truyn d liu nh nhng port khc. Cu hnh port

    khng thay i, nhng port s khng c kh nng hot ng trong mt

  • 8/13/2019 Bao Cao Vlan

    16/50

    16

    EtherChannel.

    hi bn cu hnh mt EtherChannel hot ng ch On, th khng c qu trnht

    ng iu chnh ch hotng trn cc port ca Switch na. hi tt c nhng

    port ca switch s c active v hot ng trong mt EtherChannel.

    u mt lin kt ang hot ng trong mt EtherChannel b li, th nhng lu lng

    d liu ang truyn trn lin kt s t ng c chuyn sang nhng lin kt cn li

    trong EtherChannel truyn tip. u tnh nng Traps c cu hnh hot ng trn

    switch th khi mt lin kt ca EtherChannel b li s c mt thng bo li c gi

    n switch xc nh lin kt b li. Vi nhng gi tin broadcast v gi tin

    muticast i vo mt lin kt s b chn li. 1.3.1.2c iterface ort-channel

    hi bn to ra cc EtherChannel, 1 port-channel logical interface s phi c to ra.

    Bn c th to EtherChannel theo nhng phng phpsau:

    + S dng cu lnh channel-group ch configuration. Cu lnh ny s t ng

    to interface logical port-channel khi channel group gn nhng port vt l vo. Cu

    lnh channel-group c kh nng gn vo nhng port vt l: Ethernet, Fastethernet hoc

    Gigabit Ethernet (10/100/1000 Mbps).

    + S dng cu lnh interface port-channel port-channel-number cu hnh ch

    global configuration to port-channel logical interface. Sau dng cu lnh

    channel-group channel-group-number cu hnh ch interface gn cc port vt

    l vo logical port (port-channel).Channel-group-number c th to ra ging vi port-

    channel-number, hoc bn c th s dng mt s khc. u bn s dng ch s

    channel-group-number khc so vi ch s ca port

    -channel-number th cu lnh

    channel-group t ng to mt port channel mi.

    i EtherChannel c mt port-channel logical interface c gi tr t 1 n 6. Ch s

    port-channel interface tng ng c ch ra vi cu lnh channel-group cu hnh

    ch interface.

    Sau khi bn cu hnh mt EtherChannel, nhng cu hnh thay i v port-channel

    interface s c gn vo tt c cc port vt l c chia vo port -channel interface.

    hng thay i v cu hnh s c gn cho cc port vt l, chnh v vy thay i

  • 8/13/2019 Bao Cao Vlan

    17/50

    17

    cc tham s cu hnh trn tt c cc port trong mt EtherChannel th s phi gn nhng

    cu lnh cu hnh vo port-channel interface.

    1.3.1.3Port Aggregation Protocol (PAgP)Port ggregation Protocol PgP) l mt giao thc c quyn ca cisco v vy ch c

    th chy duy nht trn cc thit b Switch ca cisco v nhng switch ca cc hng khc

    c th h tr giao thc PgP. PgP c kh nng t ng to cc EtherChannel bng

    cch trao i cc gi tin PgP gia cc Ethernet ports.

    - Bng cch s dng PgP, cc switch s hc ID identity) ca cc switch khc c h

    tr PgP thng qua mi port kt ni. Sau switch s t ng nhm nhng port c

    cng thng s cu hnh vo trong mt lin kt logical channel hoc aggregate port).Cc port c nhm li vi nhau da trn phn cng, v cc tham s khc. V d,

    PgP nhm nhng port c cng tc , cng ch duplex Full duplex hoc half

    duplex), native Vlan, di Vlan, v trng thi ng trunk. Sau khi nhm nhng lin kt

    ny vo mt EtherChannel, PgP s cho php EtherChannel hot ng nh mt port

    vi giao thc STP Spanning tree protocol)

    1.3.1.3.1PAgP ModesPgP s hot ng ch yu 2 ch :

    + uto: khi PgP hot ng ch auto th port ny s trng thi passive

    negotiating, v port ny s chu trch nhim tr li cc gi tin PgP m n nhn c

    nhng n s khng khi to mt gi tin PgP t ng iu chnh. Vi ch ny

    th s ti u c qu trnh truyn cc gi tin PgP.

    + Desirable: hi Pgp hot ng ch Desirable th port ny s trng thi

    active negotiating, v port ny s ch ng iu chnh m phn vi cc port khcbng cch gi i cc gi PgP.

    - Cc port ca Switch trao i cc gi tin PgP duy nht vi cc port khc c cu hnh

    ch auto hoc desirable. Cc port cu hnh ch On th s khng trao i cc

    gi tin PAgP.

    - hi mt port ca switch hot ng ch uto hoc Desirable th port ny s t

    ng iu chnh vi nhng port khc cng EtherChannel v tc , trng thi ng

    trunking v cc thng s Vlan.

  • 8/13/2019 Bao Cao Vlan

    18/50

    18

    1.3.1.3.2Mt s th g hc ca agGiao thc DTP Dynamic Trunking Protocol) v giao thc CDP Cisco Discovery

    Protocol) c kh nng gi v nhn nhng gi tin trn nhng port vt l trong mt

    EtherChannel. Cc port c cu hnh trunk c th gi v nhn cc gi tin PgP

    protocol data units PDUs) trn Vlan c ID thp nht.

    - Trong mi EtherChannel, port vt l u tin trong channel s hot ng v cung

    cp a ch C ca n cho EtherChannel. u port b xa b khi EtherChannel,

    th mt port no cn li trong EtherChannel s hot ng up) v cung cp a ch

    C ca n cho EtherChannel .

    - PgP c kh nng gi v nhn PgP PDU duy nht trn nhng port vt l hot ngup) v c giao thc PgP c hot ng mt trong hai ch : uto hoc

    Desirable.

    1.3.1.4 Link Aggregation Control Protocol (LACP)Giao thc CP c nh ngha v cng b bi t chc IEEE vi chun IEEE

    802.3ad v cho php cc switch ca cisco c th qun l cc Ethernet Channels. Giao

    thc CP c kh nng t ng to cc EtherChannel bng cch trao i cc gi tin

    CP gia cc Ethernet port.

    - hi s dng CP, cc switch s t hc ID identity) ca cc switch khc c h tr

    CP thng qua mi port kt ni vt l. Sau switch s t ng nhm nhng port c

    cng thng s cu hnh vo trongmt lin kt logical channel hoc aggregate port).

    Cc port c nhm li vi nhau da trn phn cng, v cc tham s khc. V d,

    CP nhm nhng port c cng tc , cng ch duplex Full duplex hoc half

    duplex), native Vlan, di Vlan, v trng thi ng trunk. Sau khi nhm nhng lin kt

    ny vo mt EtherChannel, CP s cho php EtherChannel hot ng nh mt port

    vi giao thc STP Spanning tree protocol).

    1.3.2u hh therhaelTrong phn ny bao gm nhng ch sau:

    + Cu hnh EtherChannel mc nh

    + Cu hnh EtherChannel theo guidelines.

  • 8/13/2019 Bao Cao Vlan

    19/50

    19

    + Cu hnh ayer 2 EtherChannel

    + Cu hnh EtherChannel chia ti truyn d liu

    + Cu hnh PgP earn ethod v Priority

    + Cu hnh CP Hot-Standby Ports.

    1.3.2.1u hh therchael c h1.3.2.2u hh therhael theo hg d

    u cu hnh khng hp l, mt s EtherChannel port s khng c kh nng ngn

    c nhng vng lp xy ra v mt s nhng vn khng ng c khc. Di y l

    mt s nhng tham s cu hnh cc bn nn chn trong qu trnh cu hnh

    EtherChannel ngn c cc vng lp v mt s nhng vn khc c th xy ra:

    + hng nn cu hnh nhiu hn 6 EtherChannel trn mt Switch.

    + Cu hnh giao thc PgP hot ng cng lc vi 8 port Ethernet.

    + Cu hnh giao thc CP hot ng cng lc vi 16 port Ethernet. hi 8 port

    s c hot ng v 8 port cn li s hot ng ch standby nhm mc ch d

    phng.

    + Tt c cc port hot ng trong mt EtherChannel s phi hot ng cng mt tc

    v ch duplex Full duplex hoc half duplex).

    + hi tt c cc port c cu hnh trong EtherChannel m mt port no b

    shutdown th lin kt b li, v cc lu lng d liu s c truyn trn nhng lin

    kt cn li ca EtherChannel.

    + hi mt nhm c to, th cc tham s ca port u tin c gn vo nhm

    s c ly l cc tham s dnh cho nhm . u bn thay i mt tham s no

    cho port th bn s phi thay i trn tt cc port cn li trong nhm: - Danh sch Allowed-VLAN

    - Cost path Spanning-tree cho mi V

    - Priority port Spanning-tree cho mi V.

    - Cc tham s ca Port Spanning-Tree

    + hng c php cu hnh mt port l thnh vin ca nhiu nhm EtherChannel.

    + hng cu hnh mt nhm EtherChannel hot ng cng ch PgP v CP.

    i nhm EtherChannel c th c php hot ng vi PgP hoc CP trn cng

  • 8/13/2019 Bao Cao Vlan

    20/50

    20

    mt switch.

    + hng c php gn mt port SP Switched Port nalyzer) ch l mt

    thnh phn ca mt nhm EtherChannel.

    + Khng c php gn mt port secure l thnh phn ca mt nhm EtherChannel.

    + hi bn gn mt port no hot ng trong mt nhm EtherChannel th

    bn s khng th no c php cho php port hot ng vi giao thc IEEE

    802.1x, nu bn c cho port hot ng vi giao thc ny th s c mt thng bo li

    xut hin.

    + u mt port c gn vo mt nhm EtherChannel, th bn phi di chuyn

    port ra khi EtherChannel trc khi cho php port hot ng vi giao thc IEEE802.1x

    + Layer 2 EtherChannels:

    Gn tt c cc port trng mt nhm EtherChannel vo cng mt Vlan, hoc cu hnh

    hot ng vi ch Trunk. Cc port khng thuc ative Vlan th s khng th no

    hot ng trong mt nhm EtherChannel.

    u bn gn cc port hot ng vi ch trunk vo mt nhm EtherChannel, th bn

    phi kim tra cc port yu cu phi c cu hnh cng mt giao thc l IEEE

    802.1q hoc IS

    1.3.2.3u hh laer therhaelBn cu hnh mt ayer 2 EtherChannel bng cch gn cc port vo mt channel

    group vi cu lnh: channel-group c cu hnh trong ch interface configuration.

    Cu lnh ny s t ng to mt port-channel logical interface.

    Bt u t ch privileged EXEC ca switch cc bn c th thc hin theo tng bc

    vi nhng cu lnh di y:

    + Configure terminal: vo ch global configuration

    + interface interface-id: Ch ra mt port vt l, v vo ch interface

    configuration Vi giao thc PgP EtherChannel th bn c th cu hnh c 8 port

    cng hot ng v cng tc . Cn vi giao thc CP EtherChannel th bn c th

    cu hnh ti a l 16 port cng hot ng, trong c 8 port ang hot ng cn 8 port

    cn li s hot ng ch standby.)

  • 8/13/2019 Bao Cao Vlan

    21/50

    21

    + switchport mode {access | trunk }:

    switchport access vlan vlan-id: gn tt c cc port vo cng mt vlan hoc cu hnh

    chng hot ng ch trunk.

    + channel-group channel-group-number mode {auto | desirable | on }: gn port

    vo mt channel group, v chn giao thc PgP hoc CP s dng.

    + end: thot ra ch privileged EXEC.

    1.4HSRP(Hot Standby Router Protocol)1.4.1 dg efault atewa

    t my tnh trong mng c th i n cc ng mng khc nhau th ta phi cu

    hnh default gateway. Gi s PC trn s cu hnh default gateway hng n

    Router chuyn tip gi tin i n file server . V Router B cng c cu

    hnh nh tuyn.

    Trong m hnh bn di Router c chc nng routing cc packet n nhn c nsubnet . Cn router B c chc nng routing n subnet B. u nh Router b hng

    hc khng c cn s dng c na th cc c ch nh tuyn ng s tnh ton li v

    quyt nh Router B s l thit b chuyn tip gi tin thay th cho router .

    hng PC th khng th no nhn bit c thng tin nh tuyn ny c. cc

    PC ta thng ch cu hnh duy nht mt default gateway IP v a ch IP ny s khng

    thay i khi m hnh mng ca ta thay i. h vy dn n trng hp l PC

    khng th gi traffic i n cc host thuc cc ng mng khc trong m hnh mng.

  • 8/13/2019 Bao Cao Vlan

    22/50

    22

    u nh mt router no d phng v hot ng ging nh default gateway cho

    segment th ta khng cn phi cu hnh li a ch IP default gatway cho cc PC.

    1.4.2Proxy ARP

    Cisco IOS s dng proxy rp cho php cc host m n khng c tnhnng nh

    tuyn c th ly c a ch ac address ca gateway c th forward packet ra

    khi local subnet. V d nh trong m hnh trn proxy RP router nhn c mt gi

    tin RP request t mt host cho mt a ch IP. a ch IP ny khng c cng nm

    chung mt segment so vi host gi gi tin request. Router s gi v mt gi tin RP

    vi ac address l ca router v IP l a ch m my cn i n. h vy host s gi

    ton b tt c cc packet n a ch IP c phn gii thnh ac address ca

    router. Sau router li lm tip cng vic y gi tin ny i n a ch IP cn n.

    h vy vi tnh nng proxy RP cc end-user station s coi nh l cc destination

    device c kt ni n chnh phn on mng ca n. u nh router l chc nng

    proxy RP b fail th cc end station vn tip tc gi packet n IP c phn gii

    thnh ac address ca fail router. V cc packet s b discard.

  • 8/13/2019 Bao Cao Vlan

    23/50

    23

    Thc t th Proxy ac address c thi gian sng nht nh trong bng RP cache ca

    my tnh. Sau khong thigian ny th workstation s yu cu a ch ca mt router

    khc. hng n khng th gi traffic trong sut khong thi gian ny.

    1.4.3Router Redundancy

    Trong HSRP mt thit lp cho cc router hot ng phi hp vi nhau a ra mt

    router o cho cc host trong mng . Bng cch dng chung mt a ch IP v a

    ch ac layer 2, hai hay nhiu router c th hot ng nh l mt router o. IP

    address oc cu hnh nh l default gateway cho cc my trm trong mt segment.

    hi nhng frame c gi t mt my trm n n default gateway, cc my trm

    dng c ch RP phn gii C address vi a ch IP default gateway. C ch

    RP s c tr v bngac address ca virtual router. Cc frame gi n ac

    address o v sau frame ny c x l tip tc bi active hoc l standby router

    trc thuc group router o m ta ang cu hnh.

    t hay nhiu router s dng giao thc ny quyt nh router vt l no s c trch

    nhim x l frame c gi n a ch IP o v a ch ac o. Cc my trm s gi

    traffic n router o. t router tht s c trch nhim forward traffic ny i tip tuy

  • 8/13/2019 Bao Cao Vlan

    24/50

    24

    nhin router tht nay trong trng thi transparent so vi cc my trm u cui.Giao

    thc redundacy ny cung cp cho ta mt c ch quyt nh router no s vai tr

    active trong vic forward traffic v router no s vai tr standby.

    hi mt forwarding router b fail th qu trnh chuyn i s din ra nh sau:

    hi standby router khng cn nhn c gi tin hello t mt forwarding router Sau standby router s gi nh vai tr ca n lc ny l forwarding router c ny qu trnh truyn frame ca PC s khng b nh hng g bi v router

    ang trng thi forwarding s dng IP address o vo ac address nh lc

    ban u.

    1.4.4 u hh laer edudac vi giao thc Ta c s lun l nh sau:

  • 8/13/2019 Bao Cao Vlan

    25/50

    25

    Hot Standby Router Protocol HSRP nh ngha ra mt standby group. i router c

    gn mt vai tr xc nh bn trong standby group ny. HSRP cung cp mt cch d

    phng gateway cho end station bng cch chia s chung mt IP v ac address gia

    cc redundant gateway. Giao thc ny s truyn thn g tin v IP o v ac o gia hai

    router nm trong cng mt HSRP group

    t group HSRP bao gm cc thng tin sau:

    Active router Standby router

    Virtual router Other router

    HSRP active router v standby router gi gi tin hello n a ch multicast 224.0.0.2,

    dng giao thc UDP port 1985 duy tr thng tin.

  • 8/13/2019 Bao Cao Vlan

    26/50

    26

    1.4.5u trh hot g ca

    Tt c router trong mt HSRP group c mt vai tr c th v tng tc vi nhau theo

    mt phng php xc nh

    Virtual Router: thc t ch l mt cp IP address v ac address m tt c cc thit b

    u cui dng n lm IP default gateway. ctive router x l tt c packet v tt c

    cc frame c gi ti virtual router address.

    ctive Router: trong HSRP group mt router s c chn lm active router. ctive

    router thc t l thit b vt l forward packet v n cng l thit b gi ac address o

    n cc thit b u cui

    Trong m hnh trn router c gi nh vai tr active v forward tt c cc framen a ch ac l 0000.0c07.acXX vi XX l s group ca HSRP. XX l h s hexa

    a ch IP v a ch ac tng ng ca virtual router c duy tr trong bng RP

    ca mi router thuc HSRP group. kim tra bng RP trong bng RP ta dng

    lnh show ip arp.

  • 8/13/2019 Bao Cao Vlan

    27/50

    27

    Hnh trn hin th bng RP ca mt router ang lm thnh vin ca HSRP group 1

    trong Vlan 10. Trong bng RP trn ta thy rng virtual router c a ch l

    172.16.10.110 v c mt Well-known ac l 0000.0c07.ac01 vi 01 l s group. S

    HSRP group 1 hin th di dng c s 10 v 01 l di h c s 16

    HSRP standby router lun theo di trng thi hot ng ca HSRP group v s nhanh

    chng chuyn trng thi forwarding packet nu active router khng c hot ng. C

    hai active router v standby router s truyn hello message thng bo cho tt c

    router khc trong group HSRP bit rng vai tr ca n lc ny l g ? Cc router dng

    a ch destination multicast 224.0.0.2, kiu truyn UDP port 1985. V a ch IP

    source l a ch IP ca sending router.

    goi ra bn trong HSRP group c th cha mt s router khc nhng vai tr ca n

    khng phi active hay standby. hng router dng ny s monitor hello message c

    gi bi active v standby router chc chn rng active v standby router ang tn

    ti trong HSRP group. Router ny ch forward nhng packet n chnh a ch IP ca

  • 8/13/2019 Bao Cao Vlan

    28/50

    28

    n nhng khng forward packet c t a ch n virtual router. hng router dng

    ny s c message ti mi thi gian gia hai gi tin hello

    t s thut ng trong HSRP

    Hello Interval Time: hong thi gian gia hai gi tin Hello HSRP thnh cng

    t mt router. Thi gian ny l 3 giy

    Hold Interval Time: khong thi gian gia hai gi tin hello c nhn v gi

    nh rng sender router b fail. c nh l 10 giy

    hi active router b fail, th nhng router khc thuc cng HSRP group s khng cn

    nhn c message t active router. V standby router sau s c gi nh l

    ctive router. V nu nh c router khc bn trong HSRP group th n s c a lnlm standby router. u nh c hai active v standby router b fail th tt c router

    trong group lm active v standby router.

    Trong qu trnh ny new activer router gnh ly IP o v ac o ca virtual router nh

    vy dn n cc thit b u cui s nhn thy tnh trng h hng ca cc dch v. Cc

    thit b u cui tip tc gi traffic n ac addres ca virtual router. ew activer

    router s gnh vc chp nhn phn phi gi tin.6. Cc trng thi trong giao thc HSRP

    t router trong HSRP group c mt s trng thi hot ng nh sau: initial, learn,

    listen, speak, standby hoc l active

  • 8/13/2019 Bao Cao Vlan

    29/50

    29

    hi mt router ang trong mt s nhng trng thi trn th n s thc hin mt s

    hnh ng nht nh. hng phi tt c HSRP router trong group s chuyn i sang

    tt c cc trng thi. V d nh ta c 3 router trong group, mt trong ba con router

    thuc group khng ng vai tr l standby hay active th con router ny vn duy tr

    trng thi isten.

    Tt c cc router u bt u trng thi Initial, iu ny hin th rng HSRP ang

    khng hot ng. Sau n s chuyn sang trng thi learn, trng thi ny router s

    mong ch thy c HSRP packet v tnhng packet ny n quyt nh xem virtual

    IP l g ? v xc nh active router trong HSRP group.

    hi mt interface thy HSRP packet v quyt nh xem virtual IP l g th n tip tc

    chuyn sang trng thi listen. c ch ca trng thi listen l xcnh xem c

    ctive hay Standby router cho HSRP group. u nh c active hay standby router

    ri th n vn gi nguyn trng thi. Tuy nhin nu gi tin hello khng c thy tbt k router no, interface chuyn sang trng thi Speak.

  • 8/13/2019 Bao Cao Vlan

    30/50

    30

    Trng trng thi Speak, cc router ch ng tham d vo qu trnh chn la ra active

    router, standby router bng cch nhn vo gi tin hello xc nh vai tr

    C 3 dng timer c s dng trong giao thc HSRP l active, standby, hello. u

    nh khng c mt gi tin hello no c nhn t ctive HSRP router trong khong

    thi gian active, th router chuyn sang trng thi HSRP mi.

    ctive timer: dng monitor ctive Router. Timer s reset li vo bt k thi

    im no khi mt router trong group HSRP nhn c gi tin hello c gi ra

    t ctive Router. Gi tr Timer expire ph hp vi gi tr hold time ang c

    set tng ng vi field trong HSRP hello message.

    Standby timer: dng monitor standby router. Timer s reset li vo bt kthi im no khi mt router trong group HSRP nhn c gi tin hello c

    gi ra t

    Hello timer: thi gian ca hello packet. Tt c HSRP router trong bt k trng

    thi no ca HSRP u to ra hello packetkhi m hello timer expire

    trong trng thi Standby, bi v router lc ny nh l mt ng vin tr thnh

    ctive Router k tip. nh k gi ra cc gi tin hello. cng listen cc hello

    message t active router. Trong mt mng HSRP th ch c duy nht mt standby

    router

  • 8/13/2019 Bao Cao Vlan

    31/50

  • 8/13/2019 Bao Cao Vlan

    32/50

    32

    2. 2.1M hnh thc hnh:

    Yu u:

    1/ Xy dng cu hnh

    Etherchannel ti Router 7200 v SW CORE.

    HSRP ti 3 SW-1 v 3 SW-2

    Chia VLAN.

    2/ Dng Wireshark kim tra tra ng i PC V PC Test )

    Etherchannel : Cho 1 cng down F1/0) quan st hng i.

    HSRP :Shutdown cng f1/3 trn c 2 SW 3 SW-1 v 3 SW-2) quan sthng i

  • 8/13/2019 Bao Cao Vlan

    33/50

    33

    2.2Thc hin cu hnh.Router 7200 :

    en

    conf t

    no ip domain lookup

    host Cisco7200

    inter f2/0

    ip add 10.0.0.2 255.255.255.0

    no shut

    ====== enable port-channel 1=============

    int port-channel 1

    no ip add

    no shut

    ======= add 2 fastethernet vao port-channel 1========

    int range f1/0 - 1

    no ip add

    channel-group 1no shut

    ====== Cau hinh vlan tren port-channel 1 =============

    inter port-channel 1.10

    encapsulation dot1Q 10 native

    ip address 172.32.10.1 255.255.255.0

    no shut

    inter port-channel 1.20

    encapsulation dot1Q 20

    ip address 172.32.20.1 255.255.255.0

    no shut

    inter port-channel 1.30

    encapsulation dot1Q 30

    ip address 172.32.30.1 255.255.255.0

    no shut

  • 8/13/2019 Bao Cao Vlan

    34/50

    34

    ===== quang ba mang dung router rip v2 =====

    router rip

    ver 2

    net 10.0.0.0

    net 172.32.10.0

    net 172.32.20.0

    net 172.32.30.0

    SW CORE :

    en

    vlan database

    vtp v2

    vtp domain cisco

    vtp pass 123

    vtp server

    vlan 10 name Vlan10

    vlan 20 name Vlan20

    vlan 30 name Vlan30exit

    conf t

    no ip domain lookup

    hostname CORE

    int range f1/0 - 3

    switchport trunk encapsulation dot1q

    switchport mode trunk

    switchport trunk native vlan 10

    no shut

    exit

    inter vlan 10

    ip add 172.32.10.2 255.255.255.0

    no shut

    exit

  • 8/13/2019 Bao Cao Vlan

    35/50

    35

    inter vlan 20

    ip add 172.32.20.2 255.255.255.0

    no shut

    exit

    inter vlan 30

    ip add 172.32.30.2 255.255.255.0

    no shut

    exit

    int port-channel 1

    switchport trunk encapsulation dot1q

    switchport mode trunk

    switchport trunk native vlan 10

    no shut

    exit

    int range f1/0 - 1

    channel-group 1 mode on

    no shutexit

    ip default-gateway 172.32.10.1

    router rip

    ver 2

    net 172.32.10.0

    net 172.32.20.0

    net 172.32.30.0end

    L3 SW 1 :

    en

    vlan database

    vtp domain cisco

    vtp pass 123

    vtp client

  • 8/13/2019 Bao Cao Vlan

    36/50

    36

    exit

    conf t

    no ip domain lookup

    hostname L3-SW1

    int range f1/0 - 3

    switchport trunk encapsulation dot1q

    switchport mode trunk

    switchport trunk native vlan 10

    no shut

    exit

    interface Vlan10

    ip address 172.32.10.3 255.255.255.0

    standby 1 ip 172.32.10.100

    standby 1 priority 150

    standby 1 preempt

    standby 1 track FastEthernet1/1 60

    standby 1 authentication Vlan10no shutdown

    interface Vlan 20

    ip address 172.32.20.3 255.255.255.0

    standby 2 ip 172.32.20.100

    standby 2 preempt

    standby 2 track FastEthernet1/1standby 2 authentication Vlan20

    no shutdown

    interface Vlan 30

    ip address 172.32.30.3 255.255.255.0

    standby 3 ip 172.32.30.100

    standby 3 priority 150

  • 8/13/2019 Bao Cao Vlan

    37/50

    37

    standby 3 preempt

    standby 3 track FastEthernet1/1 60

    standby 3 authentication Vlan30

    no shutdown

    exit

    ip default-gateway 172.32.10.1

    router rip

    ver 2

    net 172.32.10.0

    net 172.32.20.0

    net 172.32.30.0

    end

    L3 SW 2:

    en

    vlan database

    vtp domain cisco

    vtp pass 123vtp client

    exit

    conf t

    hostname L3-SW2

    int range f1/0 - 3

    switchport trunk encapsulation dot1q

    switchport mode trunk

    switchport trunk native vlan 10

    no shut

    exit

    interface Vlan10

    ip address 172.32.10.4 255.255.255.0

    standby 1 ip 172.32.10.100

    standby 1 preempt

  • 8/13/2019 Bao Cao Vlan

    38/50

    38

    standby 1 track FastEthernet1/1

    standby 1 authentication Vlan10

    no shutdown

    interface Vlan20

    ip address 172.32.20.4 255.255.255.0

    standby 2 ip 172.32.20.100

    standby 2 priority 150

    standby 2 preempt

    standby 2 track FastEthernet1/1 60

    standby 2 authentication Vlan20

    no shutdown

    interface Vlan30

    ip address 172.32.30.4 255.255.255.0

    standby 3 ip 172.32.30.100

    standby 3 preemptstandby 3 track FastEthernet1/1

    standby 3 authentication Vlan30

    no shutdown

    ip default-gateway 172.32.10.1

    router rip

    ver 2

    net 172.32.10.0net 172.32.20.0

    net 172.32.30.0

    end

    SW 1:

  • 8/13/2019 Bao Cao Vlan

    39/50

    39

    SW 2 :

  • 8/13/2019 Bao Cao Vlan

    40/50

  • 8/13/2019 Bao Cao Vlan

    41/50

    41

    ip default-gateway 172.32.20.100

    int f0/0

    ip add 172.32.20.11 255.255.255.0

    no shut

    end

    Bt u kim tra ng i :

    Ping tPC Vlan10-APC Testng i ca lu lng:PC Vlan10L3 SW1SW COREPC Test

    Bt Wireshark ti cng f1/3 trn 3-SW 1

    Bt Wireshark ti cng f1/0 trn L3-SW 1

  • 8/13/2019 Bao Cao Vlan

    42/50

    42

    Ping tu PC Vlan10-APC Vlan10-Bng i: PCVlan10-AL3-SW-1L3-SW-2 -> PC Vlan10-BBt wireshark ti cng f1/2 trn 3-SW1

    Ping PC Vlan20-APC Vlan20Bng i : PC Vlan20-AL3 SW-2PC Vlan20-B

    Bt Wireshark ti cng f1/2 trn L3 SW2

  • 8/13/2019 Bao Cao Vlan

    43/50

    43

    im tra EtherchannelShow cu hnh Etherchanel

    Quan st ti 2 ng dy Etherchannel , khi ping t PC V n PC TEST ta thy lulng u chy qua 2 ng.

    Shutdown 1 cng F1/0 , ta ping li v quan st thy lu lng tip tc chuyn trn ng cnli .

  • 8/13/2019 Bao Cao Vlan

    44/50

    44

    HSRPShow cu hnh trn :L3 SW 1

    L3 SW-2

  • 8/13/2019 Bao Cao Vlan

    45/50

    45

    Tip tc tin hnh tt cng v quan st hng i ca lu lnga) shutdown f1/3 trn 3-SW1 Vlan20 lm cctive, Vlan10 v Vlan30 lm backup )

    Ping PCVlan10-APCVlan10-B

    ng i : PC Vlan10-AL3 SW2L3 SW1PC Vlan10-BBt Wireshark trn cng f1/2 trn 3-SW2

  • 8/13/2019 Bao Cao Vlan

    46/50

    46

    Trn cng f1/2 trn 3 SW1

    Ping T Vlan10-BVlan10-Ang i PC Vlan10-BL3 SW1PC VLAN 10-A

    Bt Wireshark f1/2 3 SW1

  • 8/13/2019 Bao Cao Vlan

    47/50

    47

    Bt Wireshark ti f1/2 3-SW2

    b) shutdown f1/3 trn 3 SW-2 Vlan 10 v Vlan 30 ln lm ctive, Vlan 20 lmBackup)

    Ping t Vlan10-AVlan10-Bi ng : PC Vlan10-AL3 SW 1PC Vlan10 -B

  • 8/13/2019 Bao Cao Vlan

    48/50

    48

    Bt wireshark ti f1/2 3-SW1

    Ping Vlan10-B cho Vlan10-A

    i ng : PC Vlan10-B

    L3 SW1

    Vlan10 ABt Wireshark ti f1/2 3-SW1

  • 8/13/2019 Bao Cao Vlan

    49/50

    49

    Ping Vlan10AVlan20B

    ng i : Vlan10-AL3SW-1Vlan 20 BBt Wireshark ti f1/2 L3SW1

    Ping Vlan10-B Vlan20 A

    ng i : Vlan10-BL3SW1Vlan20 A

    Bt Wireshark ti cng f1/2 3SW1

  • 8/13/2019 Bao Cao Vlan

    50/50

    50

    2.3t u u lng chy u trn hai ng Etherchanel, khi shutdown 1 cng

    f1/0 ) th lu lng vn tip tc chy trn ng cn li. hi cu hnh HSRP 1 IP v C o d phng c hnh thnh , nh m khi Router ctive b li khi shutdown cng f1/3) v mt StandbyRouterc la chn s ln lm ctive ,nh m cc lu lng trnmng khng b mt host v vn tip tc chuyn.