我有一个Cisco 2960,运行12.2(58) SE2,配置了四个VLAN(10.10.10.0/24-10.40.0/24),加上192.168.1.0/24网络上的一个上行链路。我已经启用了ip路由,并且VLAN可以相互交谈--没有问题,但是我的互联网连接不起作用。
我的互联网网关是192.168.1.1,在192.168.1.0/24配置的交换机上有一个接口(GigabitEthernet0 0/2),IP为192.168.1.254。我尝试使用以下方法创建默认路由:
ip路由0.0.0.0 0.0.0.0 192.168.1.1
但这是行不通的。
在DHCP中,我将每个VLAN的默认网关设置为.1地址。
下面是配置:
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname myswitch
!
!
no aaa new-model
clock timezone CST -6
system mtu routing 1500
udld aggressive
!
sdm prefer lanbase-routing
!
ip routing
!
ip subnet-zero
!
!
mls qos map cos-dscp 0 8 16 26 32 46 46 56
!
!
macro global description cisco-global
errdisable recovery cause link-flap
errdisable recovery interval 60
no file verify auto
!
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface FastEthernet0/1
switchport access vlan 10
switchport mode access
!
interface FastEthernet0/2
switchport access vlan 10
switchport mode access
!
interface FastEthernet0/3
switchport access vlan 10
switchport mode access
!
interface FastEthernet0/4
switchport access vlan 10
switchport mode access
!
interface FastEthernet0/5
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/6
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/7
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/8
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/9
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/10
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/11
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/12
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/13
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/14
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/15
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/16
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/17
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/18
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/19
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/20
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/21
switchport access vlan 40
switchport mode access
!
interface FastEthernet0/22
switchport access vlan 40
switchport mode access
!
interface FastEthernet0/23
switchport access vlan 40
switchport mode access
!
interface FastEthernet0/24
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet0/1
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/2
switchport access vlan 192
switchport trunk native vlan 192
switchport trunk allowed vlan 10-192
switchport mode trunk
!
interface Vlan1
!
interface Vlan10
ip address 10.10.10.1 255.255.255.0
no ip route-cache
!
interface Vlan20
ip address 10.10.20.1 255.255.255.0
no ip route-cache
!
interface Vlan30
ip address 10.10.30.1 255.255.255.0
no ip route-cache
!
interface Vlan40
ip address 10.10.40.1 255.255.255.0
no ip route-cache
!
interface Vlan192
ip address 192.168.1.254 255.255.255.0
no ip route-cache
!
ip default-gateway 192.168.1.1
ip http server
!
ip domain-name domain.internal
ip name-server 10.10.10.2
!
ip dhcp pool vlan10
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
dns-server 10.10.10.2
domain-name domain.internal
lease 0 1 0
ip dhcp excluded-address 10.10.10.1 10.10.10.10
!
ip dhcp pool vlan20
network 10.10.20.0 255.255.255.0
default-router 10.10.20.1
dns-server 10.10.10.2
domain-name domain.internal
lease 0 1 0
ip dhcp excluded-address 10.10.20.1 10.10.20.10
!
ip dhcp pool vlan30
network 10.10.30.0 255.255.255.0
default-router 10.10.30.1
dns-server 10.10.10.2
domain-name domain.internal
lease 0 1 0
ip dhcp excluded-address 10.10.30.1 10.10.30.10
!
ip dhcp pool vlan40
network 10.10.40.0 255.255.255.0
default-router 10.10.40.1
dns-server 10.10.10.2
domain-name domain.internal
lease 0 1 0
ip dhcp excluded-address 10.10.40.1 10.10.40.10
!
end从交换机我可以到达互联网没有问题,但没有一个客户连接到交换机可以。我怀疑这是我在GigabitEthernet0 0/2上的开关端口配置的问题,但我是一个服务器人员,不是网络专家,我在这里有点过头了。
发布于 2013-03-30 19:23:30
您需要像前面提到的那样使用'ip路由0.0.0.0 0.0.0.0 192.168.1.1‘命令,而不是使用现有的'ip默认网关’命令。“ip路由”命令适用于所有通信量,而“ip默认网关”仅适用于该交换机产生的通信量。
另外,除非附加到Gi0/2的是一个配置为主干的开关,否则您不希望Gi0/2成为主干,而只是希望它成为一个访问端口。
int gi0/2
switchport mode access
switchport access vlan 192您还需要确保192.168.1.1知道路由10.10.10.0/24、10.10.20.0/24 10.10.30.0/24和10.10.40.0/24回到192.168.1.254。
发布于 2013-03-31 00:25:59
从你的意思来看,我觉得没有必要这样做:
interface GigabitEthernet0/2
switchport access vlan 192
switchport trunk native vlan 192
switchport trunk allowed vlan 10-192
switchport mode trunk
..
interface Vlan192
ip address 192.168.1.254 255.255.255.0
no ip route-cache你可以这么做:
interface GigabitEthernet0/2
no switchport
ip address 192.168.1.254 255.255.255.0否则,您应该将Gi0/2端口设置为访问端口,或者确保另一端是access,或者本地vlan为192。
通过进行集群,您还可以将vlans与远程终端连接起来,这会使事情变得复杂(当然,除非您是有意这样做的)。
最后,正如前面提到的,您需要"ip路由“,而不需要"ip默认网关”。
https://serverfault.com/questions/494807
复制相似问题