本公司使用3560作为核心交换机下接3台2960交换机作为接入层,公司内部划分多个vlan,但最近我发现一个问题:在任何一个网段中的一台PC机上将网关设置成网络任何一个段的网关,都可以进行内网和互联网的通信。例如:PC1属于vlan3 IP地址是:192.168.67.21,网关为192.168.67.1 但我将此网关设置成vlan2的网关192.168.66.1也可以上网。我用tracert -d www.qq.com显示如下:
公司内部网络架构图如下:
具体配置如下:
3560三层核核心交换机配置 ! hostname 3560switch ! enable secret 5 $1$5PDr$.4oW26nwkNxGQAbrkj7J61 ! no aaa new-model clock timezone UTC 8 system mtu routing 1500 ip subnet-zero ip routing ! ! ! ! no file verify auto spanning-tree mode pvst spanning-tree extend system-id ! vlan internal allocation policy ascending ! interface GigabitEthernet0/1 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/2 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/3 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/4 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/5 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/6 switchport access vlan 7 ! interface GigabitEthernet0/7 switchport access vlan 7 ! interface GigabitEthernet0/8 switchport access vlan 7 ! interface GigabitEthernet0/9 switchport access vlan 8 ! interface GigabitEthernet0/10 switchport access vlan 7 ! interface GigabitEthernet0/11 switchport access vlan 7 ! interface GigabitEthernet0/12 switchport access vlan 7 ! interface GigabitEthernet0/13 switchport access vlan 7 switchport mode access ! interface GigabitEthernet0/14 switchport access vlan 7 switchport mode access ! interface GigabitEthernet0/15 switchport mode access ! interface GigabitEthernet0/16 switchport mode access ! interface GigabitEthernet0/17 switchport mode access ! interface GigabitEthernet0/18 switchport mode access ! interface GigabitEthernet0/19 switchport mode access ! interface GigabitEthernet0/20 switchport mode access ! interface GigabitEthernet0/21 switchport mode access ! interface GigabitEthernet0/22 switchport mode access ! interface GigabitEthernet0/23 switchport mode access ! interface GigabitEthernet0/24 switchport access vlan 7 switchport mode access ! interface GigabitEthernet0/25 ! interface GigabitEthernet0/26 ! interface GigabitEthernet0/27 ! interface GigabitEthernet0/28 ! interface Vlan1 ip address 192.168.65.1 255.255.255.0 ! interface Vlan2 ip address 192.168.66.1 255.255.255.0 ! interface Vlan3 ip address 192.168.67.1 255.255.255.0 ! interface Vlan4 ip address 192.168.68.1 255.255.255.0 ! interface Vlan5 ip address 192.168.69.1 255.255.255.0 ! interface Vlan6 ip address 192.168.70.1 255.255.255.0 ! interface Vlan7 ip address 192.168.64.1 255.255.255.0 ! interface Vlan8 ip address 192.168.71.1 255.255.255.0 ! ip default-gateway 192.168.64.253 ip classless ip route 0.0.0.0 0.0.0.0 192.168.64.253 ip http server ! snmp-server community public RO snmp-server community public1 RW 2960 二层交换机配置如下:(其它二层2960配置也类似,在此就不一一写出来了) no aaa new-model system mtu routing 1500 ip subnet-zero spanning-tree mode pvst spanning-tree extend system-id ! vlan internal allocation policy ascending ! ! ! interface FastEthernet0/1 switchport access vlan 3 switchport mode access ! interface FastEthernet0/2 switchport access vlan 3 switchport mode access ! interface FastEthernet0/3 switchport access vlan 3 switchport mode access ! interface FastEthernet0/4 switchport access vlan 3 switchport mode access ! interface FastEthernet0/5 switchport access vlan 3 switchport mode access ! interface FastEthernet0/6 switchport access vlan 3 switchport mode access ! interface FastEthernet0/7 switchport access vlan 8 ! interface FastEthernet0/8 switchport access vlan 8 ! interface FastEthernet0/9 switchport access vlan 8 ! interface FastEthernet0/10 switchport access vlan 8 ! interface FastEthernet0/11 switchport access vlan 8 ! interface FastEthernet0/12 switchport access vlan 8 ! interface FastEthernet0/13 switchport access vlan 3 ! interface FastEthernet0/14 switchport access vlan 3 ! interface FastEthernet0/15 switchport access vlan 3 ! interface FastEthernet0/16 switchport access vlan 3 ! interface FastEthernet0/17 switchport access vlan 3 ! interface FastEthernet0/18 switchport access vlan 3 ! interface FastEthernet0/19 switchport access vlan 3 ! interface FastEthernet0/20 switchport access vlan 3 ! interface FastEthernet0/21 switchport access vlan 3 ! interface FastEthernet0/22 switchport access vlan 3 ! interface FastEthernet0/23 switchport access vlan 3 ! interface FastEthernet0/24 switchport access vlan 3 ! interface FastEthernet0/25 switchport access vlan 3 ! interface FastEthernet0/26 switchport access vlan 8 ! interface FastEthernet0/27 switchport access vlan 8 ! interface FastEthernet0/28 switchport access vlan 8 ! interface FastEthernet0/29 switchport access vlan 8 ! interface FastEthernet0/30 switchport access vlan 8 ! interface FastEthernet0/31 switchport access vlan 8 ! interface FastEthernet0/32 switchport access vlan 8 ! interface FastEthernet0/33 switchport access vlan 8 ! interface FastEthernet0/34 switchport access vlan 8 ! interface FastEthernet0/35 switchport access vlan 8 ! interface FastEthernet0/36 switchport access vlan 8 ! interface FastEthernet0/37 switchport access vlan 8 ! interface FastEthernet0/38 switchport access vlan 8 ! interface FastEthernet0/39 switchport access vlan 8 ! interface FastEthernet0/40 switchport access vlan 8 ! interface FastEthernet0/41 switchport access vlan 8 ! interface FastEthernet0/42 switchport access vlan 8 ! interface FastEthernet0/43 switchport access vlan 8 ! interface FastEthernet0/44 switchport access vlan 8 ! interface FastEthernet0/45 switchport access vlan 8 ! interface FastEthernet0/46 switchport access vlan 8 ! interface FastEthernet0/47 switchport access vlan 8 ! interface FastEthernet0/48 switchport access vlan 8 ! interface GigabitEthernet0/1 switchport mode trunk ! interface GigabitEthernet0/2 ! interface Vlan1 no ip address no ip route-cache shutdown ! interface Vlan7 ip address 192.168.64.3 255.255.255.0 no ip route-cache ! ip default-gateway 192.168.64.1 ip http server snmp-server community public RO snmp-server community public1 RW
|