"Huawei" MUX VLAN configuration detailed

Source: Internet
Author: User

MUX VLAN Application Scenario


In the enterprise network to achieve mutual access between customers and customers, customers and employees are not mutually accessible, employees and employees can access each other, employees and customers can access the server.

MUX VLAN is a two-layer traffic isolation mechanism


The MUX VLAN is divided into


Principal VLAN (primary VLAN) and subordinate VLAN (from VLAN), divided from VLAN to group VLAN (interworking from VLAN) and separate VLAN (isolated from VLAN)


Communication permissions


One, the primary VLAN port can communicate with all VLANs

Two, interoperability from VLAN can and own VLAN between member communication and the main VLAN communication

Third, isolated from the VLAN can only communicate with the primary VLAN, the members of their own VLAN is also non-communication


Configuration considerations

All hosts must be on the same subnet

Port must join VLAN for access mode

Configuration of the Mux VLAN cannot be used for vlanif interfaces, VLAN Mapping, VLAN stacking, Super-vlan, Sub-vlan configuration


Experimental topology

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/74/55/wKioL1YaWGGTbKx7AAGS_sSAxc4057.jpg "title=" 0408_ Zvwe4}j (919v}qcp1v.png "alt=" Wkiol1yawggtbkx7aags_ssaxc4057.jpg "/>

Experimental requirements

C2 and C3 simulate customers in-company employees, C4 and C5. Requires that employees have access to each other and that the employee can access the server, and that the client can only access the server to communicate with anyone else.


Configuration steps


IP planning


Server: 192.168.1.10/24

C2:192.168.1.20/24

C3:192.168.1.30/24

C4:192.168.1.40/24

C5:192.168.1.50/24


SW1 Configuration


<sw1>system-view

[Sw1]vlan Batch //Create VLAN

[Sw1]vlan //Enter the VLAN management view

[Sw1-vlan10]mux-vlan //configure VLAN10 to Principal VLAN

[Sw1-vlan10]subordinate group //config VLAN20 for interoperability from VLAN

[sw1-vlan10]subordinate separate //config VLAN30 for isolated slave vlan

[Sw1-vlan10]quit

[Sw1]interface G0/0/1

[Sw1-gigabitethernet0/0/1]port link-type Access //configure interface mode for access

[Sw1-gigabitethernet0/0/1]port Default VLAN //Add interface to VLAN10

[Sw1-gigabitethernet0/0/1]port Mux-vlan Enable //Mux-vlan function of the Open Interface

[Sw1-gigabitethernet0/0/1]interface G0/0/2

[Sw1-gigabitethernet0/0/2]port link-type Access

[Sw1-gigabitethernet0/0/2]port Default VLAN 20

[Sw1-gigabitethernet0/0/2]port Mux-vlan Enable

[Sw1-gigabitethernet0/0/2]int G0/0/3

[Sw1-gigabitethernet0/0/3]port link-type Access

[Sw1-gigabitethernet0/0/3]port Default VLAN 20

[Sw1-gigabitethernet0/0/3]port Mux-vlan Enable

[Sw1-gigabitethernet0/0/3]int G0/0/4

[Sw1-gigabitethernet0/0/4]port link-type Access

[Sw1-gigabitethernet0/0/4]port Default VLAN 30

[Sw1-gigabitethernet0/0/4]port Mux-vlan Enable

[Sw1-gigabitethernet0/0/4]int G0/0/5

[Sw1-gigabitethernet0/0/5]port link-type Access

[Sw1-gigabitethernet0/0/5]port Default VLAN 30

[Sw1-gigabitethernet0/0/5]port Mux-vlan Enable


Use display Mux-vlan to view mux-vlan information

[Sw1]display Mux-vlan

Principal subordinate Type Interface

-----------------------------------------------------------------------------

10-principal GIGABITETHERNET0/0/1

Ten separate GIGABITETHERNET0/0/4 GIGABITETHERNET0/0/5

Ten group GIGABITETHERNET0/0/2 GIGABITETHERNET0/0/3

-----------------------------------------------------------------------------


Experimental test

C2 (employee) Ping C3 (employee)

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/74/55/wKioL1YaX1HB0x9kAAHJN87uyH0677.jpg "title=" P1rmld7naolcrnnzyo5~juw.png "alt=" Wkiol1yax1hb0x9kaahjn87uyh0677.jpg "/>

C2 (employee) Ping Server

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/74/58/wKiom1YaX5qQb7j3AAIVbXuJivI122.jpg "title=" fhfvqj@) [o]w6o$568o$f69.png "alt=" Wkiom1yax5qqb7j3aaivbxujivi122.jpg "/>

C2 (employee) Ping C5 (customer)

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/74/55/wKioL1YaYDeAA9WkAAHZYF_IPP0067.jpg "title=") 6 ' 4 ' 4 ~{) $15bajz1esv4}o.png "alt=" Wkiol1yaydeaa9wkaahzyf_ipp0067.jpg "/>

C4 (Customer) Ping C5 (customer)

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/74/58/wKiom1YaYG-RslJhAAH1uKni_Io808.jpg "title=" 34_}5) _cy$f4[$VE 4r1mbsb.png "alt=" Wkiom1yayg-rsljhaah1ukni_io808.jpg "/>

C4 Ping Server

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/74/58/wKiom1YaYK_hncj6AAHWFD1Jl7Q148.jpg "title=" l3pdb[ qn92y (CY ' 7838$bg9.png "alt=" Wkiom1yayk_hncj6aahwfd1jl7q148.jpg "/>

This article is from the "Sunj" blog, make sure to keep this source http://sunjie123.blog.51cto.com/1263687/1701919

"Huawei" MUX VLAN configuration detailed

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.