標籤:juniper交換器
1、建立VLAN其實只要分為2步,只需要2條命令:
①如果需要把網關放在EX2200裡,就是需要建立一個虛擬三層介面SVI,所以我們可以先建立一個SVI作為即將建立的VLAN網關。
②建立VLAN的同時,把虛擬介面SVI與vlan匹配起來。
網路裝置中介面一般都會有子介面的概念,unit就是vlan的子介面
//建立一個虛擬介面unit2,地址為192.168.2.1/24
root# set interfaces vlan unit 2 family inet address 192.168.2.1/24
//建立VLAN匹配SVI
root# set vlans vlan_name vlan-id 2 l3-interfacevlan.2
//記得還要在trunk口加入允許通過的VLAN
root# set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members 2
2、建立過濾的ACL也是分2步:
①建立過濾規則,可以帶port口,今天參數可以在命令列按?查看
②把建立的ACL放在vlan的input或者output
建立ACL
//匹配流量
set firewall family ethernet-switching filter acl_name term rule_name1 from destination-address X.X.X.X/X
//定義行為
set firewall family ethernet-switching filter acl_name term rule_name1 then discard
//允許存取其他流量,這條很重要,因為產生的ACL裡面會自動帶有一條any discard的規則。
set firewall family ethernet-switching filter acl_name term rule_name1 then accept
放到有對應的vlan
set vlans vlan_name filter input acl_name
----------------------------------------------------------------------------------
set interfaces vlan unit 2 family inet address 192.168.2.1/24
set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members 2
set firewall family ethernet-switching filter acl_name term rule_name1 from destination-address X.X.X.X/X
set firewall family ethernet-switching filter acl_name term rule_name1 then discard
set firewall family ethernet-switching filter acl_name term rule_name1 then accept
set vlans vlan_name filter input acl_name
本文出自 “天邊有只熊” 部落格,謝絕轉載!
Juniper EX2200幾個常用vlan配置(建立,acl過濾,vlan間流量隔離)