calledvlan官网
vlan官网 时间:2021-05-07 阅读:(
)
VLANinMikroTikByMohammedKhomeiniBinABUMUMIndonesia,2013AboutPresentationTohelpyouunderstandfundamentalofVirtualLocalAreaNetwork(VLAN)andimplementationinMikroTikrouterToexplainafewexampleofimplementationinsiteToshowexamplerunningVLANinseveralMikroTikrouters2AboutMe.
.
MohammedKhomeiniBinAbuMikroTikCertifiedEngineer(MTCINE,MTCRE,MTCWE,MTCTCE,MTCUME)MikroTikCertifiedTrainer(TR0204)MikroTikCertifiedAcademyTrainer(ACTR0062)NetworkConsultant3ContentIntroductionVLANImplementationConclusion4INTRODUCTIONTOVLAN5VirtualLANs–WHAT(1)MostcommonlyusedprotocolforVLANonanethernetnetworkis802.
1QItinsert4bytetagintoastandardethernetframeWorkingatDataLinkLayer(OSILayer2)MaximumnumberofVLANinoneinterfaceis40956VirtualLANs–WHAT(2)EachVLANsistreatedasseparatesubnet/broadcastdomain.
DevicesonaVLANarerestrictedtoonlycommunicatingwithdevicesthatareontheirownVLANMikroTikalsosupportVlanoverVlan/802.
1QinQ/802.
1ad7VirtualLANs–WHY(1)Providesegmentation8VirtualLANs–WHY(2)MultipleLANinasinglephysicalinterfaceMakethelocalnetworkmoresimpleMultiplebroadcastdomaininasinglephysicalinterfaceVLANscanincreasesecurityandmanagementofdifferentnetworkinonesingleinterfacePriority9VirtualLANs-ParameterEdgeports:(Untagged,inCisco:calledAccessPort)SwitchportthatconfigureasapartofthevlanThisportnotsend4bytevlantag.
UsedfordevicethatnotpasstheVLAN,likecomputer,printer,server,etc.
Coreport:(Tagged,inCisco:TrunkPort)Switchportconfiguredtosend4byteormoreVLANtag.
UsedfordevicethatsupportVLANtechnologieslikeswitches,manageableswitch,routers,etc.
1011VirtualLANsinMikroTik(1)InRouterOS,VLANcanbeimplementedinswitchenvironmentandinrouterenvironmentsimultaneously.
AlsopossibletorunVLANinwirelessorbridgeinterfaceItisnotpossibletohaveVLANputonawirelessinterfaceinastationmodeFILOVLANtaggedisusedfor802.
1QinQimplementation12VirtualLANsinMikroTik(2)TocreatevlaninMikroTik,youshouldhavetheinterfacefirst(ifyouwanttoimplementinbridgeinterface)VLANID=uniqueInterfacefortrunk/access13802.
1QFlowChartinRouterOSStartAccept802.
1QCreatetrunkbridgeAddport(interface)totrunkbridgeCreatevlanontrunkinterfaceCreateaccessport11CreateaccessbridgeAddport(interface)andvlantoaccessbridgeCreateIPaddressandDHCPsetupatVlaninterfaceCreateDHCP-serverCreateDHCP-serverCreatevlanontrunkinterfaceFinish222YESYESYESYESNONONONOCreatedByMohammedKhomeiniAbu14VIRTUALLANSIMPLEMENTATION15HowVirtualLANsimplementedin:Smallnetwork(SOHO)Mediumnetwork(SME)WirelessnetworkTunneling16VirtualLANs–SoHo(1)Haveonlysinglerouterandsingle/multimanagedswitchCreate2VLANinMikroTikrouterVlan-100=officeVlan-200=wifi17VirtualLANs–SoHo(2)PublicInterface18VirtualLANs–SoHo(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)AddVLANontrunkinterface(bridge-trunk)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk19VirtualLANs–SoHo(4)CreateIPAddressforVLANCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20020QUIZFrom21VirtualLANs–SME(1)YouhavemorethanonerouterCreate3VLANinMikroTikrouterVlan-100=officeVlan-200=wifiVlan-230=voip22VirtualLANs–SME(2)PublicInterface23VirtualLANs–SME(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk24VirtualLANs–SME(4)AddVLANontrunkinterface(bridge-trunk)Tocreateaccessport,createaccessbridgeinterfacefirst.
ThenaddaccessportinterfaceandVLANintotheaccessbridge[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacevlanaddname=vlan-230interface=bridge-trunkvlan-id=230[admin@R1]>interfacebridgeportaddinterface=ether4bridge=bridge-vlan-230[admin@R1]>interfacebridgeportaddinterface=vlan-230bridge=bridge-vlan-230[admin@R1]>interfacebridgeaddname=bridge-vlan-23025VirtualLANs–SME(5)CreateIPAddressCreateDHCPsetupforinterfacevlan-100,vlan-200,andvlan-230withpublicdns(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>ipaddressaddaddress=192.
168.
230.
1/24interface=vlan-23026VirtualLANs–SME(6)R2ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConnectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk27VirtualLANs–Wireless(1)PublicInterface28VirtualLANs–Wireless(2)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk29VirtualLANs–Wireless(3)AddVLANontrunkinterface(bridge-trunk)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicdns(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=20030VirtualLANs–Wireless(4)R2andR3ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConfigureWirelessinterfaceasap-bridge(forR3,wirelessinterfaceisconfiguredasmode=station-bridge)InR3,connectmanagedswitchintointerface=ether1andconfiguremanagedswitchasdesired[admin@R1]>interfacewirelesssetwlan1mode=ap-bridgedisabled=no[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether1bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=wlan1bridge=bridge-trunk31VirtualLANsoverPPTP(1)RouterOSsupportedbridgethroughPointtoPointTunnelProtocol(PPTP)usingBCP(BridgeControlProtocol).
BCPallowstobridgeethernetpacketthroughPPPlinkToimplementVLANoverPPTPtunnel,weshoulduseBCPandMLPPPfeaturetoforwardpacketbetweensegment/subnet.
32VirtualLANs–PPTP(2)R1willbecomedhcp-serverforvlan-100andvlan-200R4willforwarduntaggedpackettoether5forclientCreatePPTPServer(R1)andclient(R4)33VirtualLANsoverPPTP(3)MakesurethereisaroutingbetweenR1toR4R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether2CreatebridgeinterfaceAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp34VirtualLANsoverPPTP(4)AddVLANontrunkinterface(bridge-pptp)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-pptpvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-pptpvlan-id=200[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20035VirtualLANsoverPPTP(5)CreatePPTP-ServerwithBCPandMLPPPenabledR4ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterface[admin@R1]>pppprofileaddbridge=bridge1name=pptp-bridge[admin@R1]>interfacepptp-serverserversetenabled=yesdefault-profile=pptp-bridge\[admin@R1]>mrru=5000[admin@R1]>pppsecretaddname=pptp-userpassword=1234profile=pptp-bridge\[admin@R1]>local-address=1.
1.
1.
1remote-address=2.
2.
2.
2[admin@R4]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R4]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp36VirtualLANsoverPPTP(6)CreatePPTP-ServerwithBCPandMLPPPenabledConnectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R4]>pppprofileaddbridge=bridge-pptpname=pptp-bridge[admin@R4]>interfacepptp-clientaddconnect=192.
168.
12.
1user=pptp-user\[admin@R4]>password=1234profile=pptp-bridgemrru=5000disabled=no[admin@R4]>37CONCLUSION38ConclusionAllVLANshouldbeputinbridgeinterfaceasitiseasytomanipulatewhetheritisatrunkportoranaccessport.
ThedisadvantageiswecreatemoreheaderondatalinklayerWhenyoudon'tenableMLPPPinPPPtunnel,youstillcanuseinternetbutslow,causethepackethasbeenfragmented.
Inwirelessmode,shoulduseotherthanmode=stationRememberflowchart39References1.
wiki.
mikrotik.
com2.
CiscoCCNAmodules3.
Vlanworkshop,www.
roamingnet.
com4.
id-networkers.
com5.
www.
mikrotik.
co.
id40CredittoMr.
RofiqFauziMr.
PujoDewobrotoMr.
GatotWibowoHamisenoMr.
HerryDarmawanMr.
MatDawamAbasMikroTikTeam41MohammedKhomeiniBinAbukhomeini1980@gmail.
com+6013-7221134(whatsapp)42
老薛主机怎么样?老薛主机这个商家有存在有一些年头。如果没有记错的话,早年老薛主机是做虚拟主机业务的,还算不错在异常激烈的市场中生存到现在,应该算是在众多商家中早期积累到一定的用户群的,主打小众个人网站业务所以能持续到现在。这不,站长看到商家有在进行夏季促销,比如我们很多网友可能有需要的香港vps主机季度及以上可以半价优惠,如果有在选择不同主机商的香港机房的可以看看老薛主机商家的香港vps。点击进入...
飞讯云官网“飞讯云”是湖北飞讯网络有限公司旗下的云计算服务品牌,专注为个人开发者用户、中小型、大型企业用户提供一站式核心网络云端部署服务,促使用户云端部署化简为零,轻松快捷运用云计算。飞讯云是国内为数不多具有ISP/IDC双资质的专业云计算服务商,同时持有系统软件著作权证书、CNNIC地址分配联盟成员证书,通过了ISO27001信息安全管理体系国际认证、ISO9001质量保证体系国际认证。 《中华...
火数云怎么样?火数云主要提供数据中心基础服务、互联网业务解决方案,及专属服务器租用、云服务器、专属服务器托管、带宽租用等产品和服务。火数云提供洛阳、新乡、安徽、香港、美国等地骨干级机房优质资源,包括BGP国际多线网络,CN2点对点直连带宽以及国际顶尖品牌硬件。专注为个人开发者用户,中小型,大型企业用户提供一站式核心网络云端服务部署,促使用户云端部署化简为零,轻松快捷运用云计算!多年云计算领域服务经...
vlan官网为你推荐
支持ipadthinksnsthinksns 好用吗?靠谱吗filezilla_serverFileZilla无法连接服务器怎么解决正大天地网二三线城市适合做生鲜b2b电商吗加多宝与王老吉加多宝王老吉有什么区别吗?徐州商标介绍徐州的一种产品discuz伪静态求虚拟主机Discuz 伪静态设置方法ie假死我的电脑,IE一直会死机,怎么回事???图文模块微信公众号底部推荐阅读,图文模块是怎么实现的建站无忧前程无忧为何上市?
个人虚拟主机 黑龙江域名注册 韩国服务器租用 山东vps 华为云服务 新世界机房 秒解服务器 12306抢票攻略 realvnc 华为网络硬盘 老左正传 域名接入 能外链的相册 网站在线扫描 无限流量 美国盐湖城 独立主机 lamp是什么意思 网站加速 七牛云存储 更多