When two PC connect with Layer2 Switch by default setting and its IP address belong to the same network segment, the result must be communication can exchange each other.
data:image/s3,"s3://crabby-images/88e60/88e60998cc52fa5c1ab5cf4fd2693879da11c722" alt="ScreenHunter_01 ScreenHunter_01"
In this network topology, when DW-HYPERV-01(192.168.101.11/24) ping DW-HYPERV-02(192.168.101.130/24) on command prompt, DW-HYPERV-02 can respond the message to DW-HYPERV-01, and vice verses.
data:image/s3,"s3://crabby-images/768c1/768c12fb2e2778425f08bb149466b99b09c1d58f" alt="ScreenHunter_03 ScreenHunter_03"
If we want to block the communication between PCs, maybe we can buy another Switch and one by one connect with the Switch port. But this behavior is not good idea because we will lose the money.
Why we separate the network segment?
Maybe need to separate the different department/floor or avoid Virus/Spam/Broadcast/ARP attack so that make this plan.
How to save the money?
Maybe it will be good method to configure VLAN on Switch!
data:image/s3,"s3://crabby-images/26064/26064734f309ebd4d2cd2aabd4877d8c4a8d5872" alt="ScreenHunter_04 ScreenHunter_04"
At first, we can realize what VLAN status is now by command line
show vlan-switch
data:image/s3,"s3://crabby-images/22b34/22b341c5aae944a76071379353dc9cd0146062cb" alt="ScreenHunter_02 ScreenHunter_02"
In the result, all Ethernet ports are active status and are assigned to VLAN 1. This is why PC can ping and the respond is normal each other.
In the next step, we will begin to create VLAN ID on switch by command
data:image/s3,"s3://crabby-images/087dc/087dccb0ab8bc42e3f117fd10bfb5e91e1d50e1c" alt="ScreenHunter_06 ScreenHunter_06"
So does that there is two new VLAN ID on Switch now.
data:image/s3,"s3://crabby-images/d086b/d086b12c71c9b33ec6b0f1dbf85581809ec7a6c8" alt="ScreenHunter_08 ScreenHunter_08"
Finally, assign the Switch port number to the special VLAN ID
data:image/s3,"s3://crabby-images/c7fbf/c7fbfcf676c76f165eefc584c2ef9d2e2ea0c912" alt="ScreenHunter_10 ScreenHunter_10"
The port number will be mapped into VLAN ID one by one.
data:image/s3,"s3://crabby-images/4f9b5/4f9b595223b9e831cc4a7a83ba61b637724ba456" alt="ScreenHunter_14 ScreenHunter_14"
In the moment, the message exchange fail between PCs each other.
data:image/s3,"s3://crabby-images/95467/954677960585a5aa7f55ae2c4386f0cc697e9de4" alt="ScreenHunter_11 ScreenHunter_11"
Of course, please remember to execute command
wr for building and saving configuration. Otherwise, the above setting will miss if the Switch device is restarted in the future.
沒有留言:
張貼留言