1. 程式人生 > >vlan綁定mac-add、ip-add

vlan綁定mac-add、ip-add

vlan綁定mac-add、ip-add

vlan綁定mac-add、ip-add實現只有綁定的用戶才能上網,否則與網關不通,本網段通的效果。

技術分享圖片

配置模板

LSW1:
[Huawei]dis cu

sysname Huawei

vlan batch 2

cluster enable
ntdp enable
ndp enable

drop illegal-mac alar

user-bind static ip-address 192.168.1.1 mac-address 5489-9891-49fd vlan 1 //綁定ip、mac
user-bind static ip-address 192.168.2.1 mac-address 5489-98a2-570a vlan 2

diffserv domain default

drop-profile default

vlan 1 //開啟檢查功能
arp anti-attack check user-bind enable
vlan 2
arp anti-attack check user-bind enable

aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin

local-user admin service-type http

interface Vlanif1
ip address 192.168.1.254 255.255.255.0

interface Vlanif2
ip address 192.168.2.254 255.255.255.0

interface MEth0/0/1

interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094

interface GigabitEthernet0/0/2

技術分享圖片

vlan綁定mac-add、ip-add