calledvlan官网
vlan官网 时间:2021-05-07 阅读:(
)
VLANinMikroTikByMohammedKhomeiniBinABUMUMIndonesia,2013AboutPresentationTohelpyouunderstandfundamentalofVirtualLocalAreaNetwork(VLAN)andimplementationinMikroTikrouterToexplainafewexampleofimplementationinsiteToshowexamplerunningVLANinseveralMikroTikrouters2AboutMe.
.
MohammedKhomeiniBinAbuMikroTikCertifiedEngineer(MTCINE,MTCRE,MTCWE,MTCTCE,MTCUME)MikroTikCertifiedTrainer(TR0204)MikroTikCertifiedAcademyTrainer(ACTR0062)NetworkConsultant3ContentIntroductionVLANImplementationConclusion4INTRODUCTIONTOVLAN5VirtualLANs–WHAT(1)MostcommonlyusedprotocolforVLANonanethernetnetworkis802.
1QItinsert4bytetagintoastandardethernetframeWorkingatDataLinkLayer(OSILayer2)MaximumnumberofVLANinoneinterfaceis40956VirtualLANs–WHAT(2)EachVLANsistreatedasseparatesubnet/broadcastdomain.
DevicesonaVLANarerestrictedtoonlycommunicatingwithdevicesthatareontheirownVLANMikroTikalsosupportVlanoverVlan/802.
1QinQ/802.
1ad7VirtualLANs–WHY(1)Providesegmentation8VirtualLANs–WHY(2)MultipleLANinasinglephysicalinterfaceMakethelocalnetworkmoresimpleMultiplebroadcastdomaininasinglephysicalinterfaceVLANscanincreasesecurityandmanagementofdifferentnetworkinonesingleinterfacePriority9VirtualLANs-ParameterEdgeports:(Untagged,inCisco:calledAccessPort)SwitchportthatconfigureasapartofthevlanThisportnotsend4bytevlantag.
UsedfordevicethatnotpasstheVLAN,likecomputer,printer,server,etc.
Coreport:(Tagged,inCisco:TrunkPort)Switchportconfiguredtosend4byteormoreVLANtag.
UsedfordevicethatsupportVLANtechnologieslikeswitches,manageableswitch,routers,etc.
1011VirtualLANsinMikroTik(1)InRouterOS,VLANcanbeimplementedinswitchenvironmentandinrouterenvironmentsimultaneously.
AlsopossibletorunVLANinwirelessorbridgeinterfaceItisnotpossibletohaveVLANputonawirelessinterfaceinastationmodeFILOVLANtaggedisusedfor802.
1QinQimplementation12VirtualLANsinMikroTik(2)TocreatevlaninMikroTik,youshouldhavetheinterfacefirst(ifyouwanttoimplementinbridgeinterface)VLANID=uniqueInterfacefortrunk/access13802.
1QFlowChartinRouterOSStartAccept802.
1QCreatetrunkbridgeAddport(interface)totrunkbridgeCreatevlanontrunkinterfaceCreateaccessport11CreateaccessbridgeAddport(interface)andvlantoaccessbridgeCreateIPaddressandDHCPsetupatVlaninterfaceCreateDHCP-serverCreateDHCP-serverCreatevlanontrunkinterfaceFinish222YESYESYESYESNONONONOCreatedByMohammedKhomeiniAbu14VIRTUALLANSIMPLEMENTATION15HowVirtualLANsimplementedin:Smallnetwork(SOHO)Mediumnetwork(SME)WirelessnetworkTunneling16VirtualLANs–SoHo(1)Haveonlysinglerouterandsingle/multimanagedswitchCreate2VLANinMikroTikrouterVlan-100=officeVlan-200=wifi17VirtualLANs–SoHo(2)PublicInterface18VirtualLANs–SoHo(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)AddVLANontrunkinterface(bridge-trunk)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk19VirtualLANs–SoHo(4)CreateIPAddressforVLANCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20020QUIZFrom21VirtualLANs–SME(1)YouhavemorethanonerouterCreate3VLANinMikroTikrouterVlan-100=officeVlan-200=wifiVlan-230=voip22VirtualLANs–SME(2)PublicInterface23VirtualLANs–SME(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk24VirtualLANs–SME(4)AddVLANontrunkinterface(bridge-trunk)Tocreateaccessport,createaccessbridgeinterfacefirst.
ThenaddaccessportinterfaceandVLANintotheaccessbridge[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacevlanaddname=vlan-230interface=bridge-trunkvlan-id=230[admin@R1]>interfacebridgeportaddinterface=ether4bridge=bridge-vlan-230[admin@R1]>interfacebridgeportaddinterface=vlan-230bridge=bridge-vlan-230[admin@R1]>interfacebridgeaddname=bridge-vlan-23025VirtualLANs–SME(5)CreateIPAddressCreateDHCPsetupforinterfacevlan-100,vlan-200,andvlan-230withpublicdns(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>ipaddressaddaddress=192.
168.
230.
1/24interface=vlan-23026VirtualLANs–SME(6)R2ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConnectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk27VirtualLANs–Wireless(1)PublicInterface28VirtualLANs–Wireless(2)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk29VirtualLANs–Wireless(3)AddVLANontrunkinterface(bridge-trunk)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicdns(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=20030VirtualLANs–Wireless(4)R2andR3ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConfigureWirelessinterfaceasap-bridge(forR3,wirelessinterfaceisconfiguredasmode=station-bridge)InR3,connectmanagedswitchintointerface=ether1andconfiguremanagedswitchasdesired[admin@R1]>interfacewirelesssetwlan1mode=ap-bridgedisabled=no[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether1bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=wlan1bridge=bridge-trunk31VirtualLANsoverPPTP(1)RouterOSsupportedbridgethroughPointtoPointTunnelProtocol(PPTP)usingBCP(BridgeControlProtocol).
BCPallowstobridgeethernetpacketthroughPPPlinkToimplementVLANoverPPTPtunnel,weshoulduseBCPandMLPPPfeaturetoforwardpacketbetweensegment/subnet.
32VirtualLANs–PPTP(2)R1willbecomedhcp-serverforvlan-100andvlan-200R4willforwarduntaggedpackettoether5forclientCreatePPTPServer(R1)andclient(R4)33VirtualLANsoverPPTP(3)MakesurethereisaroutingbetweenR1toR4R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether2CreatebridgeinterfaceAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp34VirtualLANsoverPPTP(4)AddVLANontrunkinterface(bridge-pptp)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-pptpvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-pptpvlan-id=200[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20035VirtualLANsoverPPTP(5)CreatePPTP-ServerwithBCPandMLPPPenabledR4ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterface[admin@R1]>pppprofileaddbridge=bridge1name=pptp-bridge[admin@R1]>interfacepptp-serverserversetenabled=yesdefault-profile=pptp-bridge\[admin@R1]>mrru=5000[admin@R1]>pppsecretaddname=pptp-userpassword=1234profile=pptp-bridge\[admin@R1]>local-address=1.
1.
1.
1remote-address=2.
2.
2.
2[admin@R4]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R4]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp36VirtualLANsoverPPTP(6)CreatePPTP-ServerwithBCPandMLPPPenabledConnectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R4]>pppprofileaddbridge=bridge-pptpname=pptp-bridge[admin@R4]>interfacepptp-clientaddconnect=192.
168.
12.
1user=pptp-user\[admin@R4]>password=1234profile=pptp-bridgemrru=5000disabled=no[admin@R4]>37CONCLUSION38ConclusionAllVLANshouldbeputinbridgeinterfaceasitiseasytomanipulatewhetheritisatrunkportoranaccessport.
ThedisadvantageiswecreatemoreheaderondatalinklayerWhenyoudon'tenableMLPPPinPPPtunnel,youstillcanuseinternetbutslow,causethepackethasbeenfragmented.
Inwirelessmode,shoulduseotherthanmode=stationRememberflowchart39References1.
wiki.
mikrotik.
com2.
CiscoCCNAmodules3.
Vlanworkshop,www.
roamingnet.
com4.
id-networkers.
com5.
www.
mikrotik.
co.
id40CredittoMr.
RofiqFauziMr.
PujoDewobrotoMr.
GatotWibowoHamisenoMr.
HerryDarmawanMr.
MatDawamAbasMikroTikTeam41MohammedKhomeiniBinAbukhomeini1980@gmail.
com+6013-7221134(whatsapp)42
ftlcloud(超云)目前正在搞暑假促销,美国圣何塞数据中心的云服务器低至9元/月,系统盘与数据盘分离,支持Windows和Linux,免费防御CC攻击,自带10Gbps的DDoS防御。FTL-超云服务器的主要特色:稳定、安全、弹性、高性能的云端计算服务,快速部署,并且可根据业务需要扩展计算能力,按需付费,节约成本,提高资源的有效利用率。活动地址:https://www.ftlcloud.com...
RAKsmart 商家估摸着前段时间服务器囤货较多,这两个月的促销活动好像有点针对独立服务器。前面才整理到七月份的服务器活动在有一些配置上比上个月折扣力度是大很多,而且今天看到再来部分的服务器首月半价,一般这样的促销有可能是商家库存充裕。比如近期有一些服务商挖矿服务器销售不好,也都会采用这些策略,就好比电脑硬件最近也有下降。不管如何,我们选择服务器或者VPS主机要本着符合自己需求,如果业务不需要,...
对于如今的云服务商的竞争着实很激烈,我们可以看到国内国外服务商的各种内卷,使得我们很多个人服务商压力还是比较大的。我们看到这几年的服务商变动还是比较大的,很多新服务商坚持不超过三个月,有的是多个品牌同步进行然后分别的跑路赚一波走人。对于我们用户来说,便宜的服务商固然可以试试,但是如果是不确定的,建议月付或者主力业务尽量的还是注意备份。HostYun 最近几个月还是比较活跃的,在前面也有多次介绍到商...
vlan官网为你推荐
recommendations37prohibited禁止(过去式)英语怎么说?企业ssl证书国内哪些公司是专门做ssl证书的呢?360邮箱免费注册360账号-电子邮箱怎么填写?支付宝注册网站支付宝申请流程是怎么样的??flashfxp注册码找flashfxp3.4注册码的是cuteftpAliasedinternal温州商标注册温州注册公司在哪里注册即时通平台老司机进来 求个直播平台
域名购买 php网站空间 域名查询工具 河南vps 2019年感恩节 enzu 香港机房 shopex空间 铁通流量查询 bgp双线 789电视剧 银盘服务 便宜空间 789 云营销系统 免费ftp 德讯 广州服务器托管 中美互联网论坛 e-mail 更多