calledvlan官网
vlan官网 时间:2021-05-07 阅读:(
)
VLANinMikroTikByMohammedKhomeiniBinABUMUMIndonesia,2013AboutPresentationTohelpyouunderstandfundamentalofVirtualLocalAreaNetwork(VLAN)andimplementationinMikroTikrouterToexplainafewexampleofimplementationinsiteToshowexamplerunningVLANinseveralMikroTikrouters2AboutMe.
.
MohammedKhomeiniBinAbuMikroTikCertifiedEngineer(MTCINE,MTCRE,MTCWE,MTCTCE,MTCUME)MikroTikCertifiedTrainer(TR0204)MikroTikCertifiedAcademyTrainer(ACTR0062)NetworkConsultant3ContentIntroductionVLANImplementationConclusion4INTRODUCTIONTOVLAN5VirtualLANs–WHAT(1)MostcommonlyusedprotocolforVLANonanethernetnetworkis802.
1QItinsert4bytetagintoastandardethernetframeWorkingatDataLinkLayer(OSILayer2)MaximumnumberofVLANinoneinterfaceis40956VirtualLANs–WHAT(2)EachVLANsistreatedasseparatesubnet/broadcastdomain.
DevicesonaVLANarerestrictedtoonlycommunicatingwithdevicesthatareontheirownVLANMikroTikalsosupportVlanoverVlan/802.
1QinQ/802.
1ad7VirtualLANs–WHY(1)Providesegmentation8VirtualLANs–WHY(2)MultipleLANinasinglephysicalinterfaceMakethelocalnetworkmoresimpleMultiplebroadcastdomaininasinglephysicalinterfaceVLANscanincreasesecurityandmanagementofdifferentnetworkinonesingleinterfacePriority9VirtualLANs-ParameterEdgeports:(Untagged,inCisco:calledAccessPort)SwitchportthatconfigureasapartofthevlanThisportnotsend4bytevlantag.
UsedfordevicethatnotpasstheVLAN,likecomputer,printer,server,etc.
Coreport:(Tagged,inCisco:TrunkPort)Switchportconfiguredtosend4byteormoreVLANtag.
UsedfordevicethatsupportVLANtechnologieslikeswitches,manageableswitch,routers,etc.
1011VirtualLANsinMikroTik(1)InRouterOS,VLANcanbeimplementedinswitchenvironmentandinrouterenvironmentsimultaneously.
AlsopossibletorunVLANinwirelessorbridgeinterfaceItisnotpossibletohaveVLANputonawirelessinterfaceinastationmodeFILOVLANtaggedisusedfor802.
1QinQimplementation12VirtualLANsinMikroTik(2)TocreatevlaninMikroTik,youshouldhavetheinterfacefirst(ifyouwanttoimplementinbridgeinterface)VLANID=uniqueInterfacefortrunk/access13802.
1QFlowChartinRouterOSStartAccept802.
1QCreatetrunkbridgeAddport(interface)totrunkbridgeCreatevlanontrunkinterfaceCreateaccessport11CreateaccessbridgeAddport(interface)andvlantoaccessbridgeCreateIPaddressandDHCPsetupatVlaninterfaceCreateDHCP-serverCreateDHCP-serverCreatevlanontrunkinterfaceFinish222YESYESYESYESNONONONOCreatedByMohammedKhomeiniAbu14VIRTUALLANSIMPLEMENTATION15HowVirtualLANsimplementedin:Smallnetwork(SOHO)Mediumnetwork(SME)WirelessnetworkTunneling16VirtualLANs–SoHo(1)Haveonlysinglerouterandsingle/multimanagedswitchCreate2VLANinMikroTikrouterVlan-100=officeVlan-200=wifi17VirtualLANs–SoHo(2)PublicInterface18VirtualLANs–SoHo(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)AddVLANontrunkinterface(bridge-trunk)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk19VirtualLANs–SoHo(4)CreateIPAddressforVLANCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20020QUIZFrom21VirtualLANs–SME(1)YouhavemorethanonerouterCreate3VLANinMikroTikrouterVlan-100=officeVlan-200=wifiVlan-230=voip22VirtualLANs–SME(2)PublicInterface23VirtualLANs–SME(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk24VirtualLANs–SME(4)AddVLANontrunkinterface(bridge-trunk)Tocreateaccessport,createaccessbridgeinterfacefirst.
ThenaddaccessportinterfaceandVLANintotheaccessbridge[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacevlanaddname=vlan-230interface=bridge-trunkvlan-id=230[admin@R1]>interfacebridgeportaddinterface=ether4bridge=bridge-vlan-230[admin@R1]>interfacebridgeportaddinterface=vlan-230bridge=bridge-vlan-230[admin@R1]>interfacebridgeaddname=bridge-vlan-23025VirtualLANs–SME(5)CreateIPAddressCreateDHCPsetupforinterfacevlan-100,vlan-200,andvlan-230withpublicdns(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>ipaddressaddaddress=192.
168.
230.
1/24interface=vlan-23026VirtualLANs–SME(6)R2ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConnectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk27VirtualLANs–Wireless(1)PublicInterface28VirtualLANs–Wireless(2)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk29VirtualLANs–Wireless(3)AddVLANontrunkinterface(bridge-trunk)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicdns(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=20030VirtualLANs–Wireless(4)R2andR3ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConfigureWirelessinterfaceasap-bridge(forR3,wirelessinterfaceisconfiguredasmode=station-bridge)InR3,connectmanagedswitchintointerface=ether1andconfiguremanagedswitchasdesired[admin@R1]>interfacewirelesssetwlan1mode=ap-bridgedisabled=no[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether1bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=wlan1bridge=bridge-trunk31VirtualLANsoverPPTP(1)RouterOSsupportedbridgethroughPointtoPointTunnelProtocol(PPTP)usingBCP(BridgeControlProtocol).
BCPallowstobridgeethernetpacketthroughPPPlinkToimplementVLANoverPPTPtunnel,weshoulduseBCPandMLPPPfeaturetoforwardpacketbetweensegment/subnet.
32VirtualLANs–PPTP(2)R1willbecomedhcp-serverforvlan-100andvlan-200R4willforwarduntaggedpackettoether5forclientCreatePPTPServer(R1)andclient(R4)33VirtualLANsoverPPTP(3)MakesurethereisaroutingbetweenR1toR4R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether2CreatebridgeinterfaceAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp34VirtualLANsoverPPTP(4)AddVLANontrunkinterface(bridge-pptp)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-pptpvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-pptpvlan-id=200[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20035VirtualLANsoverPPTP(5)CreatePPTP-ServerwithBCPandMLPPPenabledR4ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterface[admin@R1]>pppprofileaddbridge=bridge1name=pptp-bridge[admin@R1]>interfacepptp-serverserversetenabled=yesdefault-profile=pptp-bridge\[admin@R1]>mrru=5000[admin@R1]>pppsecretaddname=pptp-userpassword=1234profile=pptp-bridge\[admin@R1]>local-address=1.
1.
1.
1remote-address=2.
2.
2.
2[admin@R4]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R4]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp36VirtualLANsoverPPTP(6)CreatePPTP-ServerwithBCPandMLPPPenabledConnectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R4]>pppprofileaddbridge=bridge-pptpname=pptp-bridge[admin@R4]>interfacepptp-clientaddconnect=192.
168.
12.
1user=pptp-user\[admin@R4]>password=1234profile=pptp-bridgemrru=5000disabled=no[admin@R4]>37CONCLUSION38ConclusionAllVLANshouldbeputinbridgeinterfaceasitiseasytomanipulatewhetheritisatrunkportoranaccessport.
ThedisadvantageiswecreatemoreheaderondatalinklayerWhenyoudon'tenableMLPPPinPPPtunnel,youstillcanuseinternetbutslow,causethepackethasbeenfragmented.
Inwirelessmode,shoulduseotherthanmode=stationRememberflowchart39References1.
wiki.
mikrotik.
com2.
CiscoCCNAmodules3.
Vlanworkshop,www.
roamingnet.
com4.
id-networkers.
com5.
www.
mikrotik.
co.
id40CredittoMr.
RofiqFauziMr.
PujoDewobrotoMr.
GatotWibowoHamisenoMr.
HerryDarmawanMr.
MatDawamAbasMikroTikTeam41MohammedKhomeiniBinAbukhomeini1980@gmail.
com+6013-7221134(whatsapp)42
CheapWindowsVPS是一家成立于2007年的老牌国外主机商,顾名思义,一个提供便宜的Windows系统VPS主机(同样也支持安装Linux系列的哈)的商家,可选数据中心包括美国洛杉矶、达拉斯、芝加哥、纽约、英国伦敦、法国、新加坡等等,目前商家针对VPS主机推出5折优惠码,优惠后最低4GB内存套餐月付仅4.5美元。下面列出几款VPS主机配置信息。CPU:2cores内存:4GB硬盘:60G...
cmivps香港VPS带来了3个新消息:(1)双向流量改为单向流量,相当于流量间接扩大一倍;(2)Hong Kong 2T、Hong Kong 3T、Hong Kong 无限流量,这三款VPS开始支持Windows系统,如果需要中文版Windows系统请下单付款完成之后发ticket要求官方更改即可;(3)全场7折年付、8折月付优惠,优惠码有效期一个月!官方网站:https://www.cmivp...
HostKvm商家我们也不用多介绍,这个服务商来自国内某商家,旗下也有多个品牌的,每次看到推送信息都是几个服务商品牌一起推送的。当然商家还是比较稳定的,商家品牌比较多,这也是国内商家一贯的做法,这样广撒网。这次看到黑五优惠活动发布了,针对其主打的香港云服务器提供终身6折的优惠,其余机房服务器依然是8折,另还有充值50美元赠送5美元的优惠活动,有需要的可以看看。HostKvm是一个创建于2013年的...
vlan官网为你推荐
Literaturverzeichnisinternalservererrorinternal server error支付宝注册网站在哪里注册支付宝账号客服电话中国移动的人工服务电话号码是多少瑞东集团请问富源集团到底是一个怎么样的集团?400电话查询400电话号码可以查询归属地吗?办理400电话是不是很贵?免费代理加盟哪有免费的代理可以做的?论坛版块图标请教一下论坛版块图标怎么做?帝国cms教程如何使用帝国CMS模板网店系统哪个公司开发商城系统比较好?
域名系统 美国域名注册 电信服务器租赁 enzu 镇江联通宽带 绍兴高防 股票老左 hostloc 太原网通测速平台 常州联通宽带 免费私人服务器 架设邮件服务器 域名转入 卡巴斯基官网下载 博客域名 linux服务器系统 远程登录 美国达拉斯 德国代理 超低价 更多