calledvlan官网
vlan官网 时间:2021-05-07 阅读:(
)
VLANinMikroTikByMohammedKhomeiniBinABUMUMIndonesia,2013AboutPresentationTohelpyouunderstandfundamentalofVirtualLocalAreaNetwork(VLAN)andimplementationinMikroTikrouterToexplainafewexampleofimplementationinsiteToshowexamplerunningVLANinseveralMikroTikrouters2AboutMe.
.
MohammedKhomeiniBinAbuMikroTikCertifiedEngineer(MTCINE,MTCRE,MTCWE,MTCTCE,MTCUME)MikroTikCertifiedTrainer(TR0204)MikroTikCertifiedAcademyTrainer(ACTR0062)NetworkConsultant3ContentIntroductionVLANImplementationConclusion4INTRODUCTIONTOVLAN5VirtualLANs–WHAT(1)MostcommonlyusedprotocolforVLANonanethernetnetworkis802.
1QItinsert4bytetagintoastandardethernetframeWorkingatDataLinkLayer(OSILayer2)MaximumnumberofVLANinoneinterfaceis40956VirtualLANs–WHAT(2)EachVLANsistreatedasseparatesubnet/broadcastdomain.
DevicesonaVLANarerestrictedtoonlycommunicatingwithdevicesthatareontheirownVLANMikroTikalsosupportVlanoverVlan/802.
1QinQ/802.
1ad7VirtualLANs–WHY(1)Providesegmentation8VirtualLANs–WHY(2)MultipleLANinasinglephysicalinterfaceMakethelocalnetworkmoresimpleMultiplebroadcastdomaininasinglephysicalinterfaceVLANscanincreasesecurityandmanagementofdifferentnetworkinonesingleinterfacePriority9VirtualLANs-ParameterEdgeports:(Untagged,inCisco:calledAccessPort)SwitchportthatconfigureasapartofthevlanThisportnotsend4bytevlantag.
UsedfordevicethatnotpasstheVLAN,likecomputer,printer,server,etc.
Coreport:(Tagged,inCisco:TrunkPort)Switchportconfiguredtosend4byteormoreVLANtag.
UsedfordevicethatsupportVLANtechnologieslikeswitches,manageableswitch,routers,etc.
1011VirtualLANsinMikroTik(1)InRouterOS,VLANcanbeimplementedinswitchenvironmentandinrouterenvironmentsimultaneously.
AlsopossibletorunVLANinwirelessorbridgeinterfaceItisnotpossibletohaveVLANputonawirelessinterfaceinastationmodeFILOVLANtaggedisusedfor802.
1QinQimplementation12VirtualLANsinMikroTik(2)TocreatevlaninMikroTik,youshouldhavetheinterfacefirst(ifyouwanttoimplementinbridgeinterface)VLANID=uniqueInterfacefortrunk/access13802.
1QFlowChartinRouterOSStartAccept802.
1QCreatetrunkbridgeAddport(interface)totrunkbridgeCreatevlanontrunkinterfaceCreateaccessport11CreateaccessbridgeAddport(interface)andvlantoaccessbridgeCreateIPaddressandDHCPsetupatVlaninterfaceCreateDHCP-serverCreateDHCP-serverCreatevlanontrunkinterfaceFinish222YESYESYESYESNONONONOCreatedByMohammedKhomeiniAbu14VIRTUALLANSIMPLEMENTATION15HowVirtualLANsimplementedin:Smallnetwork(SOHO)Mediumnetwork(SME)WirelessnetworkTunneling16VirtualLANs–SoHo(1)Haveonlysinglerouterandsingle/multimanagedswitchCreate2VLANinMikroTikrouterVlan-100=officeVlan-200=wifi17VirtualLANs–SoHo(2)PublicInterface18VirtualLANs–SoHo(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)AddVLANontrunkinterface(bridge-trunk)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk19VirtualLANs–SoHo(4)CreateIPAddressforVLANCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20020QUIZFrom21VirtualLANs–SME(1)YouhavemorethanonerouterCreate3VLANinMikroTikrouterVlan-100=officeVlan-200=wifiVlan-230=voip22VirtualLANs–SME(2)PublicInterface23VirtualLANs–SME(3)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk24VirtualLANs–SME(4)AddVLANontrunkinterface(bridge-trunk)Tocreateaccessport,createaccessbridgeinterfacefirst.
ThenaddaccessportinterfaceandVLANintotheaccessbridge[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=200[admin@R1]>interfacevlanaddname=vlan-230interface=bridge-trunkvlan-id=230[admin@R1]>interfacebridgeportaddinterface=ether4bridge=bridge-vlan-230[admin@R1]>interfacebridgeportaddinterface=vlan-230bridge=bridge-vlan-230[admin@R1]>interfacebridgeaddname=bridge-vlan-23025VirtualLANs–SME(5)CreateIPAddressCreateDHCPsetupforinterfacevlan-100,vlan-200,andvlan-230withpublicdns(8.
8.
8.
8and8.
8.
4.
4)Connectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>ipaddressaddaddress=192.
168.
230.
1/24interface=vlan-23026VirtualLANs–SME(6)R2ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConnectmanagedswitchintointerface=ether2Configuremanagedswitchasdesired[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether2bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk27VirtualLANs–Wireless(1)PublicInterface28VirtualLANs–Wireless(2)R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether1Tobeabletoforwardtaggedpacket,weneedtocreatetrunkbridgeAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddname=bridge-trunkprotocol-mode=rstp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-trunk29VirtualLANs–Wireless(3)AddVLANontrunkinterface(bridge-trunk)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicdns(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-200[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-trunkvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-trunkvlan-id=20030VirtualLANs–Wireless(4)R2andR3ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterfaceConfigureWirelessinterfaceasap-bridge(forR3,wirelessinterfaceisconfiguredasmode=station-bridge)InR3,connectmanagedswitchintointerface=ether1andconfiguremanagedswitchasdesired[admin@R1]>interfacewirelesssetwlan1mode=ap-bridgedisabled=no[admin@R2]>interfacebridgeaddname=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=ether1bridge=bridge-trunk[admin@R2]>interfacebridgeportaddinterface=wlan1bridge=bridge-trunk31VirtualLANsoverPPTP(1)RouterOSsupportedbridgethroughPointtoPointTunnelProtocol(PPTP)usingBCP(BridgeControlProtocol).
BCPallowstobridgeethernetpacketthroughPPPlinkToimplementVLANoverPPTPtunnel,weshoulduseBCPandMLPPPfeaturetoforwardpacketbetweensegment/subnet.
32VirtualLANs–PPTP(2)R1willbecomedhcp-serverforvlan-100andvlan-200R4willforwarduntaggedpackettoether5forclientCreatePPTPServer(R1)andclient(R4)33VirtualLANsoverPPTP(3)MakesurethereisaroutingbetweenR1toR4R1ConfigurationIPAddress,SubnetMask,DefaultGatewayandmasqueradeisconfiguredatether2CreatebridgeinterfaceAddport(interface)thatyouwanttoforwardtheVLANinthetrunkbridge(atleast1port)[admin@R1]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R1]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp34VirtualLANsoverPPTP(4)AddVLANontrunkinterface(bridge-pptp)CreateIPAddressCreateDHCPsetupforinterfacevlan-100andvlan-200withpublicDNS(8.
8.
8.
8and8.
8.
4.
4)[admin@R1]>interfacevlanaddname=vlan-100interface=bridge-pptpvlan-id=100[admin@R1]>interfacevlanaddname=vlan-200interface=bridge-pptpvlan-id=200[admin@R1]>ipaddressaddaddress=192.
168.
100.
1/24interface=vlan-100[admin@R1]>ipaddressaddaddress=192.
168.
200.
1/24interface=vlan-20035VirtualLANsoverPPTP(5)CreatePPTP-ServerwithBCPandMLPPPenabledR4ConfigurationCreatebridgeinterfaceAddinterfacethatwewanttoforwardtagged(trunk)packettobridge-trunkinterface[admin@R1]>pppprofileaddbridge=bridge1name=pptp-bridge[admin@R1]>interfacepptp-serverserversetenabled=yesdefault-profile=pptp-bridge\[admin@R1]>mrru=5000[admin@R1]>pppsecretaddname=pptp-userpassword=1234profile=pptp-bridge\[admin@R1]>local-address=1.
1.
1.
1remote-address=2.
2.
2.
2[admin@R4]>interfacebridgeaddprotocol-mode=rstpname=bridge-pptp[admin@R4]>interfacebridgeportaddinterface=ether5bridge=bridge-pptp36VirtualLANsoverPPTP(6)CreatePPTP-ServerwithBCPandMLPPPenabledConnectmanagedswitchintointerface=ether5Configuremanagedswitchasdesired[admin@R4]>pppprofileaddbridge=bridge-pptpname=pptp-bridge[admin@R4]>interfacepptp-clientaddconnect=192.
168.
12.
1user=pptp-user\[admin@R4]>password=1234profile=pptp-bridgemrru=5000disabled=no[admin@R4]>37CONCLUSION38ConclusionAllVLANshouldbeputinbridgeinterfaceasitiseasytomanipulatewhetheritisatrunkportoranaccessport.
ThedisadvantageiswecreatemoreheaderondatalinklayerWhenyoudon'tenableMLPPPinPPPtunnel,youstillcanuseinternetbutslow,causethepackethasbeenfragmented.
Inwirelessmode,shoulduseotherthanmode=stationRememberflowchart39References1.
wiki.
mikrotik.
com2.
CiscoCCNAmodules3.
Vlanworkshop,www.
roamingnet.
com4.
id-networkers.
com5.
www.
mikrotik.
co.
id40CredittoMr.
RofiqFauziMr.
PujoDewobrotoMr.
GatotWibowoHamisenoMr.
HerryDarmawanMr.
MatDawamAbasMikroTikTeam41MohammedKhomeiniBinAbukhomeini1980@gmail.
com+6013-7221134(whatsapp)42
提速啦(www.tisula.com)是赣州王成璟网络科技有限公司旗下云服务器品牌,目前拥有在籍员工40人左右,社保在籍员工30人+,是正规的国内拥有IDC ICP ISP CDN 云牌照资质商家,2018-2021年连续4年获得CTG机房顶级金牌代理商荣誉 2021年赣州市于都县创业大赛三等奖,2020年于都电子商务示范企业,2021年于都县电子商务融合推广大使。资源优势介绍:Ceranetwo...
digital-vm在日本东京机房当前提供1Gbps带宽、2Gbps带宽、10Gbps带宽接入的独立服务器,每个月自带10T免费流量,一个独立IPv4。支持额外购买流量:20T-$30/月、50T-$150/月、100T-$270美元/月;也支持额外购买IPv4,/29-$5/月、/28-$13/月。独立从下单开始一般24小时内可以上架。官方网站:https://digital-vm.com/de...
湖南百纵科技有限公司是一家具有ISP ICP 电信增值许可证的正规公司,多年不断转型探索现已颇具规模,公司成立于2009年 通过多年经营积累目前已独具一格,公司主要经营有国内高防服务器,香港服务器,美国服务器,站群服务器,东南亚服务器租用,国内香港美国云服务器,以及全球专线业务!活动方案:主营:1、美国CN2云服务器,美国VPS,美国高防云主机,美国独立服务器,美国站群服务器,美国母机。2、香港C...
vlan官网为你推荐
操作httphttp500ZTCS500在哪能下载手机QQ?搜狗360因为我做百度,搜狗,360,神马竞价推广已经有一年多了,所以请问下,网上有哪些平台可以接竞价的单呢?建企业网站建立一个企业网站要多少钱特朗普吐槽iPhone华为余承东吐槽iPhone X,除了贵啥优点都没有flashftp下载禁室迷情夜下载地址给我 谢谢要能下载出来的重庆网站制作重庆网站制作,哪家公司服务,价格都比较好?重庆网站制作我想做个网站,我是重庆的人。想在本地找个做网站的公司,请教一下在重庆那个公司比较好一点,,,,谢谢重庆网站制作请问重庆那一家网站制作公司资信度比较好?技术实力雄厚呢?补贴eset
免费网站空间申请 万网域名 免费域名注册网站 hostigation directspace 精品网 鲨鱼机 rak机房 服务器cpu性能排行 网盘申请 本网站服务器在美国 193邮箱 国外免费全能空间 双十一秒杀 国外代理服务器软件 33456 vip域名 支付宝扫码领红包 能外链的相册 新睿云 更多