0

我的帖子

个人中心

设置

  发新话题
办公室网络已经做好配置,目前有VLAN1、3、40、100、103、105,其中VLAN3、103可以访问外网,其他的只能访问内网,现在想将VLAN105设置为可以访问外网,请教一下应该如何操作?比较纠结的是我设置的VLAN105和VLAN103是一样的,为什么VLAN105无法访问外网?
路由器只做了VLAN的设置,如图:

交换机的配置如下:

<A3 Office>display current-configuration
#
version 7.1.070, Release 1119P11
#
sysname A3 Office
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
dhcp enable
dhcp server forbidden-ip 192.168.3.200 192.168.3.254
#
lldp global enable
#
password-recovery enable
#
vlan 1
#
vlan 3
#
vlan 40
description BGM-music
#
vlan 100
description shehuitingchechang
#
vlan 103
#
vlan 105
description LED
#
stp global enable
#
dhcp server ip-pool office
gateway-list 192.168.3.254
network 192.168.3.0 mask 255.255.255.0
dns-list 202.103.224.68 114.114.114.114
#
interface NULL0
#
interface Vlan-interface1
ip address 192.168.1.254 255.255.255.0
#
interface Vlan-interface3
description office
ip address 192.168.3.254 255.255.255.0
dhcp server apply ip-pool office
#
interface Vlan-interface40
description BGM-music
ip address 192.168.40.252 255.255.255.0
#
interface Vlan-interface100
ip address 192.168.100.252 255.255.255.0
#
interface Vlan-interface103
ip address 192.168.103.252 255.255.255.0
#
interface Vlan-interface105
description LED
ip address 192.168.105.253 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/2
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/3
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/4
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/5
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/6
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/7
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/8
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/9
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/10
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/11
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/12
port link-mode bridge
description to XXZX
port access vlan 103
#
interface GigabitEthernet1/0/13
port link-mode bridge
port access vlan 105
#
interface GigabitEthernet1/0/14
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/15
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/16
port link-mode bridge
port access vlan 3
#
interface GigabitEthernet1/0/17
port link-mode bridge
port access vlan 3
combo enable copper
#
interface GigabitEthernet1/0/18
port link-mode bridge
port access vlan 3
combo enable copper
#
interface GigabitEthernet1/0/19
port link-mode bridge
port access vlan 3
combo enable copper
#
interface GigabitEthernet1/0/20
port link-mode bridge
port access vlan 3
combo enable copper
#
interface GigabitEthernet1/0/21
port link-mode bridge
description to jinrong-office
port access vlan 3
combo enable copper
#
interface GigabitEthernet1/0/22
port link-mode bridge
description to xiaokongshi
port link-type trunk
port trunk permit vlan 1 3 40 100 103 to 106
combo enable copper
#
interface GigabitEthernet1/0/23
port link-mode bridge
description to XXZX
port link-type trunk
port trunk permit vlan 1 3 103 105
combo enable copper
#
interface GigabitEthernet1/0/24
port link-mode bridge
description to Route
port access vlan 3
combo enable copper
#
interface M-GigabitEthernet0/0/0
#
interface Ten-GigabitEthernet1/0/25
port link-mode bridge
#
interface Ten-GigabitEthernet1/0/26
port link-mode bridge
#
interface Ten-GigabitEthernet1/0/27
port link-mode bridge
#
interface Ten-GigabitEthernet1/0/28
port link-mode bridge
#
scheduler logfile size 16
#
line class aux
user-role network-admin
#
line class usb
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line vty 0 4
authentication-mode scheme
user-role level-15
user-role network-operator
set authentication password hash $h$6$7CRs1EmwBUpu/oOu$O8BS6Do3/9sl+nG6k+Fu6sdisIksQFuNBKr4eSbSf6osO6GWei94fxtNeGV2flC7a6ksP9QB3Y6lbfrPWOxNkg==
#
line vty 5 63
user-role network-operator
#
ip route-static 0.0.0.0 0 192.168.3.253
ip route-static 192.168.2.201 32 192.168.3.202
ip route-static 192.168.40.0 24 192.168.40.254
ip route-static 192.168.100.0 24 192.168.100.1
ip route-static 192.168.103.0 24 192.168.103.254
ip route-static 192.168.105.0 24 192.168.105.254
#
radius scheme system
user-name-format without-domain
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash $h$6$MSzkEHyIi9JMntGj$b663ppKkDBmQgCNgYEBYkgCE6ZHqoWVtSL0NZZ2u2slHim+HMzw3JoPaO+Lcu1ULCIDig6flBp0NX8OLtd6p5Q==
service-type telnet http https
authorization-attribute user-role 0
authorization-attribute user-role 1
authorization-attribute user-role level-3
authorization-attribute user-role guest-manager
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
ip http enable
webui log enable
#
return



路由器的配置:
<H3C>?
    reboot         Reboot device
    restore        Restore configuration
    ip             Display the IP configuration
    display        Display current information
    ping           Ping function
    quit           Exit from the device
    admin          Admin the LAN interface
<H3C>ip ?
    address        Display IP addresses
<H3C>ip ad
<H3C>ip address ?
    <cr>
<H3C>ip address
The LAN interface information:
  IP address: 192.168.1.254
  Mask: 255.255.255.0
The VLAN3 information:
  IP address: 192.168.3.253
  Mask: 255.255.255.0

<H3C>dis
<H3C>display ?
    sysinfo        CPU and memory information
    device         Device information
    version        Version information
<H3C>display sy
<H3C>display sysinfo ?
    <cr>
<H3C>display sysinfo
CPU Used Rate:          3%
Memory Used Rate:       8.4%

<H3C>dis
<H3C>display de
<H3C>display device ?
    manuinfo       Manufacture information
<H3C>display device ma
<H3C>display device manuinfo ?
    <cr>
<H3C>display device manuinfo
DEVICE_NAME: ER8300G2-X
DEVICE_SERIAL_NUMBER: 219801A0P59189Q000KD
MAC_ADDRESS: 7485-C4CD-2BDA
MANUFACTURING_DATE: 2018-9
VENDOR_NAME: H3C

<H3C>dis
<H3C>display ve
<H3C>display version ?
    <cr>
<H3C>display version
Hardware: VER.A
Bootrom: 0.0.0.7
Software: ERHMG2-MNW100-R1117

<H3C>admin ?
    acl            Access control list
<H3C>admin acl ?
    info           Display the administrator access information in LAN
    default        Restore the access control to default, no restricted
<H3C>admin acl in
<H3C>admin acl info ?
    <cr>
<H3C>admin acl info
By default,permit all hosts to access the LAN interface



加个联系方式给你一下



静态路由写错了吧,路由器的lan口ip是多少,交换机与路由器互联的ip和vlan是多少。



建议看下路由器的静态路由,有没有到  vlan30得静态路由




引用:
原帖由 sdmz012 于 2021-6-5 09:20 发表
加个联系方式给你一下
5227990,我的QQ,麻烦加一下



引用:
原帖由 woshi_1001 于 2021-6-6 08:41 发表
静态路由写错了吧,路由器的lan口ip是多少,交换机与路由器互联的ip和vlan是多少。
路由器的设置有:LAN口IP是192.168.1.254,设置一个VLAN3(192.168.3.254),允许所有VLAN通过LAN5



引用:
原帖由 jasion55 于 2021-6-6 18:48 发表
建议看下路由器的静态路由,有没有到  vlan30得静态路由

没有VLAN30,只有交换机设置了以下静态路由:
ip route-static 0.0.0.0 0 192.168.3.253
ip route-static 192.168.2.201 32 192.168.3.202
ip route-static 192.168.40.0 24 192.168.40.254
ip route-static 192.168.100.0 24 192.168.100.1
ip route-static 192.168.103.0 24 192.168.103.254
ip route-static 192.168.105.0 24 192.168.105.254

路由器没设置路由



引用:
原帖由 sdmz012 于 2021-6-5 09:20 发表
加个联系方式给你一下
问题已经解决了,局域网内还有另外一台路由器,连接了另外一个外网,导致VLAN103可以通过那台路由器访问外网。我在那台路由器设置VLAN105,就可以访问外网了,感谢



‹‹ 上一贴:求助!路由器总是切线 CPU负载过高 内网arp包横行 ...   |   下一贴:H3C售前工程师培训资料 ››
  发新话题
快速回复主题
关于我们 | 诚聘英才 | 联系我们 | 网站大事 | 友情链接 |意见反馈 | 网站地图
Copyright©2005-2021 51CTO.COM
本论坛言论纯属发布者个人意见,不代表51CTO网站立场!如有疑义,请与管理员联系:bbs@51cto.com