ÔõÑùʹÓÃÐéÄâ¾ÖÓòÍø£¨VLAN£©±£»¤CentOSЧÀÍÆ÷µÄÍøÂçÇå¾²
ÔõÑùʹÓÃÐéÄâ¾ÖÓòÍø£¨vlan£©±£»¤centosЧÀÍÆ÷µÄÍøÂçÇå¾²
ÕªÒª£ºÐéÄâ¾ÖÓòÍø£¨VLAN£©ÊÇÒ»ÖÖÍøÂç·Ö¶ÎÊÖÒÕ£¬¿É½«Ò»¸öÎïÀíÍøÂç»®·ÖΪ¶à¸öÂß¼ÍøÂ磬ÒÔÌá¸ßÍøÂçÇå¾²ÐÔ¡£±¾ÎĽ«ÏÈÈÝÔõÑùÔÚCentOSЧÀÍÆ÷ÉÏʹÓÃVLANÀ´±£»¤ÍøÂçÇå¾²£¬²¢Ìṩ²¿·Ö´úÂëʾÀý¾ÙÐÐ˵Ã÷¡£
СÐò£º
ÔÚµ±½ñµÄÍøÂçÇéÐÎÖУ¬±£»¤Ð§ÀÍÆ÷µÄÍøÂçÇå¾²ÊÇÖÁ¹ØÖ÷ÒªµÄ¡£ÐéÄâ¾ÖÓòÍø£¨VLAN£©ÊÇÒ»ÖÖ³£ÓõÄÍøÂçÇå¾²ÊÖÒÕ£¬ËüÄܹ»½«ÎïÀíÍøÂç»®·ÖΪ¶à¸öÂß¼ÍøÂ磬´Ó¶øʵÏÖÍøÂçµÄ¸ôÀëºÍ·Ö¶Î¡£±¾ÎĽ«ÏÈÈÝÔõÑùÔÚCentOSЧÀÍÆ÷ÉÏÉèÖúÍʹÓÃVLANÀ´ÔöÇ¿ÍøÂçÇå¾²ÐÔ¡£
Ò»¡¢Ã÷È·VLANµÄÊÂÇéÔÀí
ÐéÄâ¾ÖÓòÍø£¨VLAN£©ÊÇͨ¹ý½»Á÷»ú»ò·ÓÉÆ÷À´ÊµÏֵġ£Ëüͨ¹ý½«²î±ðµÄ¶Ë¿Ú»òÎïÀí½Ó¿Ú·ÖÅɸø²î±ðµÄVLAN£¬´Ó¶ø½«ÍøÂç»®·ÖΪ¶à¸öÂß¼×ÓÍø¡£²î±ðµÄVLANÖ®¼äÊǸôÀëµÄ£¬ËüÃDz»¿ÉÖ±½ÓͨѶ£¬Ö»ÄÜͨ¹ý·ÓÉÆ÷»òÈý²ã½»Á÷»úÀ´ÊµÏÖ»¥Á¬¡£ÕâÑù£¬×ÝÈ»ÓжñÒâÓû§½øÈëÁËij¸öVLAN£¬Ò²ÎÞ·¨Ö±½Ó»á¼ûÆäËûVLANÖеÄЧÀÍÆ÷»ò×°±¸£¬´Ó¶øÌá¸ßÁËÍøÂçµÄÇå¾²ÐÔ¡£
¶þ¡¢ÔÚCentOSЧÀÍÆ÷ÉÏÉèÖÃVLAN
ÔÚCentOSЧÀÍÆ÷ÉÏÉèÖÃVLANÐèÒªÒÔϼ¸¸ö°ì·¨£º
È·ÈÏÍø¿¨Ö§³ÖVLAN£ºÊ¹Óá°ethtool¡±ÏÂÁîÉó²éÍø¿¨ÊÇ·ñÖ§³ÖVLAN¹¦Ð§¡£
ethtool -k eth0 | grep vlan
µÇ¼ºó¸´ÖÆ
ÈôÊÇÏÔʾ¡°vlan offload: off¡±»òÕßÀàËƵÄÐÅÏ¢£¬ÌåÏÖÍø¿¨²»Ö§³ÖVLAN¡£
×°ÖÃVLAN¹¤¾ß£ºÈôÊÇÍø¿¨Ö§³ÖVLAN¹¦Ð§£¬¾ÍÐèҪװÖá°vlan¡±¹¤¾ß¡£
yum install vconfig
µÇ¼ºó¸´ÖÆ
½¨ÉèVLAN½Ó¿Ú£ºÊ¹Óá°vconfig¡±ÏÂÁÉèÒ»¸öVLAN½Ó¿Ú¡£
vconfig add eth0 10
µÇ¼ºó¸´ÖÆ
ÕâÌõÏÂÁî»áÔÚeth0ÉϽ¨ÉèÒ»¸öIDΪ10µÄVLAN½Ó¿Ú£¬¿ÉÒÔƾ֤ÐèÇóÐÞ¸ÄVLANµÄID¡£
ÉèÖÃVLAN½Ó¿Ú£ºÔÚ/etc/sysconfig/network-scripts/Ŀ¼Ï£¬½¨ÉèÒ»¸öÒÔ¡°ifcfg-eth0.10¡±ÃüÃûµÄÎļþ£¬²¢±à¼¸ÃÎļþ¾ÙÐÐVLAN½Ó¿ÚµÄÉèÖá£
vi /etc/sysconfig/network-scripts/ifcfg-eth0.10
µÇ¼ºó¸´ÖÆ
½«ÒÔÏÂÄÚÈÝÌí¼Óµ½¸ÃÎļþÖУº
DEVICE=eth0.10 BOOTPROTO=none ONBOOT=yes IPADDR=192.168.10.10 NETMASK=255.255.255.0
µÇ¼ºó¸´ÖÆ
ƾ֤ÏÖʵÐèÇóÐÞ¸ÄIPµØµãºÍ×ÓÍøÑÚÂë¡£
ÖØÆôÍøÂçЧÀÍ£ºÖØÆôÍøÂçЧÀÍÒÔʹÉèÖÃÉúЧ¡£
systemctl restart network
µÇ¼ºó¸´ÖÆ
ͨ¹ýÒÔÉÏ°ì·¨£¬ÎÒÃÇÀֳɵØÔÚCentOSЧÀÍÆ÷ÉϽ¨ÉèÁËÒ»¸öVLAN½Ó¿Ú£¬²¢¶ÔÆä¾ÙÐÐÁËÉèÖá£
Èý¡¢ÉèÖ÷À»ðǽ¹æÔò
ΪÁ˽øÒ»²½ÔöÇ¿ÍøÂçÇå¾²ÐÔ£¬ÎÒÃÇ¿ÉÒÔÔÚVLAN½Ó¿ÚÉÏÉèÖ÷À»ðǽ¹æÔò¡£ÏÂÃæÊÇÒ»¸ö¼òÆӵķÀ»ðǽ¹æÔòµÄʾÀý£¬ÓÃÓÚÏÞÖÆVLAN½Ó¿ÚÉϵÄÈëÕ¾ºÍ³öÕ¾Á÷Á¿¡£
iptables -I INPUT -i eth0.10 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT iptables -I INPUT -i eth0.10 -j DROP iptables -I OUTPUT -o eth0.10 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT iptables -I OUTPUT -o eth0.10 -j DROP
µÇ¼ºó¸´ÖÆ
ÒÔÉϹæÔò½«Ö»ÔÊÐíVLAN½Ó¿ÚÉϵÄС¢Òѽ¨ÉèºÍÏà¹ØµÄÅþÁ¬Í¨¹ý£¬²¢¾Ü¾øÒ»ÇÐÆäËûµÄÁ÷Á¿¡£
ËÄ¡¢»á¼û¿ØÖƺÍÍøÂç¸ôÀë
ͨ¹ýVLANµÄʹÓã¬ÎÒÃÇ¿ÉÒÔʵÏÖ»á¼û¿ØÖƺÍÍøÂç¸ôÀ롣ͨ¹ýÉèÖÃVLAN½Ó¿ÚµÄIPµØµãºÍ×ÓÍøÑÚÂ룬ÎÒÃÇ¿ÉÒÔ½«¶à¸öЧÀÍÆ÷»®·ÖΪ²î±ðµÄÂß¼×ÓÍø£¬²¢Í¨¹ý·ÓÉÆ÷»òÈý²ã½»Á÷»úÀ´¿ØÖƲî±ð×ÓÍøÖ®¼äµÄ»á¼ûȨÏÞ¡£
ÏÂÃæÊÇÒ»¸ö¼òÆÓµÄʾÀý£¬ÑÝʾÔõÑùʹÓÃVLANʵÏÖ»á¼û¿ØÖƺÍÍøÂç¸ôÀëµÄ¡£
ÉèÖÃVLAN½Ó¿Ú1£º
vconfig add eth0 10 ifconfig eth0.10 192.168.10.10 netmask 255.255.255.0
µÇ¼ºó¸´ÖÆ
ÉèÖÃVLAN½Ó¿Ú2£º
vconfig add eth0 20 ifconfig eth0.20 192.168.20.10 netmask 255.255.255.0
µÇ¼ºó¸´ÖÆ
ÉèÖ÷ÓÉÆ÷£º
ƾ֤ÐèÒªÉèÖ÷ÓÉÆ÷£¬½«²î±ðVLAN½Ó¿ÚµÄÁ÷Á¿»¥ÁªÆðÀ´£¬²¢ÉèÖûá¼û¿ØÖÆÁÐ±í£¨ACL£©À´¿ØÖƲî±ð×ÓÍøÖ®¼äµÄ»á¼ûȨÏÞ¡£
ͨ¹ýÒÔÉÏ°ì·¨£¬ÎÒÃÇÀֳɵؽ«Ð§ÀÍÆ÷»®·ÖΪÁ½¸öÂß¼×ÓÍø£¬²¢Í¨¹ýVLANºÍ·ÓÉÆ÷ʵÏÖÁË»á¼û¿ØÖƺÍÍøÂç¸ôÀë¡£
½áÂÛ£º
ʹÓÃÐéÄâ¾ÖÓòÍø£¨VLAN£©ÊÖÒÕ¿ÉÒÔÓÐÓÃÌá¸ßCentOSЧÀÍÆ÷µÄÍøÂçÇå¾²ÐÔ¡£Í¨¹ý½«ÎïÀíÍøÂç»®·ÖΪ¶à¸öÂß¼×ÓÍø£¬ÎÒÃÇ¿ÉÒÔʵÏÖ»á¼û¿ØÖƺÍÍøÂç¸ôÀ룬²¢Í¨¹ýÉèÖ÷À»ðǽ¹æÔò½øÒ»²½ÔöÇ¿ÍøÂçµÄÇå¾²ÐÔ¡£Í¨¹ý±¾ÎÄÌṩµÄÉèÖúʹúÂëʾÀý£¬Äú½«Äܹ»ÔÚCentOSЧÀÍÆ÷ÉÏÀÖ³ÉÉèÖúÍʹÓÃVLANÀ´±£»¤ÍøÂçÇå¾²¡£
²Î¿¼ÈªÔ´£º
VLANs explained – How to implement VLANs – Practical Networking.
VLAN – ArchWiki.
CentOS – VLAN with sub interfaces – Server Fault.
How to Configure VLANs in Linux with VLAN Command – Lifewire.
CentOS – How to configure VLAN Tagging for eth0 – Stack Overflow.
ÒÔÉϾÍÊÇÔõÑùʹÓÃÐéÄâ¾ÖÓòÍø£¨VLAN£©±£»¤CentOSЧÀÍÆ÷µÄÍøÂçÇå¾²µÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡