Got it

Understanding of VLAN - Example for Assigning VLANs based on MAC Addresses

Latest reply: Jun 20, 2021 15:06:04 191 28 21 0 4

OBJECTIVE


The purpose of this post is to present an introduction to Example for Assigning VLANs based on MAC Addresses.


Networking Requirements


On a company intranet, the network administrator adds the PCs in a department to the same VLAN. To improve information security, only employees in this department are allowed to access the intranet.


As shown in Figure 1, only PC1, PC2, and PC3 are allowed to access the intranet using SwitchA and SwitchB.You can assign VLANs based on MAC addresses and associate MAC addresses of PCs with the specified VLAN.


01

Figure 1 - Networking diagram for assigning VLANs based on MAC addresses


Configuration Roadmap


The configuration roadmap is as follows:


1. Create VLANs.


2. Add Ethernet interfaces to VLANs so that packets of the VLANs can pass through the interfaces.


3. Associate MAC addresses of PC1, PC2, and PC3 with the specified VLAN so that the VLAN of the packet can be determined based on the source MAC address.


Procedure


1. Configure the Switch.


# Create VLANs.

<Huawei> system-view
[Huawei]
vlan batch 10 100 


# Set the PVID of interfaces and add interfaces to the VLANs.

[HUAWEI] interface gigabitethernet 0/0/1
[HUAWEI-GigabitEthernet0/0/1] port hybrid pvid vlan 100
[HUAWEI-GigabitEthernet0/0/1] port hybrid untagged vlan 10
[HUAWEI-GigabitEthernet0/0/1] quit
[HUAWEI] interface gigabitethernet 0/0/2
[HUAWEI-GigabitEthernet0/0/2] port hybrid tagged vlan 10
[HUAWEI-GigabitEthernet0/0/2] quit


# Associate MAC addresses of PC1, PC2, and PC3 with VLAN 10.

[HUAWEI] vlan 10
[HUAWEI-Vlan10] mac-vlan mac-address 22-22-22
[HUAWEI-Vlan10] mac-vlan mac-address 33-33-33
[HUAWEI-Vlan10] mac-vlan mac-address 44-44-44
[HUAWEI-Vlan10] quit


# Enable MAC address-based VLAN assignment on GE0/0/1.

[HUAWEI] interface gigabitethernet 0/0/1
[HUAWEI-GigabitEthernet0/0/1] mac-vlan enable
[HUAWEI-GigabitEthernet0/0/1] quit


2. Verify the configuration.


PC1, PC2, and PC3 can access the intranet, whereas other PCs cannot access the intranet.


Configuration Files


  • Configuration file of the Switch

#
sysname HUAWEI
#
vlan batch 10 100
#
vlan 10
mac-vlan mac-address 0022-0022-0022 priority 0
mac-vlan mac-address 0033-0033-0033 priority 0
mac-vlan mac-address 0044-0044-0044 priority 0
#
interface GigabitEthernet0/0/1
port hybrid pvid vlan 100
port hybrid untagged vlan 10
mac-vlan enable
#
interface GigabitEthernet0/0/2
port hybrid tagged vlan 10
#
return        



--- End




  • x
  • convention:

victorrocha
Created Jun 18, 2021 13:53:26

Thanks!
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jun 18, 2021 19:01:51 (0) (0)
 
carlosalcosta
Created Jun 18, 2021 14:16:54

Thanks, that is awesome.
View more
  • x
  • convention:

andersoncf1
andersoncf1 Created Jun 18, 2021 19:02:01 (0) (0)
 
wissal
MVE Created Jun 18, 2021 14:33:02

Excellent
View more
  • x
  • convention:

Faridrami
Created Jun 18, 2021 16:08:50

Excellent. thank u dear friend
View more
  • x
  • convention:

Irshadhussain
Irshadhussain Created Jun 19, 2021 17:09:58 (1) (0)
 
Faridrami
Faridrami Reply Irshadhussain  Created Jun 21, 2021 16:51:40 (0) (0)
 
Faridrami
Faridrami Reply Irshadhussain  Created Jun 22, 2021 16:05:06 (0) (0)
 
LilStylz237
Created Jun 18, 2021 16:12:38

Excellent Friend. Go ahead
View more
  • x
  • convention:

Irshadhussain
Irshadhussain Created Jun 19, 2021 17:10:04 (0) (0)
 
Herediano
Created Jun 18, 2021 17:21:09

Excellent
View more
  • x
  • convention:

BAZ
BAZ Created Jun 18, 2021 20:18:29 (0) (0)
Indeed  
Vlada85
MVE Author Created Jun 18, 2021 17:27:12

Good. thank you
View more
  • x
  • convention:

clecio_pinange
Created Jun 18, 2021 17:52:35

Excellent my friend!
View more
  • x
  • convention:

lucian2003
MVE Author Created Jun 19, 2021 00:59:03

Good my friends
View more
  • x
  • convention:

user_3015189
user_3015189 Created Jun 19, 2021 15:52:47 (0) (0)
:-)  
123
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.