Vlan PDF
Vlan PDF
1
Created by Fery Junaedi
Baik mari kita mulai membangun jaringan VLAN pertama kita. Pada skenario kita kali ini, VLAN
yang kita bangun terdiri dari :
- 6 buah Cisco Switch 2950 dan 1 Buah Cisco Router
- 15 Host yang masing-masing Switch terkoneksi dengan 3 host
Berikut Data lengkap Alokasi IP address dari Network VLAN yang kita bangun
Switch Vlan Subnet
name Hostname Members IP addres Mask Gateway
Switch A A_2950 VLAN 1 172.16.10.3 255.255.255.0 172.16.10.1
Host_A VLAN 2 192.168.20.2 255.255.255.0 192.168.20.1
Host_B VLAN 4 192.168.40.3 255.255.255.0 192.168.40.1
Host_C VLAN 3 192.168.30.3 255.255.255.0 192.168.30.1
Switch B B_2950 VLAN 1 172.16.10.4 255.255.255.0 172.16.10.1
Host_D VLAN 2 192.168.20.4 255.255.255.0 192.168.20.1
Host_E VLAN 5 192.168.50.3 255.255.255.0 192.168.50.1
Host_F VLAN 3 192.168.30.4 255.255.255.0 192.168.30.1
Switch C C_2950 VLAN 1 172.16.10.5 255.255.255.0 172.16.10.1
Host_G VLAN 4 192.168.40.4 255.255.255.0 192.168.40.1
Host_H VLAN 2 192.168.20.5 255.255.255.0 192.168.20.1
Host_I VLAN 5 192.168.50.4 255.255.255.0 192.168.50.1
Switch D D_2950 VLAN 1 172.16.10.6 255.255.255.0 172.16.10.1
Host_J VLAN 3 192.168.30.5 255.255.255.0 192.168.30.1
Host_K VLAN 4 192.168.40.5 255.255.255.0 192.168.40.1
Host_L VLAN 2 192.168.20.6 255.255.255.0 192.168.20.1
Switch E E_2950 VLAN 1 172.16.10.7 255.255.255.0 172.16.10.1
Host_M VLAN 5 192.168.50.5 255.255.255.0 192.168.50.1
Host_N VLAN 3 192.168.30.6 255.255.255.0 192.168.30.1
Host_O VLAN 4 192.168.40.6 255.255.255.0 192.168.40.1
Main Switch Main_Switch VLAN 1 172.16.10.2 255.255.255.0 172.16.10.1
Sub
Router interface VLAN Gateway IP address Subnet mask
0 / 0.1 VLAN_Switch 172.16.10.1 255.255.255.0
0 / 0.2 VLAN 2 192.168.20.1 255.255.255.0
0 / 0.3 VLAN 3 192.168.30.1 255.255.255.0
0 / 0.4 VLAN 4 192.168.40.1 255.255.255.0
0 / 0.5 VLAN 5 192.168.50.1 255.255.255.0
2
Created by Fery Junaedi
3
Created by Fery Junaedi
Sebenarnya konfigurasi VLAN cukup sederhana anda hanya mengikuti konfigurasi seperti dibawah
ini. tapi sekali lagi pemahaman mendasar tentang konsep yang berhubungan dengan VLAN seperti
trunking, protokol ISL atau IEE 802.1Q (dot1q) cukup membantu dalam trobleshooting ke depan
Mari kita mulai konfigurasi Network VLAN kita :
Gambar Topologi VLAN yang akan dibangun
4
Created by Fery Junaedi
Router>enable
% Incomplete command.
Router#configure terminal
% Incomplete command.
Router(config)#hostname Route_VLAN
Route_VLAN(config)#enable secret fery
Route_VLAN(config)#line console 0
Route_VLAN(config-line)#password fery
Route_VLAN(config-line)#login
Route_VLAN(config-line)#exit
Route_VLAN(config)#line vty 0 4
Route_VLAN(config-line)#password fery
Route_VLAN(config-line)#login
Route_VLAN(config-line)#exit
Route_VLAN(config)#service password-encryption
Route_VLAN(config)#interface fastethernet 0/0
Route_VLAN(config-if)#no ip address
Route_VLAN(config-if)#no shutdown
03:37:51 %LINK-3-UPDOWN: Interface Fastethernet0/0, changed state to up
03:37:51 %LINEPROTO-5-UPDOWN: Line protocol on Interface Fastethernet0/0, changed state
to up
Route_VLAN(config-if)#exit
Route_VLAN(config)#interface fastethernet 0/0.1
5
Created by Fery Junaedi
Route_VLAN(config-subif)#encapsulation dot1Q 1
Route_VLAN(config-subif)#ip address 172.16.10.1 255.255.255.0
Route_VLAN(config-subif)#exit
Route_VLAN(config)#interface fastethernet 0/0.2
Route_VLAN(config-subif)#encapsulation dot1Q 2
Route_VLAN(config-subif)#ip address 192.168.20.1 255.255.255.0
Route_VLAN(config-subif)#exit
Route_VLAN(config)#interface fastethernet 0/0.3
Route_VLAN(config-subif)#encapsulation dot1Q 3
Route_VLAN(config-subif)#ip address 192.168.30.1 255.255.255.0
Route_VLAN(config-subif)#exit
Route_VLAN(config)#interface fastethernet 0/0.4
Route_VLAN(config-subif)#encapsulation dot1Q 4
Route_VLAN(config-subif)#ip address 192.168.40.1 255.255.255.0
Route_VLAN(config-subif)#exit
Route_VLAN(config)#interface fastethernet 0/0.5
Route_VLAN(config-subif)#encapsulation dot1Q 5
Route_VLAN(config-subif)#ip address 192.168.50.1 255.255.255.0
Route_VLAN(config-subif)# --->CTRL+Z
Route_VLAN#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Route_VLAN#
6
Created by Fery Junaedi
switch>enable
% Incomplete command.
switch#configure terminal
% Incomplete command.
switch(config)#hostname 2950-MainSwitch
2950-MainSwitch(config)#enable secret fery
2950-MainSwitch(config)#line console 0
2950-MainSwitch(config-line)#password fery
2950-MainSwitch(config-line)#login
2950-MainSwitch(config-line)#exit
2950-MainSwitch(config)#line vty 0 15
2950-MainSwitch(config-line)#password fery
2950-MainSwitch(config-line)#login
2950-MainSwitch(config-line)#exit
2950-MainSwitch(config)#service password-encryption
2950-MainSwitch(config)#interface fastethernet 0/6
2950-MainSwitch(config-if)#switchport mode trunk
2950-MainSwitch(config-if)#description Trunking to Router-VLAN
2950-MainSwitch(config-if)#exit
2950-MainSwitch(config)#interface fastethernet 0/1
2950-MainSwitch(config-if)#switchport mode trunk
2950-MainSwitch(config-if)#description Trunking to A_2950
2950-MainSwitch(config-if)#exit
2950-MainSwitch(config)#interface fastethernet 0/2
7
Created by Fery Junaedi
8
Created by Fery Junaedi
VLAN 3 added:
Name: Finance
2950-MainSwitch(VLAN)#VLAN 4 name Support
VLAN 4 added:
Name: Support
2950-MainSwitch(VLAN)#VLAN 5 name Operation
VLAN 5 added:
Name: Operation
2950-MainSwitch(VLAN)#apply
2950-MainSwitch(VLAN)#exit
APPLY completed.
Exiting....
2950-MainSwitch#show VLAN
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4
Fa0/5, Fa0/6, Fa0/7, Fa0/8
Fa0/9, Fa0/10, Fa0/11, Fa0/12
2 Marketing active
3 Finance active
4 Support active
5 Operation active
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
2950-MainSwitch#
9
Created by Fery Junaedi
10
Created by Fery Junaedi
11
Created by Fery Junaedi
12
Created by Fery Junaedi
13
Created by Fery Junaedi
14
Created by Fery Junaedi
C_2950(config-if)#exit
C_2950(config)#interface fastethernet 0/7
C_2950(config-if)#switchport access VLAN 5
C_2950(config)#vtp mode client
Aetting device to VTP CLIENT mode.
C_2950(config)#vtp domain jetcoms
Changing VTP domain name from NULL to jetcoms
C_2950(config)#apply
C_2950(config)#exit
C_2950#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
C_2950#
15
Created by Fery Junaedi
switch(config)#hostname D_2950
D_2950(config)#enable secret fery
D_2950(config)#line console 0
D_2950(config-line)#password fery
D_2950(config-line)#exit
D_2950(config)#line vty 0 15
D_2950(config-line)#password fery
D_2950(config-line)#exit
D_2950(config)#service password-encryption
D_2950(config)#interface VLAN 1
D_2950(config-if)#ip address 172.16.10.6 255.255.255.0
D_2950(config-if)#no shutdown
D_2950(config-if)#exit
D_2950(config)#ip default-gateway 172.16.10.1
D_2950(config)#interface fastethernet 0/1
D_2950(config-if)#description Trunking to MainSwitch_2950
D_2950(config-if)#exit
D_2950(config)#interface fastethernet 0/5
D_2950(config-if)#switchport access VLAN 3
D_2950(config-if)#exit
16
Created by Fery Junaedi
17
Created by Fery Junaedi
switch(config)#hostname E_2950
E_2950(config)#enable secret fery
E_2950(config)#line console 0
E_2950(config-line)#password fery
E_2950(config-line)#exit
E_2950(config)#line vty 0 15
E_2950(config-line)#password fery
E_2950(config-line)#exit
E_2950(config)#service password-encryption
E_2950(config)#interface VLAN 1
E_2950(config-if)#ip address 172.16.10.7 255.255.255.0
E_2950(config-if)#no shutdown
E_2950(config-if)#exit
E_2950(config)#ip default-gateway 172.16.10.1
E_2950(config)#interface fastethernet 0/1
E_2950(config-if)#description Trunking to MainSwitch_2950
E_2950(config-if)#exit
E_2950(config)#interface fastethernet 0/5
E_2950(config-if)#switchport access VLAN 5
E_2950(config-if)#exit
E_2950(config)#interface fastethernet 0/6
18
Created by Fery Junaedi
19
Created by Fery Junaedi
20
Created by Fery Junaedi
!
!
spanning-tree extend system-id
!
!
interface FastEthernet0/1
description "Trunking to MainSwitch"
switchport mode trunk
!
interface FastEthernet0/2
switchport mode access
!
interface FastEthernet0/3
switchport mode access
!
interface FastEthernet0/4
switchport mode access
!
interface FastEthernet0/5
switchport access VLAN 2
switchport mode access
!
interface FastEthernet0/6
switchport access VLAN 4
switchport mode access
!
interface FastEthernet0/7
switchport access VLAN 3
switchport mode access
!
interface FastEthernet0/8
21
Created by Fery Junaedi
!
interface FastEthernet0/12
switchport mode access
!
interface VLAN1
ip address 172.16.10.3 255.255.255.0
no ip route-cache
!
ip default-gateway 172.16.10.1
ip http server
!
!
line con 0
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
line vty 0 15
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
!
end
22
Created by Fery Junaedi
A_2950#show VLAN
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
2 enet 100002 1500 - - - - - 0 0
3 enet 100003 1500 - - - - - 0 0
4 enet 100004 1500 - - - - - 0 0
5 enet 100005 1500 - - - - - 0 0
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
A_2950#
23
Created by Fery Junaedi
B_2950#ping 172.16.10.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.10.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/4 ms
B_2950#show running-config
Building configuration...
Current configuration : 866 bytes
!
version 12.1
no service single-slot-reload-enable
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname B_2950
!
enable secret 5 $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
24
Created by Fery Junaedi
!
ip subnet-zero
!
!
spanning-tree extend system-id
!
!
interface FastEthernet0/1
description "Trunking to MainSwitch"
switchport mode trunk
!
interface FastEthernet0/2
switchport mode access
!
interface FastEthernet0/3
switchport mode access
!
interface FastEthernet0/4
switchport mode access
!
interface FastEthernet0/5
switchport access VLAN 2
switchport mode access
!
interface FastEthernet0/6
switchport access VLAN 5
switchport mode access
!
interface FastEthernet0/7
switchport access VLAN 3
switchport mode access
25
Created by Fery Junaedi
!
interface FastEthernet0/8
switchport mode access
!
interface FastEthernet0/9
switchport mode access
!
interface FastEthernet0/10
switchport mode access
!
interface FastEthernet0/11
switchport mode access
!
interface FastEthernet0/12
switchport mode access
!
interface VLAN1
ip address 172.16.10.4 255.255.255.0
no ip route-cache
!
ip default-gateway 172.16.10.1
ip http server
!
!
line con 0
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
line vty 0 15
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
!
26
Created by Fery Junaedi
end
B_2950#show VLAN
4 Support active
5 Operation active Fa0/6
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
2 enet 100002 1500 - - - - - 0 0
3 enet 100003 1500 - - - - - 0 0
4 enet 100004 1500 - - - - - 0 0
5 enet 100005 1500 - - - - - 0 0
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
B_2950#
27
Created by Fery Junaedi
28
Created by Fery Junaedi
ip subnet-zero
!
!
spanning-tree extend system-id
!
!
interface FastEthernet0/1
description "Trunking to MainSwitch"
switchport mode trunk
!
interface FastEthernet0/2
switchport mode access
!
interface FastEthernet0/3
switchport mode access
!
interface FastEthernet0/4
switchport mode access
!
interface FastEthernet0/5
switchport access VLAN 4
switchport mode access
!
interface FastEthernet0/6
switchport access VLAN 2
switchport mode access
!
interface FastEthernet0/7
switchport access VLAN 5
switchport mode access
!
29
Created by Fery Junaedi
interface FastEthernet0/8
switchport mode access
!
interface FastEthernet0/9
switchport mode access
!
interface FastEthernet0/10
switchport mode access
!
interface FastEthernet0/11
switchport mode access
!
interface FastEthernet0/12
switchport mode access
!
interface VLAN1
ip address 172.16.10.5 255.255.255.0
no ip route-cache
!
ip default-gateway 172.16.10.1
ip http server
!
!
line con 0
password fery
login
line vty 0 15
password fery
login
!
30
Created by Fery Junaedi
end
C_2950#show VLAN
31
Created by Fery Junaedi
32
Created by Fery Junaedi
ip subnet-zero
!
!
spanning-tree extend system-id
!
!
interface FastEthernet0/1
description "Trunking to MainSwitch"
switchport mode trunk
!
interface FastEthernet0/2
switchport mode access
!
interface FastEthernet0/3
switchport mode access
!
interface FastEthernet0/4
switchport mode access
!
interface FastEthernet0/5
switchport access VLAN 3
switchport mode access
!
interface FastEthernet0/6
switchport access VLAN 4
switchport mode access
!
interface FastEthernet0/7
switchport access VLAN 2
switchport mode access
!
33
Created by Fery Junaedi
interface FastEthernet0/8
switchport mode access
!
interface FastEthernet0/9
switchport mode access
!
interface FastEthernet0/10
switchport mode access
!
interface FastEthernet0/11
switchport mode access
!
interface FastEthernet0/12
switchport mode access
!
interface VLAN1
ip address 172.16.10.6 255.255.255.0
no ip route-cache
!
ip default-gateway 172.16.10.1
ip http server
!
!
line con 0
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
line vty 0 15
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
!
end
34
Created by Fery Junaedi
D_2950#show VLAN
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4
Fa0/8, Fa0/9, Fa0/10, Fa0/11
Fa0/12
2 Marketing active Fa0/7
3 Finance active Fa0/5
4 Support active Fa0/6
5 Operation active
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
2 enet 100002 1500 - - - - - 0 0
3 enet 100003 1500 - - - - - 0 0
4 enet 100004 1500 - - - - - 0 0
5 enet 100005 1500 - - - - - 0 0
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
D_2950#
35
Created by Fery Junaedi
36
Created by Fery Junaedi
!
spanning-tree extend system-id
!
!
interface FastEthernet0/1
description "Trunking to MainSwitch"
switchport mode trunk
!
interface FastEthernet0/2
switchport mode access
!
interface FastEthernet0/3
switchport mode access
!
interface FastEthernet0/4
switchport mode access
!
interface FastEthernet0/5
switchport access VLAN 5
switchport mode access
!
interface FastEthernet0/6
switchport access VLAN 3
switchport mode access
!
interface FastEthernet0/7
switchport access VLAN 4
switchport mode access
!
interface FastEthernet0/8
switchport mode access
37
Created by Fery Junaedi
!
interface FastEthernet0/9
switchport mode access
!
interface FastEthernet0/10
switchport mode access
!
interface FastEthernet0/11
switchport mode access
!
interface FastEthernet0/12
switchport mode access
!
interface VLAN1
ip address 172.16.10.7 255.255.255.0
no ip route-cache
!
ip default-gateway 172.16.10.1
ip http server
!
!
line con 0
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
line vty 0 15
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
!
end
38
Created by Fery Junaedi
E_2950#show VLAN
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4
Fa0/8, Fa0/9, Fa0/10, Fa0/11
Fa0/12
2 Marketing active
E_2950#
39
Created by Fery Junaedi
40
Created by Fery Junaedi
ip subnet-zero
!
!
spanning-tree extend system-id
!
!
interface FastEthernet0/1
description "Trunking to A_2950"
switchport mode trunk
!
interface FastEthernet0/2
description "Trunking to B_2950"
switchport mode trunk
!
interface FastEthernet0/3
description "Trunking to C_2950"
switchport mode trunk
!
interface FastEthernet0/4
switchport mode access
!
interface FastEthernet0/5
switchport mode access
!
interface FastEthernet0/6
description "Trunking to Router"
switchport mode trunk
!
interface FastEthernet0/7
switchport mode access
!
41
Created by Fery Junaedi
interface FastEthernet0/8
switchport mode access
!
interface FastEthernet0/9
switchport mode access
!
interface FastEthernet0/10
switchport mode access
!
interface FastEthernet0/11
description "Trunking to D_2950"
switchport mode trunk
!
interface FastEthernet0/12
description "Trunking to E_2950"
switchport mode trunk
!
interface VLAN1
ip address 172.16.10.2 255.255.255.0
no ip route-cache
!
ip default-gateway 172.16.10.1
ip http server
!
!
line con 0
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
line vty 0 15
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
42
Created by Fery Junaedi
!
end
2950-MainSwitch#show VLAN
43
Created by Fery Junaedi
44
Created by Fery Junaedi
no ip directed-broadcast
!
interface FastEthernet0/0.1
encapsulation dot1Q 1
ip address 172.16.10.1 255.255.255.0
!
interface FastEthernet0/0.2
encapsulation dot1Q 2
ip address 192.168.20.1 255.255.255.0
!
interface FastEthernet0/0.3
encapsulation dot1Q 3
ip address 192.168.30.1 255.255.255.0
!
interface FastEthernet0/0.4
encapsulation dot1Q 4
ip address 192.168.40.1 255.255.255.0
!
interface FastEthernet0/0.5
encapsulation dot1Q 5
ip address 192.168.50.1 255.255.255.0
!
interface Serial0/0
no ip address
no ip directed-broadcast
shutdown
!
interface FastEthernet0/1
no ip address
no ip directed-broadcast
shutdown
45
Created by Fery Junaedi
!
interface Serial0/1
no ip address
no ip directed-broadcast
shutdown
!
!
ip classless
no ip http server
!
!
!
line con 0
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
line aux 0
line vty 0 4
password $1$u76B$IOFVJ7VxfVXYVpGDrFTcI0
login
!
end
Route_VLAN#
46
Created by Fery Junaedi
Untuk verifikasi selanjutnya lakukan hal yang sama dengan di atas. Coba cek ping ke setiap host
pada network yang berbeda :
- Network 192.168.20.0
- Network 192.168.30.0
- Network 192.168.40.0
- Network 192.168.50.0
Selamat anda baru saja menjalani langkah demi langkah bagaimana melakukan setting pada
Network VLAN. hanya itu saja. Mudah Bukan ???
Terima Kasih
Jakarta, 18-04-2007
Fery Junaedi
47