VLAN mit Linux und Cisco Nexus: Unterschied zwischen den Versionen
Zur Navigation springen
Zur Suche springen
| (9 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt) | |||
| Zeile 2: | Zeile 2: | ||
* Der Cisco-Port '''Ethernet1/1''' ist als '''802.1Q-Trunk''' konfiguriert. | * Der Cisco-Port '''Ethernet1/1''' ist als '''802.1Q-Trunk''' konfiguriert. | ||
* Der Linux-Rechner verwendet das Interface '''enp0s8'''. | * Der Linux-Rechner verwendet das Interface '''enp0s8'''. | ||
| − | * | + | * Drei VLANs werden getaggt übertragen: |
| − | * Ethernet1/2 und Ethernet1/3 → | + | * Ethernet1/2 und Ethernet1/3 → LAN |
| − | * Ethernet1/4 und Ethernet1/5 → | + | * Ethernet1/4 und Ethernet1/5 → SERVER |
| − | ** | + | * Ethernet1/6 und Ethernet1/7 → MGMT |
| + | ** VLAN 24 → '''172.18.2xx.1/24''' | ||
** VLAN 22 → '''172.17.2xx.1/24''' | ** VLAN 22 → '''172.17.2xx.1/24''' | ||
** VLAN 23 → '''172.16.2xx.1/24''' | ** VLAN 23 → '''172.16.2xx.1/24''' | ||
| Zeile 22: | Zeile 23: | ||
=== /etc/network/interfaces === | === /etc/network/interfaces === | ||
<pre> | <pre> | ||
| − | auto | + | #OHNE IP |
| − | iface | + | auto enp0s8 |
| + | iface enp0s8 inet manual | ||
| − | + | #LAN | |
| − | |||
| − | |||
| − | |||
| − | |||
auto enp0s8.22 | auto enp0s8.22 | ||
| − | iface enp0s8.22 inet static | + | iface enp0s8.22 inet static |
| − | + | address 172.17.2xx.1/24 | |
| − | + | vlan-raw-device enp0s8 | |
| − | |||
| + | #SERVER | ||
auto enp0s8.23 | auto enp0s8.23 | ||
| − | iface enp0s8.23 inet static | + | iface enp0s8.23 inet static |
| − | + | address 172.16.2xx.1/24 | |
| − | + | vlan-raw-device enp0s8 | |
| − | + | ||
| + | #MGMT | ||
| + | auto enp0s8.24 | ||
| + | iface enp0s8.24 inet static | ||
| + | address 172.18.2xx.1/24 | ||
| + | vlan-raw-device enp0s8 | ||
| + | root@fw:~# | ||
| + | |||
</pre> | </pre> | ||
| Zeile 58: | Zeile 63: | ||
vlan 23 | vlan 23 | ||
name SERVER | name SERVER | ||
| + | vlan 24 | ||
| + | name MGMT | ||
end | end | ||
copy running-config startup-config | copy running-config startup-config | ||
| Zeile 67: | Zeile 74: | ||
description Trunk zu Linux-Host | description Trunk zu Linux-Host | ||
switchport mode trunk | switchport mode trunk | ||
| − | + | switchport trunk allowed vlan 22,23,24 | |
| − | switchport trunk allowed vlan 22,23 | ||
spanning-tree port type edge trunk | spanning-tree port type edge trunk | ||
</pre> | </pre> | ||
| Zeile 90: | Zeile 96: | ||
spanning-tree port type edge | spanning-tree port type edge | ||
</pre> | </pre> | ||
| + | |||
| + | ;Ethernet1/6 und Ethernet1/7 → VLAN 24 (MGMT) | ||
| + | <pre> | ||
| + | interface Ethernet1/6-7 | ||
| + | description VLAN 24 MGMT | ||
| + | switchport mode access | ||
| + | switchport access vlan 24 | ||
| + | spanning-tree port type edge | ||
| + | </pre> | ||
| + | |||
end | end | ||
copy running-conf startup-conf | copy running-conf startup-conf | ||
| Zeile 95: | Zeile 111: | ||
==IP im MGMT NETZ Vergeben== | ==IP im MGMT NETZ Vergeben== | ||
configure terminal | configure terminal | ||
| − | interface vlan | + | interface vlan 24 |
description MGMT-IP | description MGMT-IP | ||
ip address 172.18.213.11/24 | ip address 172.18.213.11/24 | ||
| Zeile 103: | Zeile 119: | ||
==Gateway und Nameserver einstellen== | ==Gateway und Nameserver einstellen== | ||
configure terminal | configure terminal | ||
| − | ip route 0.0.0.0/0 172.18.2xx.1 | + | ip route 0.0.0.0/0 172.18.2xx.1 |
ip name-server 10.88.2xx.21 | ip name-server 10.88.2xx.21 | ||
end | end | ||
Aktuelle Version vom 31. Juli 2025, 09:13 Uhr
Zielbeschreibung
- Der Cisco-Port Ethernet1/1 ist als 802.1Q-Trunk konfiguriert.
- Der Linux-Rechner verwendet das Interface enp0s8.
- Drei VLANs werden getaggt übertragen:
- Ethernet1/2 und Ethernet1/3 → LAN
- Ethernet1/4 und Ethernet1/5 → SERVER
- Ethernet1/6 und Ethernet1/7 → MGMT
- VLAN 24 → 172.18.2xx.1/24
- VLAN 22 → 172.17.2xx.1/24
- VLAN 23 → 172.16.2xx.1/24
Plan
Voraussetzungen auf Debian/Linux
- VLAN-Paket installieren
- apt install vlan
- VLAN-Modul laden
- sudo modprobe 8021q
- Modul beim Booten automatisch laden
- echo 8021q | sudo tee -a /etc/modules
/etc/network/interfaces
#OHNE IP auto enp0s8 iface enp0s8 inet manual #LAN auto enp0s8.22 iface enp0s8.22 inet static address 172.17.2xx.1/24 vlan-raw-device enp0s8 #SERVER auto enp0s8.23 iface enp0s8.23 inet static address 172.16.2xx.1/24 vlan-raw-device enp0s8 #MGMT auto enp0s8.24 iface enp0s8.24 inet static address 172.18.2xx.1/24 vlan-raw-device enp0s8 root@fw:~#
Zum Cisco
- ssh localhost -p 3022
oder im Notfall
- nc localhost 2023
- Logindaten
- user: admin
- pass: admin
VLAN anlegen
configure terminal vlan 22 name LAN vlan 23 name SERVER vlan 24 name MGMT end copy running-config startup-config
Cisco-Konfiguration für Ethernet1/1
configure terminal
interface Ethernet1/1 description Trunk zu Linux-Host switchport mode trunk switchport trunk allowed vlan 22,23,24 spanning-tree port type edge trunk
Cisco-Konfiguration für Access-Ports
- Ethernet1/2 und Ethernet1/3 → VLAN 22 (LAN)
interface Ethernet1/2-3 description VLAN 22 LAN switchport mode access switchport access vlan 22 spanning-tree port type edge
- Ethernet1/4 und Ethernet1/5 → VLAN 23 (SERVER)
interface Ethernet1/4-5 description VLAN 23 SERVER switchport mode access switchport access vlan 23 spanning-tree port type edge
- Ethernet1/6 und Ethernet1/7 → VLAN 24 (MGMT)
interface Ethernet1/6-7 description VLAN 24 MGMT switchport mode access switchport access vlan 24 spanning-tree port type edge
end copy running-conf startup-conf
IP im MGMT NETZ Vergeben
configure terminal interface vlan 24 description MGMT-IP ip address 172.18.213.11/24 no shutdown end
Gateway und Nameserver einstellen
configure terminal ip route 0.0.0.0/0 172.18.2xx.1 ip name-server 10.88.2xx.21 end copy running-configure startup-configure
Checken
show running-config
Aktivierung der Konfiguration
Nach den obigen Anpassungen auf dem Linux-System die Netzwerkschnittstellen neu starten:
- sudo systemctl restart networking
- ip addr show
- Sicherstellen, dass die IP-Adressen korrekt zugewiesen wurden und die Kommunikation innerhalb der VLANs funktioniert.
TODO Anpassungen
- Firewall
- DHCP Server
- Sonst nochwas?
