Собственно имеем сабж 3750
Cisco IOS Software, C3750 Software (C3750-ADVIPSERVICESK9-M), Version 12.2(44)SE, RELEASE SOFTWARE (fc1)
System image file is "flash:/c3750-advipservicesk9-mz.122-44.SE.bin"
пытаюсь сделать на нем изоляцию портов по след схеме:
ISP -> порт1 Каталиста -> порт2 Каталиста - > ротутер -> порт 7 Каталиста -> остальные порты для локальных клиентов
Порты с 1 по 3 хочу использовать как 1 - вход от провайдера, 2 - выход на роутер, 3 - зеркалирование трафика для анализа
также есть резервный провайдер - под него порты 4-6 использовать в дальнейшем, по аналогичной схеме.
Настаивал по циско.ком
http://www.cisco.com/en/US/docs/switches/metro/catalyst3750m...
вот мой конфиг: version 12.2
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime
service timestamps log datetime localtime
no service password-encryption
service sequence-numbers
no service dhcp
!
hostname Catalist3750
!
boot-start-marker
boot-end-marker
!
logging buffered 262144
logging rate-limit 10 except warnings
enable secret 5 *********
enable password *********
!
username admin password 0 *********
aaa new-model
!
!
aaa authentication login default local
aaa authentication login local_authen local
aaa authentication ppp default local
aaa authorization exec local_author local
aaa authorization network default if-authenticated
!
!
aaa session-id common
clock timezone UFA 5
switch 1 provision ws-c3750g-24t
system mtu routing 1500
vtp mode transparent
ip subnet-zero
ip icmp rate-limit unreachable 1000
ip icmp rate-limit unreachable DF 1000
ip domain-list steel-prom.ru
ip domain-list google.ru
ip domain-name Catalyst
ip name-server 192.168.1.1
!
spanning-tree mode pvst
spanning-tree portfast bpdufilter default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
vlan 20
private-vlan primary
private-vlan association 501
!
vlan 100
name local
private-vlan isolated
!
vlan 501
name ISP_1
private-vlan isolated
!
ip tcp selective-ack
ip tcp timestamp
!
interface GigabitEthernet1/0/1
description ### IN ISP_1 ###
switchport private-vlan host-association 20 501
switchport mode private-vlan host
!
interface GigabitEthernet1/0/2
description ### OUT ISP_1 ###
switchport private-vlan host-association 20 501
switchport mode private-vlan host
!
interface GigabitEthernet1/0/3
description ### Zerkalo for ISP_1 ###
switchport private-vlan host-association 20 501
switchport mode private-vlan host
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
!
interface GigabitEthernet1/0/10
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
!
interface GigabitEthernet1/0/14
!
interface GigabitEthernet1/0/15
!
interface GigabitEthernet1/0/16
!
interface GigabitEthernet1/0/17
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
!
interface GigabitEthernet1/0/24
switchport mode private-vlan host
!
interface Vlan1
description ### management interface ###
ip address 192.168.1.3 255.255.255.0
no ip redirects
no ip proxy-arp
no ip route-cache
no ip mroute-cache
!
interface Vlan20
no ip address
private-vlan mapping 501
!
ip default-gateway 192.168.1.1
ip classless
no ip http server
ip http secure-server
!
!
!
control-plane
!
!
line con 0
exec-timeout 60 0
login authentication local_authen
transport output telnet
line vty 0 4
exec-timeout 60 0
privilege level 15
password 123456
authorization exec local_author
login authentication local_authen
transport input telnet
line vty 5 15
privilege level 15
password 123456
authorization exec local_author
login authentication local_authen
transport input ssh
!
ntp clock-period 36029056
ntp max-associations 1
ntp server 192.168.1.1
ntp server 192.168.1.1 version 2 source Vlan1
end
Сейчас получилось изолировать порты 1, 2, 3, от всех остальных, но трафик между ними не гуляет, т.е. они сами от себя тоже изолированные. хотя:
В чем ошибка, не могу понять
#show vlan private-vlan Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
20 501 isolated Gi1/0/1, Gi1/0/2, Gi1/0/3
100 isolated