D-Link 3-
I – IP-
•IP-
•
•
•RIP
•OSPF
•: Internet
NAT
•:
•: DHCP/BootP
•:
•VRRP
L3
IP- 1/3
1. FDB:
VLAN, MAC-
. 2.
2.ARP-:
IP MAC-.
.
3. IPFDB:
IP-
.
IP- ( L3).
4.:
.
IP-
.
L3
IP- 2/3
1234
DGS-3324SR
.254 |
.254 |
.254 |
.254 |
PC 1 |
|
PC3 |
192.168.4.1/24 |
PC2 |
|
||
192.168.1.1/24 |
|
||
192.168.1.254 |
192.168.2.1/24 |
192.168.3.1/24 |
192.168.4.254 |
ASIC |
192.168.2.254 |
192.168.3.254 |
|
|
|
3/3 “PC1
L3
IP-L3
”
:
|
ARP- |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
- |
|
ARP |
PC1
1.
.
.
ICMP
PC1
2.
|
PC1: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
3 |
3.
:
- ARP
FDB
PC1
- MAC
|
• |
|
- |
|
ARP |
|
|
|
PC1 |
|
IP/MAC |
|
|
|
|
|
|
|
• |
PC1
- ARP
•
PC1)
- ICMP
( :
ipfdb
- IP
L3
! •
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
L3 |
|
|
|
|
" |
• |
ACL
#
L3
•
|
|
|
|
|
|
|
|
|
|
|
|
|
ipfdb, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
$ |
|
|
4. |
|
|
|
|
|
& |
|
% |
|
|
L3
:
•
!
|
ipfdb. |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CPU |
|
|
|
|
|
|
.
|
|
|
|
|
|
|
|
|
|
|
|
|
# |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
(
&
('
L3
:
•
.
#
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
||
|
|
|
& |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
. |
|
. |
||
|
ipfdb, |
|
|
|||
|
|
|
$ |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CPU |
|
|
|
|
CPU |
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
L3 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
$ |
• |
|
|
|
|
Hua-Du, GuanDong,
:
:
Hua-Du, GuanDong, .
:
: 1* DES-6500,
: 70+ DES-3526. : 1500+.
DES-6500
. Ping IP will have round 20% packet lost. The firewall can capture a lot of destination IP scan packets with destination TCP port 139 and 445.
Hua-Du, GuanDong,
:
DES-6500 (1.3x firmware) xStack (R4 firmware)
L3 ,
,
“IP-scan”,
.
IP- 1/3
1 |
2 |
3 |
4 |
|
|
|
DGS-3324SR
.254 |
.254 |
.254 |
.254 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.1.x/24 |
|
|
|
|
|
|
|
|
|
|
192.168.2.x/24 |
|
|
|
|
|
192.168.3.x/24 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.4.x/24 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
: |
|
|
|
|
|
|
|
|
|
|
|
: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||
192.168.1.254 |
|
|
|
192.168.2.254 |
|
|
192.168.3.254 |
|
|
|
|
|
|
|
|
|
|
: |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.4.254 |
:
IP- can routed - L3.
:
L3 4
.
.
IP- 2/3
DGS-3324SR
1. VLAN default VLAN-. config vlan default delete 1:1-1:24
2. VLAN, IP-
VLAN.
create vlan v101 tag 101
config vlan v101 add untagged 1:1-1:6
create ipif net1 192.168.1.254/24 v101 state enabled create vlan v102 tag 102
config vlan v102 add untagged 1:7-1:12
create ipif net2 192.168.2.254/24 v102 state enabled create vlan v103 tag 103
config vlan v103 add untagged 1:13-1:18
create ipif net3 192.168.3.254/24 v103 state enabled create vlan v104 tag 104
config vlan v104 add untagged 1:19-1:24
create ipif net4 192.168.4.254/24 v104 state enabled Save
3. , IP-. show vlan
show ipif
PC :
1. IP- IP-.
2. = IP- DGS-3324SR.
IP- 3/3
:
1.PC 1 (192.168.1.254), DGS-3324SR (192.168.2.254, 192.168.3.254 ..) PC .
2.PC 2 (192.168.2.254), DGS-3324SR (192.168.1.254, 192.168.3.254 ..) PC .
3. PC 3 4.