(1)基本概念
①、二层交换机(Layer 2 Switch)指的是只具备二层交换功能的交换机
②、三层交换机(Layer 3 Switch)除了具备二层交换机的功能,还支持通过三层接口(如VLANIF接口)实现路由转发功能。
③、VLANIF接口
这是一种三层的逻辑接口,支持VLAN Tag的剥离和添加。
④、VLANIF接口编号
与所对应的VLAN ID相同,例如VLAN10对应VLANIF 10
(2)实验top

S1配置
<Huawei>system-view
[Huawei]sysname S1
[S1]port-group 1
[S1-port-group-1]group-member Ethernet 0/0/1 to Ethernet 0/0/2
[S1-port-group-1]port link-type access
[S1-port-group-1]q
[S1]vlan batch 10 20
[S1]interface Ethernet 0/0/1
[S1-Ethernet0/0/1]port default vlan 10
[S1-Ethernet0/0/1]interface Ethernet 0/0/2
[S1-Ethernet0/0/2]port default vlan 20
[S1-Ethernet0/0/2]interface Ethernet 0/0/3
[S1-Ethernet0/0/3]port link-type trunk
[S1-Ethernet0/0/3]port trunk allow-pass vlan all
[S1-Ethernet0/0/3]q
[S1]q
<S1>save
The current configuration will be written to the device.
Are you sure to continue?[Y/N]y
Info: Please input the file name ( *.cfg, *.zip ) [vrpcfg.zip]:
Sep 16 2026 15:25:17-08:00 S1 %%01CFM/4/SAVE(l)[0]:The user chose Y when decidin
g whether to save the configuration to the device.
Now saving the current configuration to the slot 0.
Save the configuration successfully.
S2配置
<Huawei>system-view
[Huawei]sysname S2
[S2]vlan batch 10 20 30
[S2]interface GigabitEthernet 0/0/1
[S2-GigabitEthernet0/0/1]port link-type trunk
[S2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[S2-GigabitEthernet0/0/2]port link-type access
[S2-GigabitEthernet0/0/2]port default vlan 30
[S2-GigabitEthernet0/0/2]q
[S2]interface vlanif 10
[S2-Vlanif10]ip address 192.168.10.1 24
[S2-Vlanif10]interface vlanif20
[S2-Vlanif20]ip address 192.168.20.1 24
[S2-Vlanif20]interface vlanif 30
[S2-Vlanif30]ip address 192.168.30.1 24
[S2-Vlanif30]q
[S2]ip route-static 0.0.0.0 0 192.168.30.2
ctrl+z
<S2>save
The current configuration will be written to the device.
Are you sure to continue?[Y/N]y
Info: Please input the file name ( *.cfg, *.zip ) [vrpcfg.zip]:
Sep 16 2026 15:28:58-08:00 S2 %%01CFM/4/SAVE(l)[6]:The user chose Y when decidin
g whether to save the configuration to the device.
Now saving the current configuration to the slot 0.
Save the configuration successfully.
AR1配置
<Huawei>system-view
[Huawei]sysname AR1
[AR1]interface GigabitEthernet 0/0/0
[AR1-GigabitEthernet0/0/0]ip address 192.168.30.2 24
[AR1-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[AR1-GigabitEthernet0/0/1]ip address 1.1.1.1 30
[AR1-GigabitEthernet0/0/1]q
[AR1]ip route-static 0.0.0.0 0 192.168.30.1
[AR1]q
<AR1>save
The current configuration will be written to the device.
Are you sure to continue? (y/n)[n]:y
It will take several minutes to save configuration file, please wait…….
Configuration file had been saved successfully
Note: The configuration file will take effect after being activated
PC1、PC2、Sever配置



(3)连通性测试
①、PC1 ping PC2

②、PC1 ping Server 1

③、PC2 ping Server 1

(4)通信过程—PC1 ping Server1
假设此时每个设备都已经建立好了各自的ARP表项。
①、PC1处理流程
PC发送报文前往1.1.1.2,经过判断目的IP地址非本地网段,所以将报文发给网关
PC封装的ICMP报文发送给网关:

②、S1的处理流程
接收到的数据帧根据目的MAC地址查找MAC地址表并转发数据

在经过S1的Ethernet 0/0/1接口时,由于S1 Ethernet 0/0/1接口的PVID为10,所以会给ICMP报文加上VLAN Tag10。再查询完MAC表后,从Ethernet 0/0/3转发给S2。

VLAN-Tag 10验证

③、S2的处理流程
S2接收到数据帧之后,查看目的MAC地址为自身接口的VLANIF10的MAC地址,并剥离VLAN Tag标签再交给路由模块在路由表中查找1.1.1.2。
S2路由查找结果为匹配默认路由,出接口为VLANIF30,下一跳为192.168.30.2:

在ARP表项中获取192.168.30.2的MAC地址:

tips:路由器AR1的接口MAC地址用MAC4、MAC5代替
S2查找ARP表项获取到192.168.30.2的MAC地址,将报文的源MAC地址替换为VLANIF30的接口MAC,转交给交换模块:

交换模块查找MAC地址表确定出接口,同时确认发送报文时是否携带VLAN Tag,由于S2的GE 0/0/2口没有PVID,所以不携带VLAN Tag发送给AR1

不带VLAN Tag验证

④、AR1接收到报文后的处理流程
查找数据帧的目的MAC为自身接口的MAC,查看目的IP,非自身IP地址,查找路由表,匹配直连路由:

下一跳为1.1.1.1,出接口为GE 0/0/1,查询ARP表:

封装ICMP,将源MAC换成GE 0/0/1接口的MAC5,目的MAC换成Server1MAC

随后Server1接收到ICMP报文后,发现目的IP地址和自己匹配,接收并回复ICMP报文。
回复报文过程反过来即可,但是要注意,由于是转发,所以在S1的Ethernet 0/0/1口并不会打上VLAN Tag标签
PC2 ping Server1同理。
