ACCESS PORTS
포트 번호가 곧 소속
각 스위치 1–10번은 VLAN10, 11–20번은 VLAN20. 서버팜이 있는 L2#2 만 21–23번을 VLAN30 으로 두었습니다.
// WHAT WE BUILT
ACCESS PORTS
각 스위치 1–10번은 VLAN10, 11–20번은 VLAN20. 서버팜이 있는 L2#2 만 21–23번을 VLAN30 으로 두었습니다.
PORTFAST · BPDUGUARD
액세스 포트에 portfast 로 연결 지연을 없애고, bpduguard 로 누가 스위치를 꽂으면 바로 포트를 닫습니다.
SSH ONLY
경고 배너, 암호화된 enable 비밀번호, 로컬 계정 로그인, SSH v2 만 허용, 5분 무입력 시 끊김.
// CONFIGURATION
장비에 입력한 순서 그대로입니다. 계정 비밀번호는 공개 사이트라 가렸습니다.
hostname CB-L2-SW1 vlan 10 name USER_VLAN10 vlan 20 name USER_VLAN20 vlan 30 name SERVER_FARM_VLAN30
interface range GigabitEthernet1/0/1-10
switchport mode access
switchport access vlan 10
switchport nonegotiate
spanning-tree portfast
spanning-tree bpduguard enable
interface range GigabitEthernet1/0/11-20
switchport mode access
switchport access vlan 20
! L2#2 에만
interface range GigabitEthernet1/0/21-23
switchport mode access
switchport access vlan 30interface GigabitEthernet1/0/24 switchport trunk encapsulation dot1q switchport mode trunk switchport trunk allowed vlan 10,20,30 switchport nonegotiate
banner motd ^ WARNING: Authorized access only. All activity is monitored and logged. ^ enable secret **** service password-encryption username cbadmin privilege 15 secret **** ip ssh version 2 line vty 0 15 transport input ssh login local exec-timeout 5 0
// VERIFICATION
CB-L2-SW2# show vlan brief 10 USER_VLAN10 active Gi1/0/1-10 20 USER_VLAN20 active Gi1/0/11-20 30 SERVER_FARM_VLAN30 active Gi1/0/21-23 CB-L2-SW2# show interfaces trunk Port Mode Encapsulation Status Native vlan Gi1/0/24 on 802.1q trunking 1 Port Vlans allowed on trunk Gi1/0/24 10,20,30
// PITFALLS
| 증상 | 원인 | 해결 |
|---|---|---|
| 트렁크가 안 올라옴 | 양쪽 모드 불일치 | L3 · L2 모두 mode trunk |
| VLAN30 서버 통신 안 됨 | allowed vlan 에 30 누락 | allowed vlan 10,20,30 |
| 포트가 err-disabled | bpduguard 동작(스위치 연결) | 원인 제거 후 shutdown / no shutdown |