1. VLAN:为什么一个 Switch 还要划分广播域

基础拓扑:

1
2
3
PC1 VLAN10 ── SW1 ───── SW2 ── PC3 VLAN10
Trunk
└─ PC4 VLAN20

VLAN 的核心作用:

在同一套物理交换网络上划分多个逻辑二层广播域。

因此:

1
2
3
4
5
VLAN10
→ 一个 Broadcast Domain

VLAN20
→ 另一个 Broadcast Domain

即使设备接在同一台 Switch:

1
2
不同 VLAN
→ 默认不能直接二层通信

Switch MAC Table 也不是单纯:

1
MAC → Port

而是:

1
VLAN + MAC → Port

所以相同 MAC 理论上可以在不同 VLAN 中拥有不同转发表项。

2. Access Port:终端如何进入 VLAN

普通 PC 通常发送:

1
Untagged Ethernet Frame

Access Port 配置:

1
2
3
interface e0/1
switchport mode access
switchport access vlan 10

PC 发来的 Frame 本身没有 802.1Q Tag。

Switch 从 Access Port 收到后:

1
2
3
4
5
Untagged Frame
↓
根据接口配置
↓
内部归类为 VLAN10

这里要区分:

1
2
3
4
5
802.1Q Tag
→ 真正在链路上传输的字段

VLAN Metadata
→ Switch 内部处理 Frame 时记录的 VLAN 信息

所以:

Access Port 收到 Untagged Frame,不代表 Switch 内部“不知道它属于哪个 VLAN”。

3. Trunk 与 802.1Q

两台 Switch 之间如果要同时承载:

1
2
3
4
VLAN10
VLAN20
VLAN30
...

通常使用 Trunk。

1
2
SW1 ================= SW2
Trunk

802.1Q 会在 Ethernet Frame 中插入 4 Byte Tag。

简化结构:

1
2
3
4
5
6
DMAC
SMAC
802.1Q Tag
Original EtherType
Payload
FCS

802.1Q Tag:

1
2
3
TPID
+
TCI

常见:

1
TPID = 0x8100

TCI:

1
2
3
PCP  3 bit
DEI 1 bit
VID 12 bit

VID 用于标识 VLAN。

例如:

1
2
VID = 10
→ VLAN10

4. Access → Trunk → Access 的完整转发

PC1 属于 VLAN10:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
PC1
|
| Untagged
↓
SW1 Access VLAN10
|
| Switch 内部:
| VLAN Metadata = 10
|
| Trunk Egress
↓
802.1Q Tag VLAN10
|
| Trunk
↓
SW2
|
| 读取 Tag = VLAN10
| 内部 Metadata = VLAN10
|
| Access VLAN10 Egress
↓
移除 Tag
|
↓
PC3

所以:

1
2
3
4
5
6
7
8
PC ↔ Access
→ 通常 Untagged

Switch ↔ Switch Trunk
→ 通常 Tagged

Switch 内部
→ 使用 VLAN Metadata 处理

802.1Q Tag 增加 4 Byte,但标准 Ethernet/IP 场景中并不是简单把 IP MTU 1500 改成 1496。

5. Trunk Allowed VLAN 与 Native VLAN

Allowed VLAN

例如:

1
2
3
interface e0/2
switchport mode trunk
switchport trunk allowed vlan 10,30

表示:

1
2
3
VLAN10 → 可以经过 Trunk
VLAN30 → 可以经过 Trunk
VLAN20 → 不能经过该 Trunk

必须区分三个概念:

1
2
3
4
5
VLAN 在 Switch 上存在
≠
Access Port 属于该 VLAN
≠
该 VLAN 被 Trunk Allow

Cisco Trunk 默认通常允许较大的 VLAN 范围,实际设计中常主动限制 Allowed VLAN。

Native VLAN

802.1Q Trunk 上存在 Native VLAN 概念。

Native VLAN 的 Frame 在常见默认行为下可以 Untagged 通过 Trunk。

但:

Native VLAN 不能绕过 Allowed VLAN List。

Native VLAN Mismatch

例如:

1
2
SW1 Native VLAN = 10
SW2 Native VLAN = 20

SW1 发出的 Untagged Frame 到达 SW2 后:

1
2
SW2 会按照自己的 Native VLAN
把它归类到 VLAN20

因此可能造成:

1
2
3
VLAN 错误映射
STP/PVST 一致性问题
安全风险

所以 Trunk 两端 Native VLAN 应保持一致。

6. 为什么二层 Loop 非常危险

假设:

1
2
3
4
    SW1
/ \
/ \
SW2-----SW3

如果所有链路都在二层 Forwarding,可能形成 Loop。

Ethernet Frame 没有类似 IP TTL 的机制。

因此 Broadcast 可能:

1
SW1 → SW2 → SW3 → SW1 → ...

产生:

1
2
3
4
Broadcast Storm
Duplicate Frames
MAC Address Flapping
网络资源耗尽

例如同一个 Source MAC:

1
2
3
4
AAAA → E0/1
AAAA → E0/2
AAAA → E0/1
AAAA → E0/2

Switch 会不断改变 MAC Table 中的接口记录。

因此二层冗余网络需要 STP。

7. STP:Root、Root Port 与 Designated Port

STP 的核心目标:

保留物理冗余,但在逻辑上阻断部分路径,形成无环二层拓扑。

Root Bridge

比较 Bridge ID(BID),更低者优先。

BID 核心包括:

1
2
3
4
5
Bridge Priority
+
Extended System ID / VLAN
+
MAC Address

现代 Cisco PVST/Rapid-PVST 中 Priority 通常按 4096 的倍数调整。

Root Bridge:

1
没有 Root Port

Root Port(RP)

每台非 Root Switch 选择一个:

到 Root Bridge 总 Root Path Cost 最低的接口。

因此:

1
2
每台非 Root Bridge
→ 通常一个 RP

Designated Port(DP)

每个二层 Segment 需要选一个 Designated Port:

该 Segment 上提供最优 Root Path 的端口。

Root Bridge 上参与 STP 的正常端口通常是 DP。

Alternate Port

RSTP 中,冗余但当前未使用的路径可能成为:

1
Alternate Port

通常处于 Discarding。

8. STP 选举与 Tie-break

Root Bridge

核心:

1
最低 BID

Root Port

首先比较:

1
Root Path Cost

如果相同,继续 Tie-break。

可以记住主干:

1
2
3
4
5
Root ID
→ Root Path Cost
→ Sender BID
→ Sender Port ID
→ Local Port ID

Designated Port

在同一个 Segment 上比较收到/发送的 BPDU 信息,提供更优 Root Path 的一侧成为 DP。

因此必须区分:

1
2
3
4
5
Role
→ RP / DP / Alternate

State
→ Forwarding / Learning / Discarding

Role ≠ State。

9. Classic STP、RSTP 与保护机制

Classic STP States

传统 802.1D:

1
2
3
4
5
Disabled
Blocking
Listening
Learning
Forwarding

经典 Timer:

1
2
3
Hello Time     2s
Max Age 20s
Forward Delay 15s

传统收敛在某些场景可能达到约 30~50 秒。

但要注意:

物理接口直接 Down 时,Switch 可以直接感知 Link Down,并不是所有故障都必须等待 Max Age 20 秒。

Max Age 更典型用于:

1
2
链路仍然 Up
但原有 BPDU / Root 信息不再更新

RSTP

RSTP 简化 State:

1
2
3
Discarding
Learning
Forwarding

并通过:

1
2
3
Proposal / Agreement
Alternate Port
更快的信息失效机制

显著加快收敛。

RSTP 中常见约:

1
3 × Hello

可用于某些“链路仍 Up、但 BPDU 消失”的故障检测场景,但不能理解成所有故障统一等待约 6 秒。

PortFast

用于 Edge Port:

1
Switch ── PC

让接口快速进入 Forwarding。

PortFast:

1
≠ 关闭 STP

BPDU Guard

常与 PortFast 配合。

如果受保护 Edge Port 收到 BPDU:

1
→ 通常进入 err-disabled

目的:

防止用户侧意外接入 Switch 并影响 STP。

Root Guard

如果某接口不应该成为通往 Root 的方向,却收到 Superior BPDU:

1
→ Root-Inconsistent

Superior BPDU 消失后可自动恢复。

Loop Guard

本来应该持续收到 BPDU 的非指定端口突然收不到:

1
2
→ 防止错误进入 Forwarding
→ Loop-Inconsistent

UDLD

用于检测:

1
Unidirectional Link

即:

1
2
A → B 正常
B → A 异常

避免单向链路引起二层问题。

10. PVST、配置、Show 与排障

Cisco PVST / Rapid-PVST 可以:

1
每个 VLAN 拥有独立 STP Instance

因此可以设计:

1
2
3
4
5
VLAN10:
SW1 为 Root

VLAN20:
SW2 为 Root

实现一定程度的 VLAN 级路径分担。

Root Primary / Secondary

Cisco 常见:

1
spanning-tree vlan 10 root primary
1
spanning-tree vlan 10 root secondary

它们本质上是帮助调整 Priority 的宏。

secondary 并不意味着协议保证:

Primary 挂掉后,这台设备一定成为下一任 Root。

最终仍然按照 STP BID 选举。


VLAN / Access 配置

1
2
3
4
5
6
vlan 10
name USERS

interface e0/1
switchport mode access
switchport access vlan 10

Trunk

1
2
3
interface e0/2
switchport mode trunk
switchport trunk allowed vlan 10,20

如需指定 Native VLAN:

1
switchport trunk native vlan 99

Rapid-PVST

1
spanning-tree mode rapid-pvst

PortFast + BPDU Guard

1
2
3
interface e0/1
spanning-tree portfast
spanning-tree bpduguard enable

重要 Show 命令

查看 VLAN:

1
show vlan brief

查看 Trunk:

1
show interfaces trunk

查看接口二层属性:

1
show interfaces e0/1 switchport

查看 MAC Table:

1
show mac address-table

查看 STP:

1
show spanning-tree

指定 VLAN:

1
show spanning-tree vlan 10

查看接口状态:

1
show interfaces status
1
show ip interface brief

二层排障顺序

同 VLAN 跨 Switch 无法通信:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
1. Physical Interface Up?
↓
2. Access VLAN 正确?
↓
3. VLAN 是否存在?
↓
4. Trunk 是否形成?
↓
5. VLAN 是否在 Allowed List?
↓
6. Native VLAN 是否一致?
↓
7. STP 是否阻断了预期路径?
↓
8. MAC Table 是否学习正确?
↓
9. ARP 是否成功?

出现二层 Loop / MAC Flapping:

1
2
3
4
5
6
7
8
9
10
11
检查 STP Root
↓
检查 RP / DP / Alternate
↓
检查异常 Trunk
↓
检查 BPDU
↓
检查 PortFast / BPDU Guard
↓
检查 Loop Guard / UDLD

V2 最终核心链条

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
VLAN
→ 划分二层 Broadcast Domain
↓
Access Port
→ 将 Untagged Endpoint Frame 归入 VLAN
↓
Trunk
→ 同一物理链路承载多个 VLAN
↓
802.1Q
→ 在线路上标识 VLAN
↓
Allowed VLAN / Native VLAN
→ 控制 Trunk 的 VLAN 行为
↓
冗余二层链路
→ 产生 Loop 风险
↓
STP / RSTP
→ Root Bridge
→ Root Port
→ Designated Port
→ Alternate / Blocking Path
↓
形成逻辑无环拓扑
↓
链路故障
→ STP/RSTP 重新收敛
→ 冗余路径接管

最终记忆

1
2
3
4
5
6
7
8
9
10
11
VLAN
→ Broadcast Domain

Access
→ Endpoint 通常 Untagged

Trunk
→ 多 VLAN 传输

802.1Q
→ 给 Frame 标记 VLAN
1
2
3
4
5
STP:
先选 Root
→ 非 Root 选 RP
→ 每个 Segment 选 DP
→ 剩余冗余路径阻断/Discarding
1
2
3
4
5
6
7
8
9
10
11
12
13
14
PortFast
→ Edge 快速 Forwarding

BPDU Guard
→ Edge 收到 BPDU 就保护

Root Guard
→ 不允许该方向成为 Root Path

Loop Guard
→ 应收 BPDU 却消失时防止误 Forwarding

UDLD
→ 检测单向链路