












D-Link 3-




I – 






IP-
•IP-








•











•














•RIP
•OSPF
•





: 


Internet 








NAT
•






: 


















•





: 










DHCP/BootP
•





: 











•VRRP












L3 










IP-








1/3
1.


FDB:
















VLAN, 


MAC-


. 





















2.
2.ARP-


:








IP
MAC-









.

























.
3.


IPFDB:


IP-
































. 












IP-





(




L3).
4.









:
























.













IP-















.












L3 










IP-








2/3

1
2
3
4
DGS-3324SR
.254 |
.254 |
.254 |
.254 |
PC 1 |
|
PC3 |
192.168.4.1/24 |
PC2 |
|
||
192.168.1.1/24 |
|
||
192.168.1.254 |
192.168.2.1/24 |
192.168.3.1/24 |
192.168.4.254 |
ASIC |
192.168.2.254 |
192.168.3.254 |
|
|
|
3/3 “PC1
L3
IP-

L3
”
:
|
ARP- |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
- |
|
ARP |
PC1
1.
.
.
ICMP
PC1
2.
|
PC1: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
3 |
3.
:
- ARP
FDB
PC1
- MAC
|
• |
|
- |
|
ARP |
|
|
|
PC1 |
|
IP/MAC |
|
|
|
|
|
|
|
• |
PC1
- ARP
•
PC1)
- ICMP
( :
ipfdb
- IP
L3
! •
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
L3 |
|
|
|
|
" |
• |
ACL
#
L3
•
|
|
|
|
|
|
|
|
|
|
|
|
|
ipfdb, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
$ |
|
|
4. |
|
|
|
|
|
& |
|
% |
|
|
L3
:
•
!
|
ipfdb. |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CPU |
|
|
|
|
|
|
.
|
|
|
|
|
|
|
|
|
|
|
|
|
# |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
(
&
('
L3
:
•
.
#
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
||
|
|
|
& |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
. |
|
. |
||
|
ipfdb, |
|
|
|||
|
|
|
$ |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CPU |
|
|
|
|
CPU |
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
L3 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
$ |
• |
|
|
|
|
|


Hua-Du, GuanDong, 










:








:



Hua-Du, GuanDong, 

.




:

: 1* DES-6500,









: 70+ DES-3526. 


: 1500+.
DES-6500 



















. 


Ping IP will have round 20% packet lost. The firewall can capture a lot of destination IP scan packets with destination TCP port 139 and 445.



Hua-Du, GuanDong, 





:
DES-6500 (1.3x firmware) 
xStack (R4 firmware) 



















L3 









,





, 













“IP-scan”,








.
IP-







1/3
1 |
2 |
3 |
4 |
|
|
|
DGS-3324SR
.254 |
.254 |
.254 |
.254 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.1.x/24 |
|
|
|
|
|
|
|
|
|
|
192.168.2.x/24 |
|
|
|
|
|
192.168.3.x/24 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.4.x/24 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
: |
|
|
|
|
|
|
|
|
|
|
|
: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||
192.168.1.254 |
|
|
|
192.168.2.254 |
|
|
192.168.3.254 |
|
|
|
|
|
|
|
|
|
|
: |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.4.254 |
|||||||||||||||


:





IP-



























can routed 










-






L3.




:





L3 


4 



















. 



































.
IP-







2/3
DGS-3324SR
1.






VLAN default 









VLAN-
. config vlan default delete 1:1-1:24
2.


VLAN, 
















IP-






VLAN.
create vlan v101 tag 101
config vlan v101 add untagged 1:1-1:6
create ipif net1 192.168.1.254/24 v101 state enabled create vlan v102 tag 102
config vlan v102 add untagged 1:7-1:12
create ipif net2 192.168.2.254/24 v102 state enabled create vlan v103 tag 103
config vlan v103 add untagged 1:13-1:18
create ipif net3 192.168.3.254/24 v103 state enabled create vlan v104 tag 104
config vlan v104 add untagged 1:19-1:24
create ipif net4 192.168.4.254/24 v104 state enabled Save
3. 



, 









IP-



. show vlan
show ipif
PC 


:
1.






IP-


















IP-


.
2.
= IP-



DGS-3324SR.
IP-







3/3

:
1.PC 

1 





(192.168.1.254), 







DGS-3324SR (192.168.2.254, 192.168.3.254 
.
.)
PC 





.
2.PC 

2 





(192.168.2.254), 







DGS-3324SR (192.168.1.254, 192.168.3.254 
.
.)
PC 





.
3.






PC 

3 

4.
