

D-Link 3-
I –
IP-

•IP-
•
•
•RIP
•OSPF
•:
Internet
NAT
•:
•:
DHCP/BootP
•:
•VRRP

L3
IP-
1/3
1. FDB:
VLAN,
MAC-
.
2.
2.ARP-:
IP
MAC-
.
.
3. IPFDB:
IP-
.
IP-
(
L3).
4.:
.
IP-
.

L3
IP-
2/3
1
2
3
4
DGS-3324SR
.254 |
.254 |
.254 |
.254 |
PC 1 |
|
PC3 |
192.168.4.1/24 |
PC2 |
|
||
192.168.1.1/24 |
|
||
192.168.1.254 |
192.168.2.1/24 |
192.168.3.1/24 |
192.168.4.254 |
ASIC |
192.168.2.254 |
192.168.3.254 |
|
|
|

3/3 “PC1
L3
IP-
L3
”
:
|
ARP- |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
- |
|
ARP |
PC1
1.
.
.
ICMP
PC1
2.
|
PC1: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
3 |
3.
:
- ARP
FDB
PC1
- MAC
|
• |
|
- |
|
ARP |
|
|
|
PC1 |
|
IP/MAC |
|
|
|
|
|
|
|
• |
PC1
- ARP
•
PC1)
- ICMP
( :
ipfdb
- IP
L3
! •
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
L3 |
|
|
|
|
" |
• |
ACL
#
L3
•
|
|
|
|
|
|
|
|
|
|
|
|
|
ipfdb, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
$ |
|
|
4. |
|
|
|
|
|
& |
|
% |
|
|
L3
:
•
!
|
ipfdb. |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CPU |
|
|
|
|
|
|
.
|
|
|
|
|
|
|
|
|
|
|
|
|
# |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
(
&
('
L3
:
•
.
#
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
||
|
|
|
& |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
. |
|
. |
||
|
ipfdb, |
|
|
|||
|
|
|
$ |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CPU |
|
|
|
|
CPU |
|
|
|
|
|
|
|
|
, |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
L3 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
$ |
• |
|
|
|
|

Hua-Du, GuanDong,
:
:
Hua-Du, GuanDong,
.
:
: 1* DES-6500,
: 70+ DES-3526.
: 1500+.
DES-6500
.
Ping IP will have round 20% packet lost. The firewall can capture a lot of destination IP scan packets with destination TCP port 139 and 445.

Hua-Du, GuanDong,
:
DES-6500 (1.3x firmware) xStack (R4 firmware)
L3
,
,
“IP-scan”,
.

IP- 1/3
1 |
2 |
3 |
4 |
|
|
|
DGS-3324SR
.254 |
.254 |
.254 |
.254 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.1.x/24 |
|
|
|
|
|
|
|
|
|
|
192.168.2.x/24 |
|
|
|
|
|
192.168.3.x/24 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.4.x/24 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
: |
|
|
|
|
|
|
|
|
|
|
|
: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||
192.168.1.254 |
|
|
|
192.168.2.254 |
|
|
192.168.3.254 |
|
|
|
|
|
|
|
|
|
|
: |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
192.168.4.254 |
:
IP-
can routed
-
L3.
:
L3
4
.
.

IP- 2/3
DGS-3324SR
1. VLAN default
VLAN-
. config vlan default delete 1:1-1:24
2. VLAN,
IP-
VLAN.
create vlan v101 tag 101
config vlan v101 add untagged 1:1-1:6
create ipif net1 192.168.1.254/24 v101 state enabled create vlan v102 tag 102
config vlan v102 add untagged 1:7-1:12
create ipif net2 192.168.2.254/24 v102 state enabled create vlan v103 tag 103
config vlan v103 add untagged 1:13-1:18
create ipif net3 192.168.3.254/24 v103 state enabled create vlan v104 tag 104
config vlan v104 add untagged 1:19-1:24
create ipif net4 192.168.4.254/24 v104 state enabled Save
3. ,
IP-
. show vlan
show ipif
PC
:
1. IP-
IP-
.
2. = IP-
DGS-3324SR.

IP- 3/3
:
1.PC 1
(192.168.1.254),
DGS-3324SR (192.168.2.254, 192.168.3.254
.
.)
PC
.
2.PC 2
(192.168.2.254),
DGS-3324SR (192.168.1.254, 192.168.3.254
.
.)
PC
.
3. PC
3
4.