配置
R1
[Huawei]interface GigabitEthernet 0/0/0
[Huawei-GigabitEthernet0/0/0]IP address 192.168.1.1 30
[Huawei-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]IP address 192.168.1.5 30
[Huawei]interface LoopBack 0
[Huawei-LoopBack0]ip address 192.168.1.33 28
[Huawei]interface LoopBack 1
[Huawei-LoopBack1]ip address 192.168.1.49 28
[r1]ip route-static 0.0.0.0 0 192.168.1.2
[r1]ip route-static 0.0.0.0 0 192.168.1.6
[r1]ip route-static 192.168.1.8 30 192.168.1.2
[r1]ip route-static 192.168.1.12 30 192.168.1.6
[r1]ip route-static 192.168.1.128 27 192.168.1.6
[r1]ip route-static 192.168.1.64 27 192.168.1.2
防环
[r1]ip route-static 192.168.1.32 27 NULL 0
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mod aaa
[r1-ui-vty0-4]aaa
[r1-aaa]local-user huawei privilege level 15 password cipher 123456
[r1-aaa]local-user huawei service-type telnet
R2
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 192.168.1.2 30
[r2-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]ip address 192.168.1.9 30
[r2]interface LoopBack 0
[r2-LoopBack0]ip address 192.168.1.65 28
[r2-LoopBack0]interface LoopBack 1
[r2-LoopBack1]ip address 192.168.1.81 28
[r2]ip route-static 0.0.0.0 0 192.168.1.10
[r2]ip route-static 192.168.1.32 27 192.168.1.1
[r2]ip route-static 192.168.1.4 30 192.168.1.1
[r2]ip route-static 192.168.1.128 27 192.168.1.1
[r2]ip route-static 192.168.1.128 27 192.168.1.10
[r2]ip route-static 192.168.1.64 27 NULL 0
R3
[r3]interface GigabitEthernet 0/0/0
[r3-GigabitEthernet0/0/0]ip address 192.168.1.14 30
[r3-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r3-GigabitEthernet0/0/1]ip address 192.168.1.10 30
[r3-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[r3-GigabitEthernet0/0/2]ip address 192.168.1.21 30
[r3-GigabitEthernet0/0/2]interface GigabitEthernet 4/0/0
[r3-GigabitEthernet4/0/0]ip address 192.168.1.17 30
[r3]interface LoopBack 0
[r3-LoopBack0]ip address 192.168.1.97 28
[r3-LoopBack0]interface LoopBack 1
[r3-LoopBack1]ip address 192.168.1.113 28
[r3]ip route-static 0.0.0.0 0 192.168.1.18
[r3]ip route-static 0.0.0.0 0 192.168.1.22 preference 90
[r3]ip route-static 192.168.1.128 27 192.168.1.13
[r3]ip route-static 192.168.1.32 27 192.168.1.13
[r3]ip route-static 192.168.1.4 30 192.168.1.13
[r3]ip route-static 192.168.1.0 30 192.168.1.9
[r3]ip route-static 192.168.1.64 27 192.168.1.9
[r3]ip route-static 192.168.1.32 27 192.168.1.9
[r3]ip route-static 192.168.1.96 27 NULL 0
R4
[r4]interface GigabitEthernet 0/0/0
[r4-GigabitEthernet0/0/0]ip address 192.168.1.6 30
[r4-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r4-GigabitEthernet0/0/1]ip address 192.168.1.13 30
[r4-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[r4-GigabitEthernet0/0/2]ip address 192.168.1.13
[r4-GigabitEthernet0/0/2]ip address 192.168.1.129 27
[r4]dhcp enable
[r4]ip pool 1
[r4-ip-pool-1]gateway-list 192.168.1.129pe
[r4-ip-pool-1]network 192.168.1.128 m
[r4-ip-pool-1]network 192.168.1.128 mask 27
[r4-ip-pool-1]dns-list 1.1.1.1
[r4]interface GigabitEthernet 0/0/2
[r4-GigabitEthernet0/0/2]dhcp select global
[r4]ip route-static 0.0.0.0 0 192.168.1.14
[r4]ip route-static 192.168.1.64 27 192.168.1.14
[r4]ip route-static 192.168.1.64 27 192.168.1.5
[r4]ip route-static 192.168.1.32 27 192.168.1.5
[r4]ip route-static 192.168.1.0 30 192.168.1.5
[r4]ip route-static 192.168.1.128 27 NULL 0
R5
[r5-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r5-GigabitEthernet0/0/1]ip address 12.0.0.1 24
[r5-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/0
[r5-GigabitEthernet0/0/0]ip address 192.168.1.22 30
[r5-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r5-GigabitEthernet0/0/1]ip address 192.168.1.18 30
[r5]interface LoopBack 0
[r5-LoopBack0]ip address 192.168.1.161 27
[r5]ip route-static 0.0.0.0 0 12.0.0.2
[r5]ip route-static 192.168.1.0 24 192.168.1.17
[r5]ip route-static 192.168.1.0 24 192.168.1.21 preference 90
[r5]ip route-static 192.168.1.160 27 NULL 0
nat:
[r5]acl 2000
[r5-acl-basic-2000]rule permit source any
[r5]interface GigabitEthernet 0/0/1
[r5-GigabitEthernet0/0/1]nat outbound 2000
[r5-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 10000 inside 192.168.1.1 23
R6
[r6]interface LoopBack 0
[r6-LoopBack0]ip address 1.1.1.1 24
DHCP配置
[r4]dhcp enable
[r4]ip pool 1
[r4-ip-pool-1]gateway-list 192.168.1.129pe
[r4-ip-pool-1]network 192.168.1.128 m
[r4-ip-pool-1]network 192.168.1.128 mask 27
[r4-ip-pool-1]dns-list 1.1.1.1
[r4]interface GigabitEthernet 0/0/2
[r4-GigabitEthernet0/0/2]dhcp select global
telent配置
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mod aaa
[r1-ui-vty0-4]aaa
[r1-aaa]local-user huawei privilege level 15 password cipher 123456
[r1-aaa]local-user huawei service-type telnet
静态路由配置
[r1]ip route-static 0.0.0.0 0 192.168.1.2
[r1]ip route-static 0.0.0.0 0 192.168.1.6
[r1]ip route-static 192.168.1.8 30 192.168.1.2
[r1]ip route-static 192.168.1.12 30 192.168.1.6
[r1]ip route-static 192.168.1.128 27 192.168.1.6
[r1]ip route-static 192.168.1.64 27 192.168.1.2
[r2]ip route-static 0.0.0.0 0 192.168.1.10
[r2]ip route-static 192.168.1.32 27 192.168.1.1
[r2]ip route-static 192.168.1.4 30 192.168.1.1
[r2]ip route-static 192.168.1.128 27 192.168.1.1
[r2]ip route-static 192.168.1.128 27 192.168.1.10
[r3]ip route-static 0.0.0.0 0 192.168.1.18 [r3]ip route-static 0.0.0.0 0 192.168.1.22 preference 90
[r3]ip route-static 192.168.1.128 27 192.168.1.13
[r3]ip route-static 192.168.1.32 27 192.168.1.13
[r3]ip route-static 192.168.1.4 30 192.168.1.13
[r3]ip route-static 192.168.1.0 30 192.168.1.9
[r3]ip route-static 192.168.1.64 27 192.168.1.9
[r3]ip route-static 192.168.1.32 27 192.168.1.9
[r4]ip route-static 0.0.0.0 0 192.168.1.14
[r4]ip route-static 192.168.1.64 27 192.168.1.14
[r4]ip route-static 192.168.1.64 27 192.168.1.5
[r4]ip route-static 192.168.1.32 27 192.168.1.5
[r4]ip route-static 192.168.1.0 30 192.168.1.5
[r5]ip route-static 0.0.0.0 0 12.0.0.2
[r5]ip route-static 192.168.1.0 24 192.168.1.17
[r5]ip route-static 192.168.1.0 24 192.168.1.21 preference 90
nat配置
easy ip:
[r5]acl 2000
[r5-acl-basic-2000]rule permit source any
[r5]interface GigabitEthernet 0/0/1
[r5-GigabitEthernet0/0/1]nat outbound 2000
端口映射:
[r5-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 10000 inside 192.168.1.1 23
防环
[r1]ip route-static 192.168.1.32 27 NULL 0
[r2]ip route-static 192.168.1.64 27 NULL 0
[r3]ip route-static 192.168.1.96 27 NULL 0
[r4]ip route-static 192.168.1.128 27 NULL 0
[r5]ip route-static 192.168.1.160 27 NULL 0
测试
nat
r6 relent r1