shi
RIP协议与OSPF协议路由引入
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r1
[r1]interface e0/0/0
[r1-Ethernet0/0/0]ip address 10.1.1.1 24
[r1-Ethernet0/0/0]quit
[r1]interface g0/0/0
[r1-GigabitEthernet0/0/0]ip address 20.1.1.2 24
[r1-GigabitEthernet0/0/0]quit
[r1]rip
[r1-rip-1]version 2
[r1-rip-1]undo summary
[r1-rip-1]network 10.0.0.0
[r1-rip-1]network 20.0.0.0
[r1-rip-1]quit
[r1]
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname ar1
[ar1]interface g0/0/0
[ar1-GigabitEthernet0/0/0]ip address 20.1.1.1 24
[ar1-GigabitEthernet0/0/0]quit
[ar1]rip
[ar1-rip-1]version 2
[ar1-rip-1]undo summary
[ar1-rip-1]network 20.0.0.0
[ar1-rip-1]quit
[ar1]interface g0/0/1
[ar1-GigabitEthernet0/0/1]ip address 30.1.1.1 24
[ar1-GigabitEthernet0/0/1]quit
[ar1]ospf
[ar1-ospf-1]area 0
[ar1-ospf-1-area-0.0.0.0]network 30.0.0.0 0.255.255.255
[ar1-ospf-1-area-0.0.0.0]quit
[ar1-ospf-1]import-route rip
[ar1-ospf-1]quit
[ar1]rip
[ar1-rip-1]import-route ospf
[ar1-rip-1]quit
[ar1]quit
<ar1>save
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r2
[r2]interface g0/0/0
[r2-GigabitEthernet0/0/0]ip address 30.1.1.2 24
[r2-GigabitEthernet0/0/0]quit
[r2]interface e0/0/0
[r2-Ethernet0/0/0]ip address 40.1.1.1 24
[r2-Ethernet0/0/0]quit
[r2]ospf
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 30.0.0.0 0.255.255.255
[r2-ospf-1-area-0.0.0.0]network 40.0.0.0 0.255.255.255
[r2-ospf-1-area-0.0.0.0]quit
display cu
R1
<r1>display cu
#
sysname r1
#
undo info-center enable
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher ~=3;Hj'/0FjKUGU-KkpB{W/
#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
ip address 10.1.1.1 255.255.255.0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 20.1.1.2 255.255.255.0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
rip 1
undo summary
version 2
network 10.0.0.0
network 20.0.0.0
#
user-interface con 0
user-int
erface vty 0 4
user-interface vty 16 20
return
<r1>
AR1
<ar1>display cu
[V200R003C00]
#
sysname ar1
#
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
#
clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load flash:/portalpage.zip
#
drop illegal-mac alarm
#
undo info-center enable
#
wlan ac-global carrier id other ac id 0
#
set cpu-usage threshold 80 restore 75
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-user admin service-type http
#
firewall zone Local
priority 15
#
interface GigabitEthernet0/0/0
ip address 20.1.1.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 30.1.1.1 255.255.255.0
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
ospf 1
import-route rip 1
area 0.0.0.0
network 30.0.0.0 0.255.255.255
#
rip 1
undo summary
version 2
network 20.0.0.0
import-route ospf 1
#
user-interface con 0
authentication-mode password
user-interface vty
0 4
user-interface vty 16 20
#
wlan ac
#
return
<ar1>
R2
<r2>display cu
#
sysname r2
#
undo info-center enable
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher L@mz+H[^kVECB7Ie7'/)wWB#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
ip address 40.1.1.1 255.255.255.0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 30.1.1.2 255.255.255.0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
ospf 1
area 0.0.0.0
network 30.0.0.0 0.255.255.255
network 40.0.0.0 0.255.255.255
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
<r2>
VLAN、OSPF、DHCP综合配置
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r1
[r1]interface e0/0/0
[r1-Ethernet0/0/0]ip address 192.168.1.1 24
[r1-Ethernet0/0/0]quit
[r1]dhcp enable
[r1]ip pool yourname
[r1-ip-pool-yourname]network 10.1.10.0 mask 255.255.255.0
[r1-ip-pool-yourname]dns-list 8.8.8.8
[r1-ip-pool-yourname]gateway-list 10.1.10.1
[r1-ip-pool-yourname]lease day 10 (可选)
[r1-ip-pool-yourname]excluded-ip-address 10.1.10.11 10.1.10.21 (可选)
[r1-ip-pool-yourname]quit
[r1]ip pool yourname2
[r1-ip-pool-yourname2]net
[r1-ip-pool-yourname2]network 10.1.20.0 mask 255.255.255.0
[r1-ip-pool-yourname2]gateway-list 114.114.114.114.
[r1-ip-pool-yourname2]gateway-list 10.1.20.1
[r1-ip-pool-yourname2]lease day 10 (可选)
[r1-ip-pool-yourname2]excluded-ip-address 10.1.20.11 10.1.20.21 (可选)
[r1-ip-pool-yourname2]dns-list 114.114.114.114
[r1-ip-pool-yourname2]quit
[r1]ospf
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[r1-ospf-1-area-0.0.0.0]quit
[r1-ospf-1]quit
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname sw1
[sw1]vlan 10
[sw1-vlan10]quit
[sw1]vlan 20
[sw1-vlan20]quit
[sw1]vlan 100
[sw1-vlan100]quit
[sw1]interface g0/0/2
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1-GigabitEthernet0/0/2]port default vlan 10
[sw1-GigabitEthernet0/0/2]quit
[sw1]interface g0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 20
[sw1-GigabitEthernet0/0/3]quit
[sw1]int
[sw1]interface g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 100
[sw1-GigabitEthernet0/0/1]quit
[sw1]interface Vlanif 100
[sw1-Vlanif100]ip address 192.168.1.2 24
[sw1-Vlanif100]quit
[sw1]dhcp enable
[sw1]interface Vlanif 10
[sw1-Vlanif10]ip address 10.1.10.1 24
[sw1-Vlanif10]dhcp select relay
[sw1-Vlanif10]dhcp relay server-ip 192.168.1.1
[sw1-Vlanif10]quit
[sw1]interface Vlanif 20
[sw1-Vlanif20]ip address 10.1.20.1 24
[sw1-Vlanif20]dhcp select relay
[sw1-Vlanif20]dhcp relay server-ip 192.168.1.1
[sw1-Vlanif20]quit
[sw1]ospf
[sw1-ospf-1]area 0
[sw1-ospf-1-area-0.0.0.0]network 10.0.0.0 0.255.255.255
[sw1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]quit
[sw1-ospf-1]quit
[sw1]display ip routing-table
dispplay cu
R1
<r1>display cu
#
sysname r1
#
undo info-center enable
#
dhcp enable
#
ip pool yourname
gateway-list 10.1.10.1
network 10.1.10.0 mask 255.255.255.0
dns-list 8.8.8.8
#
ip pool yourname2
gateway-list 10.1.20.1
network 10.1.20.0 mask 255.255.255.0
dns-list 114.114.114.114
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher R'J**ZipYH@X,k6.E\Z,r[;#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
ip address 192.168.1.1 255.255.255.0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
ospf 1
area 0.0.0.0
network 192.168.1.0 0.0.0.255
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
<r1>
SW1
<sw1>dis
<sw1>display cu
#
sysname sw1
#
undo info-center enable
#
vlan batch 10 20 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
dhcp enable
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
ip address 10.1.10.1 255.255.255.0
dhcp select relay
dhcp relay server-ip 192.168.1.1
#
interface Vlanif20
ip address 10.1.20.1 255.255.255.0
dhcp select relay
dhcp relay server-ip 192.168.1.1
#
interface Vlanif100
ip address 192.168.1.2 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 100
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 20
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
ospf 1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
network 192.168.1.0 0.0.0.255
#
user-interface con 0
user-interface vty 0 4
#
return
<sw1>
PAP与CHAP配置
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r1
#CHAP主验证方
[r1]interface S0/0/0
[r1-Serial0/0/0]ip address 10.1.1.1 30
[r1-Serial0/0/0]link-protocol ppp
[r1-Serial0/0/0]quit
[r1]aaa
[r1-aaa]local-user r2 password cipher huawei
[r1-aaa]local-user r2 service-type ppp
[r1-aaa]authentication-scheme system-a #配置认证模板(可不用)
[r1-aaa-authen-system-a]authentication-mode local
[r1-aaa-authen-system-a]quit
[r1-aaa]domain test #配置认证域
[r1-aaa-domain-test]authentication-scheme system-a #在认证域中使用认证模板
[r1-aaa-domain-test]quit
[r1-aaa]quit
[r1]interface s0/0/0
[r1-Serial0/0/0]ppp authentication-mode chap #认证模式为chap
[r1-Serial0/0/0]quit
[r1]quit
<r1>
#PAP被验证方
<r1>
<r1>sys
[r1]interface s0/0/0
#被认证方pap认证(可参考下方被认证方)
[r1-Serial0/0/0]ppp pap user tester1 #(user/password cimple)
[r1-Serial0/0/0]ppp pap password cipher yourname
[r1-Serial0/0/0]
<Huawei>sys
[Huawei]undo inf en
#CHAP被验证方
[Huawei]sysname r2
[r2]interface s0/0/0
[r2-Serial0/0/0]ppp chap local-user r2 password cipher huawei #被认证方chap认证
[r2-Serial0/0/0]quit
[r2]interface s0/0/0
[r2-Serial0/0/0]ip address 10.1.1.2 30
[r2-Serial0/0/0]quit
[r2]quit
<r2>
#PAP主验证方
<r2>
<r2>sys
[r2]aaa
[r2-aaa]local-user router1 password cipher yourname
[r2-aaa]local-user router1 service-type ppp
[r2-aaa]authentication-scheme system-b
[r2-aaa-authen-system-b]authentication-mode local
[r2-aaa-authen-system-b]quit
[r2-aaa]domain test1
[r2-aaa-domain-test1]authentication-scheme system-b
[r2-aaa-domain-test1]quit
[r2-aaa]quit
[r2]interface s0/0/0
[r2-Serial0/0/0]ppp authentication-mode pap
[r2-Serial0/0/0]quit
[r2]
display cu
[r1]display current-configuration
#
sysname r1
#
undo info-center enable
#
aaa
authentication-scheme default
authentication-scheme system-a
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
domain test
authentication-scheme system-a
local-user r2 password cipher K0AJE=zv~-]@l3D+mKgU9"@#
local-user r2 service-type ppp
local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
ppp authentication-mode chap
ppp chap user tester1
ip address 10.1.1.1 255.255.255.252
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
[r1]
<r2>display cu
#
sysname r2
#
undo info-center enable
#
aaa
authentication-scheme default
authentication-scheme system-b
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
domain test1
authentication-scheme system-b
local-user admin password cipher 7GbD!EkMQ%pe}@HMNPn@I6a#
local-user admin service-type http
local-user router1 password cipher zmnvNmpr+Vpe}@HMNPn@I6a#
local-user router1 service-type ppp
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
ppp authentication-mode chap
ppp pap local-user r2 password cipher N`C55QK<`=/Q=^Q`MAF4<1!!
ip address 10.1.1.2 255.255.255.252
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
<r2>
静态路由配置
<Huawei>system-view
[Huawei]undo info-center enable
[Huawei]sysname R1
[R1]interface g0/0/0
[R1-GigabitEthernet0/0/0]ip address 10.1.1.1 24
[R1-GigabitEthernet0/0/0]quit
[R1-GigabitEthernet0/0/1]ip address 192.168.1.1 24
[R1-GigabitEthernet0/0/1]quit
[R1]ip route-static 172.16.1.0 255.255.255.0 10.1.1.1
默认路由的配置
[R1] ip route-static 0.0.0.0 0.0.0.0 下一跳地址
注意:默认路由是最后去匹配的路由条目。
DHCP
DHCP作业
地址池名:姓名拼音
地址段:192.168.1.0 255.255.255.0
网关:192.168.1.1
dns:114.114.114.114
租约期:10天
保留的ip地址:192.168.1.10–192.168.1.20
[Huawei]undo inf en
[Huawei]sysname sw1
[sw1]dhcp enable
[sw1]ip pool liangyankun
[sw1-ip-pool-liangyankun]network 192.168.1.0 mask 255.255.255.0
[sw1-ip-pool-liangyankun]gateway-list 192.168.1.1
[sw1-ip-pool-liangyankun]dns-list 114.114.114.114
[sw1-ip-pool-liangyankun]excluded-ip-address 192.168.1.10 192.168.1.20
[sw1-ip-pool-liangyankun]lease day 10
[sw1-ip-pool-liangyankun]quit
[sw1]interface g0/0/1
[sw1-GigabitEthernet0/0/1]dhcp select global
[sw1-GigabitEthernet0/0/1]quit
[sw1-Vlanif1]quit
[sw1]vlan 1
[sw1-vlan1]quit
[sw1]interface g0/0/1
[sw1-GigabitEthernet0/0/1]port link-typeaccess
[sw1-GigabitEthernet0/0/1]port default vlan 1
[sw1-GigabitEthernet0/0/1]quit
[sw1]interface g0/0/2
[sw1-GigabitEthernet0/0/2]port link-typeaccess
[sw1-GigabitEthernet0/0/2]port default vlan 1
[sw1-GigabitEthernet0/0/2]quit
[sw1]interface Vlanif 1
[sw1-Vlanif1]ip address 192.168.1.1 24
[sw1-Vlanif1]dhcp select global
[sw1-Vlanif1]quit
DHCP考试
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname ar1
[ar1]dhcp enable
[ar1]ip pool 1
[ar1-ip-pool-1]network 192.168.4.0 mask 255.255.255.0
[ar1-ip-pool-1]gateway-list 192.168.4.1
[ar1-ip-pool-1]dns-list 8.8.8.8
[ar1-ip-pool-1]lease day ....
[ar1-ip-pool-1]excluded-ip-address 192.168.4.11 192.168.4.21
[ar1-ip-pool-1]quit
[ar1]interface g0/0/0
[ar1-GigabitEthernet0/0/0]dhcp select global
[ar1-GigabitEthernet0/0/0]quit
[ar1]ip pool 2
[ar1-ip-pool-2]network 192.168.5.0 mask 255.255.255.0
[ar1-ip-pool-2]gateway-list 192.168.5.1
[ar1-ip-pool-2]dns-list 8.8.8.8
[ar1-ip-pool-2]excluded-ip-address 192.168.5.11 192.168.5.21
[ar1-ip-pool-2]quit
[ar1]interface g0/0/0
[ar1-GigabitEthernet0/0/0]dhcp select global
[ar1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[ar1-GigabitEthernet0/0/0]quit
[ar1]ospf
[ar1-ospf-1]area 0
[ar1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[ar1-ospf-1-area-0.0.0.0]quit
[ar1-ospf-1]quit
[ar1]display cu
[SW1]vlan 4
[SW1]quit
[SW1]vlan 5
[SW1]quit
[SW1]interface g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 4
[SW1-GigabitEthernet0/0/1]quit
[SW1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 5
[SW1-GigabitEthernet0/0/2]quit
[sw1-Vlanif5]ip address 192.168.5.1 24
[sw1-Vlanif5]quit
[sw1]ospf
[sw1-ospf-1]area 0
[sw1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]network 192.168.4.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]network 192.168.5.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]quit
[sw1-ospf-1]quit
[sw1]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[sw1]dhcp server group 1
[sw1-dhcp-server-group-1]dhcp-server 192.168.1.1
[sw1-dhcp-server-group-1]quit
[sw1]interface Vlanif 4
[sw1-Vlanif4]dhcp select relay
[sw1-Vlanif4]dhcp relay server-select 1
[sw1-Vlanif4]quit
[sw1]dhcp server group 2
Info:It's successful to create a DHCP server group.
[sw1-dhcp-server-group-2]dhcp-server 192.168.1.1
[sw1-dhcp-server-group-2]quit
[sw1]interface Vlanif 5
[sw1-Vlanif5]dhcp select relay
[sw1-Vlanif5]dhcp relay server-select 2
[sw1-Vlanif5]quit
[sw1]dis cu
DHCP中继
r1与sw1都要配ospf
r1:
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r1
[r1]dhcp enable
[r1]ip pool 10.1.1.0
[r1-ip-pool-10.1.1.0]network 10.1.1.0 mask 24
[r1-ip-pool-10.1.1.0]gateway-list 10.1.1.1
[r1-ip-pool-10.1.1.0]dns-list 8.8.8.8
[r1-ip-pool-10.1.1.0]quit
[r1]interface g0/0/0
[r1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
[r1-GigabitEthernet0/0/0]dhcp select global
[r1-GigabitEthernet0/0/0]quit
[r1]ospf
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[r1-ospf-1-area-0.0.0.0]quit
[r1-ospf-1]
sw1:
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname sw1
[sw1]vlan 100
[sw1-vlan100]quit
[sw1]vlan 10
[sw1-vlan10]quit
[sw1]interface g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 100
[sw1-GigabitEthernet0/0/1]quit
[sw1]interface g0/0/2
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1-GigabitEthernet0/0/2]port default vlan 10
[sw1-GigabitEthernet0/0/2]quit
[sw1]interface Vlanif 10
[sw1-Vlanif10]ip address 10.1.1.1 24
[sw1-Vlanif10]quit
[sw1]int
[sw1]interface vlan
[sw1]interface Vlanif 100
[sw1-Vlanif100]ip address 192.168.1.2 24
[sw1-Vlanif100]quit
[sw1]dhcp enable
[sw1]interface Vlanif 10
[sw1-Vlanif10]dhcp select relay
[sw1-Vlanif10]dhcp relay server-ip 192.168.1.1
[sw1-Vlanif10]quit
[sw1]ospf
[sw1-ospf-1]area 0
[sw1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]quit
[sw1-ospf-1]
三层交换机的DHCP配置
DHCP的配置
<Huawei>sys
[Huawei]undo inf enable
[Huawei]sysname SW1
#启动DHCP服务
[SW1]dhcp enable
#在三层交换机创建Vlan 10 20
[SW1]vlan 10
[SW1-vlan10]quit
[SW1]vlan 20
[SW1-vlan20]quit
#将接口加入vlan
[SW1]interface g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 10
[SW1-GigabitEthernet0/0/1]quit
[SW1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 20
[SW1-GigabitEthernet0/0/2]quit
#配置三层端口
[SW1]interface Vlanif 10
[SW1-Vlanif10]ip address 192.168.1.1 24
[SW1-Vlanif10]quit
[SW1]interface Vlanif 20
[SW1-Vlanif20]ip address 172.16.1.1 24
[SW1-Vlanif20]quit
#配置DHCP
[SW1]ip pool vlan10
[SW1-ip-pool-vlan10]network 192.168.1.0 mask 255.255.255.0
[SW1-ip-pool-vlan10]gateway-list 192.168.1.1
[SW1-ip-pool-vlan10]dns-list 8.8.8.8
[SW1-ip-pool-vlan10]excluded-ip-address 192.168.1.10 192.168.1.20
[SW1-ip-pool-vlan10]quit
[SW1]ip pool vlan20
[SW1-ip-pool-vlan20]network 172.16.1.0 mask 255.255.255.0
[SW1-ip-pool-vlan20]gateway-list 172.16.1.1
[SW1-ip-pool-vlan20]dns-list 114.114.114.114
[SW1-ip-pool-vlan20]quit
#在三层端口启用DHCP
[SW1]interface Vlanif 10
[SW1-Vlanif10]dhcp select global
[SW1-Vlanif10]quit
[SW1]interface Vlanif 20
[SW1-Vlanif20]dhcp select global
ACL
高级ACL配置
ACl配置实例:
[Huawei]undo inf enable
[Huawei]sysname R1
[R1]acl 2000
[R1-acl-basic-2000]rule deny source 192.168.1.0 0.0.0.255
[R1-acl-basic-2000]rule permit source 192.168.2.0 0.0.0.255
[R1-acl-basic-2000]quit
[R1]interface g0/0/0
[R1-GigabitEthernet0/0/0]traffic-filter inbound acl 2000
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r1
[r1]interface g0/0/1
[r1]time-range t1 08:00 to 18:00 working-day #设置时间t1
[r1-GigabitEthernet0/0/1]ip address 100.1.1.2 24
[r1-GigabitEthernet0/0/1]quit
[r1]interface g0/0/0
[r1-GigabitEthernet0/0/0]ip address 172.16.1.1 24
[r1-GigabitEthernet0/0/0]quit
[r1]acl 3000 #启用acl编号3000
#允许自哪到哪的IP的服务通过
[r1-acl-adv-3000]rule permit tcp source 172.16.1.0 0.0.0.255 destination-port eq www destination 100.1.1.1 0.0.0.0 time-range t1
[r1-acl-adv-3000]rule permit tcp source 172.16.1.0 0.0.0.255 destination-port eq ftp destination 100.1.1.1 0.0.0.0 time-range t1
[r1-acl-adv-3000]rule permit tcp source 172.16.1.0 0.0.0.255 destination-port eq ftp-data destination 100.1.1.1 0.0.0.0 time-range t1
[r1-acl-adv-3000]rule deny tcp source 172.16.1.0 0.0.0.255 destination 100.1.1.1 0.0.0.0
[r1-acl-adv-3000]quit
[r1]interface g0/0/1
[r1-GigabitEthernet0/0/1]traffic-filter outbound acl 3000 #在接口中使用acl3000
[r1-GigabitEthernet0/0/1]quit
[r1]
NAT(网络地址转换)
NAT作业
R1 R2 SW1配置文件提交
Dis cu 查看配置文件
Sw1:
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname sw1
[sw1]vlan 10
[sw1-vlan10]quit
[sw1]vlan 20
[sw1-vlan20]quit
[sw1]vlan 30
[sw1-vlan30]quit
[sw1]interface g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 10
[sw1-GigabitEthernet0/0/1]quit
[sw1]interface g0/0/2
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1-GigabitEthernet0/0/2]port default vlan 20
[sw1-GigabitEthernet0/0/2]quit
[sw1]int
[sw1]interface g0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 30
[sw1-GigabitEthernet0/0/3]quit
[sw1]interface Vlanif 10
[sw1-Vlanif10]ip address 192.168.1.1 24
[sw1-Vlanif10]quit
[sw1]interface Vlanif 20
[sw1-Vlanif20]ip address 172.16.1.1 24
[sw1-Vlanif20]quit
[sw1]interface Vlanif 30
[sw1-Vlanif30]ip address 10.1.1.2 24
[sw1-Vlanif30]quit
[sw1]ospf
[sw1-ospf-1]area 0
[sw1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]network 172.16.1.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
[sw1-ospf-1-area-0.0.0.0]quit
Ar1:
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname ar1
[ar1]interface g0/0/0
[ar1-GigabitEthernet0/0/0]ip address 10.1.1.1 24
[ar1-GigabitEthernet0/0/0]quit
[ar1]acl 2000
[ar1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[ar1-acl-basic-2000]rule deny source 172.16.1.0 0.0.0.255
[ar1-acl-basic-2000]rule deny source any
[ar1-acl-basic-2000]quit
[ar1]interface g0/0/1
[ar1-GigabitEthernet0/0/1]quit
[ar1]nat address-group 1 100.1.1.11 100.1.1.20
[ar1]interface g0/0/1
[ar1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1
[ar1-GigabitEthernet0/0/1]quit
[ar1]ospf
[ar1-ospf-1]area 0
[ar1-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
[ar1-ospf-1-area-0.0.0.0]network 100.1.1.0 0.0.0.255
[ar1-ospf-1-area-0.0.0.0]quit
<ar1>
R1:
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r1
[r1]interface e0/0/0
[r1-Ethernet0/0/0]ip address 100.1.1.2 24
[r1-Ethernet0/0/0]quit
Telnet远程验证
aaa模式
r2(目标主机):
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r2
[r2]user-interface vty 0 4
[r2-ui-vty0-4]user privilege level 15
[r2-ui-vty0-4]authentication-mode aaa
[r2-ui-vty0-4]quit
[r2]aaa
[r2-aaa]local-user lisi password cipher 1234
Info: Add a new user.
[r2-aaa]local-user lisi service-type telnet
[r2-aaa]local-user lisi privilege level 3
[r2-aaa]quit
[r2]interface g0/0/0
[r2-GigabitEthernet0/0/0]ip address 10.1.1.2 24
[r2-GigabitEthernet0/0/0]quit
[r2]
r1(客户端):
#在普通用户视图下验证
<Huawei>sys
[Huawei]undo inf en
[Huawei]sysname r1
[r1]interface g0/0/0
[r1-GigabitEthernet0/0/0]ip address 10.1.1.1 24
[r1-GigabitEthernet0/0/0]quit
[r1]quit
<r1>telnet 10.1.1.2
Press CTRL_] to quit telnet mode
Trying 10.1.1.2 ...
Connected to 10.1.1.2 ...
Login authentication
Username:lisi
Password:
<r2>quit
Configuration console exit, please retry to log on
The connection was closed by the remote host
<r1>
password模式
r2(目标)
set auth... password simple/cipher password
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo inf en
Info: Information center is disabled.
[Huawei]sysname r2
[r2]int
[r2]interface g0/0/0
[r2-GigabitEthernet0/0/0]ip address 10.1.1.12 24
[r2-GigabitEthernet0/0/0]quit
[r2]user-interface vty 0 4
[r2-ui-vty0-4]authentication-mode password
Please configure the login password (maximum length 16):123456
[r2-ui-vty0-4]user privilege l
[r2-ui-vty0-4]user privilege level 3
[r2-ui-vty0-4]
r1(客户)
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]undo inf en
Info: Information center is disabled.
[Huawei]sysname r1
[r1]interface g0/0/0
[r1-GigabitEthernet0/0/0]ip address 10.1.1.11 24
[r1-GigabitEthernet0/0/0]quit
[r1]quit
<r1>telnet 10.1.1.12
PPP
对端IP协商
路由器:AR22400
在设置中:添加serial接口
接口: serial
R1 R2
@--------------------------------@
ip 10.1.1.1/24 ip 10.1.1.100
[r1]interface Serial 4/0/0
[r1-Serial4/0/0]link-protocol ppp
[r1-Serial4/0/0]ip address 10.1.1.1 24
[r1-Serial4/0/0]remote address 10.1.1.20
[r2]interface Serial 4/0/0
[r2-Serial4/0/0]link-protocol ppp
[r2-Serial4/0/0]ip address ppp-negotiate
[r2-Serial4/0/0]quit
[r2]display ip interface brief
*down: administratively down
^down: standby
(l): loopback
(s): spoofing
The number of interface that is UP in Physical is 2
The number of interface that is DOWN in Physical is 4
The number of interface that is UP in Protocol is 2
The number of interface that is DOWN in Protocol is 4
Interface IP Address/Mask Physical Protocol
GigabitEthernet0/0/0 unassigned down down
GigabitEthernet0/0/1 unassigned down down
GigabitEthernet0/0/2 unassigned down down
NULL0 unassigned up up(s)
Serial4/0/0 10.1.1.20/32 up up
Serial4/0/1 unassigned down down
[r2]
PAP验证单向验证(双向验证调换配置即可)
路由器:Router
接口:serial
被验证方 主验证方
@--------------------------------@
R1 R2
被验证方
[Huawei]sysname r1
[r1]interface s0/0/0
[r1-Serial0/0/0]link-protocol ppp #使用ppp协议
[r1-Serial0/0/0]ip address 10.1.1.1 24
[r1-Serial0/0/0]ppp pap local-user liangyankun password cipher 202203290214
#配置用户名和密码cipher密文密码
[R1-Serial0/0/0]shutdown #关闭接口
[R1-Serial0/0/0]undo shutdown #打开接口
display cu
主验证方
<Huawei>system-view
[Huawei]undo inf en
[Huawei]sysname r2
[r2]interface s0/0/0
[r2-Serial0/0/0]link-protocol ppp
[r2-Serial0/0/0]ip address 10.1.1.2 24
[r2-Serial0/0/0]ppp authentication-mode pap (pap改为chap即为chap验证)
[r2-Serial0/0/0]quit
[r2]aaa
[r2-aaa]local-user liangyankun password cipher 202203290214
[r2-aaa]local-user liangyankun service-type ppp
[r2-aaa]quit
OSPF
1.创建逻辑接口
interface LoopBack0
ip address 2.2.2.2 255.255.255.0
2.配置OSPF Router ID
[Huawei] ospf router-id 2.2.2.2
3.重启ospf进程
在用户视图下
<Huawei> reset ospf process
4.查看OSPF协议运行状态
在系统视图下
[Huawei] display ospf brief
5,ospf的配置
<Huawei>system-view
[Huawei]undo inf enable
[Huawei]sysname R1
[R1]interface g0/0/1
[R1-GigabitEthernet0/0/1]ip add 10.1.1.1 24
[R1-GigabitEthernet0/0/1]quit
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 100.1.1.1 24
[R1-GigabitEthernet0/0/0]quit
[R1]ospf router-id 1.1.1.1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 100.1.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]quit
[R1-ospf-1]quit
[R1]display ip routing-table
OSPF多区域配置
VLAN
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]undo inf enable
Info: Information center is disabled.
[Huawei]sysname sw
[sw]vlan batch 5 6
Info: This operation may take a few seconds. Please wait for a moment...done.
[sw]interface g0/0/1
[sw-GigabitEthernet0/0/1]port link-type access
[sw-GigabitEthernet0/0/1]port default vlan 5
[sw-GigabitEthernet0/0/1]quit
[sw]interface g0/0/2
[sw-GigabitEthernet0/0/2]port link-type access
[sw-GigabitEthernet0/0/2]port default vlan 6
[sw-GigabitEthernet0/0/2]quit
[sw]interface Vlanif 5
[sw-Vlanif5]ip address 192.168.10.1 24
[sw-Vlanif5]quit
[sw]interface Vlanif 6
[sw-Vlanif6]ip address 192.168.20.1 24
交换机trunk口vlan
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname sw
[sw]undo inf enable
[sw]vlan 10
[sw-vlan10]vlan 20
[sw-vlan20]quit
[sw]interface g0/0/1
[sw-GigabitEthernet0/0/1]port link-type access
[sw-GigabitEthernet0/0/1]port default vlan 10
[sw-GigabitEthernet0/0/1]quit
[sw]interface g0/0/2
[sw-GigabitEthernet0/0/2]port link-type access
[sw-GigabitEthernet0/0/2]port default vlan 20
[sw-GigabitEthernet0/0/2]quit
[sw]interface g0/0/3
[sw-GigabitEthernet0/0/3]port link-type trunk
[sw-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
[sw-GigabitEthernet0/0/3]quit
RIP协议
RIP协议基本配置:
1.[Router] rip 全局启用rip协议并进入rip配置进程
举例:
[Huawei]rip
[Huawei-rip-1]
[Huawei]rip 100 100是进程号,只在本地起作用,用于区分不同的rip进程。
[Huawei-rip-100]
[Huawei-rip-100] version 2 设置rip的版本号,向下兼容。
[Huawei-rip-100] undo summary 关闭路由的自动聚合功能(防止路由黑洞)
rip默认会自动聚合路由信息
配置命令:
<Huawei>sys
[Huawei] undo info-center enable
[Huawei]sysname R2
[R2]interface Serial 0/0/0
[R2-Serial0/0/0]ip address 100.1.1.2 24
[R2-Serial0/0/0]quit
[R2]interface g0/0/0
[R2-GigabitEthernet0/0/0]ip address 172.16.1.1 24
[R2-GigabitEthernet0/0/0]quit
[R2] display ip routing-table
[R2]rip
[R2-rip-1]version 2
[R2-rip-1]undo summary
[R2-rip-1]network 172.16.0.0
[R2-rip-1]network 100.0.0.0
[R2-rip-1]quit
[R2]display ip routing-table
RIP/OSPF路由引入
路由引入:
在设备B上将RIP路由引入到OSPF:
router ospf 1
imp rip
可选地,如果需要从OSPF区域向RIP区域传递路由,则在设备B上将OSPF路由引入到RIP(通常不需要,因为RIP仅用于较小规模的网络且不支持复杂的度量值计算):
router rip
imp ospf
Eth-trunk(链路聚合)
[ZCS2]interface Eth-Trunk 1 #创建聚合端口
[ZCS2]interface g0/0/23 #进入接口
[ZCS2-GigabitEthernet0/0/23]eth-trunk 1 #将接口加入 聚合
Info: This operation may take a few seconds. Please wait for a moment...done.
[ZCS2-GigabitEthernet0/0/23]quit