一、实验扩扑
二、实验思路
1、首先在每个PC上把获取IP地址的方式改为DHCP。
2、接下来在每个交换机上配置vlan
3、最后在路由器上的子接口上配置IP地址作为网关,然后开启DHCP服务来给局域网内的PC分配地址,还需要配置ACL来实现实验需求,以及ospf动态路由来实现路由路由间的通信,最后配置console口的安全认证。
三、实验步骤
在PC1到PC6上把获取ip地址改为dhcp:
SW1:
<Huawei>sys
[Huawei]sysname SW1
[SW1]vlan 10
[SW1-vlan10]vlan 100
[SW1-vlan100]q
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type access
[SW1-GigabitEthernet0/0/1]port default vlan 10
[SW1-GigabitEthernet0/0/1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan
100[SW1-GigabitEthernet0/0/2]int g0/0/3
[SW1-GigabitEthernet0/0/3]port link-type trunk
[SW1-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 100
[SW1]dis port vlan active
SW2:
<Huawei>sys
[Huawei]sysname SW2
[SW2]vlan 30
[SW2-vlan30]vlan 120
[SW2-vlan120]q
[SW2]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link-type access
[SW2-GigabitEthernet0/0/2]port default vlan 30
[SW2-GigabitEthernet0/0/2]int g0/0/3
[SW2-GigabitEthernet0/0/3]port link-type access
[SW2-GigabitEthernet0/0/3]port default vlan 120
[SW2-GigabitEthernet0/0/3]int g0/0/1
[SW2-GigabitEthernet0/0/1]port link-type trunk
[SW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 30 120
[SW2-GigabitEthernet0/0/1]q
[SW2]dis port vlan active
SW3:
<Huawei>sys
[Huawei]sysname SW3
[SW3]vlan 20
[SW3-vlan20]vlan 110
[SW3-vlan110]q
[SW3]int g0/0/2
[SW3-GigabitEthernet0/0/2]port link-type access
[SW3-GigabitEthernet0/0/2]port default vlan 20
[SW3-GigabitEthernet0/0/2]int g0/0/3
[SW3-GigabitEthernet0/0/3]port link-type access
[SW3-GigabitEthernet0/0/3]port default vlan 110
[SW3-GigabitEthernet0/0/3]int g0/0/1
[SW3-GigabitEthernet0/0/1]port link-type trunk
[SW3-GigabitEthernet0/0/1]port trunk allow-pass vlan 20 110
[SW3]dis port vlan active
R1:
<Huawei>sys
[Huawei]sysname R1
[R1]int g0/0/0.10
[R1-GigabitEthernet0/0/0.10]ip add 192.168.10.254 24
[R1-GigabitEthernet0/0/0.10]dot1q termination vid 10
[R1-GigabitEthernet0/0/0.10]arp broadcast enable
[R1-GigabitEthernet0/0/0.10]int g0/0/0.100
[R1-GigabitEthernet0/0/0.100]ip add 192.168.100.254 24
[R1-GigabitEthernet0/0/0.100]dot1q termination vid 100
[R1-GigabitEthernet0/0/0.100]arp broadcast enable
[R1-GigabitEthernet0/0/0.100]q
[R1]dhcp enable
[R1]ip pool xx
[R1-ip-pool-xx]network 192.168.10.0
[R1-ip-pool-xx]gateway-list 192.168.10.254
[R1-ip-pool-xx]dns-list 8.8.8.8 114.114.114.114
[R1-ip-pool-xx]q
[R1]int g0/0/0.10
[R1-GigabitEthernet0/0/0.10]dhcp select global
[R1-GigabitEthernet0/0/0.10]q
[R1]ip pool aa
[R1-ip-pool-aa]network 192.168.100.0
[R1-ip-pool-aa]gateway-list 192.168.100.254
[R1-ip-pool-aa]dns-list 8.8.8.8 114.114.114.114
[R1-ip-pool-aa]int g0/0/0.100
[R1-GigabitEthernet0/0/0.100]dhcp select global
[R1-GigabitEthernet0/0/0.100]q
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 12.1.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 14.1.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 192.168.100.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]q
[R1-ospf-1]q
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 12.1.1.1 24
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]ip add 14.1.1.1 24
[R1-GigabitEthernet0/0/2]q
[R1]dis ip int b
[R1]dis ospf peer brief
[R1]dis ip routing-table protocol ospf
[R1]acl 3000
[R1-acl-adv-3000]rule deny ip source 192.168.10.0 0.0.0.255 destination 192.168.
100.0 0.0.0.255
[R1-acl-adv-3000]rule deny ip source 192.168.10.0 0.0.0.255 destination 192.168.
120.0 0.0.0.255
[R1-acl-adv-3000]rule deny ip source 192.168.10.0 0.0.0.255 destination 192.168.
30.0 0.0.0.255
[R1-acl-adv-3000]rule deny ip source 192.168.10.0 0.0.0.255 destination 192.168.
20.0 0.0.0.255
[R1-acl-adv-3000]rule deny ip source 192.168.10.0 0.0.0.255 destination 192.168.
110.0 0.0.0.255
[R1-acl-adv-3000]int g0/0/0.10
[R1-GigabitEthernet0/0/0.10]traffic-filter inbound acl 3000
[R1-GigabitEthernet0/0/0.10]q
[R1]acl 2000
[R1-acl-basic-2000]rule permit source 192.168.10.0 0.0.0.255
[R1-acl-basic-2000]rule permit source 192.168.100.0 0.0.0.255
[R1-acl-basic-2000]int g0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]nat outbound 2000
[R1-GigabitEthernet0/0/2]q
[R1]aaa
[R1-aaa]local-user admin password cipher admin privilege level 15
[R1-aaa]local-user admin service-type telnet
[R1-aaa]q
[R1]user-interface console 0
[R1-ui-console0]authentication-mode aaa
[R1-ui-console0]q
[R1]q
R2:
<Huawei>sys
[Huawei]sysname R2
[R2]int g0/0/2.30
[R2-GigabitEthernet0/0/2.30]ip add 192.168.30.254 24
[R2-GigabitEthernet0/0/2.30]dot1q termination vid 30
[R2-GigabitEthernet0/0/2.30]arp broadcast enable
[R2-GigabitEthernet0/0/2.30]int g0/0/2.120
[R2-GigabitEthernet0/0/2.120]ip add 192.168.120.254 24
[R2-GigabitEthernet0/0/2.120]dot1q termination vid 120
[R2-GigabitEthernet0/0/2.120]arp broadcast enable
[R2-GigabitEthernet0/0/2.120]q
[R2]dhcp enable
[R2]ip pool bb
[R2-ip-pool-bb]network 192.168.30.0
[R2-ip-pool-bb]gateway-list 192.168.30.254
[R2-ip-pool-bb]dns-list 8.8.8.8 114.114.114.114
[R2-ip-pool-bb]int g0/0/2.30
[R2-GigabitEthernet0/0/2.30]dhcp select global
[R2-GigabitEthernet0/0/2.30]q
[R2]ip pool jj
[R2-ip-pool-jj]network 192.168.120.0
[R2-ip-pool-jj]gateway-list 192.168.120.254
[R2-ip-pool-jj]dns-list 8.8.8.8 114.114.114.114
[R2-ip-pool-jj]int g0/0/2.120
[R2-GigabitEthernet0/0/2.120]dhcp select global
[R2-GigabitEthernet0/0/2.120]q
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 14.1.1.2 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip add 34.1.1.2 24
[R2-GigabitEthernet0/0/1]q
[R2]dis ip int b
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]network 14.1.1.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 34.1.1.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 192.168.30.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 192.168.120.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]q
[R2-ospf-1]q
[R2]dis ospf peer b
[R2]acl 3000
[R2-acl-adv-3000]rule deny ip source 192.168.30.0 0.0.0.255 destination 192.168.
120.0 0.0.0.255
[R2-acl-adv-3000]rule deny ip source 192.168.30.0 0.0.0.255 destination 192.168.
10.0 0.0.0.255
[R2-acl-adv-3000]rule deny ip source 192.168.30.0 0.0.0.255 destination 192.168.
100.0 0.0.0.255
[R2-acl-adv-3000]rule deny ip source 192.168.30.0 0.0.0.255 destination 192.168.
110.0 0.0.0.255
[R2-acl-adv-3000]rule deny ip source 192.168.30.0 0.0.0.255 destination 192.168.
20.0 0.0.0.25
[R2-acl-adv-3000]int g0/0/2.30
[R2-GigabitEthernet0/0/2.30]traffic-filter inbound acl 3000
[R2-GigabitEthernet0/0/2.30]q
[R2]acl 2000
[R2-acl-basic-2000]rule permit source 192.168.30.0 0.0.0.255
[R2-acl-basic-2000]rule permit source 192.168.120.0 0.0.0.255
[R2-acl-basic-2000]int g0/0/0
[R2-GigabitEthernet0/0/0]nat outbound 2000
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]nat outbound 2000
[R2-GigabitEthernet0/0/1]q
R3:
<Huawei>sys
[Huawei]sysname R3
[R3]int g0/0/1.20
[R3-GigabitEthernet0/0/1.20]ip add 192.168.20.254 24
[R3-GigabitEthernet0/0/1.20]dot1q termination vid 20
[R3-GigabitEthernet0/0/1.20]arp broadcast enable
[R3-GigabitEthernet0/0/1.20]int g0/0/1.110
[R3-GigabitEthernet0/0/1.110]ip add 192.168.110.254 24
[R3-GigabitEthernet0/0/1.110]dot1q termination vid 110
[R3-GigabitEthernet0/0/1.110]arp broadcast enable
[R3-GigabitEthernet0/0/1.110]q
[R3]dhcp enable
[R3]ip pool cc
[R3-ip-pool-cc]network 192.168.20.0
[R3-ip-pool-cc]gateway-list 192.168.20.254
[R3-ip-pool-cc]dns-list 8.8.8.8 114.114.114.114
[R3-ip-pool-cc]int g0/0/1.20
[R3-GigabitEthernet0/0/1.20]dhcp select global
[R3-GigabitEthernet0/0/1.20]q
[R3]ip pool dd
[R3-ip-pool-dd]network 192.168.110.0
[R3-ip-pool-dd]gateway-list 192.168.110.254
[R3-ip-pool-dd]dns-list 8.8.8.8 114.114.114.114
[R3-ip-pool-dd]int g0/0/1.110
[R3-GigabitEthernet0/0/1.110]dhcp select global
[R3-GigabitEthernet0/0/1.110]q
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip add 13.1.1.3 24
[R3-GigabitEthernet0/0/0]int g0/0/2
[R3-GigabitEthernet0/0/2]ip add 34.1.1.3 24
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]network 13.1.1.0 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 34.1.1.0 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 192.168.20.0 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 192.168.110.0 0.0.0.255
[R3-ospf-1-area-0.0.0.0]q
[R3-ospf-1]q
[R3]dis ip int b
[R3]dis ospf peer b
[R3]acl 2000
[R3-acl-basic-2000]rule permit source 192.168.20.0 0.0.0.255
[R3-acl-basic-2000]rule permit source 192.168.110.0 0.0.0.255
[R3-acl-basic-2000]int g0/0/0
[R3-GigabitEthernet0/0/0]nat outbound 2000
[R3-GigabitEthernet0/0/0]int g0/0/2
[R3-GigabitEthernet0/0/2]nat outbound 2000
[R3-GigabitEthernet0/0/2]q
R4:
<Huawei>sys
[Huawei]sysname R4
[R4]int g0/0/0
[R4-GigabitEthernet0/0/0]ip add 12.1.1.4 24
[R4-GigabitEthernet0/0/1]q
[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]network 12.1.1.0 0.0.0.255
[R4-ospf-1-area-0.0.0.0]network 13.1.1.0 0.0.0.255
[R4-ospf-1-area-0.0.0.0]q
[R4]dis ospf peer b
四、实验总结
这次的实验是一次小型的仿真实验,难度不大,总体来说还是比较好接受的。这也是第一次打这么大量的代码,好在比较容易,重复的比较多。不过,这里面也有一个问题,当设备很多很多的时候设备的命名和地址等配置都会比较多,这个时候就需要有逻辑梳理来保证自己不出错。同时,这样的实验也是比较考验基本功的,总体来说这次实验的收获还是很大的。