1 实验说明
① vlan 10、vlan 20 和 vlan 30 通过 DHCP 自动获取 IP、DNS 地址 和 Gateway
② vlan 10、vlan 20 和 vlan 30 之间可以相互通信,并且可以访问服务器 Server1
③ PC1 不能访问公网,而 PC2 和 PC 3 可以访问
④ 内网服务器发布地址为 64.1.1.3,PC 4 可以访问(这里我理解错误)
⑤ 内网服务器域名为 www.hc.com
2 实验
命令设置:
# LSW3
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan 20
[Huawei-vlan20]q
[Huawei]vlan 30
[Huawei-vlan30]q
[Huawei]int g 0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 20
[Huawei-GigabitEthernet0/0/2]q
[Huawei]int g 0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 30
[Huawei-GigabitEthernet0/0/3]q
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan all
# LSW1 丢失部分
[Huawei-Vlanif10]dhcp select interface
[Huawei-Vlanif10]q
[Huawei]dhcp select interface
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]dhcp select interface
[Huawei-Vlanif20]interface Vlanif 30
[Huawei-Vlanif30]dhcp select interface
[Huawei-Vlanif30]dhcp server dns-list 172.16.1.100
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]dhcp server dns-list 172.16.1.100
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]dhcp server dns-list 172.16.1.100
[Huawei-Vlanif20]q
[Huawei]dis ip int b
*down: administratively down
^down: standby
(l): loopback
(s): spoofing
The number of interface that is UP in Physical is 6
The number of interface that is DOWN in Physical is 1
The number of interface that is UP in Protocol is 5
The number of interface that is DOWN in Protocol is 2
Interface IP Address/Mask Physical Protocol
MEth0/0/1 unassigned down down
NULL0 unassigned up up(s)
Vlanif1 unassigned up down
Vlanif10 192.168.10.254/24 up up
Vlanif20 192.168.20.254/24 up up
Vlanif30 192.168.30.254/24 up up
Vlanif40 172.16.1.254/24 up up
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]dis this
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 10
#
return
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g 0/0/2
[Huawei-GigabitEthernet0/0/2]dis this
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
return
[Huawei-GigabitEthernet0/0/2]q
[Huawei]int
[Huawei]interface vl
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]dis this
#
interface Vlanif10
ip address 192.168.10.254 255.255.255.0
dhcp select interface
dhcp server dns-list 172.16.1.100
#
return
[Huawei-Vlanif10]q
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]dis this
#
interface Vlanif20
ip address 192.168.20.254 255.255.255.0
dhcp select interface
dhcp server dns-list 172.16.1.100
#
return
[Huawei-Vlanif20]q
[Huawei]interface Vlanif 30
[Huawei-Vlanif30]dis this
#
interface Vlanif30
ip address 192.168.30.254 255.255.255.0
dhcp select interface
dhcp server dns-list 172.16.1.100
#
return
[Huawei-Vlanif30]q
[Huawei]interface Vlanif 40
[Huawei-Vlanif40]dis this
#
interface Vlanif40
ip address 172.16.1.254 255.255.255.0
#
return
[Huawei]int g 0/0/4
[Huawei-GigabitEthernet0/0/4]dis this
#
interface GigabitEthernet0/0/4
port link-type access
port default vlan 40
#
return
[Huawei-GigabitEthernet0/0/4]q
[Huawei]vlan 50
[Huawei-vlan50]q
[Huawei]interface Vlanif 50
[Huawei-Vlanif50]ip address 10.10.10.2 24
[Huawei-Vlanif50]q
[Huawei]int g 0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 50
[Huawei-GigabitEthernet0/0/3]q
[Huawei]ip route-static 0.0.0.0 0.0.0.0 10.10.10.1
# AR1
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int g 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 10.10.10.1 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 64.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 0.0.0.0 0.0.0.0 64.1.1.254
[Huawei]ip route-static 192.168.0.0 255.255.0.0 10.10.10.2
[Huawei]ip route-static 172.16.1.0 255.255.255.0 10.10.10.2
[Huawei]acl name intranet basic
[Huawei-acl-basic-intranet]rule permit source 192.128.0.0 0.0.255.255
[Huawei-acl-basic-intranet]q
[Huawei]nat address-group 1 64.1.1.5 64.1.1.6
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2999 address-group 1
[Huawei]acl name testDeny
[Huawei-acl-adv-testDeny]rule deny ip source 192.168.10.0 0.0.0.255
[Huawei-acl-adv-testDeny]rule permit ip source any destination any
[Huawei-GigabitEthernet0/0/0]traffic-filter inbound acl name testDeny
# AR2
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int g 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 64.1.1.254 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 8.8.8.254 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g 0/0/2
[Huawei-GigabitEthernet0/0/2]ip address 9.9.9.254 24
[Huawei-GigabitEthernet0/0/2]q
[Huawei]ip route-static 192.168.0.0 255.255.0.0 64.1.1.1
[Huawei]ip route-static 172.16.1.100 255.255.255.0 64.1.1.1
3 测试