HCIA
路由器配置dhcp
1.两个交换机下的同一vlan主机互通
让pc1可以ping通pc3
1.配置pc的ip:1.1.1.1~1.1.1.4,子网掩码为255.255.255.0
2.配置交换机的接口的vlan
进入系统视图创建vlan 10和vlan 20
system-view
vlan 10
vlan 20
进入接口g0/0/1,设置接口类型并绑定vlan
int g0/0/1
port link-type access
port default vlan 10
同样的方法设置g0/0/2
int g0/0/2
port link-type access
port default vlan 20
查看vlan
设置g0/0/3的接口类型并设置放行的vlan值
int g0/0/3
port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20
同样的方法设置交换机2
用pc1 ping 一下pc4
可以ping通
表示设置成功
2.三层交换机使用
1.pc1的IP为1.1.1.2,网关为1.1.1.254,pc3的IP为2.2.2.2网关为2.2.2.254
2.配置交换机的g0/0/1和g0/0/2的接口类型为access并分配vlan10和vlan 20
int g0/0/1
port link-type access
port default vlan 10
3.同样的方法设置g0/0/2
int g0/0/2
port link-type access
port default vlan 20
4.设置g0/0/3的接口类型并设置放行的vlan值
int g0/0/3
port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20
配置交换机4的g0/01的接口为trunk并放行vlan 10和vlan20
vlan 10
vlan 20
int g0/0/1
port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20
设置vlan10的网关为1.1.1.254 255.255.255.0
interface vlan 10
ip address 1.1.1.254 255.255.255.0
设置vlan 20的网关为2.2.2.254 255.255.255.0
interface vlan 20
ip address 2.2.2.254 255.255.255.0
设置完使用pc1 ping pc3,可以ping通
单臂路由
pc1
pc2
交换机配置同上
1.pc1的IP为1.1.1.2,网关为1.1.1.254,pc3的IP为2.2.2.2网关为2.2.2.254
2.配置交换机的g0/0/1和g0/0/2的接口类型为access并分配vlan10和vlan 20
int g0/0/1
port link-type access
port default vlan 10
3.同样的方法设置g0/0/2
int g0/0/2
port link-type access
port default vlan 20
4.设置g0/0/3的接口类型并设置放行的vlan值
int g0/0/3
port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20
路由器配置
1.设置g0/0/0的两个子接口g0/0/0.10和g0/0/0.20
int g0/0/0.10
int g0/0/0.20
2.配置 g0/0/0.10
分配vlan 10 :dot1q termination vid 10
开启arp广播:arp broadcast enable
分配ip:ip address 1.1.1.254 255.255.255.0
2.配置 g0/0/0.20
分配vlan 20 :dot1q termination vid 20
开启arp广播:arp broadcast enable
分配ip:ip address 2.2.2.254 255.255.255.0
测试
acl访问控制
基本配置如上
pc3
在最上层交换机上配置访问控制
新建规则:acl name test advance
设置192.168.10.0网段的ip无法访问192.168.30.0的ip:rule deny ip source 192.168.10.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
允许其它ip正常访问:rule permit ip source any destination any
选择接口执行规则
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]traffic-filter inbound acl name test
测试:pc1可以ping通192.168.20.1,无法ping通192.68.30.1
Nat地址转换
[Huawei] acl name neiwang basic
[Huawei-acl-basic-neiwang] rule permit source 192.168.0.0 0.0.255.255
[Huawei-acl-basic-neiwang] q
[Huawei] nat address-group 1 202.1.2.16 202.1.2.20
[Huawei] dis acl all
[Huawei] int g0/0/1
[Huawei-GigabitEthernet0/0/1] nat outbound 2999 address-group 1
OSPF实例
设置AR3
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 10.0.12.1 24 设置ip
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 10.0.13.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int Loop
[Huawei]int LoopBack 0 设置loopback
[Huawei-LoopBack0]ip address 10.0.1.1 24
[Huawei-LoopBack0]q
[Huawei]ospf 1 router-id 10.0.1.1 设置ospf
[Huawei-ospf-1]area 0 设置区域
[Huawei-ospf-1-area-0.0.0.0]network 10.0.1.0 0.0.0.255 发布网段到区域0
[Huawei-ospf-1-area-0.0.0.0]network 10.0.12.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 10.0.13.0 0.0.0.255
设置AR1
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 10.0.12.2 24 设置ip
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int loopback0 设置loopback
[Huawei-LoopBack0]ip address 10.0.2.2 24
[Huawei-LoopBack0]q
[Huawei]ospf 1 router-id 10.0.2.2 设置ospf
[Huawei-ospf-1]area 0 设置区域
[Huawei-ospf-1-area-0.0.0.0]network 10.0.2.0 0.0.0.255 发布网段到区域0
[Huawei-ospf-1-area-0.0.0.0]network 10.0.12.0 0.0.0.25
设置AR2
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 10.0.13.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int loopback 0
[Huawei-LoopBack0]ip address 10.0.3.3 24
[Huawei-LoopBack0]q
[Huawei]ospf 1 router-id 10.0.3.3
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 10.0.3.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 10.0.13.0 0.0.0.255
验证
查看邻居表
[Huawei]dis ospf peer
OSPF Process 1 with Router ID 10.0.3.3
Neighbors
Area 0.0.0.0 interface 10.0.13.2(GigabitEthernet0/0/0)'s neighbors
Router ID: 10.0.1.1 Address: 10.0.13.1
State: Full Mode:Nbr is Slave Priority: 1
DR: 10.0.13.1 BDR: 10.0.13.2 MTU: 0
Dead timer due in 36 sec
Retrans timer interval: 5
Neighbor is up for 00:00:16
Authentication Sequence: [ 0 ]
静态Nat
让pc2可以访问pc1
AR1
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]ip route-static 172.168.1.0 255.255.255.0 202.1.1.1 配置静态路由
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat server global 202.1.1.3 inside 192.168.1.2配置静态nat地址转换
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.1 255.255.255.0
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 202.1.1.2 255.255.255.0
AR2
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 202.1.1.1 255.255.255.0
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 172.168.1.1 255.255.255.0
pc2可以ping通pc的公网地址,但是ping不通他的私网地址
设备远程管理
1.配置云的网卡,绑定虚拟网卡
2.配置路由器
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.211.10 255.255.255.0
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]auth
[Huawei-ui-vty0-4]authentication-mode aaa
[Huawei-ui-vty0-4]aaa
[Huawei-aaa]local-user testuser password cipher 123456
Info: Add a new user.
[Huawei-aaa]local-user testuser privilege level 15
[Huawei-aaa]local-user testuser service-type telnet
[Huawei-aaa]q
[Huawei]telnet server enable
配置完后就可以用cmd远程配置路由器
中小型网络实操
Server1
LSW3
1.创建vlan
vlan batch 20 30
2.分配vlan
int e0/0/2
port link-type access
port default vlan 20
q
int e0/0/3
port link-type access
port default vlan 30
q
int e0/0/1
port link-type trunk
port trunk allow-pass vlan all
LSW1
1.创建vlan
vlan batch 10 20 30 40 100
2.开启dhcp
dhcp enable
3.给各vlan分配ip并开启dhcp
int vlan 10
ip address 192.168.10.1 255.255.255.0
dhcp select interface
dhcp server dns-list 172.168.100.2
int vlan 20
ip address 192.168.20.1 255.255.255.0
dhcp select interface
dhcp server dns-list 172.168.100.2
int vlan 30
ip address 192.168.30.1 255.255.255.0
dhcp select interface
dhcp server dns-list 172.168.100.2
int vlan 40
ip address 172.168.100.1 255.255.255.0
int vlan 100
ip address 10.10.10.2 255.255.255.0
4.绑定接口
int g0/0/1
port link-type access
port default vlan 100
int g0/0/2
port link-type access
port default vlan 10
int g0/0/3
port link-type trunk
port trunk allow-pass vlan all
int g0/0/4
port link-type access
port default vlan 40
5.配置去AR1的静态路由
ip route-static 0.0.0.0 0.0.0.0 10.10.10.1
AR1配置
配置ip
int g0/0/1
ip address 10.10.10.1 24
int g0/0/0
ip address 64.1.1.1 255.255.255.0
配置静态路由
ip route-static 0.0.0.0 0.0.0.0 64.1.1.10
ip route-static 192.168.0.0 255.255.0.0 10.10.10.2
ip route-static 172.168.100.0 255.255.255.0 10.10.10.2
配置nat地址转换
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 192.168.0.0 0.0.255.255
[Huawei-acl-basic-2000]q
[Huawei]nat address-group 1 64.1.1.5 64.1.1.6
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]nat outbound 2000 address-group 1
配置静态nat服务器
[Huawei-GigabitEthernet0/0/0]nat server global 64.1.1.3 inside 172.168.100.2
配置192.168.10.x拒绝访问外网
[Huawei]acl 2001
[Huawei-acl-basic-2001]rule deny source 192.168.10.0 0.0.0.255
[Huawei-acl-basic-2001]rule permit source any
[Huawei-acl-basic-2001]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]traffic-filter inbound acl 2001
wlan实验配置
LSW2
[Huawei]vlan 192
[Huawei-vlan192]q
[Huawei]int e0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 192
[Huawei]int e0/0/1
[Huawei-Ethernet0/0/1]port link-type trunk
[Huawei-Ethernet0/0/1]port trunk allow-pass vlan all
AC1
[AC6005]vlan batch 100 172
[AC6005]int vlan 100
[AC6005-Vlanif100]ip address 100.100.100.100 24
[AC6005-Vlanif100]q
[AC6005]int g0/0/1
[AC6005-GigabitEthernet0/0/1]port link-type trunk
[AC6005-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[AC6005]ip route-static 0.0.0.0 24 100.100.100.1
[AC6005]capwap source interface vlan 100 ac配置和ap对接的vlanif接口
配置wlan
[AC6005]wlan
[AC6005-wlan-view]ssid-profile name ssid-chj
[AC6005-wlan-ssid-prof-ssid-chj]ssid chj 配置wlan的ssid
[AC6005-wlan-view]wlan
[AC6005-wlan-view]security-profile name sec-chj
[AC6005-wlan-sec-prof-sec-chj]security wpa-wpa2 psk pass-phrase a1234567 aes 配置wlan的密码
配置vap,加入ssid后分配到哪个vlan
[AC6005]wlan
[AC6005-wlan-view]vap-profile name vap-chj
[AC6005-wlan-vap-prof-vap-chj]forward-mode tunnel
[AC6005-wlan-vap-prof-vap-chj]service-vlan vlan-id 172
[AC6005-wlan-vap-prof-vap-chj]ssid-profile ssid-chj
Info: This operation may take a few seconds, please wait.done.
[AC6005-wlan-vap-prof-vap-chj]security-profile sec-chj
[AC6005]wlan 创建ap组并关联vap
[AC6005-wlan-view]ap-group name group-chj
[AC6005-wlan-ap-group-group-chj]vap-profile vap-chj wlan 1 radio all
将ap加入ac
[AC6005]wlan
[AC6005-wlan-view]ap auth-mode mac-auth
[AC6005-wlan-view]ap-id 0 ap-mac 00e0-fc1b-0730
[AC6005-wlan-ap-0]ap-name ap-chj
[AC6005-wlan-ap-0]ap-group group-chj
LSW1
[Huawei]vlan batch 100 192 172 200
[Huawei]int vlan 100
[Huawei-Vlanif100]ip address 100.100.100.1 24
[Huawei-Vlanif100]q
[Huawei]int vlan 200
[Huawei-Vlanif200]ip address 200.200.200.1 24
[Huawei-Vlanif200]q
[Huawei]int vlan 172
[Huawei-Vlanif172]ip address 172.16.10.254 24
[Huawei-Vlanif172]q
[Huawei]int vlan 192
[Huawei-Vlanif192]ip address 192.168.10.254 24
[Huawei-Vlanif192]q
设置ap地址池,并让设备自动获取
[Huawei]ip pool foap
[Huawei-ip-pool-foap]network 192.168.10.0 mask 255.255.255.0
[Huawei-ip-pool-foap]gateway-list 192.168.10.254
[Huawei-ip-pool-foap]option 43 sub-option 2 ip-address 100.100.100.100
[Huawei-ip-pool-foap]int vlan 192
[Huawei-Vlanif192]dhcp select global
配置接口
int g0/0/1
port link-type trunk
port trunk allow-pass vlan all
int g0/0/2
port link-type trunk
port trunk allow-pass vlan all
ap1
查看ap的mac地址
<Huawei>dis interface vlan 1
Vlanif1 current state : UP
Line protocol current state : UP
Last line protocol up time : 2023-09-25 10:00:18 UTC-05:13
Description:HUAWEI, AP Series, Vlanif1 Interface
Route Port,The Maximum Transmit Unit is 1500
Internet Address is allocated by DHCP, 192.168.10.253/24
IP Sending Frames' Format is PKTFMT_ETHNT_2, Hardware address is 00e0-fc2c-07e0
Current system time: 2023-09-25 13:49:09-05:13
Input bandwidth utilization : --
Output bandwidth utilization : --
HCIP
路由引入
让不一样协议的路由通过中间路由配置使两边连通
AR1配置
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 1.1.1.1 24 配置ip
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ospf 1 配置ospf
[Huawei-ospf-1]ar 0
[Huawei-ospf-1-area-0.0.0.0]network 1.1.1.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
AR3配置
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.2.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 192.168.1.0
[Huawei-rip-1]network 192.168.2.0
[Huawei-rip-1]dis this
[V200R003C00]
#
rip 1
version 2
network 192.168.1.0
network 192.168.2.0
#
return
[Huawei-rip-1]q
AR2配置
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 1.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ospf 1
[Huawei-ospf-1]ar 0
[Huawei-ospf-1-area-0.0.0.0]network 1.1.1.0 0.0.0.255
[Huawei]rip 1 配置rip
[Huawei-rip-1]verify-source
[Huawei-rip-1]version 2
[Huawei-rip-1]network 192.168.1.0 不用掩码
[Huawei-rip-1]q
[Huawei]ospf 1
[Huawei-ospf-1]import-route rip 1 cost 123 ospf引入rip 可以使用csot或者routing-policy设置优先级
[Huawei-ospf-1]q
[Huawei]rip 1
[Huawei-rip-1]import-route ospf 1 cost 3 rip引入ospf
[Huawei-rip-1]q
测试
防火墙使用nat访问外网
防火墙不用默认的g0/0/0口,G0/0/0口有域与vpn实例关联的策略vpn实例不存在。想在local域ping通0/0/0口的电脑IP需要先放行local域至trust的策略
security-policy
rule name local-trust
source-zone local
destination trust
action permit
此时ping电脑ip还是无法不通再这样
int g0/0/0
undo ip binding vpn-instance default
ip add 192.168.0.1 24
service-manager ping permit
再ping电脑ip就通了。。。
GE0/0/0初始配置特殊,所以不用它
防火墙配置
Username:admin
Password:Admin@123
The password needs to be changed. Change now? [Y/N]: y
Please enter old password:
Please enter new password:
Please confirm new password:
先修改密码
<USG6000V1>sys 进入系统视图
[USG6000V1]int g1/0/0
[USG6000V1-GigabitEthernet1/0/0]ip address 12.1.1.254 24 配置ip
[USG6000V1-GigabitEthernet1/0/0]service-manage all permit 开启服务
[USG6000V1-GigabitEthernet1/0/0]q
[USG6000V1]int g1/0/1
[USG6000V1-GigabitEthernet1/0/1]ip address 192.168.1.254 24
[USG6000V1-GigabitEthernet1/0/1]service-manage all permit
[USG6000V1-GigabitEthernet1/0/1]q
[USG6000V1]firewall zone trust 进入信任区,添加接口
[USG6000V1-zone-trust]add int g1/0/1
[USG6000V1-zone-trust]q
[USG6000V1]firewall zone untrust 进入非信任区,添加接口
[USG6000V1-zone-untrust]add int g1/0/0
[USG6000V1-zone-untrust]q
[USG6000V1]ip route-static 1.1.1.0 255.255.255.0 12.1.1.1 配置去路由器的静态路由
[USG6000V1]nat-policy 配置nat
[USG6000V1-policy-nat]rule name ttoun
[USG6000V1-policy-nat-rule-ttoun]source-zone trust
[USG6000V1-policy-nat-rule-ttoun]destination-zone untrust
[USG6000V1-policy-nat-rule-ttoun]source-address 192.168.1.0 mask 255.255.255.0
[USG6000V1-policy-nat-rule-ttoun]action source-nat easy-ip
[USG6000V1-policy-nat-rule-ttoun]q
[USG6000V1-policy-nat]q
[USG6000V1]security-policy 配置安全域
[USG6000V1-policy-security]rule name ttu
[USG6000V1-policy-security-rule-ttu]source-zone trust
[USG6000V1-policy-security-rule-ttu]destination-zone untrust
[USG6000V1-policy-security-rule-ttu]service icmp
[USG6000V1-policy-security-rule-ttu]action permit
[USG6000V1-policy-security-rule-ttu]q
[USG6000V1-policy-security]q
路由器配置
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 12.1.1.1 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 192.168.1.0 255.255.255.0 12.1.1.254
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.254 24
测试