ensp实操

 HCIA

路由器配置dhcp

1.两个交换机下的同一vlan主机互通

 让pc1可以ping通pc3

1.配置pc的ip:1.1.1.1~1.1.1.4,子网掩码为255.255.255.0

 2.配置交换机的接口的vlan

 进入系统视图创建vlan 10和vlan 20

system-view

vlan 10

vlan 20

 进入接口g0/0/1,设置接口类型并绑定vlan

 int g0/0/1

port link-type access

port default vlan 10

同样的方法设置g0/0/2

 int g0/0/2

port link-type access

port default vlan 20

查看vlan

 设置g0/0/3的接口类型并设置放行的vlan值

int g0/0/3

port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20

 同样的方法设置交换机2

 用pc1 ping 一下pc4

 可以ping通

表示设置成功

2.三层交换机使用

1.pc1的IP为1.1.1.2,网关为1.1.1.254,pc3的IP为2.2.2.2网关为2.2.2.254

2.配置交换机的g0/0/1和g0/0/2的接口类型为access并分配vlan10和vlan 20

int g0/0/1

port link-type access

port default vlan 10

3.同样的方法设置g0/0/2

 int g0/0/2

port link-type access

port default vlan 20

 4.设置g0/0/3的接口类型并设置放行的vlan值

int g0/0/3

port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20

配置交换机4的g0/01的接口为trunk并放行vlan 10和vlan20

vlan 10

vlan 20

int g0/0/1

port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20

设置vlan10的网关为1.1.1.254 255.255.255.0

interface vlan 10

ip address 1.1.1.254 255.255.255.0

设置vlan 20的网关为2.2.2.254 255.255.255.0

interface vlan 20

ip address 2.2.2.254 255.255.255.0

设置完使用pc1 ping pc3,可以ping通

 单臂路由

 pc1

 pc2

交换机配置同上

1.pc1的IP为1.1.1.2,网关为1.1.1.254,pc3的IP为2.2.2.2网关为2.2.2.254

2.配置交换机的g0/0/1和g0/0/2的接口类型为access并分配vlan10和vlan 20

int g0/0/1

port link-type access

port default vlan 10

3.同样的方法设置g0/0/2

 int g0/0/2

port link-type access

port default vlan 20

 4.设置g0/0/3的接口类型并设置放行的vlan值

int g0/0/3

port link-type trunk
port trunk allow-pass vlan 10
port trunk allow-pass vlan 20

路由器配置

1.设置g0/0/0的两个子接口g0/0/0.10和g0/0/0.20

int g0/0/0.10

int g0/0/0.20

2.配置 g0/0/0.10

分配vlan 10 :dot1q termination vid 10 
开启arp广播:arp broadcast enable
分配ip:ip address 1.1.1.254 255.255.255.0

2.配置 g0/0/0.20

分配vlan 20 :dot1q termination vid 20 
开启arp广播:arp broadcast enable
分配ip:ip address 2.2.2.254 255.255.255.0

测试

acl访问控制

基本配置如上

pc3

在最上层交换机上配置访问控制

新建规则:acl name test advance

设置192.168.10.0网段的ip无法访问192.168.30.0的ip:rule deny ip source 192.168.10.0 0.0.0.255 destination 192.168.30.0 0.0.0.255
允许其它ip正常访问:rule permit ip source any destination any

选择接口执行规则

[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]traffic-filter inbound acl name test

测试:pc1可以ping通192.168.20.1,无法ping通192.68.30.1

Nat地址转换

[Huawei] acl name neiwang basic
[Huawei-acl-basic-neiwang] rule permit source 192.168.0.0 0.0.255.255

[Huawei-acl-basic-neiwang] q
[Huawei] nat address-group 1 202.1.2.16 202.1.2.20

[Huawei] dis acl all

[Huawei] int g0/0/1

[Huawei-GigabitEthernet0/0/1] nat outbound 2999 address-group 1


OSPF实例

设置AR3

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 10.0.12.1 24  设置ip
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 10.0.13.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int Loop    
[Huawei]int LoopBack 0    设置loopback
[Huawei-LoopBack0]ip address 10.0.1.1 24  
[Huawei-LoopBack0]q
[Huawei]ospf 1 router-id 10.0.1.1 设置ospf
[Huawei-ospf-1]area 0      设置区域
[Huawei-ospf-1-area-0.0.0.0]network 10.0.1.0 0.0.0.255      发布网段到区域0
[Huawei-ospf-1-area-0.0.0.0]network 10.0.12.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 10.0.13.0 0.0.0.255

设置AR1

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 10.0.12.2 24  设置ip
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int loopback0     设置loopback
[Huawei-LoopBack0]ip address 10.0.2.2 24
[Huawei-LoopBack0]q
[Huawei]ospf 1 router-id 10.0.2.2   设置ospf
[Huawei-ospf-1]area 0   设置区域
[Huawei-ospf-1-area-0.0.0.0]network 10.0.2.0 0.0.0.255   发布网段到区域0
[Huawei-ospf-1-area-0.0.0.0]network 10.0.12.0 0.0.0.25

设置AR2

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 10.0.13.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int loopback 0
[Huawei-LoopBack0]ip address 10.0.3.3 24
[Huawei-LoopBack0]q
[Huawei]ospf 1 router-id 10.0.3.3
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 10.0.3.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 10.0.13.0 0.0.0.255

验证

查看邻居表

[Huawei]dis ospf peer

     OSPF Process 1 with Router ID 10.0.3.3
         Neighbors 

 Area 0.0.0.0 interface 10.0.13.2(GigabitEthernet0/0/0)'s neighbors
 Router ID: 10.0.1.1         Address: 10.0.13.1       
   State: Full  Mode:Nbr is  Slave  Priority: 1
   DR: 10.0.13.1  BDR: 10.0.13.2  MTU: 0    
   Dead timer due in 36  sec 
   Retrans timer interval: 5 
   Neighbor is up for 00:00:16     
   Authentication Sequence: [ 0 ] 

静态Nat

让pc2可以访问pc1

AR1

<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]ip route-static 172.168.1.0 255.255.255.0 202.1.1.1      配置静态路由
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat server global 202.1.1.3 inside 192.168.1.2配置静态nat地址转换
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.1 255.255.255.0
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 202.1.1.2 255.255.255.0

AR2

<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 202.1.1.1 255.255.255.0 
[Huawei-GigabitEthernet0/0/0]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 172.168.1.1 255.255.255.0

pc2可以ping通pc的公网地址,但是ping不通他的私网地址

 设备远程管理

1.配置云的网卡,绑定虚拟网卡

2.配置路由器

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.211.10 255.255.255.0
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]auth    
[Huawei-ui-vty0-4]authentication-mode aaa
[Huawei-ui-vty0-4]aaa
[Huawei-aaa]local-user testuser password cipher 123456
Info: Add a new user.
[Huawei-aaa]local-user testuser privilege level 15
[Huawei-aaa]local-user testuser service-type telnet
[Huawei-aaa]q
[Huawei]telnet server enable

配置完后就可以用cmd远程配置路由器

 中小型网络实操

 Server1

 LSW3

1.创建vlan

vlan batch 20 30

2.分配vlan

int e0/0/2

port link-type access

port default vlan 20

q

int e0/0/3

port link-type access

port default vlan 30

q

int e0/0/1

port link-type trunk

port trunk allow-pass vlan all

LSW1

1.创建vlan

vlan batch 10 20 30 40 100

2.开启dhcp

dhcp enable

3.给各vlan分配ip并开启dhcp

int vlan 10

ip address 192.168.10.1 255.255.255.0

dhcp select interface
dhcp server dns-list 172.168.100.2

int vlan 20

ip address 192.168.20.1 255.255.255.0

dhcp select interface
dhcp server dns-list 172.168.100.2

int vlan 30

ip address 192.168.30.1 255.255.255.0

dhcp select interface
dhcp server dns-list 172.168.100.2

int vlan 40

ip address 172.168.100.1 255.255.255.0

int vlan 100

ip address 10.10.10.2 255.255.255.0

4.绑定接口

int g0/0/1

port link-type access

port default vlan 100

int g0/0/2 

port link-type access

port default vlan 10

int g0/0/3

port link-type trunk

port trunk allow-pass vlan all

int g0/0/4

port link-type access

port default vlan 40

5.配置去AR1的静态路由

ip route-static 0.0.0.0 0.0.0.0 10.10.10.1

AR1配置

配置ip

int g0/0/1

ip address 10.10.10.1 24

int g0/0/0

ip address 64.1.1.1 255.255.255.0

配置静态路由

ip route-static 0.0.0.0 0.0.0.0 64.1.1.10

ip route-static 192.168.0.0 255.255.0.0 10.10.10.2

ip route-static 172.168.100.0 255.255.255.0 10.10.10.2

配置nat地址转换

[Huawei]acl 2000

[Huawei-acl-basic-2000]rule permit source 192.168.0.0 0.0.255.255

[Huawei-acl-basic-2000]q
[Huawei]nat address-group 1 64.1.1.5 64.1.1.6

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]nat outbound 2000 address-group 1

配置静态nat服务器

[Huawei-GigabitEthernet0/0/0]nat server global 64.1.1.3 inside 172.168.100.2

配置192.168.10.x拒绝访问外网

[Huawei]acl 2001
[Huawei-acl-basic-2001]rule deny source 192.168.10.0 0.0.0.255
[Huawei-acl-basic-2001]rule permit source any
[Huawei-acl-basic-2001]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]traffic-filter inbound acl 2001

wlan实验配置

LSW2

[Huawei]vlan 192
[Huawei-vlan192]q

[Huawei]int e0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 192

[Huawei]int e0/0/1
[Huawei-Ethernet0/0/1]port link-type trunk
[Huawei-Ethernet0/0/1]port trunk allow-pass vlan all

AC1

[AC6005]vlan batch 100 172
[AC6005]int vlan 100
[AC6005-Vlanif100]ip address 100.100.100.100 24
[AC6005-Vlanif100]q
[AC6005]int g0/0/1
[AC6005-GigabitEthernet0/0/1]port link-type trunk
[AC6005-GigabitEthernet0/0/1]port trunk  allow-pass vlan all

[AC6005]ip route-static 0.0.0.0 24 100.100.100.1

[AC6005]capwap source interface vlan 100  ac配置和ap对接的vlanif接口

配置wlan

[AC6005]wlan
[AC6005-wlan-view]ssid-profile name ssid-chj
[AC6005-wlan-ssid-prof-ssid-chj]ssid chj  配置wlan的ssid

[AC6005-wlan-view]wlan
[AC6005-wlan-view]security-profile name sec-chj
[AC6005-wlan-sec-prof-sec-chj]security wpa-wpa2 psk pass-phrase a1234567 aes 配置wlan的密码

配置vap,加入ssid后分配到哪个vlan

[AC6005]wlan
[AC6005-wlan-view]vap-profile name vap-chj
[AC6005-wlan-vap-prof-vap-chj]forward-mode tunnel
[AC6005-wlan-vap-prof-vap-chj]service-vlan vlan-id 172

[AC6005-wlan-vap-prof-vap-chj]ssid-profile ssid-chj
Info: This operation may take a few seconds, please wait.done.
[AC6005-wlan-vap-prof-vap-chj]security-profile sec-chj

[AC6005]wlan  创建ap组并关联vap
[AC6005-wlan-view]ap-group name group-chj
[AC6005-wlan-ap-group-group-chj]vap-profile vap-chj wlan 1 radio all

将ap加入ac

[AC6005]wlan
[AC6005-wlan-view]ap auth-mode mac-auth
[AC6005-wlan-view]ap-id 0 ap-mac 00e0-fc1b-0730
[AC6005-wlan-ap-0]ap-name ap-chj
[AC6005-wlan-ap-0]ap-group group-chj

LSW1

[Huawei]vlan batch 100 192 172 200

[Huawei]int vlan 100
[Huawei-Vlanif100]ip address 100.100.100.1 24
[Huawei-Vlanif100]q

[Huawei]int vlan 200
[Huawei-Vlanif200]ip address 200.200.200.1 24
[Huawei-Vlanif200]q

[Huawei]int vlan 172
[Huawei-Vlanif172]ip address 172.16.10.254 24
[Huawei-Vlanif172]q

[Huawei]int vlan 192
[Huawei-Vlanif192]ip address 192.168.10.254 24
[Huawei-Vlanif192]q

设置ap地址池,并让设备自动获取

[Huawei]ip pool foap

[Huawei-ip-pool-foap]network 192.168.10.0 mask 255.255.255.0

[Huawei-ip-pool-foap]gateway-list 192.168.10.254

[Huawei-ip-pool-foap]option 43 sub-option 2 ip-address 100.100.100.100

[Huawei-ip-pool-foap]int vlan 192
[Huawei-Vlanif192]dhcp select global

配置接口

int g0/0/1
port link-type trunk
port trunk allow-pass vlan all

int g0/0/2
port link-type trunk
port trunk allow-pass vlan all

ap1

查看ap的mac地址

<Huawei>dis interface vlan 1
Vlanif1 current state : UP
Line protocol current state : UP
Last line protocol up time : 2023-09-25 10:00:18 UTC-05:13
Description:HUAWEI, AP Series, Vlanif1 Interface
Route Port,The Maximum Transmit Unit is 1500
Internet Address is allocated by DHCP, 192.168.10.253/24
IP Sending Frames' Format is PKTFMT_ETHNT_2, Hardware address is 00e0-fc2c-07e0
Current system time: 2023-09-25 13:49:09-05:13
    Input bandwidth utilization  : --
    Output bandwidth utilization : --

HCIP

路由引入

让不一样协议的路由通过中间路由配置使两边连通

AR1配置

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 1.1.1.1 24   配置ip
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ospf 1    配置ospf
[Huawei-ospf-1]ar 0
[Huawei-ospf-1-area-0.0.0.0]network 1.1.1.0 0.0.0.255   
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q

AR3配置

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.1.2 24
[Huawei-GigabitEthernet0/0/0]q

[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.2.1 24

[Huawei-GigabitEthernet0/0/1]q
[Huawei]rip 1
[Huawei-rip-1]version 2
[Huawei-rip-1]network 192.168.1.0
[Huawei-rip-1]network 192.168.2.0
[Huawei-rip-1]dis this
[V200R003C00]
#
rip 1
 version 2
 network 192.168.1.0
 network 192.168.2.0
#
return
[Huawei-rip-1]q

AR2配置

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 1.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q

[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 192.168.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ospf 1
[Huawei-ospf-1]ar 0
[Huawei-ospf-1-area-0.0.0.0]network 1.1.1.0 0.0.0.255
[Huawei]rip 1      配置rip
[Huawei-rip-1]verify-source   
[Huawei-rip-1]version 2
[Huawei-rip-1]network 192.168.1.0     不用掩码
[Huawei-rip-1]q
[Huawei]ospf 1    
[Huawei-ospf-1]import-route rip 1 cost 123     ospf引入rip   可以使用csot或者routing-policy设置优先级
[Huawei-ospf-1]q

[Huawei]rip 1
[Huawei-rip-1]import-route ospf 1 cost 3     rip引入ospf
[Huawei-rip-1]q

测试

  防火墙使用nat访问外网

防火墙不用默认的g0/0/0口,G0/0/0口有域与vpn实例关联的策略vpn实例不存在。想在local域ping通0/0/0口的电脑IP需要先放行local域至trust的策略
security-policy
rule name local-trust
source-zone local
destination trust
action permit
此时ping电脑ip还是无法不通再这样
int g0/0/0
undo  ip binding vpn-instance default
ip add 192.168.0.1 24
service-manager ping permit
再ping电脑ip就通了。。。

GE0/0/0初始配置特殊,所以不用它

防火墙配置

Username:admin
Password:Admin@123
The password needs to be changed. Change now? [Y/N]: y
Please enter old password: 
Please enter new password: 
Please confirm new password: 

先修改密码

<USG6000V1>sys  进入系统视图
[USG6000V1]int g1/0/0
[USG6000V1-GigabitEthernet1/0/0]ip address 12.1.1.254 24      配置ip
[USG6000V1-GigabitEthernet1/0/0]service-manage all permit   开启服务
[USG6000V1-GigabitEthernet1/0/0]q
[USG6000V1]int g1/0/1
[USG6000V1-GigabitEthernet1/0/1]ip address 192.168.1.254 24    
[USG6000V1-GigabitEthernet1/0/1]service-manage all permit
[USG6000V1-GigabitEthernet1/0/1]q    
[USG6000V1]firewall zone trust        进入信任区,添加接口
[USG6000V1-zone-trust]add int g1/0/1
[USG6000V1-zone-trust]q    
[USG6000V1]firewall zone untrust     进入非信任区,添加接口
[USG6000V1-zone-untrust]add int g1/0/0
[USG6000V1-zone-untrust]q
[USG6000V1]ip route-static 1.1.1.0 255.255.255.0 12.1.1.1        配置去路由器的静态路由
[USG6000V1]nat-policy     配置nat
[USG6000V1-policy-nat]rule name ttoun
[USG6000V1-policy-nat-rule-ttoun]source-zone trust    
[USG6000V1-policy-nat-rule-ttoun]destination-zone untrust
[USG6000V1-policy-nat-rule-ttoun]source-address 192.168.1.0 mask 255.255.255.0        
[USG6000V1-policy-nat-rule-ttoun]action source-nat easy-ip 
[USG6000V1-policy-nat-rule-ttoun]q
[USG6000V1-policy-nat]q    
[USG6000V1]security-policy   配置安全域
[USG6000V1-policy-security]rule name ttu
[USG6000V1-policy-security-rule-ttu]source-zone trust    
[USG6000V1-policy-security-rule-ttu]destination-zone untrust
[USG6000V1-policy-security-rule-ttu]service icmp    
[USG6000V1-policy-security-rule-ttu]action permit
[USG6000V1-policy-security-rule-ttu]q
[USG6000V1-policy-security]q

路由器配置

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 12.1.1.1 24
[Huawei-GigabitEthernet0/0/0]q

​​​​​​​[Huawei]ip route-static 192.168.1.0 255.255.255.0 12.1.1.254

[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 1.1.1.254 24

测试

  • 2
    点赞
  • 19
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值