LSW1配置:
vlan batch 10 20 30 //添加vlan
interface Ethernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/2
port link-type access
port default vlan 20
#
interface Ethernet0/0/3
port link-type access
port default vlan 30
#
interface Ethernet0/0/4
port link-type access
port default vlan 10
AR1配置:
vlan batch 10 20 30 //添加vlan
dhcp enable //开启DHCP功能
interface GigabitEthernet0/0/0.10 //在子接口上配置DHCP
dot1q termination vid 10 //封装vlan
ip address 192.168.10.254 255.255.255.0
arp broadcast enable //开启arp广播
dhcp select interface //配置基于接口的DHCP
#
interface GigabitEthernet0/0/0.20
dot1q termination vid 20
ip address 192.168.20.254 255.255.255.0
arp broadcast enable
dhcp select interface
#
interface GigabitEthernet0/0/0.30
dot1q termination vid 30
ip address 192.168.30.254 255.255.255.0
arp broadcast enable
dhcp select interface
#
interface GigabitEthernet0/0/1
ip address 192.168.1.1 255.255.255.0
#
ospf 1
area 0.0.0.0
network 192.168.1.0 0.0.0.255
network 192.168.10.0 0.0.0.255
network 192.168.20.0 0.0.0.255
network 192.168.30.0 0.0.0.255
AR2:
interface GigabitEthernet0/0/0
ip address 192.168.40.254 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 192.168.1.2 255.255.255.0
#
interface GigabitEthernet0/0/2
ip address 192.168.2.1 255.255.255.0
#
ospf 1
area 0.0.0.0
network 192.168.1.0 0.0.0.255
network 192.168.2.0 0.0.0.255
network 192.168.40.0 0.0.0.255
AR3:
acl number 2000 //配置ACL
rule 5 permit source 192.168.0.0 0.0.255.255 //用于NAT,运行所有数据通行
#
acl number 3000 //配置高级ACL
rule 5 deny ip source 192.168.50.1 0 destination 192.168.40.1 0 //禁止PC4(192.168.50.1)访问服务器的www服务器(192.168.40.1)
#
nat address-group 1 200.200.200.4 200.200.200.6 //动态NAT
#
interface Serial1/0/0
link-protocol ppp
ip address 200.200.200.1 255.255.255.0
nat outbound 2000 address-group 1 //将动态NAT和ACL 2000 绑定,实现内部网络与运营商提供互联网连接,实现上网功能,所有Pc、服务器均可连接互联网
#
interface GigabitEthernet0/0/0
ip address 192.168.50.254 255.255.255.0
traffic-filter outbound acl 3000 //将ACL应用到接口上,禁止PC4访问服务器的www服务器
#
int g 0/0/0.1
dot1q termination vid 50子端口封装
arp broadcast enable广播
#
interface GigabitEthernet0/0/1
ip address 192.168.2.2 255.255.255.0
#
ospf 1
default-route-advertise always //宣告默认路由
area 0.0.0.0
network 192.168.2.0 0.0.0.255
network 192.168.50.0 0.0.0.255
network 200.200.200.0 0.0.0.255
#
ip route-static 0.0.0.0 0.0.0.0 200.200.200.2 //配置默认路由
LSW2:
Vlan50
#
interface Ethernet0/0/1
port link-type access
port default vlan 50
#
interface Ethernet0/0/2
port link-type access
port default vlan 50
#
interface Ethernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
AR4:
interface Serial1/0/0
link-protocol ppp
ip address 200.200.200.2 255.255.255.0
最后就可以进行测试了