华为练习1

配置LSW1和AR1-AR3的VLAN,DHCP服务,以及OSPF路由协议。AR2和AR3涉及ACL规则以控制网络访问,并配置NAT实现互联网连接。AR3中还包含了动态NAT和默认路由的设定,以允许内部网络访问互联网。
摘要由CSDN通过智能技术生成

LSW1配置:

vlan batch 10 20 30 //添加vlan

interface Ethernet0/0/1

port link-type trunk

port trunk allow-pass vlan 2 to 4094

#

interface Ethernet0/0/2

port link-type access

port default vlan 20

#

interface Ethernet0/0/3

port link-type access

port default vlan 30

#

interface Ethernet0/0/4

port link-type access

port default vlan 10

AR1配置:

vlan batch 10 20 30 //添加vlan

dhcp enable //开启DHCP功能

interface GigabitEthernet0/0/0.10 //在子接口上配置DHCP

dot1q termination vid 10 //封装vlan

ip address 192.168.10.254 255.255.255.0

arp broadcast enable //开启arp广播

dhcp select interface //配置基于接口的DHCP

#

interface GigabitEthernet0/0/0.20

dot1q termination vid 20

ip address 192.168.20.254 255.255.255.0

arp broadcast enable

dhcp select interface

#

interface GigabitEthernet0/0/0.30

dot1q termination vid 30

ip address 192.168.30.254 255.255.255.0

arp broadcast enable

dhcp select interface

#

interface GigabitEthernet0/0/1

ip address 192.168.1.1 255.255.255.0

#

ospf 1

area 0.0.0.0

network 192.168.1.0 0.0.0.255

network 192.168.10.0 0.0.0.255

network 192.168.20.0 0.0.0.255

network 192.168.30.0 0.0.0.255

AR2:

interface GigabitEthernet0/0/0

ip address 192.168.40.254 255.255.255.0

#

interface GigabitEthernet0/0/1

ip address 192.168.1.2 255.255.255.0

#

interface GigabitEthernet0/0/2

ip address 192.168.2.1 255.255.255.0

#

ospf 1

area 0.0.0.0

network 192.168.1.0 0.0.0.255

network 192.168.2.0 0.0.0.255

network 192.168.40.0 0.0.0.255

AR3:

acl number 2000 //配置ACL

rule 5 permit source 192.168.0.0 0.0.255.255 //用于NAT,运行所有数据通行

#

acl number 3000 //配置高级ACL

rule 5 deny ip source 192.168.50.1 0 destination 192.168.40.1 0 //禁止PC4(192.168.50.1)访问服务器的www服务器(192.168.40.1)

#

nat address-group 1 200.200.200.4 200.200.200.6 //动态NAT

#

interface Serial1/0/0

link-protocol ppp

ip address 200.200.200.1 255.255.255.0

nat outbound 2000 address-group 1 //将动态NAT和ACL 2000 绑定,实现内部网络与运营商提供互联网连接,实现上网功能,所有Pc、服务器均可连接互联网

#

interface GigabitEthernet0/0/0

ip address 192.168.50.254 255.255.255.0

traffic-filter outbound acl 3000 //将ACL应用到接口上,禁止PC4访问服务器的www服务器

#

int g 0/0/0.1

dot1q termination vid 50子端口封装

arp broadcast enable广播

#

interface GigabitEthernet0/0/1

ip address 192.168.2.2 255.255.255.0

#

ospf 1

default-route-advertise always //宣告默认路由

area 0.0.0.0

network 192.168.2.0 0.0.0.255

network 192.168.50.0 0.0.0.255

network 200.200.200.0 0.0.0.255

#

ip route-static 0.0.0.0 0.0.0.0 200.200.200.2 //配置默认路由

LSW2:

Vlan50

#

interface Ethernet0/0/1

port link-type access

port default vlan 50

#

interface Ethernet0/0/2

port link-type access

port default vlan 50

#

interface Ethernet0/0/3

port link-type trunk

port trunk allow-pass vlan 2 to 4094

AR4:

interface Serial1/0/0

link-protocol ppp

ip address 200.200.200.2 255.255.255.0

最后就可以进行测试了

评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值