目录
一、实验准备
实验要求
1、内网互联互通:PC1-PC6能够相互ping通;
2、内网能够联通外部服务器Server1 202.10.102.100;
3、内部路由器AR能够获取外部服务器Server1 202.10.102.100的FTP服务;
4、LSW1为vlan100,vlan300的根桥,vlan200,vlan400的备份根桥。LSW2为vlan200,vlan400的根桥,vlan100,vlan300的备份根桥;
5、LSW1为vlan100,vlan300的vrrp master 网关,vlan200,vlan400的backup网关。LSW2为vlan200,vlan400的vrrp master网关,vlan100,vlan300的backup网关。
实验涉及知识点
OSPF+RIP+VRRP+MSTP+单臂路由+NAT+ACL+静态链路聚合
二、实验流程
实验拓扑图
注意:ENSP的所有设备,在我们输入命令之后,会弹出消息提醒可以输入以下命令关闭:
info-center source DS channel 0 log state off trap state off
LSW4的配置(二层交换机)
<LSW4>dis cu
#
sysname LSW4
#
info-center source DS channel 0 log state off trap state off
#
vlan batch 100 200
#
stp instance 1 root primary
stp instance 2 root primary
stp instance 3 root secondary
stp instance 4 root secondary
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name huawei
revision-level 1
instance 1 vlan 100
instance 2 vlan 200
instance 3 vlan 300
instance 4 vlan 400
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Ethernet0/0/1
port link-type access
port default vlan 100
#
interface Ethernet0/0/2
port link-type access
port default vlan 200
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
LSW5的配置(二层交换机)
<LSW5>dis cu
#
sysname LSW5
#
info-center source DS channel 0 log state off trap state off
#
vlan batch 300 400
#
stp instance 1 root secondary
stp instance 2 root secondary
stp instance 3 root primary
stp instance 4 root primary
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name huawei
revision-level 1
instance 1 vlan 100
instance 2 vlan 200
instance 3 vlan 300
instance 4 vlan 400
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Ethernet0/0/1
port link-type access
port default vlan 300
#
interface Ethernet0/0/2
port link-type access
port default vlan 400
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
LSW1的配置(三层交换机)
<LSW1>dis cu
#
sysname LSW1
#
info-center source DS channel 0 log state off trap state off
#
vlan batch 100 200 300 400 555
#
stp instance 1 root primary
stp instance 2 root secondary
stp instance 3 root primary
stp instance 4 root secondary
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name huawei
revision-level 1
instance 1 vlan 100
instance 2 vlan 200
instance 3 vlan 300
instance 4 vlan 400
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif100
ip address 192.168.1.10 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.1.1
vrrp vrid 1 priority 105
vrrp vrid 1 track interface GigabitEthernet0/0/1
#
interface Vlanif200
ip address 192.168.2.10 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.2.2
#
interface Vlanif300
ip address 192.168.3.10 255.255.255.0
vrrp vrid 3 virtual-ip 192.168.3.3
vrrp vrid 3 priority 105
vrrp vrid 3 track interface GigabitEthernet0/0/1
#
interface Vlanif400
ip address 192.168.4.10 255.255.255.0
vrrp vrid 4 virtual-ip 192.168.4.4
#
interface Vlanif555
ip address 192.168.15.100 255.255.255.0
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 555
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/4
eth-trunk 1
#
interface GigabitEthernet0/0/5
eth-trunk 1
#
interface GigabitEthernet0/0/6
eth-trunk 1
#
interface GigabitEthernet0/0/7
eth-trunk 1
#
ospf 1
area 0.0.0.0
network 192.168.15.0 0.0.0.255
network 192.168.0.0 0.0.255.255
#
user-interface con 0
user-interface vty 0 4
#
return
LSW2的配置(三层交换机)
<LSW2>dis cu
#
sysname LSW2
#
info-center source DS channel 0 log state off trap state off
#
vlan batch 100 200 300 400 666
#
stp instance 1 root secondary
stp instance 2 root primary
stp instance 3 root secondary
stp instance 4 root primary
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name huawei
revision-level 1
instance 1 vlan 100
instance 2 vlan 200
instance 3 vlan 300
instance 4 vlan 400
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif100
ip address 192.168.1.20 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.1.1
#
interface Vlanif200
ip address 192.168.2.20 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.2.2
vrrp vrid 2 priority 105
vrrp vrid 2 track interface GigabitEthernet0/0/3
#
interface Vlanif300
ip address 192.168.3.20 255.255.255.0
vrrp vrid 3 virtual-ip 192.168.3.3
#
interface Vlanif400
ip address 192.168.4.20 255.255.255.0
vrrp vrid 4 virtual-ip 192.168.4.4
vrrp vrid 4 priority 105
vrrp vrid 4 track interface GigabitEthernet0/0/3
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 666
#
interface GigabitEthernet0/0/4
eth-trunk 1
#
interface GigabitEthernet0/0/5
eth-trunk 1
#
interface GigabitEthernet0/0/6
eth-trunk 1
#
interface GigabitEthernet0/0/7
eth-trunk 1
#
interface NULL0
#
ospf 1
area 0.0.0.0
network 192.168.16.0 0.0.0.255
network 192.168.0.0 0.0.255.255
#
user-interface con 0
user-interface vty 0 4
#
return
<LSW2>
LSW6的配置(二层交换机)
<LSW6>dis cu
#
sysname LSW6
#
info-center source DS channel 0 log state off trap state off
#
vlan batch 500 600
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Ethernet0/0/1
port link-type access
port default vlan 500
#
interface Ethernet0/0/2
port link-type access
port default vlan 600
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return
<LSW6>
AR1的配置
<AR1>dis cu
#
sysname AR1
#
nat alg ftp enable
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 202.10.101.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 202.10.102.1 255.255.255.0
#
AR2的配置
<AR2>dis cu
[V200R003C00]
#
sysname AR2
#
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
#
clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
drop illegal-mac alarm
#
vlan batch 555 666
#
set cpu-usage threshold 80 restore 75
#
acl number 2000
rule 0 permit
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-user admin service-type http
#
firewall zone Local
priority 15
#
interface Vlanif555
ip address 192.168.15.2 255.255.255.0
#
interface Vlanif666
ip address 192.168.16.2 255.255.255.0
#
interface Ethernet0/0/0
port link-type access
#
interface Ethernet0/0/1
port link-type access
port default vlan 555
#
interface Ethernet0/0/2
#
interface Ethernet0/0/3
port link-type access
port default vlan 666
#
interface GigabitEthernet0/0/0
ip address 202.10.101.2 255.255.255.0
nat outbound 2000
#
interface GigabitEthernet0/0/1
ip address 192.168.10.2 255.255.255.0
#
interface NULL0
#
ospf 1
default-route-advertise always
area 0.0.0.0
network 192.168.0.0 0.0.255.255
network 192.168.10.0 0.0.0.255
network 192.168.15.0 0.0.0.255
network 192.168.16.0 0.0.0.255
#
ip route-static 0.0.0.0 0.0.0.0 202.10.101.1
#
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
#
wlan ac
#
return
<AR2>
AR3的配置
<AR3>dis cu
#
sysname AR3
#
info-center source DS channel 0 log state off trap state off
#
nat alg ftp enable
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 192.168.10.3 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 192.168.20.3 255.255.255.0
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
ospf 1
import-route rip 1 cost 10
area 0.0.0.0
network 192.168.10.0 0.0.0.255
#
rip 1
undo summary
default-route originate
version 2
network 192.168.20.0
import-route ospf 1 cost 0
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
AR4的配置
<AR4>dis cu
#
sysname AR4
#
info-center source DS channel 0 log state off trap state off
#
nat alg ftp enable
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 192.168.20.4 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 192.168.30.4 255.255.255.0
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
rip 1
undo summary
version 2
network 192.168.20.0
network 192.168.30.0
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
AR5的配置
<AR5>dis cu
#
sysname AR5
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 192.168.30.5 255.255.255.0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/1.1
dot1q termination vid 500
ip address 192.168.5.5 255.255.255.0
arp broadcast enable
#
interface GigabitEthernet0/0/1.2
dot1q termination vid 600
ip address 192.168.6.6 255.255.255.0
arp broadcast enable
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
rip 1
undo summary
version 2
network 192.168.30.0
network 192.168.5.0
network 192.168.6.0
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
<AR5>
server1的配置
启动FTP
三、实验结果
检查各路由器的路由表
AR2的路由表,可以看到192.168.5.0/24和192.168.6.0/24的OSPF外部路由
<AR2>dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 29 Routes : 29
Destination/Mask Proto Pre Cost Flags NextHop Interface
0.0.0.0/0 Static 60 0 RD 202.10.101.1 GigabitEthernet
0/0/0
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.1.0/24 OSPF 10 2 D 192.168.15.100 Vlanif555
192.168.1.1/32 OSPF 10 2 D 192.168.15.100 Vlanif555
192.168.2.0/24 OSPF 10 2 D 192.168.15.100 Vlanif555
192.168.2.2/32 OSPF 10 3 D 192.168.15.100 Vlanif555
192.168.3.0/24 OSPF 10 2 D 192.168.15.100 Vlanif555
192.168.3.3/32 OSPF 10 2 D 192.168.15.100 Vlanif555
192.168.4.0/24 OSPF 10 2 D 192.168.15.100 Vlanif555
192.168.4.4/32 OSPF 10 3 D 192.168.15.100 Vlanif555
192.168.5.0/24 O_ASE 150 10 D 192.168.10.3 GigabitEthernet
0/0/1
192.168.6.0/24 O_ASE 150 10 D 192.168.10.3 GigabitEthernet
0/0/1
192.168.10.0/24 Direct 0 0 D 192.168.10.2 GigabitEthernet
0/0/1
192.168.10.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
192.168.10.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
192.168.15.0/24 Direct 0 0 D 192.168.15.2 Vlanif555
192.168.15.2/32 Direct 0 0 D 127.0.0.1 Vlanif555
192.168.15.255/32 Direct 0 0 D 127.0.0.1 Vlanif555
192.168.16.0/24 Direct 0 0 D 192.168.16.2 Vlanif666
192.168.16.2/32 Direct 0 0 D 127.0.0.1 Vlanif666
192.168.16.255/32 Direct 0 0 D 127.0.0.1 Vlanif666
192.168.20.0/24 O_ASE 150 10 D 192.168.10.3 GigabitEthernet
0/0/1
192.168.30.0/24 O_ASE 150 10 D 192.168.10.3 GigabitEthernet
0/0/1
202.10.101.0/24 Direct 0 0 D 202.10.101.2 GigabitEthernet
0/0/0
202.10.101.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
202.10.101.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
AR3
<AR3>dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 20 Routes : 20
Destination/Mask Proto Pre Cost Flags NextHop Interface
0.0.0.0/0 O_ASE 150 1 D 192.168.10.2 GigabitEthernet
0/0/0
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.1.0/24 OSPF 10 3 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.1.1/32 OSPF 10 3 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.2.0/24 OSPF 10 3 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.2.2/32 OSPF 10 4 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.3.0/24 OSPF 10 3 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.3.3/32 OSPF 10 3 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.4.0/24 OSPF 10 3 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.4.4/32 OSPF 10 4 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.5.0/24 RIP 100 2 D 192.168.20.4 GigabitEthernet
0/0/1
192.168.6.0/24 RIP 100 2 D 192.168.20.4 GigabitEthernet
0/0/1
192.168.10.0/24 Direct 0 0 D 192.168.10.3 GigabitEthernet
0/0/0
192.168.10.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
192.168.15.0/24 OSPF 10 2 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.16.0/24 OSPF 10 2 D 192.168.10.2 GigabitEthernet
0/0/0
192.168.20.0/24 Direct 0 0 D 192.168.20.3 GigabitEthernet
0/0/1
192.168.20.3/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
192.168.30.0/24 RIP 100 1 D 192.168.20.4 GigabitEthernet
0/0/1
<AR3>
AR4的路由表,可以看到192.168.1.0/24和192.168.2.0/24的RIP路由
<AR4>dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 20 Routes : 20
Destination/Mask Proto Pre Cost Flags NextHop Interface
0.0.0.0/0 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.1.0/24 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.1.1/32 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.2.0/24 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.2.2/32 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.3.0/24 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.3.3/32 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.4.0/24 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.4.4/32 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.5.0/24 RIP 100 1 D 192.168.30.5 GigabitEthernet
0/0/1
192.168.6.0/24 RIP 100 1 D 192.168.30.5 GigabitEthernet
0/0/1
192.168.10.0/24 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.15.0/24 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.16.0/24 RIP 100 1 D 192.168.20.3 GigabitEthernet
0/0/0
192.168.20.0/24 Direct 0 0 D 192.168.20.4 GigabitEthernet
0/0/0
192.168.20.4/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
192.168.30.0/24 Direct 0 0 D 192.168.30.4 GigabitEthernet
0/0/1
192.168.30.4/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
<AR4>
AR5
<AR5>dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 23 Routes : 23
Destination/Mask Proto Pre Cost Flags NextHop Interface
0.0.0.0/0 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.1.0/24 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.1.1/32 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.2.0/24 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.2.2/32 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.3.0/24 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.3.3/32 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.4.0/24 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.4.4/32 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.5.0/24 Direct 0 0 D 192.168.5.5 GigabitEthernet
0/0/1.1
192.168.5.5/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1.1
192.168.5.100/32 Direct 0 0 D 192.168.5.100 GigabitEthernet
0/0/1.1
192.168.6.0/24 Direct 0 0 D 192.168.6.6 GigabitEthernet
0/0/1.2
192.168.6.6/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1.2
192.168.6.100/32 Direct 0 0 D 192.168.6.100 GigabitEthernet
0/0/1.2
192.168.10.0/24 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.15.0/24 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.16.0/24 RIP 100 2 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.20.0/24 RIP 100 1 D 192.168.30.4 GigabitEthernet
0/0/0
192.168.30.0/24 Direct 0 0 D 192.168.30.5 GigabitEthernet
0/0/0
192.168.30.5/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
<AR5>
验证内网互通,PC1可以ping通PC5
验证内网主机能访问外网服务器,PC5可以ping通Server1
路由器上获取服务器开启的服务,AR2可以访问Server1的ftp服务
输入FTP服务器(本机PC)的用户名和密码后,使用ls命令可以看到文件列表:
四、遇到的问题
1、使用ENSP的Router做AR2路由器会出现NAT功能使用不了的bug,如果使用Router做AR路由器,所有的内网PC都无法ping通AR2的G0/0/0口,建议使用AR1220做AR2
检查NAT是否正常,在PC5上长ping触发NAT转换
AR2上检查NAT会话 dis nat session number
dis nat session all
2、AR2上的ethernet无法配置IP地址,配置成二层access口,加入到vlan中
#
interface Vlanif555
ip address 192.168.15.2 255.255.255.0
#
interface Vlanif666
ip address 192.168.16.2 255.255.255.0
#
interface Ethernet0/0/0
port link-type access
#
interface Ethernet0/0/1
port link-type access
port default vlan 555
#
interface Ethernet0/0/2
#
interface Ethernet0/0/3
port link-type access
port default vlan 666
#
interface GigabitEthernet0/0/0
ip address 202.10.101.2 255.255.255.0
nat outbound 2000
#
interface GigabitEthernet0/0/1
ip address 192.168.10.2 255.255.255.0
#