华为项目实验

实验目的 

增强分析和配置中小型企业网络的综合能力

实验内容

本实验模拟了一个企业网络场景, 其中R1和R2为公司总部路由器,交换机S1、S2、S3组成了总部的园区网,R3、R4、 R5为公司分部的路由器。 总部园区网中3台交换机都运行MSTP协议,用来防止二层冗余网络中的环路以及实现 不同VLAN间流量的负载分担,同时还配置了MSTP保护功能以提高网络的可靠性和安全性。 R1、R2、S2、S3运行IS-IS路协议,以实现总部网络的互通。S2和S3使用IS-IS 下发的缺省路由访问总部之外的网络。另外,为了提高网络的安全性,还需要配置IS-IS 认证功能。 R3、R4、R5运行OSPF路由协议,以实现公司分部网络的互通。总部与分部之间 通过BGP路由协议互通,同时需要通过修改BGP路由的属性来实现流量的负载分担。

实验拓补图

实验步骤

1.先配置好图中的IP地址和Loopback 0 接口

[r5]int LoopBack 0
[r5-LoopBack0]ip address 10.0.5.5 32
[r5-LoopBack0]int LoopBack 1
[r5-LoopBack1]ip address 20.0.5.5 32
[r5-LoopBack1]q
[r5]interface GigabitEthernet 0/0/0
[r5-GigabitEthernet0/0/0]ip address 10.0.35.5 24
[r5-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r5-GigabitEthernet0/0/1]ip address 10.0.45.5 24

[r3]interface LoopBack 0
[r3-LoopBack0]ip address 10.0.4.4 32
[r3-LoopBack0]q
[r3]interface GigabitEthernet 0/0/0
[r3-GigabitEthernet0/0/0]ip address 10.0.35.3 24
[r3-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/2
[r3-GigabitEthernet0/0/2]ip address 10.0.34.3 24
[r3-GigabitEthernet0/0/2]interface GigabitEthernet 0/0/1
[r3-GigabitEthernet0/0/1]ip address 10.0.13.3 24


[r4]interface LoopBack 0
[r4-LoopBack0]ip address 10.0.4.4 32
[r4-LoopBack0]q
[r4]interface GigabitEthernet 0/0/0
[r4-GigabitEthernet0/0/0]ip address 10.0.34.4 24
[r4-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r4-GigabitEthernet0/0/1]ip address 10.0.45.4 24
[r4-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[r4-GigabitEthernet0/0/2]ip address 10.0.24.4 24

[r1]interface LoopBack 0
[r1-LoopBack0]ip address 10.0.1.1 24
[r1-LoopBack0]q
[r1]interface GigabitEthernet 0/0/1
[r1-GigabitEthernet0/0/1]ip address 10.0.13.1 24
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]ip address 10.0.12.1 24
[r1-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/2
[r1-GigabitEthernet0/0/2]ip address 10.0.17.1 24
[r1-GigabitEthernet0/0/2]interface GigabitEthernet 2/0/0
[r1-GigabitEthernet2/0/0]ip address 10.0.18.1 24

[r2]interface LoopBack 0
[r2-LoopBack0]ip address 10.0.2.2 32
[r2-LoopBack0]q
[r2]interface GigabitEthernet 0/0/2
[r2-GigabitEthernet0/0/2]ip address 10.0.24.2 24
[r2-GigabitEthernet0/0/2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 10.0.12.2 24
[r2-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]ip address 10.0.28.2 24
[r2-GigabitEthernet0/0/1]interface GigabitEthernet 2/0/0
[r2-GigabitEthernet2/0/0]ip address 10.0.27.2 24

[s2]interface LoopBack 0
[s2-LoopBack0]ip address 10.0.7.7 32
[s2]vlan batch 71 72
[s2]interface Vlanif 71
[s2-Vlanif71]ip address 10.0.17.7 24
[s2-Vlanif71]interface Vlanif 72
[s2-Vlanif72]ip address 10.0.27.7 24
[s2]interface GigabitEthernet 0/0/4
[s2-GigabitEthernet0/0/4]port link-type access
[s2-GigabitEthernet0/0/4]port default vlan 72
[s2]interface GigabitEthernet 0/0/2
[s2-GigabitEthernet0/0/2]port link-type access 
[s2-GigabitEthernet0/0/2]port default vlan 71

[s3]interface LoopBack 0
[s3-LoopBack0]ip address 10.0.8.8 32
[s3]vlan batch 81 82
[s3]interface Vlanif 81
[s3-Vlanif81]ip address 10.0.18.8 24
[s3-Vlanif81]interface Vlanif 82
[s3-Vlanif82]ip address 10.0.28.8 24
[s3]interface GigabitEthernet 0/0/1
[s3-GigabitEthernet0/0/1]port link-type access
[s3-GigabitEthernet0/0/1]port default vlan 82
[s3-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/4
[s3-GigabitEthernet0/0/4]port link-type access
[s3-GigabitEthernet0/0/4]port default vlan 81

2.s1到s3都开始创建vlan  {vlan batch 2 3 4 10 20 30 }

然后把相连的接口变为Trunk端口,允许其他vlan通行

[s1]interface GigabitEthernet 0/0/1
[s1-GigabitEthernet0/0/1]port link-type trunk
[s1-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3 10 20 30
[s1-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[s1-GigabitEthernet0/0/2]port link-type trunk
[s1-GigabitEthernet0/0/2]port trunk allow-pass vlan 2 3 10 20 30

[s2]interface GigabitEthernet 0/0/1
[s2-GigabitEthernet0/0/1]port link-type trunk
[s2-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3 10 20 30
[s2-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/3
[s2-GigabitEthernet0/0/3]port link-type trunk
[s2-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 3 10 20 30

[s3]interface GigabitEthernet 0/0/2
[s3-GigabitEthernet0/0/2]port link-type trunk
[s3-GigabitEthernet0/0/2]port trunk allow-pass vlan 2 3 10 20 30
[s3-GigabitEthernet0/0/2]interface GigabitEthernet 0/0/3
[s3-GigabitEthernet0/0/3]port link-type trunk
[s3-GigabitEthernet0/0/3]port trunk allow-pass vlan 2 3 10 20 30

3.将PC-1添加到VLAN2,PC-2添加到VLAN3

[s1]interface Ethernet 0/0/1
[s1-Ethernet0/0/1]port link-type access 
[s1-Ethernet0/0/1]port default vlan 2
[s1-Ethernet0/0/1]interface Ethernet 0/0/2
[s1-Ethernet0/0/2]port link-type access
[s1-Ethernet0/0/2]port default vlan 3

 可以测试一下

在S1上配置VLAN4为Super VLAN,VLANIF4的IP地址为70.1.30.2/24,并配置 Proxy ARP

[s1]vlan 4
[s1-vlan4]aggregate-vlan 
[s1-vlan4]access-vlan 2 to 3
[s1-vlan4]interface Vlanif 4
[s1-Vlanif4]ip address 70.1.30.2 24
[s1-Vlanif4]arp-proxy inter-sub-vlan-proxy enable 

4.配置MSTP模式,创建MSTP域RG

  s1的配置
[s1]stp mode mstp
[s1]stp region-configuration 
[s1-mst-region]region-name RG
[s1-mst-region]instance 1 vlan 2 3
[s1-mst-region]instance 2 vlan 10 20 30	
[s1-mst-region]revision-level 1
[s1-mst-region]active  region-configuration 
  s2的配置
[s2]stp mode mstp
[s2]stp region-configuration 
[s2-mst-region]region-name RG
[[s2-mst-region]instance 1 vlan 2 3
[s2-mst-region]instance 2 vlan 10 20 30
[s2-mst-region]revision-level 1
[s2-mst-region]active  region-configuration 
[s2]stp instance 1 priority 0
[s2]stp instance 0 priority 0
   s3的配置
[s3]stp mode mstp
[s3]stp region-configuration 
[s3-mst-region]region-name RG
[s3-mst-region]instance 1 vlan 2 3
[s3-mst-region]instance 2 vlan 10 20 30	
[s3-mst-region]revision-level 1
[s3-mst-region]active  region-configuration 
[s3]stp instance 2 priority  0

为了保证网络的稳定性,确保当由于链路拥塞或者单向链路故障导致交换机收不到 来自上游交换设备的BPDU时,不会产生临时环路,在S1上启用环路保护功能。

[s1]interface GigabitEthernet 0/0/1
[s1-GigabitEthernet0/0/1]stp loop-protection 
[s1-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[s1-GigabitEthernet0/0/2]stp loop-protection

为了加快生成树的收敛速度,配置交换机S1的Ethernet 0/0/1和Ethernet 0/0/2为边 缘端口,并配置保护功能以防止这些端口因收到不合法的BPDU而影响生成树的计算

[s1]stp bpdu-protection
[s1]interface Ethernet 0/0/1
[s1-Ethernet0/0/1]stp edged-port enable 
[s1-Ethernet0/0/1]interface Ethernet 0/0/2
[s1-Ethernet0/0/2]stp edged-port enable 

 5.开始配置IS-IS路由协议

   公司总部内R1、R2、S2、S3运行IS-IS路由协议,并且都属于同一个区域,System ID由Loopback 0接口地址转换而得到

[s2]isis 1
[s2-isis-1]network-entity  49.0001.0100.0000.7007.00
[s2]interface Vlanif 71
[s2-Vlanif71]isis enable 
[s2-Vlanif71]interface Vlanif 72
[s2-Vlanif72]isis enable
[s2-Vlanif72]interface LoopBack 0
[s2-LoopBack0]isis enable

[s3]isis 1
[s3-isis-1]network-entity  49.0001.0100.0000.8008.00	
[s3-isis-1]interface Vlanif 81
[s3-Vlanif81]isis enable 
[s3-Vlanif81]interface Vlanif 82
[s3-Vlanif82]isis enable
[s3-Vlanif82]interface LoopBack 0
[s3-LoopBack0]isis enable

[r1]isis 1
[r1-isis-1]network-entity  49.0001.0100.0000.1001.00
[r1-isis-1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]isis enable
[r1-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/2
[r1-GigabitEthernet0/0/2]isis enable
[r1-GigabitEthernet0/0/2]interface GigabitEthernet 2/0/0
[r1-GigabitEthernet2/0/0]isis enable
[r1-GigabitEthernet2/0/0]interface loopback 0
[r1-LoopBack0]isis enable

[r2]isis 1	
[r2-isis-1]network-entity 49.0001.0100.0000.2002.00
[r2-isis-1]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]isis enable
[r2-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]isis enable
[r2-GigabitEthernet0/0/1]interface GigabitEthernet 2/0/0
[r2-GigabitEthernet2/0/0]isis enable
[r2-GigabitEthernet2/0/0]interface loopback 0
[r2-LoopBack0]isis enable

配置vlan接口的IP地址,然后将用户网段引入IS-IS中,且对路由进行聚合

[s2]interface Vlanif 10
[s2-Vlanif10]ip address 70.1.10.1 24
[s2-Vlanif10]interface Vlanif 20
[s2-Vlanif20]ip address 70.1.20.1 24
[s2-Vlanif20]interface Vlanif 30
[s2-Vlanif30]ip address 70.1.30.1 24

[s3]interface Vlanif  10
[s3-Vlanif10]ip address 80.1.10.1 24
[s3-Vlanif10]interface Vlanif 20
[s3-Vlanif20]ip address 80.1.20.1 24
[s3-Vlanif20]interface Vlanif 30
[s3-Vlanif30]ip address 80.1.30.1 24

[s2]  isis 1
[s2-isis-1]import-route direct 
[s2-isis-1]summary 70.1.0.0 255.255.224.0

[s3]isis 1		
[s3-isis-1]import-route direct 
[s3-isis-1]summary 80.1.0.0 255.255.224.0

修改网络类型为p2p,避免选举DIS

[s2]interface Vlanif 71
[s2-Vlanif71]isis circuit-type p2p
[s2-Vlanif71]interface Vlanif 72
[s2-Vlanif72]isis circuit-type p2p

[s3]interface Vlanif 81	
[s3-Vlanif81]isis circuit-type p2p
[s3-Vlanif81]interface Vlanif 82
[s3-Vlanif82]isis circuit-type p2p

[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]isis circuit-type p2p
[r1-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/2
[r1-GigabitEthernet0/0/2]isis circuit-type p2p
[r1-GigabitEthernet0/0/2]interface GigabitEthernet 2/0/0
[r1-GigabitEthernet2/0/0]isis circuit-type p2p

[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]isis circuit-type p2p
[r2-GigabitEthernet0/0/0]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]isis circuit-type p2p
[r2-GigabitEthernet0/0/1]interface GigabitEthernet 2/0/0
[r2-GigabitEthernet2/0/0]isis circuit-type p2p

     S2和S3不运行BGP路由协议,所以为了使S2和S3能够访问外网,需要在路由器 RI和R2上配置IS-IS下发缺省路由。

[r1]isis 1	
[r1-isis-1]default-route-advertise
[r2]isis 1	
[r2-isis-1]default-route-advertise

    为了提高网络安全性,R1、R2、S2、S3均需要相互通过认证后才能交换IS-IS路由 信息。配置认证模式为MD5认证,密钥为huawei

[s2]isis 1
[s2-isis-1]area-authentication-mode md5 huawei
[s3]isis 1
[s3-isis-1]area-authentication-mode md5 huawei
[r1]isis 1
[r1-isis-1]area-authentication-mode md5 huawei
[r2]isis 1
[r2-isis-1]area-authentication-mode md5 huawei

6.配置OSPF路由协议

[r3]ospf router-id  10.0.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network  10.0.35.0 0.0.0.255
[r3-ospf-1-area-0.0.0.0]network 10.0.34.0 0.0.0.255
[r3-ospf-1-area-0.0.0.0]network 10.0.3.3 0.0.0.0

[r4]ospf router-id 10.0.4.4
[r4-ospf-1]area 0
[r4-ospf-1-area-0.0.0.0]network 10.0.45.0 0.0.0.255
[r4-ospf-1-area-0.0.0.0]network 10.0.34.0 0.0.0.255
[r4-ospf-1-area-0.0.0.0]network 10.0.4.4 0.0.0.0

[r5]ospf router-id 10.0.5.5
[r5-ospf-1]area 0
[r5-ospf-1-area-0.0.0.0]network 10.0.35.0 0.0.0.255
[r5-ospf-1-area-0.0.0.0]network 10.0.45.0 0.0.0.255
[r5-ospf-1-area-0.0.0.0]network 10.0.5.5 0.0.0.0
[r5-ospf-1-area-0.0.0.0]network 20.0.5.5 0.0.0.0

7.配置BGP协议


[r1]router id 10.0.1.1
[r1]bgp 100	
[r1-bgp]peer 10.0.13.3 as-number 200
[r1-bgp]peer 10.0.2.2 as-number 100	
[r1-bgp]peer 10.0.2.2 connect-interface  LoopBack 0

[r2]router id  10.0.2.2
[r2]bgp 100
[r2-bgp]peer 10.0.24.4 as-number 200
[r2-bgp]peer 10.0.1.1 as-number 100 	
[r2-bgp]peer 10.0.1.1 connect-interface  LoopBack 0

[r3]bgp 200
[r3-bgp]peer 10.0.13.1 as-number 100
[r3-bgp]peer 10.0.4.4 as-number 200
[r3-bgp]peer 10.0.5.5 as-number 200	
[r3-bgp]peer 10.0.5.5 connect-interface LoopBack 0
[r3-bgp]peer 10.0.4.4 connect-interface LoopBack 0

 [r4]bgp 200
[r4-bgp]peer 10.0.24.2 as-number 100
[r4-bgp]peer 10.0.3.3 as-number 200
[r4-bgp]peer 10.0.5.5 as-number 200
[r4-bgp]peer 10.0.5.5 connect-interface LoopBack 0
[r4-bgp]peer 10.0.3.3 connect-interface LoopBack 0

[r5]bgp 200	
[r5-bgp]peer 10.0.3.3 as-number 200
[r5-bgp]peer 10.0.4.4 as-number 200	
[r5-bgp]peer 10.0.4.4 connect-interface LoopBack 0
[r5-bgp]peer 10.0.3.3 connect-interface LoopBack 0

 

为了将公司总部的路由信息通告给公司分部,在Rl和R2上同时将IS-IS的路由信 息引进BGP进程。

[r1]bgp 100	
[r1-bgp]import-route isis 1
[r2]bgp 100
[r2-bgp]import-route isis 1
[r3]bgp 200	
[r3-bgp]import-route direct 
[r4]bgp 200
[r4-bgp]import-route direct 

[r1]bgp 100
[r1-bgp]import-route isis 1 med 0
[r2]bgp 100
[r2-bgp]import-route isis 1 med 0
[r3]bgp 200	
[r3-bgp]import-route ospf 1
[r4]bgp 200
[r4-bgp]import-route ospf 1

考虑到公司后续问题,把r3配置为BGP路由反射器

[r3]bgp 200
[r3-bgp]peer 10.0.4.4 reflect-client 
[r3-bgp]peer 10.0.5.5 reflect-client

8.开始配置策略

[r1]acl 2001	
[r1-acl-basic-2001]rule permit source 10.0.13.0 0
[r1-acl-basic-2001]route-policy isis permit node 10
[r1-route-policy]if-match acl 2001
[r1-route-policy]isis 1
[r1-isis-1]default-route-advertise route-policy isis

[r2]acl 2001
[r2-acl-basic-2001]rule permit source 10.0.24.0 0
[r2-acl-basic-2001]route-policy isis permit node 10
[r2-route-policy]if-match acl 2001
[r2-route-policy]isis 1
[r2-isis-1]default-route-advertise route-policy isis

为了实现从R5去往总部的流量能够负载分担,在R5上修改BGP路由的Local Preference属性,从而保证R5通过R3去访问S2所连接的总部用户网段,通过R4去访 问S3所连接的总部用户网段

[r5]acl 2001	
[r5-acl-basic-2001]rule permit source 80.1.0.0 0.0.31.255	
[r5]route-policy fuzai permit node 10
[r5-route-policy]if-match acl 2001	
[r5-route-policy]apply local-preference 200	
[r5-route-policy]route-policy fuzai permit node 20
[r5-route-policy]bgp 200	
[r5-bgp]peer 10.0.4.4 route-policy fuzai import

 改BGP路由的团体属性为No-Export

[r3]acl 2002	
[r3-acl-basic-2002]rule permit source 20.0.5.5 0
[r3-acl-basic-2002]quit	
[r3]route-policy 1 permit node 10
[r3-route-policy]if-match acl 2002
[r3-route-policy]apply community no-export
[r3-route-policy]route-policy 1 permit node 20
[r3-route-policy]bgp 200
[r3-bgp]peer 10.0.13.1 route-policy 1 export 
[r3-bgp]peer 10.0.13.1 advertise-community

[r4]acl 2002
[r4-acl-basic-2002]rule permit source 20.0.5.5 0
[r4-acl-basic-2002]quit
[r4]route-policy 1 permit node 10
[r4-route-policy]if-match acl 2002
[r4-route-policy]apply community no-export
[r4-route-policy]route-policy 1 permit node 20
[r4-route-policy]bgp 200	
[r4-bgp]peer 10.0.24.2 route-policy 1 export 
[r4-bgp]peer 10.0.24.2 advertise-community

 

  • 2
    点赞
  • 5
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值