H3CNE综合实验
实验拓扑

实验需求
- 按照图示配置IP地址
- SW1和SW2之间的直连链路配置链路聚合
- 公司内部业务网段为Vlan10和Vlan20;Vlan10是市场部,Vlan20是技术部,要求对Vlan
- 进行命名以便识别;PC1属于Vlan10,PC2属于Vlan20,Vlan30用于SW1和SW2建立
- OSPF邻居;Vlan111为SW1和R1的互联Vlan,Vlan222为SW2和R2的互联Vlan
- 所有交换机相连的端口配置为Trunk,允许相关流量通过
- 交换机连接PC的端口配置为边缘端口
- 在SW1上配置DHCP服务,为Vlan10和Vlan20的PC动态分配IP地址、网关和DNS地址;要求Vlan10的网关是192.168.1.252,Vlan20的网关是192.168.2.253
- 按图示分区域配置OSPF实现公司内部网络全网互通,ABR的环回口宣告进骨干区域;业务网段不允许出现协议报文
- R1上配置默认路由指向互联网,并引入到OSPF
- R1通过双线连接到互联网,配置PPP-MP,并配置双向chap验证
- 配置EASYIP,只有业务网段192.168.1.0/24和192.168.2.0/24的数据流可以通过R1访问互联网
- R1开启TELNET远程管理,使用用户abc登录,密码abc,只允许技术部远程管理R1
实验解法
1、配置IP
给pc配置IP地址



R1上配置IP地址
<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysname R1
[R1]int g0/1
[R1-GigabitEthernet0/1]ip add 10.0.0.1 30
[R1-GigabitEthernet0/1]quit
[R1]int g0/0
[R1-GigabitEthernet0/0]ip add 10.0.0.5 30
[R1-GigabitEthernet0/0]quit
[R1]int g0/2
[R1-GigabitEthernet0/2]ip add 10.0.0.14 30
[R1-GigabitEthernet0/2]quit
[R1]int lo0
[R1-LoopBack0]ip add 10.1.1.1 32
[R1-LoopBack0]quit
[R1]intmp-group1
[R1-MP-group1]ipa dd202.100.1.2 30
[R1-MP-group1]quit
R2上配置IP地址
<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysname R2
[R2]int g0/0
[R2-GigabitEthernet0/0]ip add 10.0.0.9 30
[R2-GigabitEthernet0/0]quit
[R2]int g0/1
[R2-GigabitEthernet0/1]ip add 10.0.0.18 30
[R2-GigabitEthernet0/1]quit
[R2]int g0/2
[R2-GigabitEthernet0/2]ip add 10.0.0.2 30
[R2-GigabitEthernet0/2]quit
R3上配置IP地址
<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysnameR3
[R3]int g0/0
[R3-GigabitEthernet0/0]ip add 10.0.0.13 30
[R3-GigabitEthernet0/0]quit
[R3]int g0/1
[R3-GigabitEthernet0/1]ip add 10.0.0.17 30
[R3-GigabitEthernet0/1]quit
[R3]int g0/2
[R3-GigabitEthernet0/2]ip add 192.168.3.254 24
[R3-GigabitEthernet0/2]quit
[R3]int lo0
[R3-LoopBack0]ip add 10.1.1.3 32
[R3-LoopBack0]quit
SW1上配置IP地址
<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysnameSW1
[SW1]vlan 10
[SW1-vlan10]quit
[SW1]vlan 20
[SW1-vlan20]quit
[SW1]vlan 30
[SW1-vlan30]quit
[SW1]vlan 111
[SW1-vlan111]port g1/0/4
[SW1-vlan111]quit
[SW1]int vlan 10
[SW1-Vlan-interface10]ip add 192.168.1.252 24
[SW1-Vlan-interface10]quit
[SW1]int vlan 20
[SW1-Vlan-interface20]ip add 192.168.2.252 24
[SW1-Vlan-interface20]quit
[SW1]int vlan 30
[SW1-Vlan-interface30]ip add 10.1.2.1 30
[SW1-Vlan-interface30]quit
[SW1]int vlan 111
[SW1-Vlan-interface111]ip add 10.0.0.6 30
[SW1-Vlan-interface111]quit
[SW1]int lo0
[SW1-LoopBack0]ip add 10.1.1.11 32
[SW1-LoopBack0]quit
SW2上配置IP地址
<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysname SW2
[SW2]vlan 10
[SW2-vlan10]quit
[SW2]vlan 20
[SW2-vlan20]quit
[SW2]vlan 30
[SW2-vlan30]quit
[SW2]vlan 222
[SW2-vlan222]port g1/0/4
[SW2-vlan222]quit
[SW2]int vlan 10
[SW2-Vlan-interface10]ip add 192.168.1.253 24
[SW2-Vlan-interface10]quit
[SW2]int vlan 20
[SW2-Vlan-interface20]ip add 192.168.2.253 24
[SW2-Vlan-interface20]quit
[SW2]int vlan 30
[SW2-Vlan-interface30]ip add 10.1.2.2 30
[SW2-Vlan-interface30]quit
[SW2]int vlan 222
[SW2-Vlan-interface222]ip add 10.0.0.10 30
[SW2-Vlan-interface222]quit
[SW2]int lo0
[SW2-LoopBack0]ip add 10.1.1.12 32
[SW2-LoopBack0]quit
Internet上配置IP地址
<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysnameinternet
[internet]int MP-group1
[internet-MP-group1]ip add 202.100.1.1 30
[internet-MP-group1]quit
[internet]int lo0
[internet-LoopBack0]ip add 100.1.1.1 32
[internet-LoopBack0]quit
2、配置链路聚合
SW1和SW2之间的直连链路配置链路聚合
[SW1]interfaceBridge-Aggregation1
[SW1-Bridge-Aggregation1]quit
[SW1]int g1/0/1
[SW1-GigabitEthernet1/0/1]port link-aggregation group 1
[SW1-GigabitEthernet1/0/1]quit
[SW1]int g1/0/2
[SW1-GigabitEthernet1/0/2]port link-aggregation group 1
[SW1-GigabitEthernet1/0/2]quit
[SW2]int Bridge-Aggregation 1
[SW2-Bridge-Aggregation1]quit
[SW2]int g1/0/1
[SW2-GigabitEthernet1/0/1]port link-aggregation group 1
[SW2-GigabitEthernet1/0/1]quit
[SW2]int g1/0/2
[SW2-GigabitEthernet1/0/2]port link-aggregation group 1
[SW2-GigabitEthernet1/0/2]quit
[SW1]display link-aggregation verbose
LoadsharingType:Shar--Loadsharing,NonS--Non-Loadsharing
Port:A--Auto
PortStatus:S--Selected,U--Unselected,I--Individual
Flags:A--LACP_Activity,B--LACP_Timeout,C--Aggregation,
D--Synchronization,E--Collecting,F--Distributing,
G--Defaulted,H--Expired
AggregateInterface:Bridge-Aggregation1
AggregationMode:Static
LoadsharingType:Shar
PortStatusPriorityOper-Key10
-----------------------
GE1/0/1 S 327681
GE1/0/2 S 327681
[SW1]
3、配置vlan
公司内部业务网段为Vlan10和Vlan20;Vlan10是市场部,Vlan20是技术部,要求对Vlan进行命名以便识别;PC1属于Vlan10,PC2属于Vlan20,Vlan30用于SW1和SW2建立OSPF邻居;Vlan111为SW1和R1的互联Vlan,Vlan222为SW2和R2的互联Vlan。所有VlanIP第一步已经配了
//配置SW1
[SW1]vlan 10
[SW1-vlan10]quit
[SW1]vlan20
[SW1-vlan20]quit
[SW1]vlan 30
[SW1-vlan30]quit
[SW1]vlan 111
[SW1-vlan111]quit
[SW1]vlan 222
[SW1-vlan222]quit
[SW1]int g1/0/4
[SW1-GigabitEthernet1/0/4]port access vlan 111
[SW1-GigabitEthernet1/0/4]quit
//配置SW2
[SW2]vlan 10
[SW2-vlan10]quit
[SW2]vlan 20
[SW2-vlan20]quit
[SW2]vlan 30
[SW2-vlan30]quit
[SW2]vlan 111
[SW2-vlan111]quit
[SW2]vlan 222
[SW2-vlan222]quit
[SW2]int g1/0/4
[SW2-GigabitEthernet1/0/4]port access vlan 222
[SW2-GigabitEthernet1/0/4]quit
//配置SW3
[SW3]vlan 10
[SW3-vlan10]name scb //给VLAN命名
[SW3-vlan10]quit
[SW3]vlan 20
[SW3-vlan20]name jsb //给VLAN命名
[SW3-vlan20]quit
[SW3]int g1/0/3
[SW3-GigabitEthernet1/0/3]port access vlan 10
[SW3-GigabitEthernet1/0/3]quit
[SW3]int g1/0/4
[SW3-GigabitEthernet1/0/4]port access vlan 20
[SW3-GigabitEthernet1/0/4]quit
4、配置Trunk
所有交换机相连的端口配置为Trunk,允许相关流量通过
//配置SW1
[SW1]int g1/0/3
[SW1-GigabitEthernet1/0/3]port link-type trunk
[SW1-GigabitEthernet1/0/3]port trunk permit vlan 10 20
[SW1-GigabitEthernet1/0/3]quit
[SW1]intBridge-Aggregation1
[SW1-Bridge-Aggregation1]port link-type trunk
[SW1-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW1-Bridge-Aggregation1]quit
//配置SW2
[SW2]int g1/0/3
[SW2-GigabitEthernet1/0/3]port link-type trunk
[SW2-GigabitEthernet1/0/3]port trunk permit vlan 10 20
[SW2]intBridge-Aggregation1
[SW2-Bridge-Aggregation1]port link-type trunk
[SW2-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW2-Bridge-Aggregation1]quit
//配置SW3
[SW3]int g1/0/1
[SW3-GigabitEthernet1/0/1]port link-type trunk
[SW3-GigabitEthernet1/0/1]port trunk permit vlan 10 20
[SW3-GigabitEthernet1/0/1]quit
[SW3]int g1/0/2
[SW3-GigabitEthernet1/0/2]port link-type trunk
[SW3-GigabitEthernet1/0/2]port trunk permit vlan 10 20
[SW3-GigabitEthernet1/0/2]quit
5、配置边缘端口
交换机连接PC的端口配置为边缘端口
[SW3]int g1/0/3
[SW3-GigabitEthernet1/0/3]stp edged-port
[SW3-GigabitEthernet1/0/3]quit
[SW3]int g1/0/4
[SW3-GigabitEthernet1/0/4]stp edged-port
[SWSW3-GigabitEthernet1/0/4]quit
6、配置DHCP
在SW1上配置DHCP服务,为Vlan10和Vlan20的PC动态分配IP地址、网关和DNS地址;要求Vlan10的网关是192.168.1.252,Vlan20的网关是192.168.2.253。
开启dhcp
[SW1]dhcp enable
[SW1]dhcp server ip-pool vlan10
[SW1-dhcp-pool-vlan10]network 192.168.1.0 mask 255.255.255.0
[SW1-dhcp-pool-vlan10]gateway-list 192.168.1.252
[SW1-dhcp-pool-vlan10]dns-list 6.6.6.6
[SW1-dhcp-pool-vlan10]quit
[SW1]dhcp server ip-pool vlan20
[SW1-dhcp-pool-vlan20]network 192.168.2.0 mask 255.255.255.0
[SW1-dhcp-pool-vlan20]gateway-list 192.168.2.253
[SW1-dhcp-pool-vlan20]dns-list 8.8.8.8
[SW1-dhcp-pool-vlan20]quit


7、配置OSPF
按图示分区域配置OSPF实现公司内部网络全网互通,ABR的环回口宣告进骨干区域;业务网段不允许出现协议报文
//配置SW1
[SW1]ospf 1 router-id 3.3.3.3
[SW1-ospf-1]silent-interface vlan 10 //业务网段不允许出现协议报文
[SW1-ospf-1]area1
[SW1-ospf-1-area-0.0.0.1]network 192.168.1.252 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]network 192.168.2.252 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]network 10.1.2.1 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]network 10.0.0.6 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]network 10.1.1.11 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]quit
[SW1-ospf-1]quit
//配置SW2
[SW2]ospf 1 router-id 4.4.4.4
[SW2-ospf-1]silent-interface vlan 20 //业务网段不允许出现协议报文
[SW2-ospf-1]area1
[SW2-ospf-1-area-0.0.0.1]network 192.168.1.253 0.0.0.25515
[SW2-ospf-1-area-0.0.0.1]network 192.168.2.253 0.0.0.255
[SW2-ospf-1-area-0.0.0.1]network 10.0.0.10 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]network 10.1.1.12 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]quit
[SW2-ospf-1]quit
//配置R1
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]silent-interface LoopBack 0 //业务网段不允许出现协议报文
[R1-ospf-1]area1
[R1-ospf-1-area-0.0.0.1]network 10.0.0.1 0.0.0.0
[R1-ospf-1-area-0.0.0.1]network 10.0.0.5 0.0.0.0
[R1-ospf-1-area-0.0.0.1]quit
[R1-ospf-1]area0
[R1-ospf-1-area-0.0.0.0]network 10.0.0.14 0.0.0.0
[R1-ospf-1-area-0.0.0.0]network 10.1.1.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]quit
[R1-ospf-1]quit
//配置R2
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area1
[R2-ospf-1-area-0.0.0.1]network 10.0.0.9 0.0.0.0
[R2-ospf-1-area-0.0.0.1]network 10.0.0.2 0.0.0.0
[R2-ospf-1-area-0.0.0.1]quit
[R2-ospf-1]area0
[R2-ospf-1-area-0.0.0.0]network 10.0.0.18 0.0.0.0
[R2-ospf-1-area-0.0.0.0]network 10.1.1.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]quit
[R2-ospf-1]quit
//配置R3
[R3]ospf 1 router-id 5.5.5.5
[R3-ospf-1]silent-interface LoopBack 0 //业务网段不允许出现协议报文
[R3-ospf-1]area0
[R3-ospf-1-area-0.0.0.0]network 10.0.0.13 0.0.0.0
[R3-ospf-1-area-0.0.0.0]network 10.0.0.17 0.0.0.0
[R3-ospf-1-area-0.0.0.0]network 192.168.3.254 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 10.1.1.3 0.0.0.0
[R3-ospf-1-area-0.0.0.0]quit
[R3-ospf-1]quit
8、配置默认路由
R1上配置默认路由指向互联网,并引入到OSPF
[R1]iproute-static 0.0.0.0 0.0.0.0 202.100.1.1
[R1]ospf 1
[R1-ospf-1]default-route-advertise
[R1-ospf-1]quit
9、配置PPP-MP
R1通过双线连接到互联网,配置PPP-MP,并配置双向chap验证
创建聚合并将端口加入进去
//配置R1
[R1]int MP-group 1
[R1-MP-group1]ip add 202.100.1.230
[R1-MP-group1]quit
[R1]ints1/0
[R1-Serial1/0]ppp mp MP-group1
[R1-Serial1/0]quit
[R1]ints2/0
[R1-Serial2/0]ppp mp MP-group1
[R1-Serial2/0]quit
//配置internet
[internet]int MP-group 1
[internet-MP-group1]ip add 202.100.1.130
[internet-MP-group1]quit
[internet]int s1/0
[internet-Serial1/0]ppp mp MP-group1
[internet-Serial1/0]quit
[internet]int s2/0
[internet-Serial2/0]ppp mp MP-group1
[internet-Serial2/0]quit
//创建用于双向验证的用户
[internet]local-user jlin class network
Newlocaluseradded.
[internet-luser-network-jlin]password simple 123456
[internet-luser-network-jlin]service-type ppp
[internet-luser-network-jlin]quit
[R1]local-user jlin class network
Newlocaluseradded.
[R1-luser-network-jlin]password simple 123456
[R1-luser-network-jlin]service-type ppp
[R1-luser-network-jlin]quit
//选择认证方式+认证
[R1]interface s1/0
[R1-Serial1/0]ppp authentication-mode chap
[R1-Serial1/0]ppp chap user jlin
[R1-Serial1/0]ppp chap password simple 123456
[R1-Serial1/0]quit
[R1]interface s2/0
[R1-Serial2/0]ppp authentication-mode chap
[R1-Serial2/0]ppp chap user jlin
[R1-Serial2/0]ppp chap password simple 123456
[R1-Serial2/0]quit
[internet]interface s1/0
[internet-Serial1/0]ppp authentication-mode chap
[internet-Serial1/0]ppp chap user jlin
[internet-Serial1/0]ppp chap password simple 123456
[internet-Serial1/0]quit
[internet]interface s2/0
[internet-Serial2/0]ppp authentication-mode chap
[internet-Serial2/0]ppp chap user jlin
[internet-Serial2/0]ppp chap password simple 123456
[internet-Serial2/0]quit
10、配置EASYIP
配置EASYIP,只有业务网段192.168.1.0/24和192.168.2.0/24的数据流可以通过R1访问互联网
[R1]acl basic 2000
[R1-acl-ipv4-basic-2000]rule 0 permit source 192.168.1.0 0.0.0.255
[R1-acl-ipv4-basic-2000]rule 5 permit source 192.168.2.0 0.0.0.255
[R1-acl-ipv4-basic-2000]quit
[R1]interface MP-group 1
[R1-MP-group1]nat outbound 2000
[R1-MP-group1]quit
此时只有pc1与pc2能访问internet没配置前都访问不了



11、开启TELNET远程管理
R1开启TELNET远程管理,使用用户abc登录,密码abc,只允许技术部远程管理R1
[R1]telnet server enable
[R1]local-user abc class manage
Newlocaluseradded.
[R1-luser-manage-abc]password simple abc
[R1-luser-manage-abc]service-typetelnet
[R1-luser-manage-abc]authorization-attribute user-role level-15
[R1-luser-manage-abc]quit
[R1]user-interface vty 0 4
[R1-line-vty0-4]authentication-mode scheme
[R1-line-vty0-4]user-role level-15
[R1-line-vty0-4]quit
[R1]acl advanced 3000
[R1-acl-ipv4-adv-3000]rule 0 permit tcp source 192.168.2.0 0.0.0.255 destination 10.0.0.0 0.0.0.255 destination-port eq 23
[R1-acl-ipv4-adv-3000]rule 5 deny tcp
[R1-acl-ipv4-adv-3000]quit
[R1]int g0/0
[R1-GigabitEthernet0/0]packet-filter 3000 inbound
[R1-GigabitEthernet0/0]quit21
[R1]int g0/1
[R1-GigabitEthernet0/1]packet-filter 3000 inbound
[R1-GigabitEthernet0/1]quit
[R1]int g0/2
[R1-GigabitEthernet0/2]packet-filter 3000 inbound
[R1-GigabitEthernet0/2]quit
配置前

配置后
[R1]int MP-group1
[R1-MP-group1]packet-filter 3000 inbound
[R1-MP-group1]qui
