H3CNE综合实验

H3CNE综合实验

实验拓扑


实验需求

  1. 按照图示配置IP地址
  2. SW1和SW2之间的直连链路配置链路聚合
  3. 公司内部业务网段为Vlan10和Vlan20;Vlan10是市场部,Vlan20是技术部,要求对Vlan
  4. 进行命名以便识别;PC1属于Vlan10,PC2属于Vlan20,Vlan30用于SW1和SW2建立
  5. OSPF邻居;Vlan111为SW1和R1的互联Vlan,Vlan222为SW2和R2的互联Vlan
  6. 所有交换机相连的端口配置为Trunk,允许相关流量通过
  7. 交换机连接PC的端口配置为边缘端口
  8. 在SW1上配置DHCP服务,为Vlan10和Vlan20的PC动态分配IP地址、网关和DNS地址;要求Vlan10的网关是192.168.1.252,Vlan20的网关是192.168.2.253
  9. 按图示分区域配置OSPF实现公司内部网络全网互通,ABR的环回口宣告进骨干区域;业务网段不允许出现协议报文
  10. R1上配置默认路由指向互联网,并引入到OSPF
  11. R1通过双线连接到互联网,配置PPP-MP,并配置双向chap验证
  12. 配置EASYIP,只有业务网段192.168.1.0/24和192.168.2.0/24的数据流可以通过R1访问互联网
  13. R1开启TELNET远程管理,使用用户abc登录,密码abc,只允许技术部远程管理R1

实验解法

1、配置IP

给pc配置IP地址

R1上配置IP地址

<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysname R1
[R1]int g0/1
[R1-GigabitEthernet0/1]ip add 10.0.0.1 30
[R1-GigabitEthernet0/1]quit
[R1]int g0/0
[R1-GigabitEthernet0/0]ip add 10.0.0.5 30
[R1-GigabitEthernet0/0]quit
[R1]int g0/2
[R1-GigabitEthernet0/2]ip add 10.0.0.14 30
[R1-GigabitEthernet0/2]quit
[R1]int lo0
[R1-LoopBack0]ip add 10.1.1.1 32
[R1-LoopBack0]quit
[R1]intmp-group1
[R1-MP-group1]ipa dd202.100.1.2 30
[R1-MP-group1]quit

R2上配置IP地址

<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysname R2
[R2]int g0/0
[R2-GigabitEthernet0/0]ip add 10.0.0.9 30
[R2-GigabitEthernet0/0]quit
[R2]int g0/1
[R2-GigabitEthernet0/1]ip add 10.0.0.18 30
[R2-GigabitEthernet0/1]quit
[R2]int g0/2
[R2-GigabitEthernet0/2]ip add 10.0.0.2 30
[R2-GigabitEthernet0/2]quit

R3上配置IP地址

<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysnameR3
[R3]int g0/0
[R3-GigabitEthernet0/0]ip add 10.0.0.13 30
[R3-GigabitEthernet0/0]quit
[R3]int g0/1
[R3-GigabitEthernet0/1]ip add 10.0.0.17 30
[R3-GigabitEthernet0/1]quit
[R3]int g0/2
[R3-GigabitEthernet0/2]ip add 192.168.3.254 24
[R3-GigabitEthernet0/2]quit
[R3]int lo0
[R3-LoopBack0]ip add 10.1.1.3 32
[R3-LoopBack0]quit

SW1上配置IP地址

<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysnameSW1
[SW1]vlan 10
[SW1-vlan10]quit
[SW1]vlan 20
[SW1-vlan20]quit
[SW1]vlan 30
[SW1-vlan30]quit
[SW1]vlan 111
[SW1-vlan111]port g1/0/4
[SW1-vlan111]quit
[SW1]int vlan 10
[SW1-Vlan-interface10]ip add 192.168.1.252 24
[SW1-Vlan-interface10]quit
[SW1]int vlan 20
[SW1-Vlan-interface20]ip add 192.168.2.252 24
[SW1-Vlan-interface20]quit
[SW1]int vlan 30
[SW1-Vlan-interface30]ip add 10.1.2.1 30
[SW1-Vlan-interface30]quit
[SW1]int vlan 111
[SW1-Vlan-interface111]ip add 10.0.0.6 30
[SW1-Vlan-interface111]quit
[SW1]int lo0
[SW1-LoopBack0]ip add 10.1.1.11 32
[SW1-LoopBack0]quit

SW2上配置IP地址

<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysname SW2
[SW2]vlan 10
[SW2-vlan10]quit
[SW2]vlan 20
[SW2-vlan20]quit
[SW2]vlan 30
[SW2-vlan30]quit
[SW2]vlan 222
[SW2-vlan222]port g1/0/4
[SW2-vlan222]quit
[SW2]int vlan 10
[SW2-Vlan-interface10]ip add 192.168.1.253 24
[SW2-Vlan-interface10]quit
[SW2]int vlan 20
[SW2-Vlan-interface20]ip add 192.168.2.253 24
[SW2-Vlan-interface20]quit
[SW2]int vlan 30
[SW2-Vlan-interface30]ip add 10.1.2.2 30
[SW2-Vlan-interface30]quit
[SW2]int vlan 222
[SW2-Vlan-interface222]ip add 10.0.0.10 30
[SW2-Vlan-interface222]quit
[SW2]int lo0
[SW2-LoopBack0]ip add 10.1.1.12 32
[SW2-LoopBack0]quit

Internet上配置IP地址

<H3C>system-view
SystemView:returntoUserViewwithCtrl+Z.
[H3C]sysnameinternet
[internet]int MP-group1
[internet-MP-group1]ip add 202.100.1.1 30
[internet-MP-group1]quit
[internet]int lo0
[internet-LoopBack0]ip add 100.1.1.1 32
[internet-LoopBack0]quit

2、配置链路聚合

SW1和SW2之间的直连链路配置链路聚合

[SW1]interfaceBridge-Aggregation1
[SW1-Bridge-Aggregation1]quit
[SW1]int g1/0/1
[SW1-GigabitEthernet1/0/1]port link-aggregation group 1
[SW1-GigabitEthernet1/0/1]quit
[SW1]int g1/0/2
[SW1-GigabitEthernet1/0/2]port link-aggregation group 1
[SW1-GigabitEthernet1/0/2]quit
[SW2]int Bridge-Aggregation 1
[SW2-Bridge-Aggregation1]quit
[SW2]int g1/0/1
[SW2-GigabitEthernet1/0/1]port link-aggregation group 1
[SW2-GigabitEthernet1/0/1]quit
[SW2]int g1/0/2
[SW2-GigabitEthernet1/0/2]port link-aggregation group 1
[SW2-GigabitEthernet1/0/2]quit
[SW1]display link-aggregation verbose
LoadsharingType:Shar--Loadsharing,NonS--Non-Loadsharing
Port:A--Auto
PortStatus:S--Selected,U--Unselected,I--Individual
Flags:A--LACP_Activity,B--LACP_Timeout,C--Aggregation,
D--Synchronization,E--Collecting,F--Distributing,
G--Defaulted,H--Expired
AggregateInterface:Bridge-Aggregation1
AggregationMode:Static
LoadsharingType:Shar
PortStatusPriorityOper-Key10
-----------------------
GE1/0/1		S	327681
GE1/0/2		S	327681
[SW1]

3、配置vlan

公司内部业务网段为Vlan10和Vlan20;Vlan10是市场部,Vlan20是技术部,要求对Vlan进行命名以便识别;PC1属于Vlan10,PC2属于Vlan20,Vlan30用于SW1和SW2建立OSPF邻居;Vlan111为SW1和R1的互联Vlan,Vlan222为SW2和R2的互联Vlan。所有VlanIP第一步已经配了

//配置SW1
[SW1]vlan 10
[SW1-vlan10]quit
[SW1]vlan20
[SW1-vlan20]quit
[SW1]vlan 30
[SW1-vlan30]quit
[SW1]vlan 111
[SW1-vlan111]quit
[SW1]vlan 222
[SW1-vlan222]quit
[SW1]int g1/0/4
[SW1-GigabitEthernet1/0/4]port access vlan 111
[SW1-GigabitEthernet1/0/4]quit

//配置SW2
[SW2]vlan 10
[SW2-vlan10]quit
[SW2]vlan 20
[SW2-vlan20]quit
[SW2]vlan 30
[SW2-vlan30]quit
[SW2]vlan 111
[SW2-vlan111]quit
[SW2]vlan 222
[SW2-vlan222]quit
[SW2]int g1/0/4
[SW2-GigabitEthernet1/0/4]port access vlan 222
[SW2-GigabitEthernet1/0/4]quit

//配置SW3
[SW3]vlan 10
[SW3-vlan10]name scb	//给VLAN命名
[SW3-vlan10]quit
[SW3]vlan 20
[SW3-vlan20]name jsb	//给VLAN命名
[SW3-vlan20]quit
[SW3]int g1/0/3
[SW3-GigabitEthernet1/0/3]port access vlan 10
[SW3-GigabitEthernet1/0/3]quit
[SW3]int g1/0/4
[SW3-GigabitEthernet1/0/4]port access vlan 20
[SW3-GigabitEthernet1/0/4]quit

4、配置Trunk

所有交换机相连的端口配置为Trunk,允许相关流量通过

//配置SW1
[SW1]int g1/0/3
[SW1-GigabitEthernet1/0/3]port link-type trunk
[SW1-GigabitEthernet1/0/3]port trunk permit vlan 10 20
[SW1-GigabitEthernet1/0/3]quit
[SW1]intBridge-Aggregation1
[SW1-Bridge-Aggregation1]port link-type trunk
[SW1-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW1-Bridge-Aggregation1]quit

//配置SW2
[SW2]int g1/0/3
[SW2-GigabitEthernet1/0/3]port link-type trunk
[SW2-GigabitEthernet1/0/3]port trunk permit vlan 10 20
[SW2]intBridge-Aggregation1
[SW2-Bridge-Aggregation1]port link-type trunk
[SW2-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW2-Bridge-Aggregation1]quit

//配置SW3
[SW3]int g1/0/1
[SW3-GigabitEthernet1/0/1]port link-type trunk
[SW3-GigabitEthernet1/0/1]port trunk permit vlan 10 20
[SW3-GigabitEthernet1/0/1]quit
[SW3]int g1/0/2
[SW3-GigabitEthernet1/0/2]port link-type trunk
[SW3-GigabitEthernet1/0/2]port trunk permit vlan 10 20
[SW3-GigabitEthernet1/0/2]quit

5、配置边缘端口

交换机连接PC的端口配置为边缘端口

[SW3]int g1/0/3
[SW3-GigabitEthernet1/0/3]stp edged-port
[SW3-GigabitEthernet1/0/3]quit
[SW3]int g1/0/4
[SW3-GigabitEthernet1/0/4]stp edged-port
[SWSW3-GigabitEthernet1/0/4]quit

6、配置DHCP

在SW1上配置DHCP服务,为Vlan10和Vlan20的PC动态分配IP地址、网关和DNS地址;要求Vlan10的网关是192.168.1.252,Vlan20的网关是192.168.2.253。
开启dhcp

[SW1]dhcp enable
[SW1]dhcp server ip-pool vlan10
[SW1-dhcp-pool-vlan10]network 192.168.1.0 mask 255.255.255.0
[SW1-dhcp-pool-vlan10]gateway-list 192.168.1.252
[SW1-dhcp-pool-vlan10]dns-list 6.6.6.6
[SW1-dhcp-pool-vlan10]quit
[SW1]dhcp server ip-pool vlan20
[SW1-dhcp-pool-vlan20]network 192.168.2.0 mask 255.255.255.0
[SW1-dhcp-pool-vlan20]gateway-list 192.168.2.253
[SW1-dhcp-pool-vlan20]dns-list 8.8.8.8
[SW1-dhcp-pool-vlan20]quit

7、配置OSPF

按图示分区域配置OSPF实现公司内部网络全网互通,ABR的环回口宣告进骨干区域;业务网段不允许出现协议报文

//配置SW1
[SW1]ospf 1 router-id 3.3.3.3
[SW1-ospf-1]silent-interface vlan 10		//业务网段不允许出现协议报文
[SW1-ospf-1]area1
[SW1-ospf-1-area-0.0.0.1]network 192.168.1.252 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]network 192.168.2.252 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]network 10.1.2.1 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]network 10.0.0.6 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]network 10.1.1.11 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]quit
[SW1-ospf-1]quit

//配置SW2
[SW2]ospf 1 router-id 4.4.4.4
[SW2-ospf-1]silent-interface vlan 20		//业务网段不允许出现协议报文
[SW2-ospf-1]area1
[SW2-ospf-1-area-0.0.0.1]network 192.168.1.253 0.0.0.25515
[SW2-ospf-1-area-0.0.0.1]network 192.168.2.253 0.0.0.255
[SW2-ospf-1-area-0.0.0.1]network 10.0.0.10 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]network 10.1.1.12 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]quit
[SW2-ospf-1]quit

//配置R1
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]silent-interface LoopBack 0		//业务网段不允许出现协议报文
[R1-ospf-1]area1
[R1-ospf-1-area-0.0.0.1]network 10.0.0.1 0.0.0.0
[R1-ospf-1-area-0.0.0.1]network 10.0.0.5 0.0.0.0
[R1-ospf-1-area-0.0.0.1]quit
[R1-ospf-1]area0
[R1-ospf-1-area-0.0.0.0]network 10.0.0.14 0.0.0.0
[R1-ospf-1-area-0.0.0.0]network 10.1.1.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]quit
[R1-ospf-1]quit

//配置R2
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area1
[R2-ospf-1-area-0.0.0.1]network 10.0.0.9 0.0.0.0
[R2-ospf-1-area-0.0.0.1]network 10.0.0.2 0.0.0.0
[R2-ospf-1-area-0.0.0.1]quit
[R2-ospf-1]area0
[R2-ospf-1-area-0.0.0.0]network 10.0.0.18 0.0.0.0
[R2-ospf-1-area-0.0.0.0]network 10.1.1.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]quit
[R2-ospf-1]quit

//配置R3
[R3]ospf 1 router-id 5.5.5.5
[R3-ospf-1]silent-interface LoopBack 0		//业务网段不允许出现协议报文
[R3-ospf-1]area0
[R3-ospf-1-area-0.0.0.0]network 10.0.0.13 0.0.0.0
[R3-ospf-1-area-0.0.0.0]network 10.0.0.17 0.0.0.0
[R3-ospf-1-area-0.0.0.0]network 192.168.3.254 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 10.1.1.3 0.0.0.0
[R3-ospf-1-area-0.0.0.0]quit
[R3-ospf-1]quit

8、配置默认路由

R1上配置默认路由指向互联网,并引入到OSPF

[R1]iproute-static 0.0.0.0 0.0.0.0 202.100.1.1
[R1]ospf 1
[R1-ospf-1]default-route-advertise
[R1-ospf-1]quit

9、配置PPP-MP

R1通过双线连接到互联网,配置PPP-MP,并配置双向chap验证
创建聚合并将端口加入进去

//配置R1
[R1]int MP-group 1
[R1-MP-group1]ip add 202.100.1.230
[R1-MP-group1]quit
[R1]ints1/0
[R1-Serial1/0]ppp mp MP-group1
[R1-Serial1/0]quit
[R1]ints2/0
[R1-Serial2/0]ppp mp MP-group1
[R1-Serial2/0]quit

//配置internet
[internet]int MP-group 1
[internet-MP-group1]ip add 202.100.1.130
[internet-MP-group1]quit
[internet]int s1/0
[internet-Serial1/0]ppp mp MP-group1
[internet-Serial1/0]quit
[internet]int s2/0
[internet-Serial2/0]ppp mp MP-group1
[internet-Serial2/0]quit

//创建用于双向验证的用户
[internet]local-user jlin class network
Newlocaluseradded.
[internet-luser-network-jlin]password simple 123456
[internet-luser-network-jlin]service-type ppp
[internet-luser-network-jlin]quit

[R1]local-user jlin class network
Newlocaluseradded.
[R1-luser-network-jlin]password simple 123456
[R1-luser-network-jlin]service-type ppp
[R1-luser-network-jlin]quit

//选择认证方式+认证
[R1]interface s1/0
[R1-Serial1/0]ppp authentication-mode chap
[R1-Serial1/0]ppp chap user jlin
[R1-Serial1/0]ppp chap password simple 123456
[R1-Serial1/0]quit
[R1]interface s2/0
[R1-Serial2/0]ppp authentication-mode chap
[R1-Serial2/0]ppp chap user jlin
[R1-Serial2/0]ppp chap password simple 123456
[R1-Serial2/0]quit

[internet]interface s1/0
[internet-Serial1/0]ppp authentication-mode chap
[internet-Serial1/0]ppp chap user jlin
[internet-Serial1/0]ppp chap password simple 123456
[internet-Serial1/0]quit
[internet]interface s2/0
[internet-Serial2/0]ppp authentication-mode chap
[internet-Serial2/0]ppp chap user jlin
[internet-Serial2/0]ppp chap password simple 123456
[internet-Serial2/0]quit

10、配置EASYIP

配置EASYIP,只有业务网段192.168.1.0/24和192.168.2.0/24的数据流可以通过R1访问互联网

[R1]acl basic 2000
[R1-acl-ipv4-basic-2000]rule 0 permit source 192.168.1.0 0.0.0.255
[R1-acl-ipv4-basic-2000]rule 5 permit source 192.168.2.0 0.0.0.255
[R1-acl-ipv4-basic-2000]quit
[R1]interface MP-group 1
[R1-MP-group1]nat outbound 2000
[R1-MP-group1]quit

此时只有pc1与pc2能访问internet没配置前都访问不了

11、开启TELNET远程管理

R1开启TELNET远程管理,使用用户abc登录,密码abc,只允许技术部远程管理R1

[R1]telnet server enable
[R1]local-user abc class manage
Newlocaluseradded.
[R1-luser-manage-abc]password simple abc
[R1-luser-manage-abc]service-typetelnet
[R1-luser-manage-abc]authorization-attribute user-role level-15
[R1-luser-manage-abc]quit
[R1]user-interface vty 0 4
[R1-line-vty0-4]authentication-mode scheme
[R1-line-vty0-4]user-role level-15
[R1-line-vty0-4]quit
[R1]acl advanced 3000
[R1-acl-ipv4-adv-3000]rule 0 permit tcp source 192.168.2.0 0.0.0.255 destination 10.0.0.0 0.0.0.255 destination-port eq 23
[R1-acl-ipv4-adv-3000]rule 5 deny tcp
[R1-acl-ipv4-adv-3000]quit
[R1]int g0/0
[R1-GigabitEthernet0/0]packet-filter 3000 inbound
[R1-GigabitEthernet0/0]quit21
[R1]int g0/1
[R1-GigabitEthernet0/1]packet-filter 3000 inbound
[R1-GigabitEthernet0/1]quit
[R1]int g0/2
[R1-GigabitEthernet0/2]packet-filter 3000 inbound
[R1-GigabitEthernet0/2]quit

配置前

配置后

[R1]int MP-group1
[R1-MP-group1]packet-filter 3000 inbound
[R1-MP-group1]qui
  • 11
    点赞
  • 68
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论
好的,您需要进行h3cne中静态路由实验,以下是具体步骤: 1. 配置路由器IP地址和管理口地址:登录路由器,进入system-view模式,输入以下命令: ``` [H3C] sysname Router [Router] interface vlan-interface 1 [Router-Vlan-interface1] ip address 192.168.1.1 24 [Router-Vlan-interface1] quit [Router] interface GigabitEthernet0/0/0 [Router-GigabitEthernet0/0/0] port link-mode route [Router-GigabitEthernet0/0/0] ip address 10.1.1.1 24 [Router-GigabitEthernet0/0/0] quit ``` 2. 配置PC1和PC2的IP地址:进入PC1和PC2的命令行界面,输入以下命令: ``` C:\>ipconfig Windows IP Configuration Ethernet adapter Ethernet0: Connection-specific DNS Suffix . : IPv4 Address. . . . . . . . . . . : 192.168.1.2 Subnet Mask . . . . . . . . . . . : 255.255.255.0 C:\>ping 192.168.1.1 ``` ``` C:\>ipconfig Windows IP Configuration Ethernet adapter Ethernet0: Connection-specific DNS Suffix . : IPv4 Address. . . . . . . . . . . : 192.168.2.2 Subnet Mask . . . . . . . . . . . : 255.255.255.0 C:\>ping 192.168.2.1 ``` 3. 配置路由器的静态路由:在路由器的命令行界面,输入以下命令: ``` [Router] ip route-static 192.168.2.0 24 10.1.1.2 [Router] ip route-static 192.168.3.0 24 10.1.1.2 ``` 4. 验证路由器的静态路由配置是否正确:在路由器的命令行界面,输入以下命令: ``` [Router] display ip routing-table ``` 5. 验证PC1和PC2之间的通信是否正常:在PC1和PC2的命令行界面,输入以下命令: ``` C:\>ping 192.168.2.2 ``` ``` C:\>ping 192.168.3.2 ``` 以上就是h3cne中静态路由实验的具体步骤,希望能对您有所帮助。

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

汉只只

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值