S1(config-if)#DO SHOW HISTORY
end
host S1
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line con 0
pass class
pass class123
login
exec-time 0 0
logging syn
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wanggong123
ip domain-name WG.com
cry key generate rsa
line vty 015
S1(config-if)#DO SHOW HISTORY
end
host S1
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line con 0
pass class
pass class123
login
exec-time 0 0
logging syn
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wanggong123
ip domain-name WG.com
cry key generate rsa
line vty 015
line vty 0 15
transport input ssh
login local
exit
ip ssh ver 2
int range f0/19-22
swi mode access
swi port-security
swi port-security max 2
swi port-security vio res
swi port-security mac-address stic
int range f0/19-24
int range f0/19-20
channel-group 3 mode active
int range f0/21-22
channel-group 1 mode active
exit
vtp mode client
vtp domain WG
vtp pass cisco123
do show int trunk
do show int status
do show int por-channel 1
do show int port-channel 1
do show int trunk
do show int port-channel 3
do show int port-channel 1
do show int trunk
end
int range f0/19-20
swi mo trunk
do show int trunk
do show vlan
spanning-tree vlan 2 root primary
spanning-tree vlan 2 root primary
spanning-tree vlan 3 root primary
spanning-tree vlan 4 root secondary
int vlan 1
no shut
DO SHOW HISTORY
S2(config)#do show history
host S2
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line con 0
pass class123
login
exec-time 0 0
logging syn
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wangong123
ip domain-name WG.com
cry key generate rsa
line vty 0 15
transport input ssh
login local
exit
ip ssh ver 2
int range f0/19-20.f0/23-24
int range f0/19-20,f0/23-24
swi mode access
swi port-security
swi port-security max 2
swi port-security vio restrict
swi port-security mac-address sticky
int range f0/19-20
channel-group 3 mode active
int range f0/21-22
channel-group 1 mode active
no channel-group 1 mode active
int range f0/23-24
channel-group 1 mode active
exit
vtp mode server
vtp domain WG
vtp pass cisco123
int port-channel 3
swi mode trun
int port-channel 2
swi mode trun
do show int trun
do show int port-channel 2
int port-channel 2
no shut
do show int port-channel 2
int port-channel 3
do show int port-channel 3
int range f0/23-24
shut
no shut
do show int port-channel 3
do show int port-channel 2
shut
no shut
do show int port-channel 2
shut
no shut
do show int port-channel 2
int f0/23-24
int range f0/23-24
channel-group 2 mode active
show int trun
do show int trun
int range f0/23-24
swi mode access
do show int port-channel 2
do show int port-channel 3
do show int port-channel 2
int port-channel 3
swi mode trun
int port-channel 2
swi mode trun
no swi mode trun
int range f0/19-20,f0/23-24
swi mode trun
do show int trunk
exit
vlan 2
vlan 3
vlan 4
exit
spanning-tree vlan 4 root primary
spanning-tree vlan 2 root secondary
spanning-tree vlan 3 root secondary
int vlan 1
no shut
do show vlan
do show int tr
int g0/1
swi mode tru
swi trun enc do
int range f0/23-24
swi mode tru
do show history
S3(config-if-range)#do show history
host S3
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
line con 0
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wanggong123
ip domain-name WG.com
cry key generate rsa
line vty 0 15
transport input ssh
login local
exit
ip ssh ver 2
int range f0/21-24
swi mode access
swi port-security
swi port-security max 2
swi port-security vio restrict
swi port-security mac-address sti
int range f0/21-22
channel-group 1 mode active
int range f0/23-24
channel-group 2 mode active
int range f0/2-4
swi port-security mac-address sti
swi port-security
swi mode access
swi port-security
swi port-security mac-address sti
swi port-security max 2
swi port-security vio restrict
exit
vtp mode client
vtp domain WG
vtp pass cisco123
int range f0/23-24
shut
no shut
int range f0/23-24
shut
no shut
do show int port-channel 1
do show int port-channel 2
int range f0/23-24
shut
no shut
do show int port-channel 1
do show int port-channel 2
int range f0/23-24
swi mo trunk
show int trunk
do show int trunk
do show vlan
int f0/2
swi acc vlan 2
int f0/3
swi acc vlan 3
int f0/4
swi acc vlan 4
exit
int vlan 1
no shut
int range f0/2-4
spanning-tree portfast
spanning-tree bpduguard enable
do show
do show vlan
do show int trunk
do show int po1
int range f0/23-24
swi mode tr
do show history
S3(config-if-range)#
R1(config)#do show history
host R1
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
line con 0
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wangong123
ip domain-name WG.com
cry key generate rsa
line vty 0 15
trans input ssh
login local
exit
ip ssh ver 2
int f0/0
no shut
int f0/0.2
enca do 2
ip add 192.168.2.254 255.255.255.0
int f0/0.3
enca do 3
ip add 192.168.3.254 255.255.255.0
int f0/0.4
enca do 4
ip add 192.168.4.254 255.255.255.0
exit
ser dhcp
ip dhcp pool vlan2
network 192.168.2.0 255.255.255.0
dns-server 192.168.2.1
default-router 192.168.2.254
ip dhcp pool vlan3
network 192.168.3.0 255.255.255.0
dns-server 192.168.3.1
default-router 192.168.3.254
ip dhcp pool vlan4
network 192.168.4.0 255.255.255.0
dns-server 192.168.4.1
default-router 192.168.4.254
exit
ip dhcp excluded-address 192.168.2.1 192.168.2.9
ip dhcp excluded-address 192.168.2.254 192.168.2.255
ip dhcp excluded-address 192.168.3.1 192.168.3.9
ip dhcp excluded-address 192.168.3.254 192.168.3.255
ip dhcp excluded-address 192.168.4.1 192.168.4.9
ip dhcp excluded-address 192.168.4.254 192.168.4.255
int f0/1
ip add 22.148.43.1 255.255.255.252
int s0/0/0
int f0/1
no ip add 22.148.43.1 255.255.255.252
ip add 202.148.43.1 255.255.255.252
int s0/0/0
ip add 202.147.144.1 255.255.255.252
no shut
int f0/1
no shut
ip route 0.0.0.0 0.0.0.0 202.148.43.2
ip route 0.0.0.0 0.0.0.0 202.147.144.2
ip route 0.0.0.0 0.0.0.0 s0/0/0 202.148.43.2
ip route 0.0.0.0 0.0.0.0 s0/0/0
ip route 0.0.0.0 0.0.0.0 f0/1 99
do show history
要求:
1、初始化:
主机名
关闭域名解析
历史记录 200条 S3#terminal history size 200
使能名文密码wanggong,加密密码cisco123
明文加密
最小密码长度为8 S3(config)#security passwords min-length 8
线路:永不超时、线路密码class123、光标跟踪
网关
地址
S3# terminal history size 200
S3(config)# hostname S3
S3(config)# no ip domain-lookup
S3(config)# enable password wanggong
S3(config)# enable secret cisco123
S3(config)# service password-encryption
S3(config)# line vty 0 15
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)# line con 0
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
2、SSH
用户名:WG 密码:wanggong123(安全高的)
域名:WG.com
SSH生效
S3(config)#username WG privilege 15 sec wanggong123
S3(config)#ip domain-name WG.com
S3(config)# crypto key generate rsa 1024
S3(config)#line vty 0 15
S3(config-line)#transport input ssh
S3(config-line)# login local
S1(config-line)#ip ssh ver 2
3、端口安全
动态粘贴 S3(config-if-range)#swi port-security mac-address sticky
最大地址数量为2
违规后不关闭端口,违规计数器记录。
S3(config)#int range f0/21-24
S3(config-if-range)#swi mode trunk
S3(config-if-range)#swi por
S3(config-if-range)#swi port-security
S3(config-if-range)#swi port-security maximum 2
S3(config-if-range)#swi port-security violation restrict
S3(config-if-range)#swi port-security mac-address sticky
interface FastEthernet0/2
switchport mode access
switchport access vlan 2
switchport port-security maximum 1
switchport port-security
switchport port-security violation restrict
spanning-tree portfast
interface FastEthernet0/3
switchport mode access
switchport access vlan 3
switchport port-security maximum 1
switchport port-security
switchport port-security violation restrict
spanning-tree portfast
interface FastEthernet0/4
switchport mode access
switchport access vlan 4
switchport port-security maximum 1
switchport port-security
switchport port-security violation restrict
spanning-tree portfast
4、Etherchannel
S1、S2、S3间的链路利用LACP实现Channel 1-3之前的捆绑,具体端口对应关系如图示。
S1(config)#int range f0/19-20
S1(config-if-range)#channel-group 3 mode active
Int port-channel 3
Swi mode trunk
5、VTP
VTP设置S2 Server,其他交换机为Clinet。
VTP域名:WG
VTP密码:cisco123
S3(config)#vtp mode client
Setting device to VTP CLIENT mode.
S3(config)#vtp domain WG
Changing VTP domain name from NULL to WG
S3(config)#vtp pass cisco123
Swi mode trunk
S1(config)#int range f0/19-20
S1(config-if-range)#swi mo trunk
S3(config-if-range)#int range f0/23-24
S3(config-if-range)#swi mo trunk
S2(config-if)#int range f0/19-20,f0/23-24
S2(config-if-range)#swi mode trun
6、VLAN
VLAN 2、3、4
7、STP
S1为VLAN2、VLAN3主根,VLAN4次根;S2为VLAN4主根,VLAN2、VLAN30次根,
相关端口设置PortFast 及BPDU防护。
交换机S1配置:
spanning-tree vlan 2 root primary
spanning-tree vlan 3 root primary
spanning-tree vlan 4 root secondary
spanning-tree portfast
spanning-tree bpduguard enable
交换机S2配置:
spanning-tree vlan 4 root primary
spanning-tree vlan 2 root secondary
spanning-tree vlan 3 root secondary
8、VLAN间路由+
R1单臂路由,实现VLAN2、VLAN3、VLAN4间由
R1(config)#int f0/0
R1(config-if)#no shut
R1(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up
R1(config-if)#int f0/0.2
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.2, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.2, changed state to up
R1(config-subif)#enca do 2
R1(config-subif)#ip add 192.168.2.254 255.255.255.0
R1(config-subif)#int f0/0.3
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.3, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.3, changed state to up
R1(config-subif)#enca do 3
R1(config-subif)#ip add 192.168.3.254 255.255.255.0
R1(config-subif)#exit
R1(config)#int f0/0.4
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.4, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.4, changed state to up
R1(config-subif)#enca do 4
R1(config-subif)#ip add 192.168.4.254 255.255.255.0
S3(config)#int f0/2
S3(config-if)#swi acc vlan 2
S3(config-if)#int f0/3
S3(config-if)#swi acc vlan 3
S3(config-if)#int f0/4
S3(config-if)#swi acc vlan 4
9、DHCP
R1为VLAN2、VLAN3、VLAN4下PC的DHCP Sever ,每个主机从该网络的第10个主机地址开始分配。
R1(config)#int f0/0
R1(config-if)#no shut
R1(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up
R1(config-if)#int f0/0.2
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.2, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.2, changed state to up
R1(config-subif)#enca do 2
R1(config-subif)#ip add 192.168.2.254 255.255.255.0
R1(config-subif)#int f0/0.3
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.3, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.3, changed state to up
R1(config-subif)#enca do 3
R1(config-subif)#ip add 192.168.3.254 255.255.255.0
R1(config-subif)#int f0/0.4
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.4, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.4, changed state to up
R1(config-subif)#enca do 4
R1(config-subif)#ip add 192.168.4.254 255.255.255.0
R1(config-subif)#exit
R1(config)#ser dhcp
R1(config)#ip dhcp pool vlan2
R1(dhcp-config)#network 192.168.2.0 255.255.255.0
R1(dhcp-config)#dns
R1(dhcp-config)#dns-server 192.168.2.1
R1(dhcp-config)#def
R1(dhcp-config)#default-router 192.168.2.254
R1(dhcp-config)#ip dhcp pool vlan3
R1(dhcp-config)#network 192.168.3.0 255.255.255.0
R1(dhcp-config)#dns-server 192.168.3.1
R1(dhcp-config)#default-router 192.168.3.254
R1(dhcp-config)#ip dhcp pool vlan4
R1(dhcp-config)#network 192.168.4.0 255.255.255.0
R1(dhcp-config)#dns-server 192.168.4.1
R1(dhcp-config)#default-router 192.168.4.254
R1(dhcp-config)#exit
R1(config)#ip dhcp ex
R1(config)#ip dhcp excluded-address 192.168.2.1 192.168.2.9
R1(config)#ip dhcp excluded-address 192.168.2.254 192.168.2.255
R1(config)#ip dhcp excluded-address 192.168.3.1 192.168.3.9
R1(config)#ip dhcp excluded-address 192.168.3.254 192.168.3.255
R1(config)#ip dhcp excluded-address 192.168.4.1 192.168.4.9
R1(config)#ip dhcp excluded-address 192.168.4.254 192.168.4.255
R1(config)#
S2(config-if)#int g0/1
S2(config-if)#swi mode tru
S2(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to up
S2(config-if)#swi trun enc do
^
% Invalid input detected at '^' marker.
S2(config-if)#int range f0/23-24
S2(config-if-range)#swi mode tru
10、静态路由
(1)静态默认路由
R1为内部网络边界路由器,为实现与外部ISP间通信。
R1(config)#ip route 0.0.0.0 0.0.0.0 202.148.43.2
R1(config)#ip route 0.0.0.0 0.0.0.0 202.147.144.2
(2)静态浮动路由
R1为保证与外部网络间的可持续访问,要求设置浮动静态路由,S0/0/0为主路由,f0/1为备份(AD:99)
R1(config)#int s0/0/0
R1(config-if)#ip add 202.147.144.1 255.255.255.252
R1(config-if)#no shut
R1(config-if)#
%LINK-5-CHANGED: Interface Serial0/0/0, changed state to up
R1(config-if)#int f0/
%LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0/0, changed state to up
R1(config-if)#int f0/1
R1(config-if)#ip add 202.148.43.1 255.255.255.252
R1(config-if)#no shut
R1(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up
R1(config-if)#exit
R1(config)#ip route 0.0.0.0 0.0.0.0 202.147.144.2
R1(config)#ip route 0.0.0.0 0.0.0.0 202.148.43.2 99
R1(config-if)#ip route 0.0.0.0 0.0.0.0 202.148.43.2
R1(config)#ip route 0.0.0.0 0.0.0.0 202.147.144.2
R1(config)#ip route 0.0.0.0 0.0.0.0 s0/0/0 202.148.43.2
^
% Invalid input detected at '^' marker.
R1(config)#ip route 0.0.0.0 0.0.0.0 s0/0/0
R1(config)#ip route 0.0.0.0 0.0.0.0 f0/1 99
11、测试
测试LAN内部主机与不ISP下的主机202.149.32.10间连通性。
R1
S3# terminal history size 200
S3(config)# hostname S3
S3(config)# no ip domain-lookup
S3(config)# enable password wanggong
S3(config)# enable secret cisco123
S3(config)# service password-encryption
S3(config)# line vty 0 15
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)# line con 0
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)#username WG privilege 15 sec wanggong123
S3(config)#ip domain-name WG.com
S3(config)# crypto key generate rsa 1024
S3(config)#line vty 0 15
S3(config-line)#transport input ssh
S3(config-line)# login local
S1(config-line)#ip ssh ver 2
R1(config)#int f0/0
R1(config-if)#no shut
R1(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up
R1(config-if)#int f0/0.2
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.2, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.2, changed state to up
R1(config-subif)#enca do 2
R1(config-subif)#ip add 192.168.2.254 255.255.255.0
R1(config-subif)#int f0/0.3
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.3, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.3, changed state to up
R1(config-subif)#enca do 3
R1(config-subif)#ip add 192.168.3.254 255.255.255.0
R1(config-subif)#int f0/0.4
R1(config-subif)#
%LINK-5-CHANGED: Interface FastEthernet0/0.4, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0.4, changed state to up
R1(config-subif)#enca do 4
R1(config-subif)#ip add 192.168.4.254 255.255.255.0
R1(config-subif)#exit
R1(config)#ser dhcp
R1(config)#ip dhcp pool vlan2
R1(dhcp-config)#network 192.168.2.0 255.255.255.0
R1(dhcp-config)#dns
R1(dhcp-config)#dns-server 192.168.2.1
R1(dhcp-config)#def
R1(dhcp-config)#default-router 192.168.2.254
R1(dhcp-config)#ip dhcp pool vlan3
R1(dhcp-config)#network 192.168.3.0 255.255.255.0
R1(dhcp-config)#dns-server 192.168.3.1
R1(dhcp-config)#default-router 192.168.3.254
R1(dhcp-config)#ip dhcp pool vlan4
R1(dhcp-config)#network 192.168.4.0 255.255.255.0
R1(dhcp-config)#dns-server 192.168.4.1
R1(dhcp-config)#default-router 192.168.4.254
R1(dhcp-config)#exit
R1(config)#ip dhcp ex
R1(config)#ip dhcp excluded-address 192.168.2.1 192.168.2.9
R1(config)#ip dhcp excluded-address 192.168.2.254 192.168.2.255
R1(config)#ip dhcp excluded-address 192.168.3.1 192.168.3.9
R1(config)#ip dhcp excluded-address 192.168.3.254 192.168.3.255
R1(config)#ip dhcp excluded-address 192.168.4.1 192.168.4.9
R1(config)#ip dhcp excluded-address 192.168.4.254 192.168.4.255
R1(config-if)#int f0/1
R1(config-if)#no shut
%LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0/0, changed state to up
R1(config-if)#no shut
R1(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up
R1(config-if)#ip route 0.0.0.0 0.0.0.0 202.148.43.2
R1(config)#ip route 0.0.0.0 0.0.0.0 202.147.144.2
R1(config)#ip route 0.0.0.0 0.0.0.0 s0/0/0
R1(config)#ip route 0.0.0.0 0.0.0.0 f0/1 99
S2
S3# terminal history size 200
S3(config)# hostname S3
S3(config)# no ip domain-lookup
S3(config)# enable password wanggong
S3(config)# enable secret cisco123
S3(config)# service password-encryption
S3(config)# line vty 0 15
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)# line con 0
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)#username WG privilege 15 sec wanggong123
S3(config)#ip domain-name WG.com
S3(config)# crypto key generate rsa 1024
S3(config)#line vty 0 15
S3(config-line)#transport input ssh
S3(config-line)# login local
S1(config-line)#ip ssh ver 2
S2(config-if-range)#int range f0/19-20,f0/23-24
S2(config)#swi mode access
S2(config)#swi port-security
S2(config)#swi port-security max 2
S2(config)#swi port-security vio restrict
S2(config)#swi port-security mac-address sticky
S2(config)#int range f0/19-20
S2(config)#channel-group 3 mode active
S2(config)#int range f0/21-22
S2(config)#channel-group 1 mode active
S2(config)#no channel-group 1 mode active
S2(config)#int range f0/23-24
S2(config)#channel-group 1 mode active
S2(config)#vtp mode server
S2(config)#vtp domain WG
S2(config)#vtp pass cisco123
S2(config)#int port-channel 3
S2(config)#swi mode trun
S2(config)#int port-channel 2
S2(config)#swi mode trun
S2(config)#do show int trun
S2(config)#do show int port-channel 2
S2(config)#int port-channel 2
S2(config)#no shut
S2(config)#do show int port-channel 2
S2(config)#int range f0/23-24
S2(config)#shut
S2(config)#no shut
S2(config)#int range f0/23-24
S2(config)#channel-group 2 mode active
S2(config)#show int trun
S2(config)#int range f0/23-24
S2(config)#swi mode access
S2(config)#int port-channel 3
S2(config)#swi mode trun
S2(config)#int port-channel 2
S2(config)#swi mode trun
S2(config)#int range f0/19-20,f0/23-24
S2(config)#swi mode trun
VLAN 2 VLAN 3 VLAN 4
spanning-tree vlan 4 root primary
spanning-tree vlan 2 root secondary
spanning-tree vlan 3 root secondary
S2(config)#int vlan 1
NO SHUT
S2(config)#int g0/1
S2(config)#swi mode tru
S2(config)#swi trun enc do
S2(config)#int range f0/23-24
S2(config)#swi mode tru
S3
S3# terminal history size 200
S3(config)# hostname S3
S3(config)# no ip domain-lookup
S3(config)# enable password wanggong
S3(config)# enable secret cisco123
S3(config)# service password-encryption
S3(config)# line vty 0 15
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)# line con 0
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)#username WG privilege 15 sec wanggong123
S3(config)#ip domain-name WG.com
S3(config)# crypto key generate rsa 1024
S3(config)#line vty 0 15
S3(config-line)#transport input ssh
S3(config-line)# login local
S1(config-line)#ip ssh ver 2
S3(config-if-range)#int range f0/21-24
S3(config-if-range)#swi mode access
S3(config-if-range)#swi port-security
S3(config-if-range)#swi port-security max 2
S3(config-if-range)#swi port-security vio restrict
S3(config-if-range)#swi port-security mac-address sti
S3(config-if-range)#int range f0/21-22
S3(config-if-range)#channel-group 1 mode active
S3(config-if-range)#int range f0/23-24
S3(config-if-range)#channel-group 2 mode active
S3(config-if-range)#int range f0/2-4
S3(config-if-range)#swi port-security mac-address sti
S3(config-if-range)#swi port-security
S3(config-if-range)#swi mode access
S3(config-if-range)#swi port-security
S3(config-if-range)#swi port-security mac-address sti
S3(config-if-range)#swi port-security max 2
S3(config-if-range)#swi port-security vio restrict
S3(config-if-range)#vtp mode client
S3(config-if-range)#vtp domain WG
S3(config-if-range)#vtp pass cisco123
S3(config-if-range)#int range f0/23-24
S3(config-if-range)#shut
S3(config-if-range)#no shut
S3(config-if-range)#int range f0/23-24
S3(config-if-range)#swi mo trunk
S3(config-if-range)#show int trunk
S3(config-if-range)#do show vlan
S3(config-if-range)#int f0/2
S3(config-if)#swi acc vlan 2
S3(config-if)#int f0/3
S3(config-if)#swi acc vlan 3
S3(config-if)#int f0/4
S3(config-if)#swi acc vlan 4
S3(config-if)#exit
S3(config)#int vlan 1
S3(config-if)#no shut
S3(config-if)#
%LINK-5-CHANGED: Interface Vlan1, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to up
S3(config-if)#int range f0/2-4
S3(config-if-range)#spanning-t
S3(config-if-range)#spanning-tree por
S3(config-if-range)#spanning-tree portfast
%Warning: portfast should only be enabled on ports connected to a single
host. Connecting hubs, concentrators, switches, bridges, etc... to this
interface when portfast is enabled, can cause temporary bridging loops.
Use with CAUTION
%Portfast has been configured on FastEthernet0/2 but will only
have effect when the interface is in a non-trunking mode.
%Warning: portfast should only be enabled on ports connected to a single
host. Connecting hubs, concentrators, switches, bridges, etc... to this
interface when portfast is enabled, can cause temporary bridging loops.
Use with CAUTION
%Portfast has been configured on FastEthernet0/3 but will only
have effect when the interface is in a non-trunking mode.
%Warning: portfast should only be enabled on ports connected to a single
host. Connecting hubs, concentrators, switches, bridges, etc... to this
interface when portfast is enabled, can cause temporary bridging loops.
Use with CAUTION
%Portfast has been configured on FastEthernet0/4 but will only
have effect when the interface is in a non-trunking mode.
S3(config-if-range)#spanning-tree bug
S3(config-if-range)#spanning-tree bpdu
S3(config-if-range)#spanning-tree bpduguard enable
S3(config-if-range)#do show
show
% Incomplete command.
S3(config-if-range)#do show vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Po1, Fa0/1, Fa0/5, Fa0/6
Fa0/7, Fa0/8, Fa0/9, Fa0/10
Fa0/11, Fa0/12, Fa0/13, Fa0/14
Fa0/15, Fa0/16, Fa0/17, Fa0/18
Fa0/19, Fa0/20, Fa0/21, Fa0/22
Gig0/1, Gig0/2
2 VLAN0002 active Fa0/2
3 VLAN0003 active Fa0/3
4 VLAN0004 active Fa0/4
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
2 enet 100002 1500 - - - - - 0 0
3 enet 100003 1500 - - - - - 0 0
S3(config-if-range)#do show int trunk
Port Mode Encapsulation Status Native vlan
Po2 on 802.1q trunking 1
Port Vlans allowed on trunk
Po2 1-1005
Port Vlans allowed and active in management domain
Po2 1,2,3,4
Port Vlans in spanning tree forwarding state and not pruned
Po2 1,2,3,4
S3(config-if-range)#do show int po1
Port-channel1 is up, line protocol is up (connected)
Hardware is EtherChannel, address is 0060.3ec3.5d38 (bia 0060.3ec3.5d38)
MTU 1500 bytes, BW 200000 Kbit, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Half-duplex, 200Mb/s
input flow-control is off, output flow-control is off
Members in this channel: Fa0/21 ,Fa0/22 ,
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:08, output 00:00:05, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue :0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
956 packets input, 193351 bytes, 0 no buffer
Received 956 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 watchdog, 0 multicast, 0 pause input
0 input packets with dribble condition detected
S3(config-if-range)#int range f0/23-24
S3(config-if-range)#swi mode tr
S3(config-if-range)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to up
%LINK-3-UPDOWN: Interface Port-channel2, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface Port-channel2, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to up
%LINK-5-CHANGED: Interface Port-channel2, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Port-channel2, changed state to up
S3(config-if-range)#
S1
S3# terminal history size 200
S3(config)# hostname S3
S3(config)# no ip domain-lookup
S3(config)# enable password wanggong
S3(config)# enable secret cisco123
S3(config)# service password-encryption
S3(config)# line vty 0 15
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)# line con 0
S3(config-line)# exec-timeout 0 0
S3(config-line)# password class123
S3(config-line)#login
S3(config-line)# logging synchronous
S3(config)#username WG privilege 15 sec wanggong123
S3(config)#ip domain-name WG.com
S3(config)# crypto key generate rsa 1024
S3(config)#line vty 0 15
S3(config-line)#transport input ssh
S3(config-line)# login local
S1(config-line)#ip ssh ver 2
S1(config-if)#int range f0/19-22
S1(config-if)#swi mode access
S1(config-if)#swi port-security
S1(config-if)#swi port-security max 2
S1(config-if)#swi port-security vio res
S1(config-if)#swi port-security mac-address stic
S1(config-if)#int range f0/19-24
S1(config-if)#int range f0/19-20
S1(config-if)#channel-group 3 mode active
S1(config-if)#int range f0/21-22
S1(config-if)#channel-group 1 mode active
S1(config-if)#vtp mode client
S1(config-if)#vtp domain WG
S1(config-if)#vtp pass cisco123
S1(config-if)#do show int trunk
S1(config-if)#int range f0/19-20
S1(config-if)#swi mo trunk
S1(config-if-range)#spanning-tree vlan 2 root pri
S1(config-if-range)#spanning-tree vlan 2 root primary
S1(config)#spanning-tree vlan 2 root primar
S1(config)#spanning-tree vlan 2 root primary
S1(config)#spanning-tree vlan 3 root primary
S1(config)#spanning-tree vlan 4 root se
S1(config)#spanning-tree vlan 4 root secondary
S1(config)#int vlan 1
S1(config-if)#no shut
S1(config-if)#DO SHOW HISTORY
end
host S1
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line con 0
pass class
pass class123
login
exec-time 0 0
logging syn
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wanggong123
ip domain-name WG.com
cry key generate rsa
line vty 015
S1(config-if)#DO SHOW HISTORY
end
host S1
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line con 0
pass class
pass class123
login
exec-time 0 0
logging syn
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wanggong123
ip domain-name WG.com
cry key generate rsa
line vty 015
line vty 0 15
transport input ssh
login local
exit
ip ssh ver 2
int range f0/19-22
swi mode access
swi port-security
swi port-security max 2
swi port-security vio res
swi port-security mac-address stic
int range f0/19-24
int range f0/19-20
channel-group 3 mode active
int range f0/21-22
channel-group 1 mode active
exit
vtp mode client
vtp domain WG
vtp pass cisco123
do show int trunk
do show int status
do show int por-channel 1
do show int port-channel 1
do show int trunk
do show int port-channel 3
do show int port-channel 1
do show int trunk
end
int range f0/19-20
swi mo trunk
do show int trunk
do show vlan
spanning-tree vlan 2 root primary
spanning-tree vlan 2 root primary
spanning-tree vlan 3 root primary
spanning-tree vlan 4 root secondary
int vlan 1
no shut
DO SHOW HISTORY
S2(config)#do show history
host S2
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line con 0
pass class123
login
exec-time 0 0
logging syn
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wangong123
ip domain-name WG.com
cry key generate rsa
line vty 0 15
transport input ssh
login local
exit
ip ssh ver 2
int range f0/19-20.f0/23-24
int range f0/19-20,f0/23-24
swi mode access
swi port-security
swi port-security max 2
swi port-security vio restrict
swi port-security mac-address sticky
int range f0/19-20
channel-group 3 mode active
int range f0/21-22
channel-group 1 mode active
no channel-group 1 mode active
int range f0/23-24
channel-group 1 mode active
exit
vtp mode server
vtp domain WG
vtp pass cisco123
int port-channel 3
swi mode trun
int port-channel 2
swi mode trun
do show int trun
do show int port-channel 2
int port-channel 2
no shut
do show int port-channel 2
int port-channel 3
do show int port-channel 3
int range f0/23-24
shut
no shut
do show int port-channel 3
do show int port-channel 2
shut
no shut
do show int port-channel 2
shut
no shut
do show int port-channel 2
int f0/23-24
int range f0/23-24
channel-group 2 mode active
show int trun
do show int trun
int range f0/23-24
swi mode access
do show int port-channel 2
do show int port-channel 3
do show int port-channel 2
int port-channel 3
swi mode trun
int port-channel 2
swi mode trun
no swi mode trun
int range f0/19-20,f0/23-24
swi mode trun
do show int trunk
exit
vlan 2
vlan 3
vlan 4
exit
spanning-tree vlan 4 root primary
spanning-tree vlan 2 root secondary
spanning-tree vlan 3 root secondary
int vlan 1
no shut
do show vlan
do show int tr
int g0/1
swi mode tru
swi trun enc do
int range f0/23-24
swi mode tru
do show history
S3(config-if-range)#do show history
host S3
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
line con 0
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wanggong123
ip domain-name WG.com
cry key generate rsa
line vty 0 15
transport input ssh
login local
exit
ip ssh ver 2
int range f0/21-24
swi mode access
swi port-security
swi port-security max 2
swi port-security vio restrict
swi port-security mac-address sti
int range f0/21-22
channel-group 1 mode active
int range f0/23-24
channel-group 2 mode active
int range f0/2-4
swi port-security mac-address sti
swi port-security
swi mode access
swi port-security
swi port-security mac-address sti
swi port-security max 2
swi port-security vio restrict
exit
vtp mode client
vtp domain WG
vtp pass cisco123
int range f0/23-24
shut
no shut
int range f0/23-24
shut
no shut
do show int port-channel 1
do show int port-channel 2
int range f0/23-24
shut
no shut
do show int port-channel 1
do show int port-channel 2
int range f0/23-24
swi mo trunk
show int trunk
do show int trunk
do show vlan
int f0/2
swi acc vlan 2
int f0/3
swi acc vlan 3
int f0/4
swi acc vlan 4
exit
int vlan 1
no shut
int range f0/2-4
spanning-tree portfast
spanning-tree bpduguard enable
do show
do show vlan
do show int trunk
do show int po1
int range f0/23-24
swi mode tr
do show history
S3(config-if-range)#
R1(config)#do show history
host R1
no ip domain-loo
enable pass wanggong
enable sec cisco123
service password-encryption
line vty 0 15
pass class123
login
exec-time 0 0
logging syn
line con 0
pass class123
login
exec-time 0 0
logging syn
exit
username WG privilege 15 sec wangong123
ip domain-name WG.com
cry key generate rsa
line vty 0 15
trans input ssh
login local
exit
ip ssh ver 2
int f0/0
no shut
int f0/0.2
enca do 2
ip add 192.168.2.254 255.255.255.0
int f0/0.3
enca do 3
ip add 192.168.3.254 255.255.255.0
int f0/0.4
enca do 4
ip add 192.168.4.254 255.255.255.0
exit
ser dhcp
ip dhcp pool vlan2
network 192.168.2.0 255.255.255.0
dns-server 192.168.2.1
default-router 192.168.2.254
ip dhcp pool vlan3
network 192.168.3.0 255.255.255.0
dns-server 192.168.3.1
default-router 192.168.3.254
ip dhcp pool vlan4
network 192.168.4.0 255.255.255.0
dns-server 192.168.4.1
default-router 192.168.4.254
exit
ip dhcp excluded-address 192.168.2.1 192.168.2.9
ip dhcp excluded-address 192.168.2.254 192.168.2.255
ip dhcp excluded-address 192.168.3.1 192.168.3.9
ip dhcp excluded-address 192.168.3.254 192.168.3.255
ip dhcp excluded-address 192.168.4.1 192.168.4.9
ip dhcp excluded-address 192.168.4.254 192.168.4.255
int f0/1
ip add 22.148.43.1 255.255.255.252
int s0/0/0
int f0/1
no ip add 22.148.43.1 255.255.255.252
ip add 202.148.43.1 255.255.255.252
int s0/0/0
ip add 202.147.144.1 255.255.255.252
no shut
int f0/1
no shut
ip route 0.0.0.0 0.0.0.0 202.148.43.2
ip route 0.0.0.0 0.0.0.0 202.147.144.2
ip route 0.0.0.0 0.0.0.0 s0/0/0 202.148.43.2
ip route 0.0.0.0 0.0.0.0 s0/0/0
ip route 0.0.0.0 0.0.0.0 f0/1 99
do show history