实验拓扑
注意:描述中的R1、R2或SW1、SW2对应拓扑中设备名称末尾数字为1、2的设备,以此类推
1.按照图示配置IP地址;
2.按照图示区域划分配置对应的动态路由协议;
3.在R7上配置dhcp服务器,能够让pc可以获取IP地址;
4.将所有环回⼝宣告进ospf中,将环回⼝7宣告进rip中,将rip路由引⼊ospf 中,ospf路由引⼊rip中
5.要求实现全⽹互通;
6.在r3和r6上开启rip的端⼝验证,密码为hyzy
7.在R7上开启rip静默接⼝,要求业务⽹段不允许接收协议报⽂
8.在R5和R4上开启ospf端⼝验证,密码为hyzy
9.要求在R4上配置ftp服务,测试时可以允许所有设备均可登录访问
10.要求在R1上配置telnet服务,测试时可以允许所有设备均可登录访问管理
11.要求拒绝R5访问R1的telnet服务,其他设备均不影响
12.要求拒绝R2访问R4的ftp服务,其他设备均不影响
13.要求拒绝10.1.1.0/24⽹段ping通R1地址
14.要求拒绝10.1.1.1/24地址访问R4地址
实验步骤
1.依照图配置IP地址
[H3C]sysn R1
[R1]int g0/0
[R1-GigabitEthernet0/0]ip add 192.168.1.1 24
[R1-GigabitEthernet0/0]int g0/1
[R1-GigabitEthernet0/1]ip add 192.168.2.1 24
[R1-GigabitEthernet0/1]int g0/2
[R1-GigabitEthernet0/2]ip add 100.3.3.1 24
[R1-GigabitEthernet0/2]int l0
[R1-LoopBack0]ip add 1.1.1.1 32
[H3C]sysn R2
[R2]int g0/0
[R2-GigabitEthernet0/0]ip add 192.168.1.2 24
[R2-GigabitEthernet0/0]int g0/1
[R2-GigabitEthernet0/1]ip add 192.168.3.2 24
[R2-GigabitEthernet0/1]int g0/2
[R2-GigabitEthernet0/2]ip add 100.1.1.2 24
[R2-GigabitEthernet0/2]int l0
[R2-LoopBack0]ip add 2.2.2.2 32
[H3C]sysn R3
[R3]int g0/0
[R3-GigabitEthernet0/0]ip add 192.168.2.3 24
[R3-GigabitEthernet0/0]int g0/1
[R3-GigabitEthernet0/1]ip add 192.168.3.3 24
[R3-GigabitEthernet0/1]int g0/2
[R3-GigabitEthernet0/2]ip add 200.2.2.3 24
[R3-GigabitEthernet0/2]int g5/0
[R3-GigabitEthernet5/0]ip add 200.1.1.3
[R3-GigabitEthernet5/0]int l0
[R3-LoopBack0]ip add 3.3.3.3 32
[R4]int g0/0
[R4-GigabitEthernet0/0]ip add 172.16.3.4 24
[R4-GigabitEthernet0/0]int g0/1
[R4-GigabitEthernet0/1]ip add 172.16.1.4 24
[R4-GigabitEthernet0/1]int g0/2
[R4-GigabitEthernet0/2]ip add 100.3.3.4 24
[R4-GigabitEthernet0/2]int l0
[R4-LoopBack0]ip add 4.4.4.4 32
[R5]sysn R5
[R5]int g0/0
[R5-GigabitEthernet0/0]ip add 172.16.1.5 24
[R5-GigabitEthernet0/0]int g0/1
[R5-GigabitEthernet0/1]ip add 172.16.2.5 24
[R5-GigabitEthernet0/1]int g0/2
[R5-GigabitEthernet0/2]ip add 100.2.2.5 24
[R5-GigabitEthernet0/2]int l0
[R5-LoopBack0]ip add 5.5.5.5 32
[H3C]sysn R6
[R6]int g0/0
[R6-GigabitEthernet0/0]ip add 200.3.3.6 24
[R6-GigabitEthernet0/0]int g0/1
[R6-GigabitEthernet0/1]ip add 200.1.1.6 24
[R6-GigabitEthernet0/1]int g0/2
[R6-GigabitEthernet0/2]ip add 172.16.3.6 24
[R6-GigabitEthernet0/2]int g5/0
[R6-GigabitEthernet5/0]ip add 172.16.2.6 24
[R6-GigabitEthernet5/0]int l0
[R6-LoopBack0]ip add 6.6.6.6 32
[H3C]sysn R6
[R6]int g0/0
[R6-GigabitEthernet0/0]ip add 200.3.3.6 24
[R6-GigabitEthernet0/0]int g0/1
[R6-GigabitEthernet0/1]ip add 200.1.1.6 24
[R6-GigabitEthernet0/1]int g0/2
[R6-GigabitEthernet0/2]ip add 172.16.3.6 24
[R6-GigabitEthernet0/2]int g5/0
[R6-GigabitEthernet5/0]ip add 172.16.2.6 24
[R6-GigabitEthernet5/0]int l0
[R6-LoopBack0]ip add 6.6.6.6 32
2.按照图示区域划分配置对应的动态路由协议
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 100.3.3.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]network 1.1.1.1 0.0.0.0
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255 ^
[R2-ospf-1-area-0.0.0.0]network 100.1.1.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 2.2.2.2 0.0.0.0
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]network 192.168.2.0 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 192.168.3.0 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 3.3.3.3 0.0.0.0
[R3-ospf-1-area-0.0.0.0]quit
[R3-ospf-1]quit
[R3]rip 1
[R3-rip-1]version 2
[R3-rip-1]undo summary
[R3-rip-1]network 200.1.1.0
[R3-rip-1]network 200.2.2.2
[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]network 172.16.3.0 0.0.0.255
[R4-ospf-1-area-0.0.0.0]network 192.16.1.0 0.0.0.255
[R4-ospf-1-area-0.0.0.0]network 100.3.3.0 0.0.0.255
[R4-ospf-1-area-0.0.0.0]network 3.3.3.3 0.0.0.0
[R5]ospf 1 router-id 5.5.5.5
[R5-ospf-1]area 0
[R5-ospf-1-area-0.0.0.0]network 172.16.1.0 0.0.0.255
[R5-ospf-1-area-0.0.0.0]network 172.16.2.0 0.0.0.255
[R5-ospf-1-area-0.0.0.0]network 100.2.2.0 0.0.0.255
[R5-ospf-1-area-0.0.0.0]network 5.5.5.5 0.0.0.0
[R6]ospf 2 router-id 6.6.6.6
[R6-ospf-2]area 0
[R6-ospf-2-area-0.0.0.0]network 172.16.3.0 0.0.0.255
[R6-ospf-2-area-0.0.0.0]network 172.16.2.0 0.0.0.255
[R6-ospf-2-area-0.0.0.0]network 6.6.6.6 0.0.0.0
[R6-ospf-2-area-0.0.0.0]quit
[R6-ospf-2]quit
[R6]rip 1
[R6-rip-1]version 2
[R6-rip-1]undo summary
[R6-rip-1]network 200.1.1.0
[R6-rip-1]network 200.3.3.0
[R7]rip 1
[R7-rip-1]version 2
[R7-rip-1]undo summary
[R7-rip-1]network 200.2.2.0
[R7-rip-1]network 200.3.3.0
[R7]ospf 1
[R7-ospf-1]area 0[R7-ospf-1-area-0.0.0.0]network 100.1.1.0 0.0.0.255
[R7-ospf-1-area-0.0.0.0]network 100.1.1.0 0.0.0.255
[R7-ospf-1]quit
[R7]ospf 2
[R7-ospf-2]area 0
[R7-ospf-2-area-0.0.0.0]network 100.2.2.0 0.0.0.255
3.在R7上配置dhcp服务器,能够让pc可以获取IP地址
[R7]dhcp enable
[R7]dhcp server ip-pool 1
[R7-dhcp-pool-1]network 10.1.1.0 24
[R7-dhcp-pool-1]gateway-list 10.1.1.254
4.将所有环回口宣告进ospf中,将环回口宣告进rip中,将rip路由引入ospf中,ospf路由引入rip中
[R3]rip 1
[R3-rip-1]import-route ospf 1
[R3-rip-1]import-route direct
[R3-rip-1]quit
[R3]ospf 1
[R3-ospf-1]import-route rip
[R3-ospf-1]import-rout direct
[R6]ospf 2
[R6-ospf-2]import-route rip
[R6-ospf-2]import-route direct
[R6-ospf-2]quit
[R6]rip 1
[R6-rip-1]import-route ospf 2
[R6-rip-1]import-route direct
[R7]rip
[R7-rip-1]import-route ospf 1
[R7-rip-1]import-route ospf 2
[R7-rip-1]import-route direct
[R7-rip-1]quit
[R7]ospf 1
[R7-ospf-1]import-route rip
[R7-ospf-1]import-route direct
[R7]ospf 2
[R7-ospf-2]import-route rip
[R7-ospf-2]import-route direct
5.要求实现全⽹互通
查看路由状况
6.在r3和r6上开启rip的端⼝验证,密码为yy(密码随意)
[R3]int g5/0
[R3-GigabitEthernet5/0]rip authentication-mode simple plain yy
[R6]int g0/1
[R6-GigabitEthernet0/1]rip authentication-mode simple plain yy
7.在R7上开启rip静默接⼝,要求业务⽹段不允许接收协议报⽂
[R7]rip 1
[R7-rip-1]silent-interface g5/1
8.在R5和R4上开启ospf端⼝验证,密码为yy
[R4]int g0/1
[R4-GigabitEthernet0/1]ospf authentication-mode simple plain yy
[R5]int g0/0
[R5-GigabitEthernet0/0]ospf authentication-mode simple plain yy
9.要求在R4上配置ftp服务,测试时可以允许所有设备均可登录访问
R4]ftp server enable
[R4]local-user yy class manage
New local user added.
[R4-luser-manage-yy]password simple 123456789q
[R4-luser-manage-yy]service-type ftp
[R4-luser-manage-yy]authorization-attribute user-role level-15
[R4-luser-manage-yy]line v 0 4
[R4-line-vty0-4]authentication-mode scheme
[R4-line-vty0-4]user-role level-15
在R1登录访问
10.要求在R1上配置telnet服务,测试时可以允许所有设备均可登录访问管理
[R1]telnet server enable
[R1]local-user aaa class manage
[R1-luser-manage-aaa]password simple 123456789q
[R1-luser-manage-aaa]service-type telnet
[R1-luser-manage-aaa]authorization-attribute user-role level-15
[R1-luser-manage-aaa]line v 0 4
[R1-line-vty0-4]authentication-mode scheme
[R1-line-vty0-4]user-role level-15
在PC9测试
11.要求拒绝R5访问R1的telnet服务,其他设备均不影响
[R1]acl advanced 3000
[R1-acl-ipv4-adv-3000]rule deny tcp source 172.16.1.5 0 destination-port eq 23
[R1-acl-ipv4-adv-3000]rule deny tcp source 172.16.2.5 0 destination-port eq 23
[R1-acl-ipv4-adv-3000]rule deny tcp source 100.2.2.5 0 destination-port eq 23
[R1-acl-ipv4-adv-3000]rule deny tcp source 5.5.5.5 0 destination-port eq 23
[R1-acl-ipv4-adv-3000]quit
[R1]int g0/0
[R1-GigabitEthernet0/0]packet-filter 3000 inbound
[R1-GigabitEthernet0/0]int g0/1
[R1-GigabitEthernet0/1]packet-filter 3000 inbound
[R1-GigabitEthernet0/1]int g0/2
[R1-GigabitEthernet0/2]packet-filter 3000 inbound
[R1-GigabitEthernet0/2]
R5访问R1的telnet被拒
12. 要求拒绝R2访问R4的ftp服务,其他设备均不影响
[R4]acl advanced 3000
[R4-acl-ipv4-adv-3000]rule deny tcp source 192.168.1.2 0 destination-port range
20 21
[R4-acl-ipv4-adv-3000]rule deny tcp source 192.168.3.2 0 destination-port range
20 21
[R4-acl-ipv4-adv-3000]rule deny tcp source 100.1.1.2 0 destination-port range 20
21
[R4-acl-ipv4-adv-3000]rule deny tcp source 2.2.2.2 0 destination-port range 20 2
1
[R4-acl-ipv4-adv-3000]quit
[R4]int g0/0
[R4-GigabitEthernet0/0]packet-filter 3000 inbound
[R4-GigabitEthernet0/0]int g0/1
[R4-GigabitEthernet0/1]packet-filter 3000 inbound
[R4-GigabitEthernet0/1]int g0/2
[R4-GigabitEthernet0/2]packet-filter 3000 inbound
R2访问R4的ftp被拒
13.要求拒绝10.1.1.0/24⽹段ping通R1地址
[R1]acl basic 2000
[R1-acl-ipv4-basic-2000]rule deny source 10.1.1.0 0.0.0.255
[R1-acl-ipv4-basic-2000]quit
[R1]int g0/0
[R1-GigabitEthernet0/0]packet-filter 2000 inbound
[R1-GigabitEthernet0/0]int g0/1
[R1-GigabitEthernet0/1]packet-filter 2000 inbound
[R1-GigabitEthernet0/1]int g0/2
[R1-GigabitEthernet0/2]packet-filter 2000 inbound
在PC中查看
14.要求拒绝10.1.1.1/24地址访问R4地址
[R4]acl basic 2000
[R4-acl-ipv4-basic-2000]rule deny source 10.1.1.1 0.0.0.255
[R4-acl-ipv4-basic-2000]quit
[R4]int g0/0
[R4-GigabitEthernet0/0]packet-filter 2000 inbound
[R4-GigabitEthernet0/0]int g0/1
[R4-GigabitEthernet0/1]packet-filter 2000 inbound
[R4-GigabitEthernet0/1]int g0/2
[R4-GigabitEthernet0/2]packet-filter 2000 inbound
在PC中查看