要求如图,划分网段:
先配置路由器ip:
[r1]int lo0
[r1-LoopBack0]ip add 192.168.1.1 30
[r1-LoopBack0]int lo1
[r1-LoopBack1]ip add 192.168.1.5 30
[r1-LoopBack1]int lo2
[r1-LoopBack2]ip add 192.168.1.9 30
[r1-LoopBack2]int g 0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.1.17 28
[r1-GigabitEthernet0/0/0]int g0/0/1
[r1-GigabitEthernet0/0/1]ip add 192.168.1.65 28
[r2]int g0/0/0
[r2-GigabitEthernet0/0/0]ip add 192.168.1.18 28
[r2-GigabitEthernet0/0/0]int g0/0/1
[r2-GigabitEthernet0/0/1]ip add 192.168.1.33 28
[r3]int g0/0/0
[r3-GigabitEthernet0/0/0]ip add 192.168.1.34 28
[r3-GigabitEthernet0/0/0]int g0/0/1
[r3-GigabitEthernet0/0/1]ip add 192.168.1.82 28
[r3-GigabitEthernet0/0/1]int g4/0/0
[r3-GigabitEthernet4/0/0]ip add 192.168.1.129 28
[r3-GigabitEthernet4/0/0]int g0/0/2
[r3-GigabitEthernet0/0/2]ip add 192.168.1.145 28
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip add 192.168.1.66 28
[r4-GigabitEthernet0/0/0]int g 0/0/1
[r4-GigabitEthernet0/0/1]ip add 192.168.1.81 28
[r4-GigabitEthernet0/0/1]int g0/0/2.1
[r4-GigabitEthernet0/0/2.1]ip add 192.168.1.97 28
[r4-GigabitEthernet0/0/2.1]int g0/0/2.2
[r4-GigabitEthernet0/0/2.2]ip add 192.168.1.113 28
[r4]int g0/0/2.1
[r4-GigabitEthernet0/0/2.1]dot1q termination vid 2
[r4-GigabitEthernet0/0/2.1]arp broadcast enable
[r4-GigabitEthernet0/0/2.1]int g0/0/2.2
[r4-GigabitEthernet0/0/2.2]dot1q termination vid 3
[r4-GigabitEthernet0/0/2.2]arp broadcast enable
[r4-GigabitEthernet0/0/2.2]q
[r4]ip pool aaa
Info: It's successful to create an IP address pool.
[r4-ip-pool-aaa]network 192.168.1.96 mask 28
[r4-ip-pool-aaa]gateway-list 192.168.1.97
[r4-ip-pool-aaa]dns-list 114.114.114.114
[r4-ip-pool-aaa]q
[r4]dhcp en
[r4]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[r4]ip pool bbb
Info: It's successful to create an IP address pool.
[r4-ip-pool-bbb]network 192.168.1.112 mask 28
[r4-ip-pool-bbb]gateway-list 192.168.1.113
[r4-ip-pool-bbb]dns-list 114.114.114.114
[r4]int g0/0/2.1
[r4-GigabitEthernet0/0/2.1]dhcp select global
[r4-GigabitEthernet0/0/2.1]int g0/0/2.2
[r4-GigabitEthernet0/0/2.2]dhcp select global
[r5]int g0/0/1
[r5-GigabitEthernet0/0/1]ip add 192.168.1.130 28
[r5-GigabitEthernet0/0/1]int g0/0/0
[r5-GigabitEthernet0/0/0]ip add 192.168.1.146 28
[isp]int g0/0/0
[isp-GigabitEthernet0/0/0]ip add 100.1.1.2 24
配置静态路由:
[r1]ip route-static 192.168.1.32 28 192.168.1.18
[r1]ip route-static 192.168.1.128 28 192.168.1.18
[r1]ip route-static 192.168.1.144 28 192.168.1.18
[r1]ip route-static 192.168.1.144 28 192.168.1.66
[r1]ip route-static 192.168.1.128 28 192.168.1.66
[r1]ip route-static 192.168.1.80 28 192.168.1.66
[r1]ip route-static 192.168.1.96 28 192.168.1.66
[r1]ip route-static 192.168.1.112 28 192.168.1.6
[r1]ip route-static 0.0.0.0 0 192.168.1.18
[r1]ip route-static 0.0.0.0 0 192.168.1.66
[r2]ip route-static 192.168.1.128 28 192.168.1.34
[r2]ip route-static 192.168.1.144 28 192.168.1.34
[r2]ip route-static 192.168.1.80 28 192.168.1.34
[r2]ip route-static 192.168.1.96 28 192.168.1.34
[r2]ip route-static 192.168.1.112 28 192.168.1.34
[r2]ip route-static 192.168.1.112 28 192.168.1.17
[r2]ip route-static 192.168.1.96 28 192.168.1.17
[r2]ip route-static 192.168.1.64 28 192.168.1.17
[r2]ip route-static 192.168.1.0 28 192.168.1.17
[r3]ip route-static 192.168.1.96 28 192.168.1.81
[r3]ip route-static 192.168.1.112 28 192.168.1.8
[r3]ip route-static 192.168.1.64 28 192.168.1.81
[r3]ip route-static 192.168.1.0 28 192.168.1.81
[r3]ip route-static 192.168.1.0 28 192.168.1.33
[r3]ip route-static 192.168.1.16 28 192.168.1.33
[r3]ip route-static 0.0.0.0 0 192.168.1.146
[r3]ip route-static 0.0.0.0 0 192.168.1.130 preference 61
[r4]ip route-static 192.168.1.0 28 192.168.1.65
[r4]ip route-static 192.168.1.16 28 192.168.1.65
[r4]ip route-static 192.168.1.32 28 192.168.1.82
[r4]ip route-static 192.168.1.128 28 192.168.1.82
[r4]ip route-static 192.168.1.144 28 192.168.1.82
[r4]ip route-static 0.0.0.0 0 192.168.1.82
[r5]ip route-static 192.168.1.0 24 192.168.1.145
[r5]ip route-static 192.168.1.0 24 192.168.1.129 preference 61
[r5]ip route-static 0.0.0.0 0 100.1.1.2
此时内网全网可达
[r5]acl 2000
[r5-acl-basic-2000]rule 1 permit source any
[r5-acl-basic-2000]q
[r5]int g0/0/2
[r5-GigabitEthernet0/0/2]nat outbound 2000
此时pc1可以ping通isp
结束