实验要求:
实验预览图:
实验分析:
1、仅对私网设备进行OSPF配置,公网仅对test设备配置缺省路由,和配置R3端口IP
2、对私网配置OSPF,R2对公网的端口IP不宣发,同时对R2配置缺省路由,指向公网,再在R2配置缺省路由下发,对telnet、test配置缺省路由
3、4:先对私网和公网分开配置,使用NAT将私网与公网进行联系起来
5、在R3的端口上配置ACL,使得test-可以登入telnet server;而test-2不可以
6、在R2的0/0/0口配置ACL,使pc1可以访问test-1;test-2不可以
7、分别在R1、R2开启DHCP协议,对pc1、pc2进行IP分配
实验过程:
配置IP:
telnet:
[telnet server]interface GigabitEthernet 0/0/0
[telnet server-GigabitEthernet0/0/0]ip address 192.168.1.2 24
r1:
对0/0/0口:
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]ip address 192.168.1.1 24
对0/0/1口:
[r1]interface GigabitEthernet 0/0/1
[r1-GigabitEthernet0/0/1]ip address 192.168.12.1 24
检查配置:
[r1]display ip interface brief
Interface IP Address/Mask Physical Protocol
GigabitEthernet0/0/0 192.168.1.1/24 up up
GigabitEthernet0/0/1 192.168.12.1/24 up up
GigabitEthernet0/0/2 unassigned down down
NULL0 unassigned up up(s)
r2:
对0/0/0口:
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]ip address 192.168.12.2 24
对0/0/1口:
[r2]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]ip address 192.168.2.1 24
对0/0/2口:
[r2]interface GigabitEthernet 0/0/2
[r2-GigabitEthernet0/0/2]ip address 23.0.0.1 24
检查配置:
[r2]display ip interface brief
Interface IP Address/Mask Physical Protocol
GigabitEthernet0/0/0 192.168.12.2/24 up up
GigabitEthernet0/0/1 192.168.2.1/24 up up
GigabitEthernet0/0/2 23.0.0.1/24 up up
NULL0 unassigned up up(s)
r3:
对0/0/0口:
[r3]interface GigabitEthernet 0/0/0
[r3-GigabitEthernet0/0/0]ip address 34.0.0.1 24
对0/0/1口:
[r3]interface GigabitEthernet 0/0/1
[r3-GigabitEthernet0/0/1]ip address 23.0.0.2 24
检查配置:
[r3]display ip interface brief
Interface IP Address/Mask Physical Protocol
GigabitEthernet0/0/0 34.0.0.1/24 up up
GigabitEthernet0/0/1 23.0.0.2/24 up up
GigabitEthernet0/0/2 unassigned down down
NULL0 unassigned up up(s)
test-1:
对0/0/0口:
[test1]interface GigabitEthernet 0/0/0
[test1-GigabitEthernet0/0/0]ip address 34.0.0.2 24
检查配置:
[test1]display ip interface brief
Interface IP Address/Mask Physical Protocol
GigabitEthernet0/0/0 34.0.0.2/24 up up
GigabitEthernet0/0/1 unassigned down down
GigabitEthernet0/0/2 unassigned down down
NULL0 unassigned up up(s)
test-2:
对0/0/0口:
[test2]interface GigabitEthernet 0/0/0
[test2-GigabitEthernet0/0/0]ip address 34.0.0.3 24
检查配置:
[test2]display ip interface brief
Interface IP Address/Mask Physical Protocol
GigabitEthernet0/0/0 34.0.0.3/24 up up
GigabitEthernet0/0/1 unassigned down down
GigabitEthernet0/0/2 unassigned down down
NULL0 unassigned up up(s)
IP配置完成图:
配置DHCP协议
r1:
[r1]dhcp enable
[r1]ip pool aa
[r1-ip-pool-aa]network 192.168.1.0 mask 24
[r1-ip-pool-aa]gateway-list 192.168.1.1
[r1-ip-pool-aa]dns-list 8.8.8.8
[r1]interface GigabitEthernet 0/0/0
[r1-GigabitEthernet0/0/0]dhcp select global
在pc1开启DHCP服务:
测试:
r2:
[r2]dhcp enable
[r2]ip pool aa
[r2-ip-pool-aa]network 192.168.2.0 mask 24
[r2-ip-pool-aa]gateway-list 192.168.2.1
[r2-ip-pool-aa]dns-list 8.8.8.8
[r2]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]dhcp select global
在pc2开启DHCP服务:
测试:
全网可达:
r1:
[r1]ospf 1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.1 0.0.0.0
[r1-ospf-1-area-0.0.0.0]network 192.168.12.1 0.0.0.0
r2:
[r2]ospf 1
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 192.168.12.2 0.0.0.0
[r2-ospf-1-area-0.0.0.0]network 192.168.2.1 0.0.0.0
[r2]ip route-static 0.0.0.0 0 23.0.0.2
[r2]ospf 1
[r2-ospf-1]default-route-advertise
[r2]acl 2000
[r2-acl-basic-2000]rule permit source 192.168.0.0 0.0.255.255
[r2]interface GigabitEthernet 0/0/2
[r2-GigabitEthernet0/0/2]nat outbound 2000
telnet:
[telnet server]ip route-static 0.0.0.0 0 192.168.1.1
test-1:
[test1]ip route-static 0.0.0.0 0 34.0.0.1
test-2:
[test2]ip route-static 0.0.0.0 0 34.0.0.1
开启telnet服务:
telnet端:
[telnet server]user-interface vty 0 4
[telnet server-ui-vty0-4]authentication-mode aaa
[telnet server-aaa]local-user huawei password cipher 123456
[telnet server-aaa]local-user huawei privilege level 15
[telnet server-aaa]local-user huawei service-type telnet
r2开启telnet服务映射:
[r2]interface GigabitEthernet 0/0/2
[r2-GigabitEthernet0/0/2]nat server protocol tcp global current-interface telne t inside 192.168.1.2 telnet
Are you sure to continue?[Y/N]:y
测试映射是否成功:
test-1:
test-2:
配置test设备权限:
在r3的0/0/0口配置ACL:
[r3]acl 3000
[r3-acl-adv-3000]rule permit tcp source 34.0.0.2 0 destination 23.0.0.1 0 destin ation-port eq 23
[r3-acl-adv-3000]rule deny tcp source 34.0.0.3 0 destination 23.0.0.1 0 destinat ion-port eq 23
[r3]interface GigabitEthernet 0/0/0
[r3-GigabitEthernet0/0/0]traffic-filter inbound acl 3000
在r2的0/0/0口配置ACL:
[r2]acl 3100
[r2-acl-adv-3100]rule deny ip source 192.168.1.254 0 destination 34.0.0.3 0
[r2-acl-adv-3100]rule permit ip source 192.168.1.254 0 destination 34.0.0.2 0
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]traffic-filter inbound acl 3100