实验
实验要求
client为公网上的一个用户,R1为内网出口路由器,内网PC可以访问web server,并且PC和web server可以访问公网client,client可以访问内网的web server.
1.配置主机PC,client,web server的IP地址子网掩码和网关。
2.配置交换机SW
<Huawei>sys
[Huawei]sys SW
[SW]vlan batch 10 20 100
[SW]int e0/0/1
[SW-Ethernet0/0/1]p l a
[SW-Ethernet0/0/1]p d v 20
[SW-Ethernet0/0/1]int e0/0/2
[SW-Ethernet0/0/2]p l a
[SW-Ethernet0/0/2]p d v 10
[SW-Ethernet0/0/2]int e0/0/3
[SW-Ethernet0/0/3]p l t
[SW-Ethernet0/0/3]p t a v a
[SW-Ethernet0/0/3]
3.配置三层交换机RSW
<Huawei>sys
[Huawei]sys RSW
[RSW]vlan batch 10 20 100
[RSW]int g0/0/1
[RSW-GigabitEthernet0/0/1]p l t
[RSW-GigabitEthernet0/0/1]p t a v a
[RSW-GigabitEthernet0/0/1]int g0/0/2
[RSW-GigabitEthernet0/0/2]p l a
[RSW-GigabitEthernet0/0/2]p d v 100
[RSW-GigabitEthernet0/0/2]int vlanif 100
[RSW-Vlanif100]ip add 192.168.30.1 24
[RSW-Vlanif100]q
[RSW]ip route-static 0.0.0.0 0.0.0.0 192.168.30.2
4.配置路由器R1
<Huawei>sys
[Huawei]sys R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 192.168.30.2 24
[R1-GigabitEthernet0/0/0]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 10.0.0.1 24
[R1-GigabitEthernet0/0/1]nat static global 10.0.0.3 inside 192.168.10.1
[R1-GigabitEthernet0/0/1]nat server protocol tcp global 10.0.0.4 80 inside 192.1
68.20.1 80
[R1-GigabitEthernet0/0/1]q
[R1]
[R1]ip route-static 0.0.0.0 0 10.0.0.2
[R1]ip route-static 192.168.0.0 255.255.0.0 192.168.30.1
5.配置路由器R2
<Huawei>sys
[Huawei]sys R2
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 10.0.0.2 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip add 100.1.1.1 24
6.测试