实验拓扑:
实验需求:
1.VLAN创建与划分(详情见规划表)
2.实现VALN间的通信
3.链路聚合(LSW1与LSW2之间完成链路聚合)
4.VLAN10、20、30使用DHCP下发地址
5.私网1内部(LSW1、LSW2以及AR1)运行OSPF
6.NAT配置(私网1可以通过公网网段访问公网23.1.1.3),NAT Server配置(私网2内客户端可以访问私网1内服务器)
终端设备规划表:
设备名称 | 部门 | 网段 | 网关 | VLAN |
PC1 | 技术部 | 192.168.10.0/24 | 192.168.10.254 | 10 |
PC2 | 技术部 | 192.168.10.0/24 | 192.168.10.254 | 10 |
Server1 | 192.168.20.0/24 | 192.168.20.254 | 20 | |
PC3 | 财务部 | 192.168.30.0/24 | 192.168.30.254 | 30 |
Client1 | 财务部 | 192.168.30.0/24 | 192.168.30.254 | 30 |
设备互联规划表:
设备 | 接口:IP | 对端设备 | VLAN |
AR1 | G0/0/0:10.1.1.1/24 | LSW1 | |
AR1 | G0/0/1:10.1.2.1/24 | LSW2 | |
AR1 | G1/0/0:12.1.1.1/24 | AR2 | |
AR1 | Loopback0:1.1.1.1/32 | ||
LSW1 | Vlanif4000:10.1.1.2/24 | AR1 | 4000 |
LSW1 | Vlanif10:192.168.10.254/24 | PC1、PC2 | 10 |
LSW1 | Vlanif20:192.168.20.254/24 | Server1 | 20 |
LSW1 | Loopback0:2.2.2.2/32 | ||
LSW2 | Vlanif4001:10.1.2.2/24 | AR1 | 4001 |
LSW2 | Vlanif30:192.168.30.254/24 | PC3、Client1 | 30 |
LSW2 | Loopback0:3.3.3.3/32 | ||
AR2 | G0/0/0:12.1.1.2/24 | AR1 | |
AR2 | G0/0/1:23.1.1.2/24 | AR3 | |
AR3 | G0/0/0:172.16.1.254/24 | Client3 | |
AR3 | G0/0/1:23.1.1.3/24 | AR2 | |
Server1 | 静态绑定:192.168.20.1/24 | LSW1 | |
Client1 | 静态绑定:192.168.30.1/24 | LSW2 | |
Client3 | 静态绑定:172.16.1.1/24 | AR3 |
实验步骤:
- 创建VLAN,划分到对应的接口,并进行VLANIF的配置
- 配置LSW1
<huawei> system-view //进入系统视图
[huawei] sysname LSW1 //修改设备名称
[LSW1] vlan batch 10 20 30 4000 //创建vlan
[LSW1] interface GigabitEthernet 0/0/1 //进入接口视图
[LSW1-GigabitEthernet0/0/1] port link-type access //更改接口属性
[LSW1-GigabitEthernet0/0/1] port default vlan 4000 //配置接口对应的vlan
[LSW1] interface GigabitEthernet 0/0/5
[LSW1-GigabitEthernet0/0/5] port link-type access
[LSW1-GigabitEthernet0/0/5] port default vlan 10
[LSW1] interface GigabitEthernet 0/0/6
[LSW1-GigabitEthernet0/0/6] port link-type access
[LSW1-GigabitEthernet0/0/6] port default vlan 10
[LSW1] interface GigabitEthernet 0/0/7
[LSW1-GigabitEthernet0/0/7] port link-type access
[LSW1-GigabitEthernet0/0/7] port default vlan 20
[LSW1] interface Vlanif 10
[LSW1-Vlanif10] ip address 192.168.10.254 24 //配置ip地址
[LSW1] interface Vlanif 20
[LSW1-Vlanif10] ip address 192.168.20.254 24
[LSW1] interface Vlanif 4000
[LSW1-Vlanif10] ip address 10.1.1.2 24
- 配置LSW2
<huawei> system-view
[huawei] sysname LSW2
[LSW2] vlan batch 10 20 30 4001
[LSW2] interface GigabitEthernet 0/0/1
[LSW2-GigabitEthernet0/0/1] port link-type access
[LSW2-GigabitEthernet0/0/1] port default vlan 4001
[LSW2] interface GigabitEthernet 0/0/7
[LSW2-GigabitEthernet0/0/7] port link-type access
[LSW2-GigabitEthernet0/0/7] port default vlan 30
[LSW2] interface GigabitEthernet 0/0/8
[LSW2-GigabitEthernet0/0/7] port link-type access
[LSW2-GigabitEthernet0/0/7] port default vlan 30
[LSW2] interface Vlanif 30
[LSW2-Vlanif30] ip address 192.168.30.254 24
[LSW2] interface Vlanif 4001
[LSW2-Vlanif4001] ip address 10.1.2.2 24
- 配置链路聚合
- 在LSW1上配置
[LSW1] interface Eth-Trunk 1
[LSW1-Eth-Trunk1] port link-type trunk
[LSW1-Eth-Trunk1] port trunk allow-pass vlan all
[LSW1-Eth-Trunk1] mode lacp-static
[LSW1-Eth-Trunk1] trunkport GigabitEthernet 0/0/3 to 0/0/4
- 在LSW2上配置
[LSW2] interface Eth-Trunk 1
[LSW2-Eth-Trunk1] port link-type trunk
[LSW2-Eth-Trunk1] port trunk allow-pass vlan all
[LSW2-Eth-Trunk1] mode lacp-static
[LSW2-Eth-Trunk1] trunkport GigabitEthernet 0/0/3 to 0/0/4
- 配置DHCP服务器,并创建地址池
- 在LSW1上配置
[LSW1] dhcp enable
[LSW1] ip pool vlan10
[LSW1-ip-pool-vlan10] network 192.168.10.0 mask 24
[LSW1-ip-pool-vlan10] gateway-list 192.168.10.254
[LSW1-ip-pool-vlan10] dns-list 8.8.8.8
[LSW1] interface Vlanif 10
[LSW1-Vlanif10] dhcp select global
- 在LSW2上配置
[LSW2] dhcp enable
[LSW2] ip pool vlan30
[LSW2-ip-pool-vlan30] network 192.168.30.0 mask 24
[LSW2-ip-pool-vlan30] gateway-list 192.168.30.254
[LSW2-ip-pool-vlan30] dns-list 8.8.8.8
[LSW2] interface Vlanif 30
[LSW2-Vlanif30] dhcp select global
在所有PC机上开启DHCP自动获取地址
通过ipconfig命令查看获取地址
- 配置OSPF互联
- 在AR1上配置:
[AR1]interface GigabitEthernet 0/0/0
[AR1-GigabitEthernet0/0/0]ip address 10.1.1.1 24
[AR1]interface GigabitEthernet 0/0/1
[AR1-GigabitEthernet0/0/0]ip address 10.1.2.1 24
[AR1] interface LoopBack 0
[AR1-LoopBack0] ip address 1.1.1.1 32 //配置环回口地址,作为ospf的router-id
[AR1] ospf 1 router-id 1.1.1.1
[AR1-ospf-1] area 0
[AR1-ospf-1-area-0.0.0.0] network 1.1.1.1 0.0.0.0
[AR1-ospf-1-area-0.0.0.0] network 10.1.1.0 0.0.0.255
[AR1-ospf-1-area-0.0.0.0] network 10.1.2.0 0.0.0.255
2)在LSW1上配置:
[LSW1] interface LoopBack 0
[LSW1-LoopBack0] ip address 2.2.2.2 32
[LSW1] ospf 1 router-id 2.2.2.2
[LSW1-ospf-1] area 0
[LSW1-ospf-1-area-0.0.0.0] network 2.2.2.2 0.0.0.0
[LSW1-ospf-1-area-0.0.0.0] network 10.1.1.0 0.0.0.255
[LSW1-ospf-1-area-0.0.0.0] network 192.168.10.0 0.0.0.255
[LSW1-ospf-1-area-0.0.0.0] network 192.168.20.0 0.0.0.255
- 在LSW2上配置:
[LSW2] interface LoopBack 0
[LSW2-LoopBack0] ip address 3.3.3.3 32
[LSW2] ospf 1 router-id 3.3.3.3
[LSW2-ospf-1] area 0
[LSW2-ospf-1-area-0.0.0.0] network 3.3.3.3 0.0.0.0
[LSW2-ospf-1-area-0.0.0.0] network 10.1.2.0 0.0.0.255
[LSW2-ospf-1-area-0.0.0.0] network 192.168.30.0 0.0.0.255
- 配置NAT
- 在AR1上配置:
[AR1] interface GigabitEthernet 1/0/0
[AR1-GigabitEthernet1/0/0] ip address 12.1.1.1 24
[AR1-GigabitEthernet1/0/0] nat static global 192.168.100.1 inside 192.168.10.0 netmask 255.255.255.0
[AR1] ip route-static 0.0.0.0 0 12.1.1.2
2)在LSW1上配置
[LSW1] ip route-static 0.0.0.0 0 10.1.1.1
3)在LSW2上配置
[LSW2] ip route-static 0.0.0.0 0 10.1.2.1
- 配置公网
在AR2上配置:
[AR2] interface GigabitEthernet 0/0/0
[AR2-GigabitEthernet0/0/0] ip address 12.1.1.2 24
[AR2] interface GigabitEthernet 0/0/1
[AR2-GigabitEthernet0/0/1] ip address 23.1.1.2 24
[AR2]ip route-static 0.0.0.0 0.0.0.0 12.1.1.1 #(针对从AR3返回关于192.168.100.0的数据包可以正常返回)
- 配置私网2
在AR3上配置:
[AR3] interface GigabitEthernet 0/0/0
[AR3-GigabitEthernet0/0/0] ip add 172.16.1.254 24
[AR3] acl 2000
[AR3-acl-basic-2000] rule permit
[AR3] interface GigabitEthernet 0/0/1
[AR3-GigabitEthernet0/0/1] ip ad 23.1.1.3 24
[AR3-GigabitEthernet0/0/1] nat outbound 2000
[AR3]ip route-static 0.0.0.0 0 23.1.1.2
- 在LSW1、LSW2查看创建的VLAN,操作如下:
二、在LSW/AR查看接口IP详情,示例如下:
三、在LSW1、LSW2查看链路聚合状态,示例如下:
四、在AR1、LSW1、LSW2查看OSPF配置及状态,示例如下:
五、在PC查看DHCP是否下发地址,示例如下:(以PC1为例)
- 测试PC1与sever1、PC3的连通性
- 验证NAT配置是否成功,示例如下:
在AR3的G0/0/1接口抓包
通过抓包可见PC1的ip地址192.168.10.252映射为192.168.100.0网段的公网网段192.168.100.192
- 验证Client3是否可以访问Server1,示例如下: