综合实验-(H1-1)STP、VALN、OSPF、NAT、NAT Server、ACL日晟信息公司企业局域网搭建与维护

 

1.试题编号:H1-1日晟信息公司企业局域网搭建与维护

(1)任务描述

日晟信息公司近年来发展迅速,员工数量急剧增加。原有网络已经不能满足业务不断增长的需要。公司高层要求行政部IT专员对公司网络进行重新规划,统一管理,以提升网络性能并增强安全性。公司还需要架设两台WEB服务器,需要发布2个网站,一台用于宣传公司形象,另一台用于公司内部消息的发布。公司行政部IT专员经过调研,决定新增一台3层交换机,实现对公司现有网络的扩容。原有的2台2层交换机作为接入交换机继续使用。各交换机之间两两相连以提高网络可靠性,因此需要起用生成树协议。公司将继续使用原有IP地址网段172.16.10.0/24,划分为6个VLAN。其中,前四个vlan给四个部门使用,第五个vlan信息中心专用,第六个vlan备用,每个VLAN最后一个可用IP作为网关的IP。使用OSPF协议实现公司网络的内部互通。公司有三个外部地址,配置NAT以实现所有内网用户都可以访问外网。为了保证公司内部数据安全,对外宣传网站和对内信息发布网站分别架设在不同的服务器上。

网络拓扑结构如下图所示:

任务一:网络系统分析与设计(15分)

根据项目需求完成总公司网络IP地址分配,并将下表填写完整。

1)子网规划

描述

子网号

子网掩码

VLAN 10

172.16.10.0

255.255.255.224

VLAN 20

      172.16.10.32

255.255.255.224

VLAN 30

172.16.10.64

255.255.255.224

VLAN 40

172.16.10.96

255.255.255.224

VLAN 50

172.16.10.128

255.255.255.224

VLAN 60

172.16.10.160

255.255.255.224

2)外网地址

设备名

接口号

IP地址

子网掩码

AR1

G0/0/0

53.31.29.2

255.255.255.248

AR1

netserver

53.31.29.4

255.255.255.248

AR2

G0/0/0

53.31.29.1

255.255.255.248

3)网关地址

VLAN

网关IP

子网掩码

VLAN 10

172.16.10.30

255.255.255.224

VLAN 20

172.16.10.62

255.255.255.224

VLAN 30

172.16.10.94

255.255.255.224

VLAN 40

172.16.10.126

255.255.255.224

VLAN 50

172.16.10.158

255.255.255.224

VLAN 60

172.16.10.190

255.255.255.224

4)服务器IP地址

描述

IP地址

子网掩码

宣传服务器

172.16.10.130

255.255.255.252

信息发布服务器

172.16.10.131

255.255.255.252

5)路由器内网地址

设备名

接口号

IP地址

子网掩码

AR1

G0/0/1

172.16.10.157

255.255.255.224

注意:

把“网络地址分配表”以指定的文件名存放到指定位置——考场说明指定路径考生号试卷编号网络地址分配表。

任务二:网络设备选型与互联(15分)

① 使用eNSP模拟器进行组网。(2分)

② 选择合适的连接线缆,用于连接网络设备。(3分)

③ 三层交换机使用S5700,二层交换机使用S3700,路由器选择Router,将网线连接到各网络设备接口上,完成拓扑图。(10分)

任务三:交换机配置(30分)

① 使用eNSP模拟器,创建LSW1、LSW2和LSW3,配置LSW1的主机名为S1,LSW2的主机名为S2,LSW3的主机名为S3。(3分)

sysname S1
sysname S2
sysname S3

② 在LSW1、LSW2和LSW3上配置生成树协议,配置LSW1为生成树的root根。(4分)

S1、S2、S3

stp enable
stp mode stp

S1

stp instance 0 root primary

③ 在LSW1上创建VLAN50及其他业务vlan,并将g0/0/1、g0/0/23、g0/0/24加入该vlan 50中,在LSW2上创建业务vlan,将E0/0/1-9加入VLAN 10,E0/0/10-20加入vlan20。在LSW3上创建创建业务vlan,将E0/0/1-9加入VLAN 30,E0/0/10-20加入vlan40。配置交换机之间相连的接口为TRUNK,并允许业务vlan通过。(15分)

S1、S2、S3

vlan batch 10 20 30 40 50 60

S1

interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 50
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 10 20 30 40 50 60
#
interface GigabitEthernet0/0/3
 port link-type trunk
 port trunk allow-pass vlan 10 20 30 40 50 60
interface GigabitEthernet0/0/23
 port link-type access
 port default vlan 50
#
interface GigabitEthernet0/0/24
 port link-type access
 port default vlan 50

S2

interface Ethernet0/0/1
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/2
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/3
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/4
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/5
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/6
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/7
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/8
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/9
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/10
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/11
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/12
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/13
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/14
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/15
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/16
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/17
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/18
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/19
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/20
 port link-type access
 port default vlan 20

interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 10 20
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 10 20

S3

interface Ethernet0/0/1
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/2
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/3
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/4
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/5
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/6
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/7
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/8
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/9
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/10
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/11
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/12
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/13
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/14
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/15
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/16
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/17
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/18
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/19
 port link-type access
 port default vlan 40
#
interface Ethernet0/0/20
 port link-type access
 port default vlan 40

interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 30 40
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 30 40

④ 配置LSW1的VLAN接口,并且按照IP表上配置IP地址,实现VLAN之间互通。(4分)

interface Vlanif10
 ip address 172.16.10.30 255.255.255.224
#
interface Vlanif20
 ip address 172.16.10.62 255.255.255.224
#
interface Vlanif30
 ip address 172.16.10.94 255.255.255.224
#
interface Vlanif40
 ip address 172.16.10.126 255.255.255.224
#
interface Vlanif50
 ip address 172.16.10.158 255.255.255.224
#
interface Vlanif60
 ip address 172.16.10.190 255.255.255.224

⑤ 在LSW1上配置相应OSPF协议,进程号为1,汇总地址,确保内部网络互通。(4分)

ospf 1
 area 0.0.0.0
  network 172.16.10.0 0.0.0.255

任务四:路由器配置(20分)

① 配置AR1主机名为R1,AR2主机名为R2(6分)

sysname R1
sysname R2

② 根据网络IP地址规划表配置AR1各端口的IP地址和子网掩码。(6分)

interface GigabitEthernet0/0/0
 ip address 53.31.29.2 255.255.255.248 
#
interface GigabitEthernet0/0/1
 ip address 172.16.10.157 255.255.255.224 

③ 在AR1上配置ospf路由和地址转换,配置路由器连接内网的口为进口,连接外网的口为出口,使得内网主机能访问位于外网的服务器。配置AR1指向AR2的默认路由,配置AR2指向AR1的默认路由。配置内网用户访问外网使用地址53.31.29.3,配置外网用户访问信息宣传服务器使用53.31.29.4地址。(8分)

R1

acl number 2000  
 rule 5 permit source 172.16.10.0 0.0.0.255 
 rule 10 permit 

interface GigabitEthernet0/0/0
 nat server global 53.31.29.4 inside 172.16.10.130
 nat outbound 2000

ospf 1 
 default-route-advertise
 area 0.0.0.0 
  network 53.31.29.0 0.0.0.255 
  network 172.16.10.157 0.0.0.0 
 area 0.0.0.4 

ip route-static 0.0.0.0 0.0.0.0 53.31.29.1

R2

interface GigabitEthernet0/0/0
 ip address 53.31.29.1 255.255.255.248 

interface GigabitEthernet0/0/1
 ip address 10.10.10.1 255.255.255.0 

interface GigabitEthernet0/0/2
 ip address 192.168.10.1 255.255.255.0 

ip route-static 0.0.0.0 0.0.0.0 53.31.29.2

④ 外部网络自行配置,全网测试!(必含以下测试:外部用户访问宣传服务器,内部用户访问信息发布服务器,内部用户访问外网服务器)


测试

外部用户访问宣传服务器

内部用户访问信息发布服务器

内部用户访问外网服务器


全部命令

S1
sysname S1

vlan batch 10 20 30 40 50 60

stp mode stp
stp instance 0 root primary

interface Vlanif10
 ip address 172.16.10.30 255.255.255.224 

interface Vlanif20
 ip address 172.16.10.62 255.255.255.224 

interface Vlanif30
 ip address 172.16.10.94 255.255.255.224 

interface Vlanif40
 ip address 172.16.10.126 255.255.255.224 

interface Vlanif50
 ip address 172.16.10.158 255.255.255.224 

interface Vlanif60
 ip address 172.16.10.190 255.255.255.224 

interface GigabitEthernet0/0/1
 port link-type access
 port default vlan 50

interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 10 20 30 40 50 60

interface GigabitEthernet0/0/3
 port link-type trunk
 port trunk allow-pass vlan 10 20 30 40 50 60

interface GigabitEthernet0/0/23
 port link-type access
 port default vlan 50

interface GigabitEthernet0/0/24
 port link-type access
 port default vlan 50

ospf 1 
 area 0.0.0.0 
  network 172.16.10.0 0.0.0.255 
S2
sysname S2

vlan batch 10 20

stp mode stp
stp instance 0 root secondary

interface Ethernet0/0/1
 port link-type access
 port default vlan 10

interface Ethernet0/0/2
 port link-type access
 port default vlan 10

interface Ethernet0/0/3
 port link-type access
 port default vlan 10

interface Ethernet0/0/4
 port link-type access
 port default vlan 10

interface Ethernet0/0/5
 port link-type access
 port default vlan 10

interface Ethernet0/0/6
 port link-type access
 port default vlan 10

interface Ethernet0/0/7
 port link-type access
 port default vlan 10

interface Ethernet0/0/8
 port link-type access
 port default vlan 10

interface Ethernet0/0/9
 port link-type access
 port default vlan 10

interface Ethernet0/0/10
 port link-type access
 port default vlan 20

interface Ethernet0/0/11
 port link-type access
 port default vlan 20

interface Ethernet0/0/12
 port link-type access
 port default vlan 20

interface Ethernet0/0/13
 port link-type access
 port default vlan 20

interface Ethernet0/0/14
 port link-type access
 port default vlan 20

interface Ethernet0/0/15
 port link-type access
 port default vlan 20

interface Ethernet0/0/16
 port link-type access
 port default vlan 20

interface Ethernet0/0/17
 port link-type access
 port default vlan 20

interface Ethernet0/0/18
 port link-type access
 port default vlan 20

interface Ethernet0/0/19
 port link-type access
 port default vlan 20

interface Ethernet0/0/20
 port link-type access
 port default vlan 20

interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 10 20

interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 10 20
S3
sysname S3

vlan batch 30 40

stp mode stp
stp instance 0 root secondary

interface Ethernet0/0/1
 port link-type access
 port default vlan 30

interface Ethernet0/0/2
 port link-type access
 port default vlan 30

interface Ethernet0/0/3
 port link-type access
 port default vlan 30

interface Ethernet0/0/4
 port link-type access
 port default vlan 30

interface Ethernet0/0/5
 port link-type access
 port default vlan 30

interface Ethernet0/0/6
 port link-type access
 port default vlan 30

interface Ethernet0/0/7
 port link-type access
 port default vlan 30

interface Ethernet0/0/8
 port link-type access
 port default vlan 30

interface Ethernet0/0/9
 port link-type access
 port default vlan 30

interface Ethernet0/0/10
 port link-type access
 port default vlan 40

interface Ethernet0/0/11
 port link-type access
 port default vlan 40

interface Ethernet0/0/12
 port link-type access
 port default vlan 40

interface Ethernet0/0/13
 port link-type access
 port default vlan 40

interface Ethernet0/0/14
 port link-type access
 port default vlan 40

interface Ethernet0/0/15
 port link-type access
 port default vlan 40

interface Ethernet0/0/16
 port link-type access
 port default vlan 40

interface Ethernet0/0/17
 port link-type access
 port default vlan 40

interface Ethernet0/0/18
 port link-type access
 port default vlan 40

interface Ethernet0/0/19
 port link-type access
 port default vlan 40

interface Ethernet0/0/20
 port link-type access
 port default vlan 40

interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 30 40

interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 30 40
R1
sysname R1

acl number 2000  
 rule 5 permit source 172.16.10.0 0.0.0.255 
 rule 10 permit 

interface GigabitEthernet0/0/0
 ip address 53.31.29.2 255.255.255.248 
 nat server global 53.31.29.4 inside 172.16.10.130
 nat outbound 2000

interface GigabitEthernet0/0/1
 ip address 172.16.10.157 255.255.255.224 

ospf 1 
 default-route-advertise
 area 0.0.0.0 
  network 53.31.29.0 0.0.0.255 
  network 172.16.10.157 0.0.0.0 
 area 0.0.0.4 

ip route-static 0.0.0.0 0.0.0.0 53.31.29.1
R2
sysname R2

interface GigabitEthernet0/0/0
 ip address 53.31.29.1 255.255.255.248 

interface GigabitEthernet0/0/1
 ip address 10.10.10.1 255.255.255.0 

interface GigabitEthernet0/0/2
 ip address 192.168.10.1 255.255.255.0 

ip route-static 0.0.0.0 0.0.0.0 53.31.29.2
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值