CSDN话题挑战赛第2期
参赛话题:学习笔记
文章目录
前言
华为模拟器配置实训总结:
设备配置命令(考配置思路,到考配置命令)
基础配置:system-view、sysname、interface vlanif10、ip address xx.xx.xx.xx 24、vlan batch 10 20
高频考点: DHCP、ACL、策略路由、NAT、VLAN间路由、静态路由/默认路由、RIP/OSPF…
前沿技术类:4G、WLAN、IPv6(策略:尽力而为,去题干中找答案,不要留白)
一、华为基础(配置+实训)
—
二、VLAN(配置)
<Huawei>sys
<Huawei>system-view
[Huawei]un
[Huawei]undo in
[Huawei]undo info-center e
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]user-in
[Huawei]user-interface v
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]in
[Huawei-ui-vty0-4]interface g0/0/0
[Huawei-GigabitEthernet0/0/0]q
[Huawei]acl 2000
[Huawei-acl-basic-2000]q
[Huawei]vlan 10
[Huawei-vlan10]q
[Huawei]ospf 1
[Huawei-ospf-1]q
[Huawei]
三、 DHCP(配置)
四、ACL(配置)
五、NAT(配置)
六、华为模拟器综合(原理+基础配置+实训)
1️⃣ACL
[1]ACL技术背景
[2]ACL概述
[3]ACL组成
[4]ACL特殊通配符(反掩码)
[5]ACL分类
-
基于ACL规格定义方式的分类
-
!!!基本和高级
-
-
基于ACL标识方法的分类
-
[6]ACL匹配效果![请添加图片描述](https://img-blog.csdnimg.cn/6d44e84c204a47fcb5ea8878b86f0c35.png)
[7]ACL应用位置
[8]ACL具体配置
AR1
<Huawei>system-view
[Huawei]undo info-center enable
[Huawei]sysname Router
[Router]interface g0/0/0
[Router-GigabitEthernet0/0/0]ip add
[Router-GigabitEthernet0/0/0]ip address 192.168.2.254 24
[Router-GigabitEthernet0/0/0]int
[Router-GigabitEthernet0/0/0]interface g0/0/1
[Router-GigabitEthernet0/0/1]ip address 192.168.3.254 24
[Router-GigabitEthernet0/0/1]q
[Router]interface g0/0/2
[Router-GigabitEthernet0/0/2]ip add
[Router-GigabitEthernet0/0/2]ip address 12.0.0.1 24
[Router-GigabitEthernet0/0/2]q
[Router]
[Router]acl 3000
[Router-acl-adv-3000]rule 10 permit ip source 192.168.3.0 0.0.0.255 destination
192.168.4.4 0 //只允许192.168.3.0过
[Router-acl-adv-3000]rule 20 deny ip source 192.168.2.0 0.0.0.255 destination
192.168.4.4 0
[Router-acl-adv-3000]rule 30 deny ip source any destination 192.168.4.4 0
[Router]
[Router]int g4/0/0
[Router-GigabitEthernet4/0/0]tr
[Router-GigabitEthernet4/0/0]tra
[Router-GigabitEthernet4/0/0]traffic-filter o
[Router-GigabitEthernet4/0/0]traffic-filter outbound a
[Router-GigabitEthernet4/0/0]traffic-filter outbound acl 3000
[Router-GigabitEthernet4/0/0]q
[Router]
AR2
<Huawei>system-view
[Huawei]undo info-center e
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]sysname AR2
[AR2]interface g0/0/0
[AR2-GigabitEthernet0/0/0]ip add
[AR2-GigabitEthernet0/0/0]ip address 12.0.0.2 24
[AR2-GigabitEthernet0/0/0]q
[AR2]undo ip route-static 0.0.0.0 0 12.1.1.1
2️⃣DHCP
【1】DHCP工作原理
【2】DHCP租期更新
【3】DHCP配置命令
【4】DHCP接口地址池配置
【5】DHCP具体配置
LSW1
##############################
<Huawei>sys
[Huawei]undo info-center enable
[Huawei]vlan 10
[Huawei-vlan10]vlan 20
[Huawei-vlan20]q
[Huawei]
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/1]port default vlan 10
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 20
[Huawei-GigabitEthernet0/0/2]q
[Huawei]interface g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type trunk
[Huawei-GigabitEthernet0/0/3]port trunk allow-pass vlan all
LSW2
##############################
<Huawei>sys
[Huawei]undo info-center enable
[Huawei]vlan 10
[Huawei-vlan10]vlan 20
[Huawei-vlan20]q
[Huawei]
[Huawei]int vlanif 10
[Huawei-Vlanif10]ip address 192.168.10.254 24
[Huawei-Vlanif10]q
[Huawei]
[Huawei]int vlanif 20
[Huawei-Vlanif20]ip address 192.168.20.254 24
[Huawei-Vlanif20]q
[Huawei]
[Huawei]interface g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[Huawei-GigabitEthernet0/0/1]q
[Huawei]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[Huawei]ip pool 10
Info:It's successful to create an IP address pool.
[Huawei-ip-pool-10]network 192.168.10.0 mask 24
[Huawei-ip-pool-10]gateway-list 192.168.10.254
[Huawei-ip-pool-10]dns-list 8.8.8.8
[Huawei-ip-pool-10]excluded-ip-address 192.168.10.101 192.168.10.253//排除的地址范围192.168.10.101 192.168.10.253(此范围内不能分配,则能用的为192。168.10.1-100)
[Huawei-ip-pool-10]
[Huawei-ip-pool-10]lease day 3// 租期为3天
[Huawei]
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]dhcp select global
[Huawei-Vlanif10]q
[Huawei]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[Huawei]ip pool 20
Info:It's successful to create an IP address pool.
[Huawei-ip-pool-20]network 192.168.20.0 mask 24
[Huawei-ip-pool-20]gateway-list 192.168.20.254
[Huawei-ip-pool-20]dns-list 114.114.114.114![请添加图片描述](https://img-blog.csdnimg.cn/dc61f25b57d4446bb0fcc2a94a0f8d15.png)
[Huawei-ip-pool-20]excluded-ip-address 192.168.20.2 192.168.20.253//排除的地址范围192.168.20.2 192.168.20.253(此范围内不能分配,则能用的为192.168.20.1)
[Huawei-ip-pool-20]
[Huawei-ip-pool-20]lease day 19// 租期为19天
[Huawei]
[Huawei]interface Vlanif 20
[Huawei-Vlanif10]dhcp select global
[Huawei-Vlanif10]q
PC自动获取到IP
3️⃣NAT
【1】产生背景
【2】私有地址
【3】NAT技术原理
【4】静态NAT配置示例
【5】动态NAT配置示例
①NAPT
②easyIP(端口映射)
③NAT Server
【6】动态NAT具体配置
AR1
<Huawei>system-view
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.254 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 12.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]
//可用公网地址池范围
12.1.1.2 - 12.1.1.5
[Huawei]nat address-group 1 12.1.1.2 12.1.1.5
//转换源IP(动态nat)
[Huawei]
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 10 permit source 192.168.1.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]nat outbound 2000 address-group 1
[Huawei-GigabitEthernet0/0/0]q
[Huawei]
//在AR1配一个静态路由指向出口
[Huawei]ip route-static 0.0.0.0 0 12.1.1.2
[Huawei]q
AR2
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add
[Huawei-GigabitEthernet0/0/0]ip address 12.1.1.2 24
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 23.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]
//AR2 和 AR3 做OSPF
[Huawei]ospf 1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 12.1.1.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]network 23.1.1.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]
AR3
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 23.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]
//AR2 和 AR3 做OSPF
[Huawei]ospf 1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 23.1.1.0 0.0.0.255
[Huawei-ospf-1-area-0.0.0.0]q
4️⃣BFD
【1】BDF原理
【2】BDF配置
AR1
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 12.1.1.1 24
[Huawei-GigabitEthernet0/0/0]q
//BFD网络监测
[Huawei]bfd R1R2 bind peer-ip 12.1.1.2 source-ip 12.1.1.1 auto
[Huawei-bfd-session-R1R2]commit
//BFD跟踪R1R2端口状态
[Huawei]ip route-static 2.2.2.0 255.255.255.0 12.1.1.2 track bfd-session R1R2
AR2
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]undo info-center enable
Info: Information center is disabled.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 12.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
//BFD网络监测
[Huawei]bfd R1R2 bind peer-ip 12.1.1.1 source-ip 12.1.1.2 auto
[Huawei-bfd-session-R1R2]commit
5️⃣综合实训(涵盖所有常考配置!!!)
acsw接入交换机配置
<Huawei>system-view
[Huawei]undo info-center enable
[Huawei]sysname acsw
[acsw]
[acsw]
[acsw]vlan batch 10 20
[acsw]int g0/0/1
[acsw-GigabitEthernet0/0/1]port link-type access
[acsw-GigabitEthernet0/0/1]port default vlan 10
[acsw-GigabitEthernet0/0/1]int g0/0/2
[acsw-GigabitEthernet0/0/2]port link-type access
[acsw-GigabitEthernet0/0/2]port default vlan 20
[acsw-GigabitEthernet0/0/2]int g0/0/3
[acsw-GigabitEthernet0/0/3]port link-type trunk
[acsw-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[acsw-GigabitEthernet0/0/3]q
coresw汇聚交换机配置
##################
<Huawei>system-view
[coresw]vlan batch 10 20
[coresw]int g0/0/3
[coresw-GigabitEthernet0/0/3]port link-type trunk
[coresw-GigabitEthernet0/0/3]port trunk allow-pass vlan all
[coresw-GigabitEthernet0/0/3]q
[coresw]interface Vlanif 10
[coresw-Vlanif10]ip address 192.168.10.254 24
[coresw-Vlanif10]int vlanif 20
[coresw-Vlanif20]ip address 192.168.20.254 24
[coresw-Vlanif20]q
[coresw]dhcp enable
[coresw-ip-pool-10]network 192.168.10.0 mask 24
[coresw-ip-pool-10]gateway-list 192.168.10.254
[coresw-ip-pool-10]dns-list 8.8.8.8
[coresw-ip-pool-10]lease day 3
[coresw-ip-pool-10]excluded-ip-address 192.168.10.3 192.168.10.253
[coresw-ip-pool-10]q
[coresw]
[coresw]
[coresw]int Vlanif 10
[coresw-Vlanif10]dhcp select global
[coresw-Vlanif10]q
[coresw]
[coresw]
[coresw]ip pool 20
[coresw-ip-pool-20]network 192.168.20.0 mask 24
[coresw-ip-pool-20]
[coresw-ip-pool-20]gateway-list 192.168.20.254
[coresw-ip-pool-20]
[coresw-ip-pool-20]dns-list 114.114.114.114
[coresw-ip-pool-20]e
[coresw-ip-pool-20]excluded-ip-address 192.168.20.2 192.168.20.253
[coresw-ip-pool-20]l
[coresw-ip-pool-20]lease day 2
[coresw-ip-pool-20]q
[coresw]
[coresw]
[coresw]interface Vlanif 20
[coresw-Vlanif20]dhcp select global
[coresw-Vlanif20]q
[coresw]
配置好DHCP后主机自动获取到IP地址
coresw汇聚交换机配置(为了让三层交换机与路由器通信)
[coresw]int g0/0/1
[coresw-GigabitEthernet0/0/1]port default vlan 30
[coresw-GigabitEthernet0/0/1]
[coresw-GigabitEthernet0/0/1]int vlan 30
[coresw-Vlanif30]ip add 192.168.30.254 24
[coresw-Vlanif30]q
[coresw]
出口路由器router上配置
[router]int g0/0/1
[router-GigabitEthernet0/0/1]ip add 192.168.30.3 24
[router-GigabitEthernet0/0/1]q
配置出口路由器回程路由
(1)静态路由
[router]ip route-static 192.168.10.0 24 192.168.30.254
配置回程静态路由后效果
(2)动态路由
这里增加一点点难度配置为动态路由
//首先删除之前配的静态路由
[router]undo ip route-static 192.168.10.0 24 192.168.30.254
[router]
删除好发现没有连通
(3)RIP配置路由
//配置出口路由器动态路由
[router]
[router]rip
[router-rip-1]version 2
[router-rip-1]network 192.168.30.0
[router-rip-1]
[coresw]
[coresw]rip
[coresw-rip-1]ver 2
[coresw-rip-1]network 192.168.10.0
[coresw-rip-1]network 192.168.20.0
[coresw-rip-1]network 192.168.30.0
[coresw-rip-1]
(4)OSPF配置路由
[router]ospf 1
[router-ospf-1]area 0
[router-ospf-1-area-0.0.0.0]network 192.168.30.0 0.0.0.255
[router-ospf-1-area-0.0.0.0]q
[router-ospf-1]
[coresw]ospf 1
[coresw-ospf-1]are
[coresw-ospf-1]area 0
[coresw-ospf-1-area-0.0.0.0]network 192.168.10.0 0.0.0.255
[coresw-ospf-1-area-0.0.0.0]network 192.168.20.0 0.0.0.255
[coresw-ospf-1-area-0.0.0.0]network 192.168.30.0 0.0.0.255
[coresw-ospf-1-area-0.0.0.0]q
[coresw-ospf-1]
[router]int g0/0/0
[router-GigabitEthernet0/0/0]ip address 12.1.1.1 24
[router-GigabitEthernet0/0/1]int g0/0/2
[router-GigabitEthernet0/0/2]ip address 23.1.1.1 24
[router-GigabitEthernet0/0/2]q
[router]
电信路由器
[dianxin]
[dianxin]int g0/0/0
[dianxin-GigabitEthernet0/0/0]ip add 12.1.1.1 24
[dianxin-GigabitEthernet0/0/0]int g0/0/1
[dianxin-GigabitEthernet0/0/1]ip add 100.1.1.1 24
[dianxin-GigabitEthernet0/0/1]q
[dianxin]
[dianxin]
[dianxin]rip
[dianxin-rip-1]ver 2
[dianxin-rip-1]network 100.0.0.0
[dianxin-rip-1]network 12.0.0.0
[dianxin-rip-1]network 1.0.0.0
[dianxin-rip-1]q
[dianxin]
联通路由器
[liantong]
[liantong]int g0/0/1
[liantong-GigabitEthernet0/0/1]ip add 100.1.1.1 24
[liantong-GigabitEthernet0/0/1]int g0/0/2
[liantong-GigabitEthernet0/0/2]ip add 23.1.1.2 24
[liantong-GigabitEthernet0/0/2]
[liantong-GigabitEthernet0/0/2]int lo0
[liantong-LoopBack0]ip add 2.2.2.2 24
[liantong-LoopBack0]q
[liantong]
[liantong]rip
[liantong-rip-1]ver 2
[liantong-rip-1]network 1.0.0.0
[liantong-rip-1]network 100.0.0.0
[liantong-rip-1]network 23.0.0.0
[liantong-rip-1]q
[liantong]
配置NAT和ACL
[router]acl 2000
[router-acl-basic-2000]rule permit source 192.168.10.0 0.0.0.255
[router-acl-basic-2000]rule permit source 192.168.20.0 0.0.0.255
[router-acl-basic-2000]q
[router]
[router]int g0/0/0
[router-GigabitEthernet0/0/0]nat outbound 2000
[router-GigabitEthernet0/0/0]
[router-GigabitEthernet0/0/0]int g0/0/2
[router-GigabitEthernet0/0/2]nat outbound 2000
[router-GigabitEthernet0/0/2]
[router]ip route-static 0.0.0.0 0 12.1.1.1 preference 50
配置BFD
总结
掩码与反掩码