
//接入层交换机1
Switch>en
Switch#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#vlan 2
Switch(config)#vlan 3
Switch(config-vlan)#int f0/2
Switch(config-if)#sw ac vlan 2
Switch(config-if)#switchport port-security violation shutdown
Switch(config-if)#switchport port-security max 3
Switch(config)#int f0/3
Switch(config-if)#sw ac vlan 3
Switch(config-if)#switchport port-security violation shutdown
Switch(config-if)#switchport port-security mac-address 0060.2F79.A6A0
Switch(config-if)#int f0/1
Switch(config-if)#sw mo trunk
Switch(config-if)#no shutdown
//汇聚层路由器
Router>en
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int f0/1.2
Router(config-subif)#en dot1Q 2
Router(config-subif)#ip add 192.168.2.1 255.255.255.0
Router(config-subif)#no shutdown
Router(config)#int f0/1.3
Router(config-subif)#en dot1Q 3
Router(config-subif)#ip add 192.168.3.1 255.255.255.0
Router(config-subif)#no shutdown
Router(config-if)#int f0/1
Router(config-if)#no shutdown
Router(config)#int f0/0
Router(config-if)#ip add 192.168.179.101 255.255.255.0
Router(config-if)#no shutdown
Router(config)#router ospf 1
Router(config-router)#net 192.168.2.0 0.0.0.255 area 0
Router(config-router)#net 192.168.3.0 0.0.0.255 area 0
Router(config-router)#net 192.168.179.0 0.0.0.255 area 0
Router(config-router)#exit
//汇聚层交换机1
Switch>en
Switch#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#ip routing
Switch(config)#int vlan 1
Switch(config-if)#ip add 172.16.179.101 255.255.255.0
Switch(config-if)#no shutdown
Switch(config)#vlan 4
Switch(config)#vlan 5
Switch(config)#int vlan 4
Switch(config-if)#ip add 172.16.4.1 255.255.255.0
Switch(config-if)#no shutdown
Switch(config)#int vlan 5
Switch(config-if)#ip add 172.16.5.1 255.255.255.0
Switch(config-if)#no shutdown
Switch(config)#router ospf 1
Switch(config-router)#net 172.16.4.0 0.0.0.255 area 0
Switch(config-router)#net 172.16.5.0 0.0.0.255 area 0
Switch(config-router)#net 172.16.179.0 0.0.0.255 area 0
Switch(config)#int f0/24
Switch(config-if)#sw tr en dot1q
Switch(config-if)#sw mo trunk
//接入层交换机2
Switch>en
Switch#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#int f0/1
Switch(config-if)#sw mo trunk
Switch(config-if)#exit
Switch(config)#vlan 4
Switch(config)#vlan 5
Switch(config)#int f0/2
Switch(config-if)#sw ac vlan 4
Switch(config-if)#sw port-security violation restrict
Switch(config-if)#sw port-security mac-address 0002.170D.ABC5
Switch(config-if)#exit
Switch(config)#int f0/3
Switch(config-if)#sw ac vlan 5
Switch(config-if)#sw port-security violation restrict
Switch(config-if)#sw port-security maximum 3
Switch(config-if)#
//汇聚层交换机2
Switch>en
Switch#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#ip routing
Switch(config)#int f0/1
Switch(config-if)#no switchport
Switch(config-if)#ip add 10.179.179.101 255.255.255.0
Switch(config-if)#no shutdown
Switch(config-if)#int f0/2
Switch(config-if)#no switchport
Switch(config-if)#ip add 10.179.1.1 255.255.255.0
Switch(config-if)#no shutdown
Switch(config-if)#router ospf 1
Switch(config-router)#net 10.179.1.0 0.0.0.255 area 0
Switch(config-router)#net 10.179.179.0 0.0.0.255 area 0
//核心路由器
access-list 1 permit 192.168.2.0 0.0.0.255
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 1 permit 172.16.4.0 0.0.0.255
access-list 1 permit 172.16.5.0 0.0.0.255
ip nat pool cisco 219.220.241.110 219.220.241.120 netmask 255.255.255.0
ip nat inside source list 1 pool cisco overload
ip nat inside source static 10.179.1.2 219.220.241.200
router ospf 1
network 192.168.179.0 0.0.0.255 area 0
network 172.16.179.0 0.0.0.255 area 0
network 10.179.179.0 0.0.0.255 area 0
//路由重分布
Router(config)#router ospf 1
Router(config-router)#default-information originate
ip route 0.0.0.0 0.0.0.0 219.220.241.100
interface FastEthernet1/0
ip address 10.179.179.100 255.255.255.0
ip nat inside
interface FastEthernet0/1
ip address 172.16.179.100 255.255.255.0
ip nat inside
interface FastEthernet0/0
ip address 192.168.179.100 255.255.255.0
ip nat inside
interface Serial0/0/0
ip address 219.220.241.101 255.255.255.0
ip nat outside
//出口路由器
interface FastEthernet0/1
ip address 219.220.240.1 255.255.255.0
interface Serial0/0/0
ip address 219.220.241.100 255.255.255.0
clock rate 64000