拓扑图
- 接口和路由配置
R1的接口和路由配置
R1(config)#int fa1/0
R1(config-if)#ip address 172.16.1.254 255.255.255.0
R1(config)#no shutdown
R1(config-if)#int fa0/0
R1(config-if)#ip address 172.16.4.1 255.255.255.0
R1(config)#no shutdown
R1(config-if)#router ospf 1
R1(config-router)#network 172.16.1.0 0.0.0.255 area 0
R1(config-router)#network 172.16.4.0 0.0.0.255 area 0
R2的接口和路由配置
R2(config)#int fa2/0
R2(config-if)#ip address 172.16.2.254 255.255.255.0
R2(config)#no shutdown
R2(config)#int fa1/0
R2(config-if)#ip address 172.16.5.1 255.255.255.0
R2(config)#no shutdown
R2(config-if)#int fa0/0
R2(config-if)#ip address 172.16.4.2 255.255.255.0
R2(config)#no shutdown
R2(config-if)#router ospf 1
R2(config-router)#network 172.16.2.0 0.0.0.255 area 0
R2(config-router)#network 172.16.4.0 0.0.0.255 area 0
R2(config-router)#network 172.16.5.0 0.0.0.255 area 0
R3的接口和路由配置
R3(config)#int fa1/0
R3(config-if)#ip address 172.16.5.3 255.255.255.0
R3(config)#no shutdown
R3(config-if)#int fa0/0
R3(config-if)#ip address 172.16.3.254 255.255.255.0
R3(config)#no shutdown
R3(config-if)#router ospf 1
R3(config-router)#network 172.16.3.0 0.0.0.255 area 0
R3(config-router)#network 172.16.5.0 0.0.0.255 area 0
- DHCP
R1上DHCP创建
ip dhcp pool 1
network 172.16.1.0 255.255.255.0
default-router 172.16.1.254
R1上DHCP创建
ip dhcp pool 2
network 172.16.2.0 255.255.255.0
default-router 172.16.2.254
R1上DHCP创建
ip dhcp pool 3
network 172.16.3.0 255.255.255.0
default-router 172.16.3.254
- 时间创建
time-range work
periodic weekdays 8:00 to 12:00
periodic weekdays 13:30 to 17:30
人事ACL,permit ip any any eq bootpc和permit ip any any eq bootps允许DHCP流量
ip access-list extended renshi_acl
permit ip any any eq bootpc
permit ip any any eq bootps
permit ip any 172.16.2.0 0.0.0.255 time-range work
permit ip any 172.16.3.0 0.0.0.255 time-range work
deny ip any any time-range work
permit ip any any
- 财务ACL
ip access-list extended caiwu_acl
permit ip any any eq bootpc
permit ip any any eq bootps
permit ip any 172.16.1.0 0.0.0.255 time-range work
permit ip any 172.16.3.0 0.0.0.255 time-range work
deny ip any any time-range work
deny ip any 172.16.1.0 0.0.0.255
deny ip any 172.16.3.0 0.0.0.255
permit ip any any
人事ACL
时间在18:00截图,所以ACL时间条目显示为inactive
ip access-list extended yanfa_acl
permit ip any any eq bootpc
permit ip any any eq bootps
deny tcp any 172.16.1.0 0.0.0.255 any
deny tcp any 172.16.2.0 0.0.0.255 any
permit ip any any