文章简介:本文用华为ensp对企业网络进行了规划和模拟,也同样适用于校园、医院等场景,文章附完整设备配置命令。附件为ensp项目,如有需要可下载后联系作者,提供售后服务,可以根据定制化需求做修改。ensp项目下载地址:
华为ensp模拟企业网络规划与设计.zip_基于ensp的校园网网络拓扑结构-网络基础文档类资源-CSDN下载
作者简介:网络工程师,希望能认识更多的小伙伴一起交流
---------------------------------------------------------------------------------------------------------------------------------
目录
一、摘要
本文用到的技术:VLAN,各终端地址使用静态地址分配;核心设备之间使用链路聚合,MSTP,VRRP协议提高办公效率;网络设备之间使用 运行OSPF协议;防火墙使用NAT技术,保证信息安全;搭建无线网络保证无线网络全公司覆盖,提高办公效率。
二、网络拓扑图
三、IP地址及VLAN规划
VLAN编号 | 网络地址 | 子网掩码 | 区域 |
VLAN10 | 192.168.10.5 | 255.255.255.0 | 市场部 |
VLAN20 | 192.168.20.5 | 255.255.255.0 | 财务部 |
VLAN30 | 192.168.30.5 | 255.255.255.0 | 行政部 |
VLAN40 | 192.168.40.5 | 255.255.255.0 | 研发部 |
VLAN50 | 192.168.50.10 | 255.255.255.0 | 食堂 |
VLAN90 | 192.168.90.5 | 255.255.255.0 | 人事部 |
VLAN100 | 192.168.100.5 | 255.255.255.0 | 测试部 |
四、设备选型
1.核心层交换机
参数项 | 华为S9306 |
产品类型 | 路由交换机 POE交换机 |
应用层级 | 三层 |
背板带宽 | 6Tbps |
包转发率 | 1152Mpps |
端口结构 | 模块化 |
电源功率 | 1600W |
2.汇聚层交换机
参数项 | 华为S5720-36C-EI-28S-AC |
产品类型 | 千兆以太网交换机 |
应用层级 | 三层 |
背板带宽 | 598Gbps/5.98Tbps |
包转发率 | 222Mpps |
端口结构 | 非模块化 |
传输速率 | 10/100/1000 |
电源功率 | 47.9W |
3.接入层交换机
参数项 | 华为S5720-52p-SI-AC |
产品类型 | 千兆以太网交换机 |
应用层级 | 三层 |
包转发率 | 96Mpps |
端口结构 | 非模块化 |
端口数量 | 52 |
背板带宽 | 336Gdps/3.024Tdps |
传输速率(Mbps) | 10/100/1000 |
五、综合布线
六、设备完整配置命令
核心交换机:
#
sysname Huawei
#
vlan batch 10 20 30 40 50 60 70 80 90 100
#
stp instance 0 priority 0
stp instance 1 priority 0
stp instance 2 priority 0
stp instance 3 priority 4096
stp instance 4 priority 4096
stp instance 5 priority 4096
stp instance 8 priority 4096
#
cluster enable
ntdp enable
ndp enable
#
undo nap slave enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name qian
instance 1 vlan 10
instance 2 vlan 20
instance 3 vlan 30
instance 4 vlan 40
instance 5 vlan 50
instance 8 vlan 80
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user qian password simple qian123
local-user qian privilege level 3
local-user qian service-type telnet
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
ip address 192.168.10.2 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.10.1
vrrp vrid 1 priority 120
#
interface Vlanif20
ip address 192.168.20.2 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.20.1
vrrp vrid 2 priority 120
#
interface Vlanif30
ip address 192.168.30.2 255.255.255.0
vrrp vrid 3 virtual-ip 192.168.30.1
#
interface Vlanif40
ip address 192.168.40.2 255.255.255.0
vrrp vrid 4 virtual-ip 192.168.40.1
#
interface Vlanif50
ip address 192.168.50.2 255.255.255.0
vrrp vrid 5 virtual-ip 192.168.50.1
#
interface Vlanif70
ip address 192.168.70.1 255.255.255.0
#
interface Vlanif80
ip address 192.168.80.2 255.255.255.0
vrrp vrid 8 virtual-ip 192.168.80.1
#
interface Vlanif90
ip address 192.168.90.2 255.255.255.0
vrrp vrid 9 virtual-ip 192.168.90.1
vrrp vrid 9 priority 120
#
interface Vlanif100
ip address 192.168.100.2 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.100.1
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
mode lacp-static
#
interface GigabitEthernet0/0/1
eth-trunk 1
#
interface GigabitEthernet0/0/2
eth-trunk 1
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/4
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/5
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/6
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/7
port link-type access
port default vlan 70
#
interface GigabitEthernet0/0/8
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
ospf 1
import-route direct
area 0.0.0.0
network 192.168.70.0 0.0.0.255
network 192.168.80.0 0.0.0.255
#
user-interface con 0
user-interface vty 0 4
authentication-mode aaa
#
port-group qian
group-member GigabitEthernet0/0/3
group-member GigabitEthernet0/0/4
group-member GigabitEthernet0/0/5
group-member GigabitEthernet0/0/6
#
return
汇聚层交换机:
#
sysname Huawei
#
vlan batch 10 20 30 90 150 200
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name qian
instance 1 vlan 10
instance 2 vlan 20
instance 3 vlan 30
instance 4 vlan 40
instance 5 vlan 50
instance 8 vlan 80
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Ethernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/4
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/5
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
port-group qian
group-member Ethernet0/0/1
group-member Ethernet0/0/2
group-member Ethernet0/0/3
group-member Ethernet0/0/4
group-member Ethernet0/0/5
#
return
接入层交换机:
#
sysname Huawei
#
vlan batch 10
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Ethernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/2
port link-type access
port default vlan 10
#
interface Ethernet0/0/3
port link-type access
port default vlan 10
#
interface Ethernet0/0/4
port link-type access
port default vlan 10
#
interface Ethernet0/0/5
port link-type access
port default vlan 10
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
port-group qian
group-member Ethernet0/0/2
group-member Ethernet0/0/3
group-member Ethernet0/0/4
group-member Ethernet0/0/5
#
return
其余设备配置请联系作者获取
七、网络测试
1.网络连通测试
2.链路备份功能测试
3.服务器ftp服务测试
4、http服务测试
5、无线上网连通测试
6.查看生成树
7.查看Vrrp及链路聚合
8.查看路由表
9.查看OSPF路由表