第一步:192.168.1.0/24 --- 划分网段
192.168.1.000 00000/27
192.168.1.0/27 --- 骨干链路
192.168.1.0/30
192.168.1.4/30
192.168.1 8/30
192.168.1.12/30
192.168.1.16/30
192.168.1.20/30
192.168.1.24/30
192.168.1.28/30
192.168.1.001 00000/27
192.168.1.32/27 --- R1
192.168.1.32/28
192.168.1.48/28
192.168.1.010 00000/27
192.168.1.64/27 --- R2
192.168.1.64/28
192.168.1.80/28
192.168.1.011 00000/27
192.168.1.96/27 ---- R3
192.168.1.100 00000/27
192.168.1.128/27 ----R4
192.168.1.128/28
192.168.1.144/28
192.168.1.101 00000/27
192.168.1.160/27 ---- R5
备用:
192.168.1.110 00000/27
192.168.1.192/27
192.168.1.111 00000/27
192.168.1.224/27
第二步:配置IP地址
R1
[r1]int g 0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.1.1 30
[r1-GigabitEthernet0/0/0]int g 0/0/1
[r1-GigabitEthernet0/0/1]ip add 192.168.1.5 30
[r1]int l 0
[r1-LoopBack0]ip add 192.168.1.33 28
[r1-LoopBack0]int l 1
[r1-LoopBack1]ip add 192.168.1.49 28
R2
[r2]int g 0/0/0
[r2-GigabitEthernet0/0/0]ip add 192.168.1.2 30
[r2-GigabitEthernet0/0/0]int g 0/0/1
[r2-GigabitEthernet0/0/1]ip add 192.168.1.9 30
[r2]int l0
[r2-LoopBack0]ip add 192.168.1.65 28
[r2-LoopBack0]int l 1
[r2-LoopBack1]ip add 192.168.1.81 28
R3
[r3]int g 0/0/0
[r3-GigabitEthernet0/0/0]ip add 192.168.1.6 30
[r3-GigabitEthernet0/0/0]int g 0/0/1
[r3-GigabitEthernet0/0/1]ip add 192.168.1.13 30
[r3-GigabitEthernet0/0/1]int g 0/0/2
[r3-GigabitEthernet0/0/2]ip add 192.168.1.97 27
R4
[r4]int g 0/0/0
[r4-GigabitEthernet0/0/0]ip add 192.168.1.10 30
[r4-GigabitEthernet0/0/0]int g 0/0/1
[r4-GigabitEthernet0/0/1]ip add 192.168.1.14 30
[r4-GigabitEthernet0/0/1]int g 0/0/2
[r4-GigabitEthernet0/0/2]ip add 192.168.1.17 30
[r4-GigabitEthernet0/0/2]int g 4/0/0
[r4-GigabitEthernet4/0/0]ip add 192.168.1.21 30
[r4-GigabitEthernet4/0/0]int l0
[r4-LoopBack0]ip add 192.168.1.129 28
[r4-LoopBack0]int l 1
[r4-LoopBack1]ip add 192.168.1.145 28
R5
[r5]int g 0/0/0
[r5-GigabitEthernet0/0/0]ip add 192.168.1.18 30
[r5-GigabitEthernet0/0/0]
[r5-GigabitEthernet0/0/0]int g 0/0/2
[r5-GigabitEthernet0/0/2]ip add 192.168.1.22 30
[r5-GigabitEthernet0/0/2]int g 0/0/1
[r5-GigabitEthernet0/0/1]i add 12.0.0.1 24
[r5]int l 0
[r5-LoopBack0]ip add 192.168.1.161 27
R6
[r6]int g 0/0/0
[r6-GigabitEthernet0/0/0]ip add 12.0.0.2 24
[r6-GigabitEthernet0/0/0]
Sep 23 2021 13:27:48-08:00 r6 %%01IFNET/4/LINK_STATE(l)[0]:The line protocol IP
on the interface GigabitEthernet0/0/0 has entered the UP state.
[r6-GigabitEthernet0/0/0]q
[r6]int l0
[r6-LoopBack0]i add 1.1.1.1 24
第三步:R3下的两台PC通过DHCP自动获取IP地址
[r3]dhcp enable
[r3]ip pool dhcp
[r3-ip-pool-dhcp]network 192.168.1.96 mask 27
[r3-ip-pool-dhcp]gateway-list 192.168.1.97
[r3-ip-pool-dhcp]dns-list 114.114.114.114
[r3]interface GigabitEthernet 0/0/2
[r3-GigabitEthernet0/0/2]dhcp select global
PC1,PC2通过DHCP获取IP地址
第四步:配置路由信息
每台路由器上均配置缺省
R1
[r1]ip route-static 0.0.0.0 0 192.168.1.2 --- 缺省路由
[r1]ip route-static 0.0.0.0 0 192.168.1.6 --- 负载均衡
[r1]ip route-static 192.168.1.64 27 192.168.1.2 --- 汇总路由
[r1]ip route-static 192.168.1.8 30 192.168.1.2
[r1]ip route-static 192.168.1.12 30 192.168.1.6
[r1]ip route-static 192.168.1.97 27 192.168.1.6
R2
[r2]ip route-static 0.0.0.0 0 192.168.1.10 ---缺省
[r2]ip route-static 192.168.1.96 27 192.168.1.10---负载均衡
[r2]ip route-static 192.168.1.32 27 192.168.1.1---汇总路由
[r2]ip route-static 192.168.1.96 27 192.168.1.1
[r2]ip route-static 192.168.1.4 30 192.168.1.1
R3
[r3]ip route-static 0.0.0.0 0 192.168.1.14 ---缺省
[r3]ip route-static 192.168.1.64 27 192.168.1.14---负载均衡
[r3]ip route-static 192.168.1.32 27 192.168.1.5---汇总路由
[r3]ip route-static 192.168.1.64 27 192.168.1.5
[r3]ip route-static 192.168.1.0 30 192.168.1.5
R4
[r4]ip route-static 0.0.0.0 0 192.168.1.22 preference 70--浮动路由
[r4]ip route-static 192.168.1.32 27 192.168.1.9 --- 负载均衡
[r4]ip route-static 192.168.1.32 27 192.168.1.13---汇总路由
[r4]ip route-static 192.168.1.0 30 192.168.1.9
[r4]ip route-static 192.168.1.64 27 192.168.1.9---汇总路由
[r4]ip route-static 192.168.1.96 27 192.168.1.13
[r4]ip route-static 192.168.1.4 30 192.168.1.13
[r4]ip route-static 192.168.1.160 27 192.168.1.18
[r4]ip route-static 0.0.0.0 0 GigabitEthernet 0/0/2 192.168.1.18
[r4]ip route-static 192.168.1.128 27 NULL 0
[r4]ip route-static 192.168.1.0 24 NULL 0
R5
[r5]ip route-static 0.0.0.0 0 12.0.0.2---缺省
[r5]ip route-static 192.168.1.0 24 192.168.1.17---汇总
[r5]ip route-static 192.168.1.0 24 192.168.1.21 preference 70---配置浮动路由
第五步:在边界路由配置NET
[r5]acl 2000 --- 2000为基础ACL
[r5-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255---抓取内网流量匹配的是192.168.1.0
[r5-acl-basic-2000]q
[r5]int g 0/0/1
[r5-GigabitEthernet0/0/1]nat outbound 2000
第六步:实现远程登陆 --- 配置端口映射
启动R1的telnet服务,
[r1]aaa
[r1-aaa]local-user admin privilege level 15 password cipher 12 ---创建用户名和密码并设置它的权限为15(最高权限)
[r1-aaa]local-user admin service-type telnet ---设置用户名和密码的用途
[r1-aaa]q
[r1]user-interface vty 0 4 ---开启虚拟的登录端口
[r1-ui-vty0-4]authentication-mode aaa ---开启登录认证
[r1-ui-vty0-4]q
设置nat端口映射,通过telnet R5的公有IP地址实际登录到R1上。
[r5]interface GigabitEthernet 0/0/1
[r5-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 23 ins
ide 192.168.1.1 23
Warning:The port 23 is well-known port. If you continue it may cause function fa
ilure.
Are you sure to continue?[Y/N]:y
在R6上进行测试。
<r6>telnet 12.0.0.1
Press CTRL_] to quit telnet mode
Trying 12.0.0.1 ...
Connected to 12.0.0.1 ...
Login authentication
Username:admin
Password:
<r1>