首先,配置PC的IP地址、子网掩码、网关。
PC1:
IP地址:192.168.1.2
子网掩码:255.255.255.0
网关:192.168.1.254
PC2:
IP地址:192.168.1.3
子网掩码:255.255.255.0
网关:192.168.1.254
PC3:
IP地址:172.20.1.2
子网掩码:255.255.255.0
网关:172.20.1.254
PC4:
IP地址:172.20.1.3
子网掩码:255.255.255.0
网关:172.20.1.254
创建VLAN、配置网关:LSW1
LSW1:
[Huawei]vlan 1
[Huawei-vlan1]q
[Huawei]vlan 2
[Huawei-vlan2]q
[Huawei]vlan 3
[Huawei-vlan3]q
[Huawei]vlan 4
[Huawei-vlan4]q
[Huawei]int v1
[Huawei-Vlanif1]ip address 192.168.1.254 24
[Huawei-Vlanif1]q
[Huawei]int v2
[Huawei-Vlanif2]ip address 172.20.1.254 24
[Huawei-Vlanif2]q
[Huawei]int v3
[Huawei-Vlanif3]ip address 10.10.10.254 24
[Huawei-Vlanif3]q
[Huawei]int v4
[Huawei-Vlanif4]ip address 4.4.4.254 24
[Huawei-Vlanif4]q
此时,LSW3到PC1等还是不通的,把接口配成ACCESS并划入VLAN中。
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/1]port default vlan 1
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g 0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 2
[Huawei-GigabitEthernet0/0/2]q
[Huawei]int g 0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 3
[Huawei-GigabitEthernet0/0/3]q
[Huawei]int g 0/0/4
[Huawei-GigabitEthernet0/0/4]port link-type access
[Huawei-GigabitEthernet0/0/4]port default vlan 4
[Huawei-GigabitEthernet0/0/3]q
LSW4:
LSW4:
[SW4]v 3
[SW4]inter v 3
[SW4-Vlanif3]ip address 10.10.10.2 24
[SW4-Vlanif3]q
[SW4]int g 0/0/1
[SW4-GigabitEthernet0/0/1]port link-type access
[SW4-GigabitEthernet0/0/1]port default vlan 3
[SW4-GigabitEthernet0/0/1]q
[SW4]v 5
[SW4]inter v 5
[SW4-Vlanif5]ip address 10.165.1.1 24
[SW4-Vlanif2]q
[SW4]int g 0/0/2
[SW4-GigabitEthernet0/0/2]port link-type access
[SW4-GigabitEthernet0/0/2]port default vlan 5
[SW4-GigabitEthernet0/0/2]q
此时,10.1 与 10.165.1.2 不通,原因是路由表中没有它的路由表,解决:在lsw1上添加静态路由
LSW1:
[Huawei]ip route-static 10.165.1.0 255.255.255.0 10.10.10.2
LSW4:向上写条缺省指向any
[Huawei]ip route-static 0.0.0.0 0.0.0.0 10.10.10.254
AR1:
AR1:
[Huawei]int g 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 4.4.4.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 192.168.1.0 255.255.255.0 4.4.4.254
[Huawei]ip route-static 172.20.1.0 255.255.255.0 4.4.4.254
[Huawei]ip route-static 10.165.1.0 255.255.255.0 4.4.4.254
[Huawei]ip route-static 10.10.10.0 255.255.255.0 4.4.4.254
AR1与server 1不通,解决:在AR1写条缺省。
[Huawei]ip route-static 0.0.0.0 0.0.0.0 10.10.10.254
备注:想要全网通,要保证每个三层上都有对方的路由表。
在此步骤时,AR1向下全网可达,现向上走。
AR1:
[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 220.1.1.1 24
[Huawei-GigabitEthernet0/0/1]q
192.168.1.2 ping220.1.1.1 ping不通时,先从网管交换机上排查,原因是未添加静态路由:
LSW1:
[Huawei] ip route-static 220.1.1.0 255.255.255.0 4.4.4.2
192.168.1.2 ping220.1.1.2 ping不通时,需要在路由器上地址转换,解决:写条ACL
AR1:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 5 permit source 192.168.1.0 0.0.0.255 //把地址抓出来
[Huawei-acl-basic-2000]q
进入接口调用nat,
[Huawei] int g 0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 // 用NAT调用ACL2000在出来时转换成接口地址
[Huawei-GigabitEthernet0/0/1]q
Client 3访问Server1:
AR2:
AR2:
[Huawei]acl 2000 //创建acl
[Huawei-acl-basic-2000]rule 5 permit source 6.6.6.0 0.0.0.255
[Huawei] int g 0/0/0
[Huawei-GigabitEthernet0/0/0]nat outbound 2000 // 用NAT调用ACL2000在出来时转换成接口地址
[Huawei-GigabitEthernet0/0/0]ip address 220.1.1.2 24
[Huawei-GigabitEthernet0/0/0]q
[Huawei] int g 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 6.6.6.1 24
[Huawei-GigabitEthernet0/0/1]q
[Huawei]ip route-static 10.165.1.0 255.255.255.0 220.1.1.2
[Huawei]ip route-static 192.168.1.0 255.255.255.0 220.1.1.2
在出口路由器AR1上添加端口映射关系:
[Huawei]inter g 0/0/1
[Huawei-GigabitEthernet0/0/1]nat server protocol tcp global current-interface www inside 10.165.1.2 www //只映射www服务,也就是80端口
接下来就是警告信息:这个80端口是否都知道。
输入:Y 确认即可