企业的三层架构

 

SW3

[SW3]vlan 2
[SW3-vlan2]
[SW3]interface e0/0/2
[SW3-Ethernet0/0/2]port link-type access
[SW3-Ethernet0/0/2]port default vlan 2
[sw3]port-group group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/2
[sw3-port-group]port link-type trunk
[sw3-port-group]port trunk allow-pass vlan 2

SW4

[SW4]vlan 2
[SW4-vlan2]
[SW4]interface e0/0/2
[SW4-Ethernet0/0/2]port link-type access
[SW4-Ethernet0/0/2]port default vlan 2
[sw4]port-group group-member GigabitEthernet 0/0/1 to GigabitEthernet 0/0/2
[sw4-port-group]port link-type trunk
[sw4-port-group]port trunk allow-pass vlan 2

SW1

[sw1]int Eth-Trunk 0
[sw1-Eth-Trunk0]q
[sw1]int g0/0/2
[sw1-GigabitEthernet0/0/2]eth-trunk 0
[sw1-GigabitEthernet0/0/2]int g0/0/3
[sw1-GigabitEthernet0/0/2]eth-trunk 0
[SW1]vlan 2
[SW1-vlan2]
[sw1]port-group group-member GigabitEthernet 0/0/1 GigabitEthernet 0/0/5 Eth-Trunk 0
[sw1-port-group]port link-type trunk
[sw1-port-group]port trunk allow-pass vlan 1 to 2

 SW2

[sw2]int Eth-Trunk 0
[sw2-Eth-Trunk0]q
[sw2]int g0/0/2
[sw2-GigabitEthernet0/0/2]eth-trunk 0
[sw2-GigabitEthernet0/0/2]int g0/0/3
[sw2-GigabitEthernet0/0/3]eth-trunk 0
[SW2]vlan 2
[SW2-vlan2]
[sw2]port-group group-member GigabitEthernet 0/0/4 GigabitEthernet 0/0/1 Eth-Trunk 0
[sw2-port-group]port link-type trunk
[sw2-port-group]port trunk allow-pass vlan 1 to 2

STP配置

[sw1]stp mode mstp
[sw1]stp enable
[sw1]stp region-configuration
[sw1-mst-region]region-name a 
[sw1-mst-region]instance 1 vlan 1
[sw1-mst-region]instance 2 vlan 2
[sw1-mst-region]active region-configuration 

各自实现Vlan

[sw1]stp instance 1 root primary
[sw1]stp instance 2 root secondary
 
[sw2]stp instance 1 root secondary
[sw2]stp instance 2 root primary

调stp的边缘接口

[sw3]port-group group-member Ethernet 0/0/1 to Ethernet 0/0/2
[sw3-port-group]stp edged-port enable
 
[sw4]port-group group-member Ethernet 0/0/1 to Ethernet 0/0/2
[sw4-port-group]stp edged-port enable

创建SVI

[sw1]interface vlan 1
[sw1-Vlanif1]ip ad 172.16.1.1 24
[sw1]interface vlan 2
[sw1-Vlanif2]ip ad 172.16.2.1 24
 
[sw2]interface vlan 1
[sw2-Vlanif1]ip ad 172.16.1.2 24
[sw2]interface vlan 2
[sw2-Vlanif2]ip ad 172.16.2.2 24
7、配置VRRP

[sw1]interface vlan 1
[sw1-Vlanif1]vrrp vrid 1 virtual-ip 172.16.1.254
[sw1-Vlanif1]vrrp vrid 1 priority 120
[sw1-Vlanif1]vrrp vrid 1 track interface GigabitEthernet 0/0/4 reduced 30
[sw1]interface vlan 2
[sw1-Vlanif2]vrrp vrid 1 virtual-ip 172.16.2.254
[sw1-Vlanif2]
 
[sw2]interface vlan 1
[sw2-Vlanif1]vrrp vrid 1 virtual-ip 172.16.1.254
[sw2]interface vlan 2
[sw2-Vlanif2]vrrp vrid 1 vir
[sw2-Vlanif2]vrrp vrid 1 virtual-ip 172.16.2.254
[sw2-Vlanif2]vrrp vrid 1 priority 120
[sw2-Vlanif2]vrrp vrid 1 track interface GigabitEthernet 0/0/5 reduced 30

配置DHCp

[sw1]dhcp enable
[sw1]ip pool v1
[sw1-ip-pool-v1]network 172.16.1.0 mask 24
[sw1-ip-pool-v1]gateway-list 172.16.1.254
[sw1-ip-pool-v1]dns-list 114.114.114.114 
[sw1]ip pool v2
[sw1-ip-pool-v1]network 172.16.2.0 mask 24
[sw1-ip-pool-v1]gateway-list 172.16.2.254
[sw1-ip-pool-v1]dns-list 114.114.114.114 
[sw1]int vlan 1
[sw1-Vlanif1]dhcp select global
[sw1-Vlanif1]int vlan 2
[sw1-Vlanif2]dhcp select global
 
[sw2]dhcp enable
[sw2]ip pool v1
[sw2-ip-pool-v1]network 172.16.1.0 mask 24
[sw2-ip-pool-v1]gateway-list 172.16.1.254
[sw2-ip-pool-v1]dns-list 114.114.114.114 
[sw2]ip pool v2
[sw2-ip-pool-v1]network 172.16.2.0 mask 24
[sw2-ip-pool-v1]gateway-list 172.16.2.254
[sw2-ip-pool-v1]dns-list 114.114.114.114 
[sw2]int vlan 1
[sw2-Vlanif1]dhcp select global
[sw2-Vlanif1]int vlan 2
[sw2-Vlanif2]dhcp select global

配置路由

先将三层交换机和路由器之间配置好IP

[sw1]vlan 100
[sw1-vlan100]q
[sw1]int g0/0/4
[sw1-GigabitEthernet0/0/4]po l a 
[sw1-GigabitEthernet0/0/4]p d vlan 100 
[sw1-GigabitEthernet0/0/4]int vlan 100
[sw1-Vlanif100]ip ad 172.16.3.1 24
 
[sw2]vlan 100
[sw2-vlan100]int vlan 100
[sw2-Vlanif100]ip ad 172.16.4.1 24
[sw2-Vlanif100]int g0/0/5
[sw2-GigabitEthernet0/0/5]p l a
[sw2-GigabitEthernet0/0/5]p d vlan 100
配置路由i地址

[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip ad 172.16.3.2 24
[r1-GigabitEthernet0/0/0]int g0/0/2
[r1-GigabitEthernet0/0/2]ip ad 172.16.4.2 24
[r1-GigabitEthernet0/0/2]int g0/0/1
[r1-GigabitEthernet0/0/1]ip ad 11.1.1.1 24
 
[r2]int lo0
[r2-LoopBack0]ip ad 2.2.2.2 24
[r2-LoopBack0]int g0/0/0
[r2-GigabitEthernet0/0/0]ip ad 11.1.1.2 24
 现在查看路由表会发现,R1没有到172.16.1.0/2.0的路由,SW1没有到172.16.4.0/11.1.1.0的路由,SW2则是没有到3.0/11.1.1.0的路由,这时我们需要配置静态/动态路由协议,我配置的是静态路由。

SW1配置

[SW1]ip route-static 0.0.0.0 0 172.16.3.2
 
[SW1]ip route-static 172.16.4.0 24 172.16.3.2
SW2配置

[SW2]ip route-static 0.0.0.0 0 172.16.4.2
 
[SW2]ip route-static 172.16.3.0 24 172.16.4.2 
R1的配置

[r1]ip route-static 0.0.0.0 0 11.1.1.2
[r1]ip route-static 172.16.1.0 24 172.16.3.1
[r1]ip route-static 172.16.1.0 24 172.16.4.1
[r1]ip route-static 172.16.2.0 24 172.16.4.1
[r1]ip route-static 172.16.2.0 24 172.16.3.1
[r1]ip route-static 11.1.1.0 24 NULL 0
最后再在R1到公网的出接口上做nat,即可实现全网可达

[r1]acl 2000
[r1-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r1-acl-basic-2000]int g0/0/1
[r1-GigabitEthernet0/0/1]nat outbound 2000
测试:

 

 

 

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值