要求:
1、分配IP
2、 给每个路由先添加缺省路由,在看要添加几条静态路由
2.1添加缺省路由
[r1]ip route-static 0.0.0.0 0 192.168.1.2 [r1]ip route-static 0.0.0.0 0 192.168.1.6 [r2]ip route-static 0.0.0.0 0 192.168.1.10 [r3]ip route-static 0.0.0.0 0 192.168.1.14 [r4]ip route-static 0.0.0.0 0 192.168.1.18 [r5]ip route-static 0.0.0.0 0 56.1.1.2
2.2给R1---R5添加静态路由
[r1]ip route-static 192.168.1.64 27 192.168.1.2 [r1]ip route-static 192.168.1.8 30 192.168.1.2 [r1]ip route-static 192.168.1.96 27 192.168.1.6 [r1]ip route-static 192.168.1.12 30 192.168.1.6 //[r1]ip route-static 192.168.1.128 27 192.168.1.2 [r1]ip route-static 192.168.1.128 27 192.168.1.6 这两条不写是因为前面我们写了两条缺省路由,负载均衡都可以到 [r2]ip route-static 192.168.1.32 30 192.168.1.1 [r2]ip route-static 192.168.1.4 30 192.168.1.1 [r2]ip route-static 192.168.1.96 27 196.168.1.1 [r2]ip route-static 192.168.1.96 27 196.168.1.10 [r3]ip route-static 192.168.1.32 27 192.168.1.5 [r3]ip route-static 192.168.1.0 30 192.168.1.5 [r3]ip route-static 192.168.1.64 27 192.168.1.5 [r3]ip route-static 192.168.1.64 27 192.168.1.14 [r4]ip route-static 192.168.1.0 30 192.168.1.9 [r4]ip route-static 192.168.1.64 27 192.168.1.9 [r4]ip route-static 192.168.1.32 27 192.168.1.9 [r4]ip route-static 192.168.1.32 27 192.168.1.13 [r4]ip route-static 192.168.1.4 30 192.168.1.13 [r4]ip route-static 192.168.1.96 27 192.168.1.13 [r5]ip route-static 192.168.1.32 27 192.168.1.17 [r5]ip route-static 192.168.1.64 27 192.168.1.17 [r5]ip route-static 192.168.1.128 27 192.168.1.17 [r5]ip route-static 192.168.1.96 27 192.168.1.17 [r5]ip route-static 192.168.1.0 30 192.168.1.17 [r5]ip route-static 192.168.1.4 30 192.168.1.17 [r5]ip route-static 192.168.1.8 30 192.168.1.17 [r5]ip route-static 192.168.1.12 30 192.168.1.17
3、手工汇总防环,在环回和多跳路由处
[r1]ip route-static 192.168.1.32 27 NULL 0
[r2]ip route-static 192.168.1.64 27 n 0
[r4]ip route-static 192.168.1.128 27 n 0
4、DHCP自动获取IP
[r3]dhcp enable
[r3]ip pool 1
[r3-ip-pool-1]network 192.168.1.96 mask 27
[r3-ip-pool-1]gateway-list 192.168.1.97
[r3-ip-pool-1]q
[r3]int g0/0/2
[r3-GigabitEthernet0/0/2]dhcp select global
5、都可以访问R6的环回------局域网访问公有ip,要想上网,就要进行地址转换:将私有IP转为公有IP ,这里用一对多来转换
[r5]acl 2000
[r5-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[r5-acl-basic-2000]int g0/0/1
[r5-GigabitEthernet0/0/1]nat outbound 2000
6、正常通过G接口,故障则通过E接口
6.1R4的缺省路由哟啊备份一条通过E接口的
[r4]ip route-static 0.0.0.0 0 192.168.1.22 pre 66 //优先级小于G接口即可
6.2当G链路故障时, 其他路由器到R5的静态路由全部都没有了,所有我们也需要备份E链路的静态路由
[r5]ip route-static 192.168.1.0 255.255.255.252 192.168.1.21 pr 66 [r5]ip route-static 192.168.1.4 255.255.255.252 192.168.1.21 pr 66 [r5]ip route-static 192.168.1.8 255.255.255.252 192.168.1.21 pr 66 [r5]ip route-static 192.168.1.12 255.255.255.252 192.168.1.21 pr 66 [r5]ip route-static 192.168.1.32 255.255.255.224 192.168.1.21 pr 66 [r5]ip route-static 192.168.1.64 255.255.255.224 192.168.1.21 pr 66 [r5]ip route-static 192.168.1.96 255.255.255.224 192.168.1.21 pr 66 [r5]ip route-static 192.168.1.128 255.255.255.224 192.168.1.21 pr 66
7、R6登录R5公有IP时,实际登录的是R1----端口映射 --- 属于静态nat;仅用于一个ip地址的一个固定端口与另一个ip地址的一个固定端口进行地址转换(telnet端口为23)
7.1先给R1有登录的权限,设置用户及密码
[r1]aaa [r1-aaa]local-user huang privilege level 15 password cipher 123 [r1]user-interface vty 0 4 [r1-ui-vty0-4]authentication-mode aaa
7.2在R5的公有IP接口处进行端口映射
[r5]int g0/0/1 [r5-GigabitEthernet0/0/1]nat static protocol tcp global current-interface 23 ins ide 192.168.1.33 23 Warning:The port 23 is well-known port. If you continue it may cause function fa ilure. Are you sure to continue?[Y/N]:y