实训项目六
任务清单
基础配置
根据实训项目 6-拓扑图和实训项目 6-地址规划表上要求,为每一个PC和接口配置IP地址。
链路聚合配置
SW1与SW3相连接的两个端口采用链路聚合,聚合模式为active,端口模式为trunk。ds
OSPF配置
R1,R2,SW1,SW2运行OSPF协议,进程号10,区域0
NAT配置
在R1上运行动态NAT协议,使PC1能够ping通internet
Telnet配置
在SW2上运行telnet协议,让其他设备能够远程访问SW2,telnet密码为Ruijie666。
设备名称 | 端口号 | IP地址 | VLAN |
VPC1 | eth0 | 172.18.47.1/24 | VLAN10 |
VPC2 | eth0 | 172.18.48.1/24 | VLAN20 |
VPC3 | eth0 | 172.18.49.1/24 | VLAN30 |
SW1 | G0/2 | 10.1.1.1/24 | def |
R1 | G0/0 | 10.1.1.2/24 | def |
R1 | G0/1 | 11.1.1.1/24 | def |
R1 | G0/2 | 100.1.1.1/24 | def |
R2 | G0/0 | 12.1.1.1/24 | def |
R2 | G0/1 | 11.1.1.2/24 | def |
SW2 | G0/0 | 12.1.1.2/24 | def |
Inter | G0/0 | 100.1.1.2/24 | def |
SW1 | Vlan10 | 172.18.47.254/24 | VLAN10 |
SW1 | Vlan20 | 172.18.48.254/24 | VLAN10 |
SW2 | Vlan30 | 172.18.49.254/24 | VLAN30 |
SW3 | G0/2 | 无 | VALN10 |
SW3 | G0/3 | 无 | VLAN20 |
下面是每个设备的配置和配置验证截图,一般第一张是配置,有"show"开始为验证截图。最后有一个验证拓扑图各功能ping通的验证。
pc1
VPCS> ip 172.18.47.1 24 172.18.47.254
Checking for duplicate address...
VPCS : 172.18.47.1 255.255.255.0 gateway 172.18.47.254
VPCS> show ip
NAME : VPCS[1]
IP/MASK : 172.18.47.1/24
GATEWAY : 172.18.47.254
DNS :
MAC : 00:50:79:66:68:1d
LPORT : 20000
RHOST:PORT : 127.0.0.1:30000
MTU : 1500
VPCS>
pc2
VPCS> ip 172.18.48.1 24 172.18.48.254
Checking for duplicate address...
VPCS : 172.18.48.1 255.255.255.0 gateway 172.18.48.254
VPCS> show ip
NAME : VPCS[1]
IP/MASK : 172.18.48.1/24
GATEWAY : 172.18.48.254
DNS :
MAC : 00:50:79:66:68:1e
LPORT : 20000
RHOST:PORT : 127.0.0.1:30000
MTU : 1500
VPCS>
pc3
VPCS> ip 172.18.49.1 24 172.18.49.254
Checking for duplicate address...
VPCS : 172.18.49.1 255.255.255.0 gateway 172.18.49.254
VPCS> show ip
NAME : VPCS[1]
IP/MASK : 172.18.49.1/24
GATEWAY : 172.18.49.254
DNS :
MAC : 00:50:79:66:68:1f
LPORT : 20000
RHOST:PORT : 127.0.0.1:30000
MTU : 1500
VPCS>
SW3
Ruijie>en
Password:******
User's password is too weak. Please change the password!
Ruijie#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Ruijie(config)#host SW3
SW3(config)#vlan 10
SW3(config-vlan)#vlan 20 //创建VLAN10,VLAN20
SW3(config-vlan)#exit
SW3(config)#int g0/2
SW3(config-if-GigabitEthernet 0/2)#switchport mode access //设置为access口
SW3(config-if-GigabitEthernet 0/2)#switchport access vlan 10 //设置为VLAN10
SW3(config-if-GigabitEthernet 0/2)#int g0/3
SW3(config-if-GigabitEthernet 0/3)#switchport mode access
SW3(config-if-GigabitEthernet 0/3)#switchport access vlan 20
SW3(config-if-GigabitEthernet 0/3)#exit
SW3(config)#int range g0/0-1 //进入G0/0-1口
SW3(config-if-range)#port-group 1 mode active //定义为聚合口1,模式为active
SW3(config-if-range)#exit
SW3(config)#int aggregatePort 1 //进入聚合组1配置界面
SW3(config-if-AggregatePort 1)#switchport mode trunk //设置为Trunk口
SW3(config-if-AggregatePort 1)#exit
SW3(config)#exit
SW3#wr
SW3#show vlan
VLAN Name Status Ports
---------- -------------------------------- --------- -----------------------------------
1 VLAN0001 STATIC Gi0/4, Gi0/5, Gi0/6, Gi0/7
Gi0/8, Ag1
10 VLAN0010 STATIC Gi0/2, Ag1
20 VLAN0020 STATIC Gi0/3, Ag1
SW3#show agg summary
AggregatePort MaxPorts SwitchPort Mode Ports
------------- -------- ---------- ------ -----------------------------------
Ag1 16 Enabled TRUNK Gi0/0 ,Gi0/1
SW3#
SW1
SW1(config)#vlan 10
SW1(config-vlan)#vlan 20 //创建VLAN10,VLAN20
SW1(config-vlan)#exit
SW1(config)#int vlan 10 //进入VLAN10
SW1(config-if-VLAN 10)#ip address 172.18.47.254 24 //添加VALN10网关
SW1(config-if-VLAN 10)#int vlan 20
SW1(config-if-VLAN 20)#ip address 172.18.48.254 24
SW1(config-if-VLAN 20)#exit
SW1(config)#int range g0/0-1 //进入G0/0-1口
SW1(config-if-range)#port-group 1 mode active //定义为聚合组1,模式为active
SW1(config-if-range)#exit
SW1(config)#int aggregatePort 1 //进入聚合组1配置界面
SW1(config-if-AggregatePort 1)#switchport mode trunk //设置为Trunk口
SW1(config-if-AggregatePort 1)#exit
SW1(config)#route ospf 10 //进入OSPF进程10
SW1(config-router)#router-id 1.1.1.1 //设置R1的router-id为1.1.1.1
Change router-id and update OSPF process! [yes/no]:y //开启OSPF
SW1(config-router)#network 172.18.47.0 0.0.0.255 area 0
SW1(config-router)#network 172.18.48.0 0.0.0.255 area 0
SW1(config-router)#network 10.1.1.0 0.0.0.255 area 0 //宣告网段
SW1(config-router)#exit
SW1(config)#wr
SW1#show ip int br
Interface IP-Address(Pri) IP-Address(Sec) Status Protocol
VLAN 1 no address no address up down
VLAN 10 172.18.47.254/24 no address up up
VLAN 20 172.18.48.254/24 no address up up
SW1#show vlan
VLAN Name Status Ports
---------- -------------------------------- --------- -----------------------------------
1 VLAN0001 STATIC Gi0/2, Gi0/3, Gi0/4, Gi0/5
Gi0/6, Gi0/7, Gi0/8, Ag1
10 VLAN0010 STATIC Ag1
20 VLAN0020 STATIC Ag1
SW1#show run
...
interface VLAN 10
ip address 172.18.47.254 255.255.255.0
!
interface VLAN 20
ip address 172.18.48.254 255.255.255.0
!
router ospf 10
router-id 1.1.1.1
graceful-restart
network 10.1.1.0 0.0.0.255 area 0
network 172.18.47.0 0.0.0.255 area 0
network 172.18.48.0 0.0.0.255 area 0
...
end
R1
R1(config)#int g0/0 //进入g0/0口
R1(config-if-GigabitEthernet 0/0)#no switchport //开启路由功能
R1(config-if-GigabitEthernet 0/0)#ip add 10.1.1.2 24 //添加IP地址
R1(config-if-GigabitEthernet 0/0)#ip nat inside //设置为内网口
R1(config-if-GigabitEthernet 0/0)#int g0/1
R1(config-if-GigabitEthernet 0/1)#no switchport
R1(config-if-GigabitEthernet 0/1)#ip add 11.1.1.1 24
R1(config-if-GigabitEthernet 0/1)#ip nat inside //设置为内网口
R1(config-if-GigabitEthernet 0/1)#int g0/2
R1(config-if-GigabitEthernet 0/0)#no switchport
R1(config-if-GigabitEthernet 0/0)#ip add 100.1.1.1 24
R1(config-if-GigabitEthernet 0/0)#ip nat outside //设置为外网口
R1(config-if-GigabitEthernet 0/0)#exit
R1(config)#route ospf 10 //进入OSPF进程10
R1(config-router)#router-id 2.2.2.2 //设置R1的router-id为2.2.2.2
Change router-id and update OSPF process! [yes/no]:y //开启OSPF
R1(config-router)#network 10.1.1.0 0.0.0.255 area 0
R1(config-router)#network 11.1.1.0 0.0.0.255 area 0
R1(config-router)#network 100.1.1.0 0.0.0.255 area 0 //宣告网段
R1(config-router)#exit
R1(config)#access-list 1 permit 172.18.47.0 0.0.0.255
R1(config)#access-list 1 permit 172.18.48.0 0.0.0.255
R1(config)#access-list 1 permit 172.18.49.0 0.0.0.255
R1(config)#access-list 1 deny any //定义ACL1的规则
R1(config)#ip nat pool ssj 100.1.1.1 100.1.1.1 netmask 255.255.255.0 //添加NAT地址池
R1(config)#ip nat inside source list 1 pool ssj overload //把ACL1与NAT地址池关联起来
R1(config)#exit
R1#wr
R1#show ip int br
Interface IP-Address(Pri) IP-Address(Sec) Status Protocol
GigabitEthernet 0/0 10.1.1.2/24 no address up up
GigabitEthernet 0/1 11.1.1.1/24 no address up up
GigabitEthernet 0/2 100.1.1.1/24 no address up up
VLAN 1 no address no address up down
R1#show run
...
ip access-list standard 1
10 permit 172.18.47.0 0.0.0.255
20 permit 172.18.48.0 0.0.0.255
30 permit 172.18.49.0 0.0.0.255
40 deny any
...
router ospf 10
router-id 2.2.2.2
graceful-restart
network 10.1.1.0 0.0.0.255 area 0
network 11.1.1.0 0.0.0.255 area 0
network 100.1.1.0 0.0.0.255 area 0
!
ip nat pool ssj 100.1.1.1 100.1.1.1 netmask 255.255.255.0
ip nat inside source list 1 pool ssj overload
...
end
R2
Ruijie>en
Password:******
User's password is too weak. Please change the password!
Ruijie#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Ruijie(config)#host R2
R2(config)#int g0/1 //进入g0/1口
R2(config-if-GigabitEthernet 0/1)#no switchport //开启路由功能
R2(config-if-GigabitEthernet 0/1)#ip add 11.1.1.2 24 //添加IP
R2(config-if-GigabitEthernet 0/1)#int g0/0
R2(config-if-GigabitEthernet 0/0)#no switchport
R2(config-if-GigabitEthernet 0/0)#ip add 12.1.1.1 24
R2(config-if-GigabitEthernet 0/0)#exit
R2(config)#route ospf 10 //进入OSPF进程10
R2(config-router)#router-id 3.3.3.3 //设置R2的router-id为3.3.3.3
Change router-id and update OSPF process! [yes/no]:y //开启OSPF
R2(config-router)#network 11.1.1.0 0.0.0.255 area 0
R2(config-router)#network 12.1.1.0 0.0.0.255 area 0 //宣告网段
R2(config-router)#exit
R2(config)#exit
R2#wr
R2#show ip int br
Interface IP-Address(Pri) IP-Address(Sec) Status Protocol
GigabitEthernet 0/0 12.1.1.1/24 no address up up
GigabitEthernet 0/1 11.1.1.2/24 no address up up
VLAN 1 no address no address up down
R2#show run
...
router ospf 10
router-id 3.3.3.3
graceful-restart
network 11.1.1.0 0.0.0.255 area 0
network 12.1.1.0 0.0.0.255 area 0
...
end
SW2
SW3(config)#vlan 30 //创建VALN30
SW3(config-vlan)#exit
SW3(config)#int vlan 30 //进入VLAN30
SW3(config-if-VLAN 30)#ip add 172.18.49.254 24 //添加VLAN网关
SW3(config-if-VLAN 30)#exit
SW3(config)#int g0/1
SW3(config-if-GigabitEthernet 0/1)#switchport mode access //设置为access口
SW3(config-if-GigabitEthernet 0/1)#switchport access vlan 30 //设置为VLAN30
SW3(config-if-GigabitEthernet 0/1)#exit
SW3(config)#int g0/0
SW3(config-if-GigabitEthernet 0/0)#no switchport //开启路由功能
SW3(config-if-GigabitEthernet 0/0)#ip add 12.1.1.2 24 //添加IP地址
SW3(config-if-GigabitEthernet 0/0)#exit
SW3(config)#route ospf 10 //进入OSPF进程10
SW3(config-router)#router-id 4.4.4.4 //设置SW2的router-id为4.4.4.4
Change router-id and update OSPF process! [yes/no]:y //开启OSPF
SW3(config-router)#network 12.1.1.0 0.0.0.255 area 0
SW3(config-router)#network 172.18.49.0 0.0.0.255 area 0 //宣告网段
SW3(config-router)#exit
SW3(config)#line vty 0 4 //进入Telnet密码配置模式
SW3(config-line)#password Ruijie666 //设置密码为Ruijie666
SW3(config-line)#login //开启Telnet
SW3(config-line)#exit
SW3(config)#exit
SW3#wr
SW3#show ip int br
Interface IP-Address(Pri) IP-Address(Sec) Status Protocol
GigabitEthernet 0/0 12.1.1.2/24 no address up up
VLAN 1 no address no address up down
VLAN 30 172.18.49.254/24 no address up up
SW3#show vlan
VLAN Name Status Ports
---------- -------------------------------- --------- -----------------------------------
1 VLAN0001 STATIC Gi0/2, Gi0/3, Gi0/4, Gi0/5
Gi0/6, Gi0/7, Gi0/8
30 VLAN0030 STATIC Gi0/1
SW3#show run
...
router ospf 10
router-id 4.4.4.4
graceful-restart
network 12.1.1.0 0.0.0.255 area 0
network 172.18.49.0 0.0.0.255 area 0
...
end
Inter
Ruijie>en
Password:******
User's password is too weak. Please change the password!
Ruijie#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Ruijie(config)#host Inter
Inter(config)#int g0/0 //进入g0/0口
Inter(config-if-GigabitEthernet 0/0)#no switchport //开启路由功能
Inter(config-if-GigabitEthernet 0/0)#ip add 100.1.1.2 24 //添加IP
Inter(config-if-GigabitEthernet 0/0)#exit
Inter(config)#ip route 0.0.0.0 0.0.0.0 100.1.1.1 //配置去往内网的默认路由
Inter(config)#exit
Inter#wr
Inter#show ip int br
Interface IP-Address(Pri) IP-Address(Sec) Status Protocol
GigabitEthernet 0/0 100.1.1.2/24 no address up up
VLAN 1 no address no address up down
Inter#show ip route
Codes: C - Connected, L - Local, S - Static
R - RIP, O - OSPF, B - BGP, I - IS-IS, V - Overflow route
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
SU - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
IA - Inter area, EV - BGP EVPN, A - Arp to host
LA - Local aggregate route
* - candidate default
Gateway of last resort is 100.1.1.1 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 100.1.1.1
C 100.1.1.0/24 is directly connected, GigabitEthernet 0/0
C 100.1.1.2/32 is local host.
Inter#
验证截图
R1#show ip int br
Interface IP-Address(Pri) IP-Address(Sec) Status Protocol
GigabitEthernet 0/0 10.1.1.2/24 no address up up
GigabitEthernet 0/1 11.1.1.1/24 no address up up
GigabitEthernet 0/2 100.1.1.1/24 no address up up
VLAN 1 no address no address up down
R1#show ip ospf nei
OSPF process 10, 2 Neighbors, 2 is Full:
Neighbor ID Pri State BFD State Dead Time Address Interface
1.1.1.1 1 Full/DR - 00:00:34 10.1.1.1 GigabitEthernet 0/0
3.3.3.3 1 Full/BDR - 00:00:32 11.1.1.2 GigabitEthernet 0/1
R1#show ip ospf nei
OSPF process 10, 2 Neighbors, 2 is Full:
Neighbor ID Pri State BFD State Dead Time Address Interface
1.1.1.1 1 Full/DR - 00:00:34 10.1.1.1 GigabitEthernet 0/0
3.3.3.3 1 Full/BDR - 00:00:32 11.1.1.2 GigabitEthernet 0/1
R1#show ip route
Codes: C - Connected, L - Local, S - Static
R - RIP, O - OSPF, B - BGP, I - IS-IS, V - Overflow route
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
SU - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
IA - Inter area, EV - BGP EVPN, A - Arp to host
LA - Local aggregate route
* - candidate default
Gateway of last resort is 100.1.1.2 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 100.1.1.2
C 10.1.1.0/24 is directly connected, GigabitEthernet 0/0
C 10.1.1.2/32 is local host.
C 11.1.1.0/24 is directly connected, GigabitEthernet 0/1
C 11.1.1.1/32 is local host.
O 12.1.1.0/24 [110/2] via 11.1.1.2, 00:33:42, GigabitEthernet 0/1
C 100.1.1.0/24 is directly connected, GigabitEthernet 0/2
C 100.1.1.1/32 is local host.
O 172.18.47.0/24 [110/2] via 10.1.1.1, 00:40:01, GigabitEthernet 0/0
O 172.18.48.0/24 [110/2] via 10.1.1.1, 00:40:01, GigabitEthernet 0/0
O 172.18.49.0/24 [110/3] via 11.1.1.2, 00:14:23, GigabitEthernet 0/1
R1#
R1#show access-lists
ip access-list standard 1
10 permit 172.18.47.0 0.0.0.255
20 permit 172.18.48.0 0.0.0.255
30 permit 172.18.49.0 0.0.0.255
40 deny any
R1#
R1#show run
Building configuration...
Current configuration: 1503 bytes
version X86_RGOS 12.5(5)
hostname R1
!
ip access-list standard 1
10 permit 172.18.47.0 0.0.0.255
20 permit 172.18.48.0 0.0.0.255
30 permit 172.18.49.0 0.0.0.255
40 deny any
!
no cwmp
!
install 0 X86
!
sysmac 5000.0002.0001
no ip domain-lookup
!
webmaster level 0 username admin secret 8 $1c$7eyy23uMQk$!b(`dhh`n<nxlvxn&tp8$.<h!dfp46#2rlzj>x#h$
!
no service password-encryption
!
redundancy
!
vpdn limit_rate 15
!
enable secret 8 $1c$7eyy23uMQk$!b(`dhh`n<nxlvxn&tp8$.<h!dfp46#2rlzj>x#h$
!
vlan 1
!
interface GigabitEthernet 0/0
no switchport
ip address 10.1.1.2 255.255.255.0
ip nat inside
!
interface GigabitEthernet 0/1
no switchport
ip address 11.1.1.1 255.255.255.0
ip nat inside
!
interface GigabitEthernet 0/2
no switchport
ip address 100.1.1.1 255.255.255.0
ip nat outside
!
interface GigabitEthernet 0/3
!
interface GigabitEthernet 0/4
!
interface GigabitEthernet 0/5
!
interface GigabitEthernet 0/6
!
interface GigabitEthernet 0/7
!
interface GigabitEthernet 0/8
!
interface GigabitEthernet 0/9
!
interface VLAN 1
!
router ospf 10
router-id 2.2.2.2
graceful-restart
network 10.1.1.0 0.0.0.255 area 0
network 11.1.1.0 0.0.0.255 area 0
network 100.1.1.0 0.0.0.255 area 0
!
ip nat pool ssj 100.1.1.1 100.1.1.1 netmask 255.255.255.0
ip nat inside source list 1 pool ssj overload
!
ip route 0.0.0.0 0.0.0.0 100.1.1.2
!
line console 0
logging synchronous
exec-timeout 0 0
line vty 0 4
login
!
end
R1#
SW1#show agg summary
AggregatePort MaxPorts SwitchPort Mode Ports
------------- -------- ---------- ------ -----------------------------------
Ag1 16 Enabled TRUNK Gi0/0 ,Gi0/1
SW1#
VPCS> show ip
NAME : VPCS[1]
IP/MASK : 172.18.47.1/24
GATEWAY : 172.18.47.254
DNS :
MAC : 00:50:79:66:68:1d
LPORT : 20000
RHOST:PORT : 127.0.0.1:30000
MTU : 1500
VPCS> ping 172.18.49.1
84 bytes from 172.18.49.1 icmp_seq=1 ttl=60 time=16.617 ms
84 bytes from 172.18.49.1 icmp_seq=2 ttl=60 time=4.908 ms
84 bytes from 172.18.49.1 icmp_seq=3 ttl=60 time=5.677 ms
84 bytes from 172.18.49.1 icmp_seq=4 ttl=60 time=5.118 ms
84 bytes from 172.18.49.1 icmp_seq=5 ttl=60 time=5.221 ms
VPCS> ping 100.1.1.2
84 bytes from 100.1.1.2 icmp_seq=1 ttl=62 time=4.407 ms
84 bytes from 100.1.1.2 icmp_seq=2 ttl=62 time=10.265 ms
84 bytes from 100.1.1.2 icmp_seq=3 ttl=62 time=5.012 ms
84 bytes from 100.1.1.2 icmp_seq=4 ttl=62 time=4.619 ms
84 bytes from 100.1.1.2 icmp_seq=5 ttl=62 time=3.617 ms
VPCS>