HCIA综合实验

 要求:

1、ISP路由器仅配置IP地址
2、内部网络基于192.168.1.0/24网段进行IP规划
3、R1/R2之间使用OSPF做到内网全通,单区域
4、PC1-4使用DHCP获取地址
5、PC2-4可以访问PC5 ,PC1不行
6、R2出口只拥有一个公网IP
7、test-1设备可以登录到内网telnet服务器, test-2不行

思路:

网段划分:

内:
192.168.1.0/24
192.168.1.0/26
AR1:192.168.64/26
VLAN2:192.168.1.64/28
VLAN3:192.168.1.80/28
VLAN4:192.168.1.96/28
AR2:192.168.1.128/26
VLAN2:192.168.1.128/27
VLAN3:192.168.1.160/27

外:
AR2-ISP:23.1.1.0/24
ISP001:1.1.1.0/24

交换机配置VLAN、TRUNK

AR1:000口创建3个子接口,配置2个地址池,创建ACL表

配置:

LSW1:

[Huawei]vlan 2
[Huawei-vlan2]int g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 2

[Huawei-GigabitEthernet0/0/2]vlan 4
[Huawei-vlan4]vlan 3
[Huawei-vlan3]int g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access  
[Huawei-GigabitEthernet0/0/3]port default vlan 3
[Huawei-GigabitEthernet0/0/3]int g0/0/4
[Huawei-GigabitEthernet0/0/4]port link-type access
[Huawei-GigabitEthernet0/0/4]port default vlan 4
[Huawei-GigabitEthernet0/0/2]int g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3 4

LSW2:

[Huawei]vlan 3
[Huawei-vlan3]vlan 2
[Huawei-vlan2]int g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 2
[Huawei-GigabitEthernet0/0/2]int g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port defa    
[Huawei-GigabitEthernet0/0/3]port default vlan 3

LSW3:

AR1:

[Huawei]int g0/0/0.1
[Huawei-GigabitEthernet0/0/0.1]ip add 192.168.1.65 28
[Huawei-GigabitEthernet0/0/0.1]dot1q termination vid 2
[Huawei-GigabitEthernet0/0/0.1]arp broadcast enable

[Huawei-GigabitEthernet0/0/0.1]int g0/0/0.2
[Huawei-GigabitEthernet0/0/0.2]ip add 192.168.1.81 28
[Huawei-GigabitEthernet0/0/0.2]dot1q termination vid 3
[Huawei-GigabitEthernet0/0/0.2]arp broadcast enable

[Huawei-GigabitEthernet0/0/0.2]int g0/0/0.3
[Huawei-GigabitEthernet0/0/0.3]ip add 192.168.1.97 28
[Huawei-GigabitEthernet0/0/0.3]dot1q termination vid 4
[Huawei-GigabitEthernet0/0/0.3]arp broadcast enable

[Huawei-GigabitEthernet0/0/1]ip add 192.168.1.1 26

[Huawei]ospf 1 router-id 1.1.1.1
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.1 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.65 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.81 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.97 0.0.0.0

[Huawei]dhcp enable
[Huawei]ip p 1
[Huawei-ip-pool-1]network 192.168.1.64 mask 28
[Huawei-ip-pool-1]gateway-list 192.168.1.65
[Huawei-ip-pool-1]ip p 2
[Huawei-ip-pool-2]network 192.168.1.80 mask 28
[Huawei-ip-pool-2]gateway-list 192.168.1.81
[Huawei-ip-pool-2]int g0/0/0.1
[Huawei-GigabitEthernet0/0/0.1]dhcp select global
[Huawei-GigabitEthernet0/0/0.1]int g0/0/0.2
[Huawei-GigabitEthernet0/0/0.2]dhcp select global

[Huawei]acl 3000
[Huawei-acl-adv-3000]rule deny ip source  192.168.1.64 0.0.0.15 destination 1.1.
1.11 0.0.0.0
[Huawei-acl-adv-3000]int g0/0/0.1
[Huawei-GigabitEthernet0/0/0.1]traffic-filter inbound acl 3000

AR2:

[Huawei]int g0/0/0.1
[Huawei-GigabitEthernet0/0/0.1]ip add 192.168.1.129 27
[Huawei-GigabitEthernet0/0/0.1]dot1q termination vid 2
[Huawei-GigabitEthernet0/0/0.1]arp broadcast enable

[Huawei-GigabitEthernet0/0/0.1]int g0/0/0.2
[Huawei-GigabitEthernet0/0/0.2]ip add 192.168.1.161 27
[Huawei-GigabitEthernet0/0/0.2]dot1q termination vid 3
[Huawei-GigabitEthernet0/0/0.2]arp broadcast enable

[Huawei-GigabitEthernet0/0/0.2]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 192.168.1.2 26
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]ip add 23.1.1.1 24

[Huawei]ospf 1 router-id 2.2.2.2
[Huawei-ospf-1]area 0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.2 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.129 0.0.0.0
[Huawei-ospf-1-area-0.0.0.0]network 192.168.1.161 0.0.0.0

[Huawei]dhcp enable

[Huawei]ip pool 1

[Huawei-ip-pool-1]network 192.168.1.128 mask 27

[Huawei-ip-pool-1]gateway-list 192.168.1.129

[Huawei-ip-pool-1]ip p 2
[Huawei-ip-pool-2]network 192.168.1.160 mask 27
[Huawei-ip-pool-2]gate    
[Huawei-ip-pool-2]gateway-list 192.168.1.161

[Huawei-ip-pool-2]int g0/0/0.1
[Huawei-GigabitEthernet0/0/0.1]dhcp select global
[Huawei-GigabitEthernet0/0/0.1]int g0/0/0.2
[Huawei-GigabitEthernet0/0/0.2]dhcp select global

[Huawei]acl 2000 
[Huawei-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[Huawei-acl-basic-2000]int g0/0/2
[Huawei-GigabitEthernet0/0/2]nat outbound 2000
[Huawei-GigabitEthernet0/0/2]q
[Huawei]ip route-static 0.0.0.0 0 23.1.1.2
[Huawei]ospf 1
[Huawei-ospf-1]default-route-advertise 

TELNET SERVER:

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 192.168.1.98 28

TEST-1:

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 1.1.1.2 24

TEST-2:

[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 1.1.1.3 24

测试:

 

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值