实验过程:
1.划分网段 从图中可以看出需要4个网段
划分为:
172.16.1.0/24
172.16.2.0/24
172.16.3.0/24
172.16.4.0/24
2.对每一个路由器进行ip配置和本地环回配置,进而运用ospf使不同区域的路由器可以互通
这里用r4 ping r7证明ospf已经成立
3.在交换机上通过vlan使得pc在不同网段下可以互通
vlan batch 2 3
interface e0/0/1
port link-type trunk
port trunk allow-pass vlan all
interface e0/0/2
port link-type access
port default vlan 2
interface e0/0/3
port link-type access
port default vlan 3
4.建立pool使得Pc自动获得ip地址 启动dhcp
[Huawei]dhcp enable
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]dhcp select global
[Huawei-GigabitEthernet0/0/0]dot1q termination vid 2
[Huawei-GigabitEthernet0/0/0]arp broadcast enable
[Huawei]int g0/0/1.2
[Huawei-GigabitEthernet0/0/0]dhcp select global
[Huawei-GigabitEthernet0/0/0]dot1q termination vid 3
[Huawei-GigabitEthernet0/0/0]arp broadcast enable
运用以下代码使pc间可以通信
[dhcp]interface g0/0/0.2
[dhcp-GigabitEthernet0/0/0.2]arp broadcast enable
结果:
5. 使router1有DR没有BDR
[Huawei-GigabitEthernet0/0/0]ospf dr-priority 0
6.加快收敛速度
[R2]interface g0/0/0
[R2-GigabitEthernet0/0/0]ospf timer hello 5
[R2-GigabitEthernet0/0/0]qu
[R2]interface g0/0/1
[R2-GigabitEthernet0/0/1]ospf timer hello 5
7.给r6配置nat
[r6]interface g0/0/1
[r6-GigabitEthernet0/nat outbound 2000 address-group 1
禁用pc4进入r6
[r4]acl 3000
[r4-acl-adv-3000]rule deny tcp source 192.168.3.0 0.0.0.255 destination 172.16.1
.1 255.255.255.255 destination-port eq 23
[r4-acl-adv-3000]interface g0/0/1.1
[r4-GigabitEthernet0/0/1.1]traffic-filter outbound acl 3000
禁用pc5icmp到pc3
[r4]acl 3001
[r4-acl-adv-3001]rule 5 deny icmp source 192.168.4.0 0.0.0.255 destination 192.1
68.2.0 0.0.0.255 icmp-type echo
[r4-acl-adv-3001]interface g0/0/1.2
[r4-GigabitEthernet0/0/1.2]traffic-filter outbound acl 3000
实验结果