HCIA综合实验

实验要求

一、实验分析

1、划分IP 把连接交换机接口看作路由的环回,子网划分时候会更清晰,逐步划分

2、注意内网配置顺序 配IP后 首先配置二层交换机,其次是单臂路由,然后DHCP,OSPF,telnet

3、内网与外网边界AR2注意:ospf不宣告0/0/2接口。做NAT,并且test端登录telnet服务器需要做映射。

4、在做ACL时,注意源与目的的顺序。

实操拓扑图

二、子网划分

内网是基于192.168.1.0/24

首先内网一个躯干两个环回 所以需要三个网段  由于2^2=4  所以用掩码26

192.168.1.00 000000  /26        0            躯干    

192.168.1.01 000000   /26        64          R1下的网段

192.168.1.01 00 0000   /28        64

192.168.1.01 01 0000   /28        80

192.168.1.01 10 0000   /28        96

192.168.1.01 11 0000   /28        112

192.168.1.10 000000  /26        128        R2下的网段

192.168.1.10 0 00000 /27        128

192.168.1.10 1 00000 /27        160

192.168.1.11 000000   /26        192       预留 

202.1.1.0 /30        R2--ISP

203.1.1.0 /24        ISP的下方网络

三、内网

(一)二层交换机

Vlan技术

LSW1端

[LSW1]undo info-center enable   
[LSW1]vlan batch 2 3 4
   
[LSW1]interface GigabitEthernet 0/0/2   
[LSW1-GigabitEthernet0/0/2]port link-type access 
[LSW1-GigabitEthernet0/0/2]port default vlan 2
[LSW1-GigabitEthernet0/0/2]q
  
[LSW1]interface GigabitEthernet 0/0/3  
[LSW1-GigabitEthernet0/0/3]port link-type access  
[LSW1-GigabitEthernet0/0/3]port default vlan 3
[LSW1-GigabitEthernet0/0/3]q

[LSW1]interface GigabitEthernet 0/0/4  
[LSW1-GigabitEthernet0/0/4]port link-type access  
[LSW1-GigabitEthernet0/0/4]port default vlan 4
[LSW1-GigabitEthernet0/0/4]q


[LSW1]interface GigabitEthernet 0/0/1
[LSW1-GigabitEthernet0/0/1]port link-type  trunk 

[LSW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3 4

[LSW1]display vlan
 

2    common  UT:GE0/0/2(U)                                                      
             TG:GE0/0/1(U)                                                      

3    common  UT:GE0/0/3(U)                                                      

             TG:GE0/0/1(U)                                                      

4    common  UT:GE0/0/4(U)                                                      

             TG:GE0/0/1(U)  

LSW2端

[LSW2]undo info-center enable    
[LSW2]vlan batch 20 30
  
[LSW2]interface GigabitEthernet 0/0/2  
[LSW2-GigabitEthernet0/0/2]port link-type access  
[LSW2-GigabitEthernet0/0/2]port default vlan 20
[LSW2-GigabitEthernet0/0/2]q

[LSW2]interface GigabitEthernet 0/0/3
[LSW2-GigabitEthernet0/0/3]port link-type access 
[LSW2-GigabitEthernet0/0/3]port default vlan 30
[LSW2-GigabitEthernet0/0/3]q

[LSW2]interface GigabitEthernet 0/0/1   
[LSW2-GigabitEthernet0/0/1]port link-type trunk 
[LSW2-GigabitEthernet0/0/1]port trunk allow-pass vlan 20 30 

[LSW2]display vlan

20   common  UT:GE0/0/2(U)                                                      
             TG:GE0/0/1(U)                                                      

30   common  UT:GE0/0/3(U)                                                      

             TG:GE0/0/1(U)

(二)三层路由器

1、IP配置

AR1端

[AR1]interface GigabitEthernet 0/0/1   
[AR1-GigabitEthernet0/0/1]ip address 192.168.1.1 26

AR2端

[AR2]interface GigabitEthernet 0/0/1  
[AR2-GigabitEthernet0/0/1]ip address 192.168.1.2 26
[AR2-GigabitEthernet0/0/1]q

[AR2]interface GigabitEthernet 0/0/2
[AR2-GigabitEthernet0/0/2]ip address 202.1.1.1 30 

AR3端

[AR3]interface GigabitEthernet 0/0/0    
[AR3-GigabitEthernet0/0/0]ip address 202.1.1.2 30
[AR3-GigabitEthernet0/0/0]q

[AR3]interface GigabitEthernet 0/0/1  
[AR3-GigabitEthernet0/0/1]ip address 203.1.1.1 24

telent server端

[telnet server]interface GigabitEthernet 0/0/0  
[telnet server-GigabitEthernet0/0/0]ip address 192.168.1.98 28

test-1端

[test-1]interface GigabitEthernet 0/0/0
[test-1-GigabitEthernet0/0/0]ip address 203.1.1.2 24

test-2端

[test-2]interface GigabitEthernet 0/0/0
[test-2-GigabitEthernet0/0/0]ip address 203.1.1.3 24

2、单臂路由

AR1端

[AR1]interface  GigabitEthernet 0/0/0.1
[AR1-GigabitEthernet0/0/0.1]ip address 192.168.1.65 28   
[AR1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[AR1-GigabitEthernet0/0/0.1]arp broadcast enable 
[AR1-GigabitEthernet0/0/0.1]q

[AR1]interface GigabitEthernet 0/0/0.2 
[AR1-GigabitEthernet0/0/0.2]ip address 192.168.1.81 28  
[AR1-GigabitEthernet0/0/0.2]dot1q termination vid 3
[AR1-GigabitEthernet0/0/0.2]arp broadcast enable 
[AR1-GigabitEthernet0/0/0.2]q

[AR1]interface GigabitEthernet 0/0/0.3
[AR1-GigabitEthernet0/0/0.3]ip address 192.168.1.97 28 
[AR1-GigabitEthernet0/0/0.3]dot1q termination vid 4
[AR1-GigabitEthernet0/0/0.3]arp broadcast enable 

AR2端

[AR2]interface GigabitEthernet 0/0/0.1
[AR2-GigabitEthernet0/0/0.1]ip address 192.168.1.129 27   
[AR2-GigabitEthernet0/0/0.1]dot1q termination vid 20
[AR2-GigabitEthernet0/0/0.1]arp broadcast enable 
[AR2-GigabitEthernet0/0/0.1]q
    
[AR2]interface GigabitEthernet 0/0/0.2
[AR2-GigabitEthernet0/0/0.2]ip address 192.168.1.161 27    
[AR2-GigabitEthernet0/0/0.2]dot1q termination vid 30
[AR2-GigabitEthernet0/0/0.2]arp broadcast enable 

3、DHCP

AR1端

[AR1]dhcp enable 

[AR1]ip pool 1 
[AR1-ip-pool-1]network 192.168.1.64 mask 28
[AR1-ip-pool-1]gateway-list 192.168.1.65
[AR1-ip-pool-1]q

[AR1]ip pool 2
[AR1-ip-pool-2]network 192.168.1.80 mask 28
[AR1-ip-pool-2]gateway-list 192.168.1.81
[AR1-ip-pool-2]q
  
[AR1]interface GigabitEthernet 0/0/0.1
[AR1-GigabitEthernet0/0/0.1]dhcp select global 
[AR1-GigabitEthernet0/0/0.1]q
   
[AR1]interface GigabitEthernet 0/0/0.2 
[AR1-GigabitEthernet0/0/0.2]dhcp select global 

AR2端

[AR2]dhcp enable 

[AR2]ip pool 1  
[AR2-ip-pool-1]network 192.168.1.128 mask 27
[AR2-ip-pool-1]gateway-list 192.168.1.129
[AR2-ip-pool-1]q

[AR2]ip pool 2
[AR2-ip-pool-2]network 192.168.1.160 mask 27
[AR2-ip-pool-2]gateway-list 192.168.1.161
[AR2-ip-pool-2]q
  
[AR2]interface GigabitEthernet 0/0/0.1   
[AR2-GigabitEthernet0/0/0.1]dhcp select global 
[AR2-GigabitEthernet0/0/0.1]q

[AR2]interface GigabitEthernet 0/0/0.2 
[AR2-GigabitEthernet0/0/0.2]dhcp select global 

4、OSPF

AR1端

[AR1]ospf 1 router-id 1.1.1.1 
[AR1-ospf-1]area 0
[AR1-ospf-1-area-0.0.0.0]network 192.168.1.1 0.0.0.0
[AR1-ospf-1-area-0.0.0.0]network 192.168.1.65 0.0.0.0
[AR1-ospf-1-area-0.0.0.0]network 192.168.1.81 0.0.0.0
[AR1-ospf-1-area-0.0.0.0]network 192.168.1.97 0.0.0.0

AR2端

[AR2]ospf 1 router-id 2.2.2.2  

[AR2-ospf-1]area 0 
[AR2-ospf-1-area-0.0.0.0]network 192.168.1.2 0.0.0.0

[AR2-ospf-1-area-0.0.0.0]network 192.168.1.129 0.0.0.0
[AR2-ospf-1-area-0.0.0.0]network 192.168.1.161 0.0.0.0

[AR2]ip route-static 0.0.0.0 0 202.1.1.2

[AR2]ospf 1   
[AR2-ospf-1]default-route-advertise

四、NAT

AR2端

[AR2]acl 2000    
[AR2-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[AR2-acl-basic-2000]q

[AR2]interface GigabitEthernet 0/0/2
[AR2-GigabitEthernet0/0/2]nat outbound 2000

五、telnet

telnet server端

[telnet server]telnet server enable 

[telnet server]user-interface vty 0 4
[telnet server-ui-vty0-4]authentication-mode aaa
[telnet server-ui-vty0-4]q
[telnet server]aaa
[telnet server-aaa]local-user huawei password cipher 123456 
[telnet server-aaa]local-user huawei privilege level 15
[telnet server-aaa]local-user huawei service-type telnet

[telnet server]ip route-static 0.0.0.0 0 192.168.1.97

AR2端

[AR2]interface GigabitEthernet 0/0/2

[AR2-GigabitEthernet0/0/2]nat server protocol tcp global current-interface telne
t inside 192.168.1.98 telnet
Warning:The port 23 is well-known port. If you continue it may cause function fa
ilure.
Are you sure to continue?[Y/N]:y
[AR2-GigabitEthernet0/0/2]

test-1端

[test-1]ip route-static 202.1.1.1 32 203.1.1.1

test-2端

[test-2]ip route-static 202.1.1.1 32 203.1.1.1

六、外网与内网全网可达

七、ACL

AR1端

[AR1]acl 3000
 
[AR1-acl-adv-3000]rule deny ip source 192.168.1.64 0.0.0.15 destination 203.1.1.
100 0.0.0.0
[AR1-acl-adv-3000]q

[AR1]interface GigabitEthernet 0/0/0.1  
[AR1-GigabitEthernet0/0/0.1]traffic-filter inbound acl 3000
 

AR2端

[AR2]acl 3000  
[AR2-acl-adv-3000]rule deny tcp source 203.1.1.3 0 destination-port eq 23
[AR2-acl-adv-3000]q

[AR2]interface GigabitEthernet 0/0/2
[AR2-GigabitEthernet0/0/2]traffic-filter inbound acl 3000

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值