@实验要求
补充:1、ISP公有地址,有环回;
2、PC1和PC3在Vlan1中,PC2和PC4在Vlan2中。
1.构建拓扑
2.创建TRUNK通道
LSW1的配置:
LSW2的配置:
3.创建trunk干道
LSW1的配置:
[LSW1]port-group group-member GigabitEthernet 0/0/4 to GigabitEthernet 0/0/5 Eth
-Trunk 0 //合并接口为一组,使操作更加简单
[LSW1-port-group]port link-type trunk //为上面合并的组中所有的接口自动添加接口类型
[LSW1-GigabitEthernet0/0/4]port link-type trunk
[LSW1-GigabitEthernet0/0/5]port link-type trunk
[LSW1-Eth-Trunk0]port link-type trunk
[LSW1-port-group]port trunk allow-
[LSW1-port-group]port trunk allow-pass vlan 2 //配置Trunk类型接口加入的VLAN 2
[LSW1-GigabitEthernet0/0/4]port trunk allow-pass vlan 2
[LSW1-GigabitEthernet0/0/5]port trunk allow-pass vlan 2
[LSW1-Eth-Trunk0]port trunk allow-pass vlan 2
[LSW1-port-group]
LSW2的配置:
[LSW2]port-group group-member g0/0/4 to g0/0/5 eth
[LSW2]port-group group-member g0/0/4 to g0/0/5 Eth-Trunk 0
[LSW2-port-group]port link-type trunk
[LSW2-GigabitEthernet0/0/4]port link-type trunk
[LSW2-GigabitEthernet0/0/5]port link-type trunk
[LSW2-Eth-Trunk0]port link-type trunk
[LSW2-port-group]port trunk all
[LSW2-port-group]port trunk allow-pass vlan 2
[LSW2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2
[LSW2-GigabitEthernet0/0/5]port trunk allow-pass vlan 2
[LSW2-Eth-Trunk0]port trunk allow-pass vlan 2
[LSW2-port-group]
LSW3的配置:
[LSW3]port-group group-member g0/0/1 to g0/0/2
[LSW3-port-group]port link-type trunk
[LSW3-GigabitEthernet0/0/1]port link-type trunk
[LSW3-GigabitEthernet0/0/2]port link-type trunk
[LSW3-port-group]port trunk all
[LSW3-port-group]port trunk allow-pass vlan 2
[LSW3-GigabitEthernet0/0/1]port trunk allow-pass vlan 2
[LSW3-GigabitEthernet0/0/2]port trunk allow-pass vlan 2
[LSW3-port-group]
LSW4的配置:
[Huawei]sysname LSW4
[LSW4]port-group group-member g0/0/1 to g0/0/2
[LSW4-port-group]port link-type trunk
[LSW4-GigabitEthernet0/0/1]port link-type trunk
[LSW4-GigabitEthernet0/0/2]port link-type trunk
[LSW4-port-group]port trunk all
[LSW4-port-group]port trunk allow-pass vlan 2
[LSW4-GigabitEthernet0/0/1]port trunk allow-pass vlan 2
[LSW4-GigabitEthernet0/0/2]port trunk allow-pass vlan 2
[LSW4-port-group]
4.创建vlan,划分PC接口
LSW1的配置:
这时默认拥有vlan 1 且接口全为trunk
LSW2的配置:
LSW3的配置:
LSW4的配置:
划分PC接口:
LSW3的配置:
[LSW3]inter g0/0/4 //LSW3连接PC2的接口
[LSW3-GigabitEthernet0/0/4]port link-type access //配置接口的链路类型为Access
[LSW3-GigabitEthernet0/0/4]port default vlan 2 //配置接口的缺省VLAN并同时加入这个VLAN。
[LSW3-GigabitEthernet0/0/4]
接口类型补充:
-
Access类型的接口用来连接用户主机,它只能连接接入链路,且接入链路上通过的帧为不带Tag的以太网帧。如果Access接口配置了缺省VLAN,则在该报文上加上Tag标记,并将Tag中的VID字段的值设置为接口所属的缺省VLAN编号,此时接入链路上允许与缺省VLAN
Tag匹配的以太网帧通过。 -
Hybrid类型的接口既可以用来连接用户主机也可以用来连接其它交换机设备,Hybrid接口既可以连接接入链路又可以连接干道链路。Hybrid接口允许多个VLAN的帧通过,并可以在出接口方向将某些VLAN帧的Tag剥掉。
-
Trunk类型的接口用来连接其它交换机设备,它只能连接干道链路。Trunk接口允许多个VLAN的帧通过。
LSW4的配置:
[LSW4]inter g0/0/4 //LSW4连接PC4的接口
[LSW4-GigabitEthernet0/0/4]port link-type access
[LSW4-GigabitEthernet0/0/4]port default vlan 2
[LSW4-GigabitEthernet0/0/4]
5.配置STP生成树协议
首先配置STP:
LSW1的配置:
[LSW1]stp mode mstp
[LSW1]stp enable //开启stp协议
[LSW1]stp region-
[LSW1]stp region-configuration
[LSW1-mst-region]region-name 1 //创建域名
[LSW1-mst-region]instance 1 vlan 1
[LSW1-mst-region]instance 2 vlan 2
[LSW1-mst-region]active region-
[LSW1-mst-region]active region-configuration //激活配置
Info: This operation may take a few seconds. Please wait for a moment...done.
[LSW1-mst-region]
display stp brief //用来查看生成树列表
下面的配置相同:
LSW2的配置:
LSW3的配置:
LSW4的配置:
[LSW4]stp mode mstp
[LSW4]stp enable
[LSW4]stp region-configuration
[LSW4-mst-region]region-name 1
[LSW4-mst-region]instance 1 vlan 1
[LSW4-mst-region]instance 2 vlan 2
[LSW4-mst-region]active region-configuration
LSW1和LSW2互相为备份:
LSW2的配置:
LSW3的配置:
6.配置SVI
划分172.16.0.0网段
172.16.0.0/16
172.16.0.0/18
172.16.64.0/18
172.16.128.0/18
172.16.192.0/18
LSW1的配置:
[LSW1]inter vlan 1
[LSW1-Vlanif1]ip add 172.16.64.1 18
[LSW1]inter vlan 2
[LSW1-Vlanif2]ip add 172.16.128.1 18
LSW2的配置:
[LSW2]inter vlan 1
[LSW2-Vlanif1]ip add 172.16.64.2 18
[LSW2-Vlanif1]inter vlan 2
[LSW2-Vlanif2]ip add 172.16.128.2 18
[LSW2-Vlanif2]
7.启用VRRP
LSW1的配置:
[LSW1]inter vlan 1
[LSW1-Vlanif1]vrrp vrid 1 vir
[LSW1-Vlanif1]vrrp vrid 1 virtual-ip 172.16.64.3
[LSW1-Vlanif1]vrrp vrid 1 p
[LSW1-Vlanif1]vrrp vrid 1 prior
[LSW1-Vlanif1]vrrp vrid 1 priority 130 //修改优先级
[LSW1-Vlanif1]vrrp vrid 1 track inter g0/0/1 reduced 30 //上行进行链路追踪
[LSW1-Vlanif1]inter vlan 2
[LSW1-Vlanif2]vrrp vrid 1 virtual-ip 172.16.128.3 //作为备份
LSW2的配置:
8.启用DHCP
LSW1的配置:
[LSW1]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[LSW1]ip pool v1
Info:It's successful to create an IP address pool.
[LSW1-ip-pool-v1]net 172.16.192.1 mask 18
[LSW1-ip-pool-v1]gatway-li
[LSW1-ip-pool-v1]gate
[LSW1-ip-pool-v1]gateway-list 172.16.0.1
[LSW1-ip-pool-v1]dns
[LSW1-ip-pool-v1]dns-list 144.144.144.144 8.8.8.8
[LSW1-ip-pool-v1]ip pool v2
[LSW1-ip-pool-v2]network 172.16.192.2 mask 18
[LSW1-ip-pool-v2]gateway-list 172.16.1.254
[LSW1-ip-pool-v2]dns-list 144.144.144.144 8.8.8.8
[LSW1]int vlan 1
[LSW1-Vlanif1]dhcp select global
[LSW1-Vlanif1]int vlan2
[LSW1-Vlanif2]dhcp select global
*LSW2的配置:*同上
9.配置骨干IP
LSW2的配置:
LSW2的配置:
R1的配置:
R2的配置:
10.宣告OPSF
R1的配置:
[R1]ospf 1 router-id 1.1.1.1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]net 172.16.0.0 0.255.255.255
LSW1的配置:
[LSW1]ospf 1 router-id 1.1.1.2
[LSW1-ospf-1]area 0
[LSW1-ospf-1-area-0.0.0.0]net 172.16.0.0 0.255.255.255
[LSW1-ospf-1-area-0.0.0.0]q
[LSW1-ospf-1]area 1
[LSW1-ospf-1-area-0.0.0.1]net 172.16.64.0 0.0.255.255
LSW2的配置:
[LSW2]ospf 1 router-id 2.2.2.3
[LSW2-ospf-1]area 0
[LSW2-ospf-1-area-0.0.0.0]network 172.16.64.0 0.0.0.255
[LSW2-ospf-1-area-0.0.0.0]q
[LSW2-ospf-1]area 1
[LSW2-ospf-1-area-0.0.0.1]network 172.16.128.0 0.0.0.255
11.配置LSW1、LSW2的沉默接口
LSW1的配置:
[LSW1]ospf 1
[LSW1-ospf-1]silent-interface all //沉默所有接口
//打开需要的接口
[LSW1-ospf-1]undo silent-interface GigabitEthernet 0/0/1
[LSW1-ospf-1]undo silent-interface Eth-Trunk 0 v
[LSW1-ospf-1]undo silent-interface vlanif 1
[LSW1-ospf-1]undo silent-interface vlanif 10
LSW2的配置:
12.配置缺省路由、NAT
R1的配置: