HCIA综合实验

例图:

需求:

1.ISP路由器仅配置IP地址

2.内网基于192.168.1.0/24网段进行IP划分

3.R1/R2之间使用OSPF做到内网全通,单区域

4.PC1-PC4使用DHCP获取地址

5.PC2-PC4可以访问PC5,PC1不行

6.R2出口只拥有一个公网IP

7.test-1设备可以登录内网telnet服务器,test-2不行

内网交换器的区域划分:

[SW1]vlan 2
[SW1]vlan 3
[SW1]vlan 4
[SW1-GigabitEthernet0/0/2]port link-type access
[SW1-GigabitEthernet0/0/2]port default vlan 2
[SW1-GigabitEthernet0/0/3]port link-type access
[SW1-GigabitEthernet0/0/3]port default vlan 3
[SW1-GigabitEthernet0/0/4]port link-type access
[SW1-GigabitEthernet0/0/4]port default vlan 4
[SW1-GigabitEthernet0/0/1]port link-type trunk
[SW1-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 3 4 

[SW2]vlan 2
[SW2]vlan 3
[SW2-GigabitEthernet0/0/1]port link-type access 
[SW2-GigabitEthernet0/0/1]port default vlan 2
[SW2-GigabitEthernet0/0/2]port link-type access 
[SW2-GigabitEthernet0/0/2]port default vlan 3

路由IP配置:

[r1-GigabitEthernet0/0/1]ip address 192.168.1.1 26
[r1-GigabitEthernet0/0/0.1]ip address 192.168.1.65 28
[r1-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/0.1]arp broadcast enable
[r1-GigabitEthernet0/0/0.2]ip add 192.168.1.81 28
[r1-GigabitEthernet0/0/0.2]dot1q termination vid 3
[r1-GigabitEthernet0/0/0.2]arp broadcast enable 
[r1-GigabitEthernet0/0/0.3]ip add 192.168.1.97 28
[r1-GigabitEthernet0/0/0.3]dot1q termination vid 4
[r1-GigabitEthernet0/0/0.3]arp broadcast enable

[r2-GigabitEthernet0/0/0]ip add 192.168.1.2 26
[r2-GigabitEthernet0/0/0.1]ip add 192.168.1.129 27
[r2-GigabitEthernet0/0/0.1]dot1q termination vid 2
[r2-GigabitEthernet0/0/0.1]arp broadcast enable
[r2-GigabitEthernet0/0/0.2]ip add 192.168.1.161 27
[r2-GigabitEthernet0/0/0.2]dot1q termination vid 3
[r2-GigabitEthernet0/0/0.2]arp broadcast enable
[r2-GigabitEthernet0/0/1]ip add 202.1.1.1 30

[ISP-GigabitEthernet0/0/0]ip add 202.1.1.2 30
[ISP-GigabitEthernet0/0/1]ip add 203.1.1.1 24

[Telnet Server-GigabitEthernet0/0/0]ip add 192.168.1.98 28

[test-1-GigabitEthernet0/0/0]ip add 203.1.1.2 24

[test-2-GigabitEthernet0/0/0]ip add 203.1.1.3 24

内网的OSPF协议:

[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.1 0.0.0.0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.65 0.0.0.0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.81 0.0.0.0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.97 0.0.0.0

[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 192.168.1.2 0.0.0.0
[r2-ospf-1-area-0.0.0.0]network 192.168.1.129 0.0.0.0
[r2-ospf-1-area-0.0.0.0]network 192.168.1.161 0.0.0.0

DHCP:

[r1]dhcp enable
[r1]ip pool 1
[r1-ip-pool-1]network 192.168.1.64 mask 28
[r1-ip-pool-1]gateway-list 192.168.1.65
[r1]ip pool 2
[r1-ip-pool-2]network 192.168.1.80 mask 28
[r1-ip-pool-2]gateway-list 192.168.1.81
[r1-GigabitEthernet0/0/0.1]dhcp select global 
[r1-GigabitEthernet0/0/0.2]dhcp select global 

[r2]ip pool 1
[r2-ip-pool-1]network 192.168.1.128 mask 27
[r2-ip-pool-1]gateway-list 192.168.1.129
[r2]ip pool 2
[r2-ip-pool-2]network 192.168.1.160 mask 27
[r2-ip-pool-2]gateway-list 192.168.1.161
[r2-GigabitEthernet0/0/0.1]dhcp select global
[r2-GigabitEthernet0/0/0.2]dhcp select global

NAT:

[r2]acl 2000
[r2-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[r2-acl-basic-2000]quit 
[r2]int g 0/0/1
[r2-GigabitEthernet0/0/1]nat outbound 2000

缺省:
[r2]ip route-static 0.0.0.0 0 202.1.1.2
[r2]ospf 1 
[r2-ospf-1]default-route-advertise

静止访问:
[r1]acl 3000
[r1-acl-adv-3000]rule deny ip source 192.168.1.64 0.0.0.15 destination 203.1.1.1
00 0.0.0.0
[r1]interface g 0/0/0.1
[r1-GigabitEthernet0/0/0.1]traffic-filter inbound acl 3000

开启telnet服务:

[Telnet Server]user-interface vty 0 4
[Telnet Server-ui-vty0-4]authentication-mode aaa
[Telnet Server-aaa]local-user huawei password cipher hauwei
[Telnet Server-aaa]local-user huawei privilege level 15
[Telnet Server-aaa]local-user hauwei service-type telnet

[r2]int g 0/0/1
[r2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface telnet
 inside 192.168.1.98 telnet
Are you sure to continue?[Y/N]:y

[test-1]ip rou 202.1.1.1 32 203.1.1.1
[test-2]ip rou 202.1.1.1 32 203.1.1.1

[Telnet Server]ip rou 0.0.0.0 0 19.168.1.97

[r2]acl 3000
[r2-acl-adv-3000]rule deny tcp source 203.1.1.3 0 destination-port eq 23
[r2]int g 0/0/1
[r2-GigabitEthernet0/0/1]traffic-filter inbound acl 3000

  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值