企业网络拓扑设计
设备
接入层
PC
PC*9:
- 人事部
- 行政部
- 生产技术部
- 维护技术部
- 财务室
- 销售部A
- 销售部B
- 销售部C
- 监管部
交换机
S5700 Switch*5:
使用此设备是因为该设备有千兆以太网光纤,且可使用三层功能
- 人力行政交换口机
- 技术部门交换机
- 财务室交换机
- 销售部交换机
- 监管部门交换机
汇聚层
路由器
AR1220 Router*2:
在此设备基础上,各自添加了2个GE接口
- 汇聚路由1
- 汇聚路由2
- 汇聚路由3
核心层
路由器
AR1220*2:
在此设备基础上,各自添加了2个GE接口
- 核心路由
- 核心路由备份
AR3260*3:
在此设备基础上,各自添加了4个GE接口
使用此设备是因为该设备有3个固有GE接口且处理速度高,适合放在核心层 - 总路由
- 服务器路由
服务器
Server*5:
- FTP server
- DNS server
- www.mun.com(公司办公网)
- www.mun_finance.com(公司财政网)
- www.mun_tech.com(公司技术网)
测试端
client*1
使用此设备是为了检测ftp和http服务,其中使用的网页为我本人制作的成型网站
- TEST_Clients
Network Distribution
NO | Subnet Name | IP/Mask | Gateway | VLAN |
---|---|---|---|---|
1 | 人力资源部 | 192.168.5.1/24 | 192.168.5.254 | VLAN5 |
2 | 行政部 | 192.168.20.1/24 | 192.168.20.254 | VLAN20 |
3 | 生产技术部 | 192.168.40.1/24 | 192.168.50.254 | VLAN30 |
4 | 维护技术部 | 192.168.50.1/24 | 192.168.30.254 | VLAN40 |
5 | 财政部 | 192.168.30.1/24 | 192.168.40.254 | -VLAN50 |
6 | 销售部A | 192.168.60.1/24 | 192.168.60.254 | VLAN60 |
7 | 销售部B | 192.168.70.1/24 | 192.168.70.254 | VLAN70 |
8 | 销售部C | 192.168.80.1/24 | 192.168.80.254 | VLAN80 |
9 | 监管部 | 192.168.90.1/24 | 192.168.90.254 | VLAN90 |
10 | FTP server | 192.168.100.1/24 | 192.168.100.254/24 | – |
11 | DNS server | 192.168.200.1/24 | 192.168.200.254/24 | – |
12 | DNS server | 192.168.200.1/24 | 192.168.110.254/24 | – |
13 | DNS server | 192.168.200.1/24 | 192.168.140.254/24 | – |
14 | DNS server | 192.168.200.1/24 | 192.168.130.254/24 | – |
15 | DNS server | 192.168.200.1/24 | 192.168.120.254/24 | – |
Command
Swicth
人力行政交换机
sys
sysname HA_Switch
vlan batch 5 20
int g 0/0/1
port link-type access
port default vlan 5
int g 0/0/2
port link-type access
port default vlan 20
int g 0/0/24
port link-type trunk
port trunk allow-pass vlan 5 20
技术部门交换机
sys
sysname Tech_Switch
vlan batch 30 40
int g 0/0/1
port link-type access
port default vlan 30
int g 0/0/2
port link-type access
port default vlan 40
int g 0/0/24
port link-type trunk
port trunk allow-pass vlan 30 40
财务室交换机
sys
sysname FO_Switch
vlan batch 50
int g 0/0/1
port link-type access
port default vlan 50
int g 0/0/24
port link-type trunk
port trunk allow-pass vlan 50
销售部门交换机
sys
sysname Sales_Switch
vlan batch 60 70 80
int g 0/0/1
port link-type access
port default vlan 60
int g 0/0/2
port link-type access
port default vlan 70
int g 0/0/3
port link-type access
port default vlan 80
int g 0/0/24
port link-type trunk
port trunk allow-pass vlan 60 70 80
####监管部门交换机
sys
sysname SV_Switch
vlan batch 90
int g 0/0/1
port link-type access
port default vlan 90
int g 0/0/24
port link-type trunk
port trunk allow-pass vlan 90
Router
汇聚路由1
sys
sysname DRouter_1
int g 0/0/0.5
dot1q termination vid 5
ip address 192.168.5.254 24
arp broadcast enable
int g 0/0/0.20
dot1q termination vid 20
ip address 192.168.20.254 24
arp broadcast enable
int g 0/0/1.30
dot1q termination vid 30
ip address 192.168.30.254 24
arp broadcast enable
int g 0/0/1.40
dot1q termination vid 40
ip address 192.168.40.254 24
arp broadcast enable
int g 1/0/0
ip address 192.168.11.1 24
int g 2/0/0
ip address 192.168.22.1 24
quit
ospf 1 router-id 1.1.1.1
area 0
network 192.168.5.0 0.0.0.255
network 192.168.20.0 0.0.0.255
network 192.168.30.0 0.0.0.255
network 192.168.40.0 0.0.0.255
network 192.168.11.0 0.0.0.255
network 192.168.22.0 0.0.0.255
汇聚路由2
sys
sysname DRouter_2
int g 0/0/0.50
dot1q termination vid 50
ip address 192.168.50.254 24
arp broadcast enable
int g 1/0/0
ip address 192.168.33.1 24
int g 2/0/0
ip address 192.168.44.1 24
quit
ospf 1 router-id 2.2.2.2
area 0
network 192.168.50.0 0.0.0.255
network 192.168.33.0 0.0.0.255
network 192.168.44.0 0.0.0.255
汇聚路由3
sys
sysname DRouter_1
int g 0/0/0.60
dot1q termination vid 60
ip address 192.168.60.254 24
arp broadcast enable
int g 0/0/0.70
dot1q termination vid 70
ip address 192.168.70.254 24
arp broadcast enable
int g 0/0/0.80
dot1q termination vid 80
ip address 192.168.80.254 24
arp broadcast enable
int g 0/0/1.90
dot1q termination vid 90
ip address 192.168.90.254 24
arp broadcast enable
int g 1/0/0
ip address 192.168.55.1 24
int g 2/0/0
ip address 192.168.66.1 24
quit
ospf 1 router-id 3.3.3.3
area 0
network 192.168.60.0 0.0.0.255
network 192.168.70.0 0.0.0.255
network 192.168.80.0 0.0.0.255
network 192.168.90.0 0.0.0.255
network 192.168.55.0 0.0.0.255
network 192.168.66.0 0.0.0.255
####核心路由
sys
sysname Core_Router
int g 0/0/0
ip address 192.168.55.2 24
int g 0/0/1
ip address 192.168.77.1 24
int g 1/0/0
ip address 192.168.11.2 24
int g 2/0/0
ip address 192.168.33.2 24
quit
ospf 1 router-id 4.4.4.4
area 0
network 192.168.11.0 0.0.0.255
network 192.168.33.0 0.0.0.255
network 192.168.55.0 0.0.0.255
network 192.168.77.0 0.0.0.255
核心路由备份
sys
sysname Core_Router_Backup
int g 0/0/0
ip address 192.168.66.2 24
int g 0/0/1
ip address 192.168.88.1 24
int g 1/0/0
ip address 192.168.22.2 24
int g 2/0/0
ip address 192.168.44.2 24
quit
ospf 1 router-id 5.5.5.5
area 0
network 192.168.66.0 0.0.0.255
network 192.168.88.0 0.0.0.255
network 192.168.22.0 0.0.0.255
network 192.168.44.0 0.0.0.255
总路由
sys
sysname Central_Router
int g 0/0/0
ip address 192.168.99.1 24
int g 0/0/1
ip address 192.168.77.2 24
int g 0/0/2
ip address 192.168.88.2 24
quit
ospf 1 router-id 6.6.6.6
area 0
network 192.168.77.0 0.0.0.255
network 192.168.88.0 0.0.0.255
area 1
network 192.168.99.0 0.0.0.255
服务器路由
sys
sysname Server_Router
int g 0/0/0
ip address 192.168.99.2 24
int g 0/0/1
ip address 192.168.100.254 24
int g 0/0/2
ip address 192.168.200.254 24
int g 1/0/0
ip address 192.168.110.254 24
int g 2/0/0
ip address 192.168.120.254 24
int g 3/0/0
ip address 192.168.130.254 24
int g 4/0/0
ip address 192.168.140.254 24
quit
ospf 1 router-id 7.7.7.7
area 1
network 192.168.99.0 0.0.0.255
network 192.168.100.0 0.0.0.255
network 192.168.200.0 0.0.0.255
network 192.168.110.0 0.0.0.255
network 192.168.120.0 0.0.0.255
network 192.168.130.0 0.0.0.255
network 192.168.140.0 0.0.0.255
ACL
在AR3260上的GE0/0/0装载
ACL 3500
由于本网络用于mun公司内网办公,不联入互联网
本访问控制列表针对公司内网,规定所有部门工作时间可以访问公司主页网站,但只要技术相关部门和监管部门能够访问技术网,只有财政部门和监管部门能访问财政网
RULE NO | DEVICE | SOURCE IP/MASK | DESTINATION IP/MASK | TIME | SERVICE | Protocol | Port |
---|---|---|---|---|---|---|---|
1 | 人力资源部 | 192.168.5.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
2 | 行政部 | 192.168.20.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
3 | 生产技术部 | 192.168.40.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
4 | 维护技术部 | 192.168.50.0/24 | 192.168.110.0/24 | VLAN40 | Mon-Fri 8:00-18:00 | permit | tcp |
5 | 财务室 | 192.168.30.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
6 | 销售部A | 192.168.60.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
7 | 销售部B | 192.168.70.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
8 | 销售部C | 192.168.80.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
9 | 监管部 | 192.168.90.0/24 | 192.168.110.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
10 | 生产技术部 | 192.168.30.0/24 | 192.168.130.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
11 | 维护技术部 | 192.168.40.0/24 | 192.168.130.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
12 | 监管部 | 192.168.90.0/24 | 192.168.130.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
13 | 财务室 | 192.168.50.0/24 | 192.168.140.254/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
14 | 监管部 | 192.168.90.0/24 | 192.168.140.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 80 |
15 | 人力资源部 | 192.168.5.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
16 | 行政部 | 192.168.20.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
17 | 生产技术部 | 192.168.40.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
18 | 维护技术部 | 192.168.50.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
19 | 财务室 | 192.168.30.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
20 | 销售部A | 192.168.60.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
21 | 销售部B | 192.168.70.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
22 | 销售部C | 192.168.80.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
23 | 监管部 | 192.168.90.0/24 | 192.168.100.0/24 | Mon-Fri 8:00-18:00 | permit | tcp | 53 |
Code
Time-range
time-range work_time 08:00 to 18:00 working-day
Rule
acl number 3500
rule 1 permit tcp source 192.168.5.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 2 permit tcp source 192.168.20.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 3 permit tcp source 192.168.30.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 4 permit tcp source 192.168.40.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 5 permit tcp source 192.168.50.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 6 permit tcp source 192.168.60.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 7 permit tcp source 192.168.70.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 8 permit tcp source 192.168.80.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 9 permit tcp source 192.168.90.0 0.0.0.255 destination 192.168.110.0 0.0.0.255 time-range work_time destination-port eq 80
rule 10 permit tcp source 192.168.30.0 0.0.0.255 destination 192.168.130.0 0.0.0.255 time-range work_time destination-port eq 80
rule 11 permit tcp source 192.168.40.0 0.0.0.255 destination 192.168.130.0 0.0.0.255 time-range work_time destination-port eq 80
rule 12 permit tcp source 192.168.90.0 0.0.0.255 destination 192.168.130.0 0.0.0.255 time-range work_time destination-port eq 80
rule 13 permit tcp source 192.168.50.0 0.0.0.255 destination 192.168.140.0 0.0.0.255 time-range work_time destination-port eq 80
rule 14 permit tcp source 192.168.90.0 0.0.0.255 destination 192.168.140.0 0.0.0.255 time-range work_time destination-port eq 80
rule 15 permit tcp source 192.168.5.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 16 permit tcp source 192.168.20.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 17 permit tcp source 192.168.30.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 18 permit tcp source 192.168.40.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 19 permit tcp source 192.168.50.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 20 permit tcp source 192.168.60.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 21 permit tcp source 192.168.70.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 22 permit tcp source 192.168.80.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
rule 23 permit tcp source 192.168.90.0 0.0.0.255 destination 192.168.100.0 0.0.0.255 time-range work_time destination-port eq 53
int g 0/0/0
traffic-filter inbound acl 3500
功能测试
连通测试
VLAN 5 和VLAN 20互访
VLAN 5 和VLAN 30 互访
VLAN 5 和VLAN 40 互访
VLAN 5 和VLAN 50 互访
VLAN 5 和VLAN 60 互访
VLAN 5 和VLAN 70 互访
VLAN 5 和VLAN 80 互访
VLAN 5 和VLAN 90 互访
VLAN访问FTPserver
VLAN 5 访问TEST_Terminal
VLAN访问DNS server
由此可见,整个网络拓扑的连通性得以实现