小实验练习
要求按照拓扑图配置MSTP、VRRP、DHCP、NAT 等相关命令使得图中所有终端能够网络互通
- MSTP+链路聚合:正常情况下各VLAN流量路径要求如下:
VLAN10:SW3->SW1->R1;VLAN20:SW3->SW2->R1;VLAN30:SW4->SW1->R1;VLAN40:SW4->SW2->R1 - VRRP:正常情况下要求VLAN10、VLAN30的Master为SW1;VLAN20、VLAN40的Master为SW2
- DHCP:R3为DHCP中继代理,R2为DHCP服务器,为PC5、PC6提供动态分配IP服务
- NAT:使用EasyIp进行转换使得Client1能够使用R1的外网口IP访问外网;并使用NAT-Server使得Client1访问Server1的http服务时能够使用R3的g0/0/0的接口IP:8080端口进行访问
SW3二层交换机配置:
SW3二层交换机配置:
#
vlan batch 10 20
##### 生成树的配置
stp mode mstp /将交换机设置位MSTP模式/
stp region-configuration /进入MSTP域配置视图/
region-name SW1 /对MSTP域命名,默认MAC地址/
revision-level 1 /配置MSTP的修订级别为1,关联的各设备级别需要一致/
instance 1 vlan 10 /将VLAN10放在实例1中,配置生成树与VLAN的映射关系,一个VLAN只能对应一个实例/
instance 2 vlan 20
active region-configuration 激活MSTP域
#
######配置access模式连接PC端
interface Ethernet0/0/1
port link-type access
port default vlan 10
#
interface Ethernet0/0/2
port link-type access
port default vlan 20
#
interface Ethernet0/0/3
port link-type access
port default vlan 10
#### 配置Trunk模式连接上层交换机(允许所有VLAN通过该端口传输)
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
==================================================
SW4二层交换机配置:
类似于SW3,在此不做详解
#
SW4二层交换机配置:
#
vlan batch 30 40
#
stp region-configuration
region-name SW1
revision-level 1
instance 1 vlan 30
instance 2 vlan 40
active region-configuration
#
interface Ethernet0/0/1
port link-type access
port default vlan 30
#
interface Ethernet0/0/2
port link-type access
port default vlan 40
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
==============================================
SW1三层交换机配置
# 创建VLAN
vlan batch 10 20 30 40 100
# 定义以太网聚合链路级别
lacp priority 1000
#
stp mode mstp ###将交换机配置成MSTP模式,MSTP兼容
stp region-configuration ###进入MSTP域视图MSTP配置模式
region-name SW1 ###配置MSTP域的域名为huawei1,缺省为交换设备主控板上管理网口的MAC地址。
revision-level 1 ###配置MST域的MSTP修订级别为1,缺省情况下MSTP域的MSTP修订级别为0,需要将各设备的MSTP修订级别修改为一致
instance 1 vlan 10 30 将vlan 10加入实例1中
instance 2 vlan 20 40
active region-configuration 激活MSTP域的配置(必须配置)
#
stp instance 1 root primary 配置此交换机为实例1的主根桥(secondary/28672,primary/24576)
stp instance 2 root secondary 配置此交换机为实例2的备份根桥
##
设置VLAN,同时创建虚拟路由器
interface Vlanif10
ip address 192.168.10.10 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.10.1 创建VRRP虚拟路由器的虚拟IP地址。
vrrp vrid 1 priority 120 设置当前设备VLAN10的优先级为120
vrrp vrid 1 preempt-mode timer delay 6 设置抢占时延(防止主备路由器频繁切换)
vrrp vrid 1 track interface GigabitEthernet0/0/5 reduced 30 跟踪上行接口,当端口故障时,路由器自动降级,优先级低30。
#
设置VRRP的虚拟IP,对应VLAN20,设为备用路由器。
interface Vlanif20
ip address 192.168.20.10 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.20.1
#
同理于VLAN10
interface Vlanif30
ip address 192.168.30.10 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.30.1
vrrp vrid 2 priority 120
vrrp vrid 2 preempt-mode timer delay 6
vrrp vrid 2 track interface GigabitEthernet0/0/5 reduced 30
#
同理于VLAN20
interface Vlanif40
ip address 192.168.40.10 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.40.1
#
interface Vlanif100
ip address 10.0.0.10 255.255.255.0
#
创建以太网聚合链路:
interface Eth-Trunk1 进入Eth-Trunk1的配置视图(将需要聚合的链路添加进入)
port link-type trunk 设置为Trunk类型额链路
port trunk allow-pass vlan 2 to 4094 允许所有VLAN通过该模式的接口。
mode lacp-static 配置Ete-Trunk1为静态LACP模式
max active-linknumber 2 设置最大活跃状态的链路
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
eth-trunk 1
#
interface GigabitEthernet0/0/4
eth-trunk 1
##
interface GigabitEthernet0/0/5
port link-type access
port default vlan 100
##
配置动态路由:宣告直连路由,学习非直连路由。
rip 1 启动RIP
undo summary 关闭路由自动聚合(让路由器按照IP地址分类归类)
version 2 启动版本号
network 192.168.10.0 宣告主网络
network 10.0.0.0
network 192.168.20.0
network 192.168.30.0
network 192.168.40.0
#
SW2三层交换机配置
该SW2交换机类似于SW1交换机配置,不做详细说明
#
vlan batch 10 20 30 40 100
#
stp instance 1 root secondary
stp instance 2 root primary
#
lacp priority 1000
##
stp region-configuration
region-name SW1
revision-level 1
instance 1 vlan 10 30
instance 2 vlan 20 40
active region-configuration
##
interface Vlanif10
ip address 192.168.10.20 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.10.1
#
interface Vlanif20
ip address 192.168.20.20 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.20.1
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 6
vrrp vrid 1 track interface GigabitEthernet0/0/5 reduced 30
#
interface Vlanif30
ip address 192.168.30.20 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.30.1
#
interface Vlanif40
ip address 192.168.40.20 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.40.1
vrrp vrid 2 priority 120
vrrp vrid 2 preempt-mode timer delay 6
vrrp vrid 2 track interface GigabitEthernet0/0/5 reduced 30
##
interface Vlanif100
ip address 11.0.0.20 255.255.255.0
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
mode lacp-static
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
eth-trunk 1
#
interface GigabitEthernet0/0/4
eth-trunk 1
#
interface GigabitEthernet0/0/5
port link-type access
port default vlan 100
##
rip 1
undo summary
version 2
network 11.0.0.0
network 192.168.10.0
network 192.168.20.0
network 192.168.30.0
network 192.168.40.0
#
AR1路由器配置
#
设置访问控制列表
acl number 2000 定义控制列表级别(高级ACL)
rule 5 permit source 192.168.10.0 0.0.0.255 允许源地址为该网段的数据通过。
##
interface GigabitEthernet0/0/0
ip address 10.0.0.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 11.0.0.1 255.255.255.0
#
interface GigabitEthernet0/0/2
ip address 12.0.0.1 255.255.255.0
nat outbound 2000 在端口中添加ACL2000规则,控制网段192.168.10.0的数据流通。
#
创建RIP动态路由
rip 1
undo summary
version 2
network 10.0.0.0
network 11.0.0.0
network 12.0.0.0
#
AR2路由器的配置
将该路由器作为DHCP服务器。
#
启动DHCP功能
dhcp enable
#
ip pool 1 创建地址池1,作为IP地址分配依据
gateway-list 192.168.100.1 配置下行设备网段
network 192.168.100.0 mask 255.255.255.0 配置网络号和子网掩码
dns-list 8.8.8.8 配置DNS
##
interface GigabitEthernet0/0/0
ip address 12.0.0.2 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 23.0.0.2 255.255.255.0
dhcp select global 配置DHCP的global全局模式,
##
rip 1
undo summary
version 2
network 12.0.0.0
network 23.0.0.0
#
AR4路由器的配置
#
dhcp enable
##
interface GigabitEthernet0/0/0
ip address 23.0.0.1 255.255.255.0
nat server protocol tcp global current-interface 8080 inside 192.168.200.200 www 在连接公网的接口上将私网服务器地址和外网接口做一对NAT映射绑定。
#
interface GigabitEthernet0/0/1
ip address 192.168.100.1 255.255.255.0
dhcp select relay 在该端口开启DHCP的中继功能
dhcp relay server-ip 23.0.0.2 指向DHCP服务器的地址请求DHCP服务,为下行设备分配IP地址。
#
interface GigabitEthernet0/0/2
ip address 192.168.200.1 255.255.255.0
##
配置动态路由RIP
rip 1
undo summary
version 2
network 23.0.0.0
network 192.168.100.0
network 192.168.200.0
#
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
#