小型网络设计

在这里插入图片描述

2.6.1 vlan划分

LSW3:
Vlan batch 10 20
Int e0/0/3
Port link-type acces
Port default vlan 10
Int e0/0/4
Port link-type acces
Port default vlan 20

Int e0/0/1
Port link-type trunk
Port trunk-allow-pass vlan all
Int e0/0/2
Port link-type trunk
Port trunk-allow-pass vlan all
LSW3:
Vlan batch 10 20
Int e0/0/3
Port link-type acces
Port default vlan 10
Int e0/0/4
Port link-type acces
Port default vlan 20

Int e0/0/1
Port link-type trunk
Port trunk-allow-pass vlan all
Int e0/0/2
Port link-type trunk
Port trunk-allow-pass vlan all

LSW1:
LSW1,LSW2一样:
Int e0/0/3
Port link-type trunk
Port trunk-allow-pass vlan all
Int e0/0/4
Port link-type trunk
Port trunk-allow-pass vlan all
2.6.2 链路捆绑

LSW1,LSW2一样:
[Huawei]interface Eth-Trunk 12
[Huawei-Eth-Trunk12]port link-type trunk
[Huawei-Eth-Trunk12]port trunk allow-pass vlan all
[Huawei-Eth-Trunk12]quit
[Huawei]interface GigabitEthernet 0/0/1 加入逻辑接口
[Huawei-GigabitEthernet0/0/1]eth-trunk 12
[Huawei-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]eth-trunk 12

2.6.3 vrrp(冗余)
LSW1:
[Huawei]vlan batch 10 20
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]ip address 192.168.10.253 24
[Huawei-Vlanif10]vrrp vrid 10 virtual-ip 192.168.10.25
[Huawei-Vlanif10]vrrp vrid 10 priority 150
[Huawei-Vlanif10]quit
[Huawei]interface Vlanif 20
[Huawei-Vlanif20]ip address 192.168.20.252 24
[Huawei-Vlanif20]vrrp vrid 20 virtual-ip 192.168.20.254
[Huawei-Vlanif20]vrrp vrid 20 priority 120
LSW2:VLAN10 优先级120;VLAN20 优先级150

2.6.4 dhcp(自动IP分配)
LSW1,LSW2一样:
[Huawei]dhcp enable
[Huawei]ip pool vlan10 创建IP池名字VLAN10
[Huawei-ip-pool-vlan10]gateway-list 192.168.10.254 此IP池分配的网关
[Huawei-ip-pool-vlan10]network 192.168.10.0 mask 255.255.255.0
[Huawei-ip-pool-vlan10]excluded-ip-address 192.168.10.100 192.168.10.251 排除地址池不用动态分配地址
[Huawei-ip-pool-vlan10]dns-list 8.8.8.8 114.114.114.114
[Huawei-ip-pool-vlan10]ip pool vlan20
Info:It’s successful to create an IP address pool.
[Huawei-ip-pool-vlan20]gateway-list 192.168.20.254
[Huawei-ip-pool-vlan20]network 192.168.20.0 mask 255.255.255.0
[Huawei-ip-pool-vlan20]excluded-ip-address 192.168.20.100 192.168.20.150
[Huawei-ip-pool-vlan20]dns-list 8.8.8.8 114.114.114.114
[Huawei-ip-pool-vlan20]quit
[Huawei]interface Vlanif 10
[Huawei-Vlanif10]dhcp select global 使VLAN10 接口具备DHCP的地址分配能力
[Huawei-Vlanif10]interface Vlanif 20
[Huawei-Vlanif20]dhcp select global

2.6.5 mstp(多生成树,防止环路)
LSW1,LSW2:
[Huawei]stp mode mstp //配置成mstp模式
[Huawei]stp instance 1 priority 4096
[Huawei]stp region-configuration //进入mstp模式
[Huawei-mst-region]instance 1 vlan 10 //生成树1
[Huawei-mst-region]instance 2 vlan 20 //生成树2
[Huawei-mst-region]region-name regin1 //域名rgin1
[Huawei-mst-region]revision-level 1 //版本等级
[Huawei-mst-region]check region-configuration
[Huawei-mst-region]active region-configuration
LSW3,4:
相同(除没有优先级这一条命令)

2.6.6 配置连接路由的端口和新添网络
LSW1:
[Huawei]vlan 2
[Huawei]interface vlan 2
[Huawei-Vlanif2]ip address 12.1.1.2 24
[Huawei]interface GigabitEthernet 0/0/6
[Huawei-GigabitEthernet0/0/6]port link-type access
[Huawei-GigabitEthernet0/0/6]port default VLAN 2
LSW2:
[Huawei]interface vlan 3
[Huawei-Vlanif3]ip address 13.1.1.2 24
[Huawei]interface GigabitEthernet 0/0/6
[Huawei-GigabitEthernet0/0/6]port link-type access
[Huawei-GigabitEthernet0/0/6]port default VLAN 2
AR:
int g0/0/0/0
ip add 12.1.1.1 24
int g0/0/0/1
ip add 13.1.1.1 24
int g0/0/0/2
ip add 100.1.1.1
AR1:
int g0/0/0
ip add 100.1.1.10
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]ip address 12.1.2.1 24

2.6.7 ospf(路由选择)
AR:
[Huawei]ospf 100 router-id 1.1.1.1
[Huawei-ospf-100]area 0.0.0.0
[Huawei-ospf-100-area-0.0.0.0]network 12.1.1.1 0.0.0.0
[Huawei-ospf-100-area-0.0.0.0]network 13.1.1.1 0.0.0.0
[Huawei-ospf-100-area-0.0.0.0]display this

LSW1:
[Huawei]ospf 100 router-id 12.12.12.12
[Huawei-ospf-100]area 0.0.0.0
[Huawei-ospf-100-area-0.0.0.0]network 12.1.1.2 0.0.0.0
[Huawei-ospf-100-area-0.0.0.0]network 192.168.10.0 0.0.0.255
[Huawei-ospf-100-area-0.0.0.0]network 192.168.20.0 0.0.0.255
[Huawei-ospf-100-area-0.0.0.0]display this
LSW2:
[Huawei]ospf 100 router-id 13.13.13.13
[Huawei-ospf-100]area 0.0.0.0
[Huawei-ospf-100-area-0.0.0.0]network 13.1.1.2 0.0.0.0
[Huawei-ospf-100-area-0.0.0.0]network 192.168.10.0 0.0.0.255
[Huawei-ospf-100-area-0.0.0.0]network 192.168.20.0 0.0.0.255
[Huawei-ospf-100-area-0.0.0.0]display this

AR:
[Huawei]ospf 100 router-id 1.1.1.1
[Huawei-ospf-100]default-route-advertise 在ospf进程下
强制下发默认路由使得ospf区域内所有设备都能学习到该条默认路由
[Huawei-ospf-100]display this

2.6.8 默认路由
AR:
[Huawei]ip route-static 0.0.0.0 0.0.0.0 100.1.1.10
AR1:
[Huawei]ip route-static 0.0.0.0 0.0.0.0 100.1.1.1

2.6.9 nat(内网访问外网)
AR:
[Huawei]acl 2000 访问控制策略
[Huawei-acl-basic-2000]rule 5 permit source 192.168.10.0 0.0.0.255
[Huawei-acl-basic-2000]rule 10 permit source 192.168.20.0 0.0.0.255
[Huawei-acl-basic-2000]display this
[Huawei-acl-basic-2000]quit
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/2]nat outbound 2000 进入路由外端口实现全网通
AR1:
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 5 permit source 12.1.2.0 0.0.0.255
[Huawei-acl-basic-2000]display this
[Huawei-acl-basic-2000]quit
[Huawei]interface GigabitEthernet 0/0/0
[Huawei-GigabitEthernet0/0/0]nat outbound 2000

2.6.10 IPSec (安全隧道) 静态路由
AR:
[Huawei]ip route-static 12.1.2.0 255.255.255.0 100.1.1.10 //配置静态路由
[Huawei]acl number 3001 //配置acl定义各保护的数据流
[Huawei-acl-adv-3001]rule permit ip source 13.1.1.0 0.0.0.255 destination 12.1.2.0 0.0.0.255
[Huawei-acl-adv-3001]rule permit ip source 12.1.1 .0 0.0.0.255 destination 12.1.2.0 0.0.0.255 rule permit ip source 13.1.1.0 0.0.0.255 destination 12.1.2.0
[Huawei-acl-adv-3001]display this
[Huawei]ipsec proposal tran1 //创建ipsec安全提议
[Huawei-ipsec-proposal-tran1]esp authentication-algorithm sha1
[Huawei-ipsec-proposal-tran1]quit
[Huawei]display ipsec proposal name tran1
[Huawei]ipsec policy map1 10 manual //配置手工安全策略(即一个组)
[Huawei-ipsec-policy-manual-map1-10]security acl 3001
[Huawei-ipsec-policy-manual-map1-10]proposal tran1
[Huawei-ipsec-policy-manual-map1-10]tunnel remote 100.1.1.10
[Huawei-ipsec-policy-manual-map1-10]tunnel local 100.1.1.1
[Huawei-ipsec-policy-manual-map1-10]sa spi outbound esp 12345
[Huawei-ipsec-policy-manual-map1-10]sa spi inbound esp 54321
[Huawei-ipsec-policy-manual-map1-10]sa string-key outbound esp simple abc
[Huawei-ipsec-policy-manual-map1-10]sa string-key inbound esp simple cba
[Huawei-ipsec-policy-manual-map1-10]quit
[Huawei]display ipsec policy name map1
[Huawei]interface GigabitEthernet 0/0/2 //在接口引用安全策略组
[Huawei-GigabitEthernet0/0/2]ipsec policy map1
[Huawei]display ipsec sa
AR1:同理
[Huawei]ip route-static 12.1.1.0 255.255.255.0 100.1.1.1
[Huawei]ip route-static 13.1.1.0 255.255.255.0 100.1.1.1
[Huawei]acl number 3001
[Huawei-acl-adv-3001]rule permit ip source 12.1.2.0 0.0.0.255 destination 13.1.1.0 0.0.0.255
[Huawei-acl-adv-3001]rule permit ip source 12.1.2.0 0.0.0.255 destination 12.1.1 .0 0.0.0.255
[Huawei-acl-adv-3001]display this

  • 0
    点赞
  • 11
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值