要求:
R8和r9的环回分别是172.16.1.0/24和172.16.2.0/24
中间使用78.1.1.0/24
剩下的路由器2-6使用172.16.0.0/20
R1为运营商 r1远程登录r2实际登录r7
R2访问r7要求走r5去访问
全网可达
一、网段划分
名称 | 接口 | IP地址 | 环回地址 |
---|---|---|---|
ISP | g0/0/0 | 12.1.1.1/24 | |
R2 | g0/0/0 | 12.1.1.2/24 | |
R2 | g0/0/1 | 172.16.0.1/20 | |
R3 | g0/0/0 | 172.16.0.2/20 | |
R3 | g0/0/1 | 172.16.16.1/20 | |
R3 | g0/0/2 | 172.16.32.1/20 | |
R4 | g0/0/0 | 172.16.16.2/20 | |
R4 | g0/0/1 | 172.16.64.1/20 | |
R5 | g0/0/0 | 172.16.32.2/20 | |
R5 | g0/0/1 | 172.16.48.1/20 | |
R6 | g0/0/0 | 172.16.48.2/20 | |
R6 | g0/0/1 | 172.16.80.2/20 | |
R6 | g0/0/2 | 172.16.96.1/20 | |
R7 | g0/0/0 | 172.16.64.2/20 | |
R7 | g0/0/1 | 172.16.80.1/20 | 7.7.7.7/24 |
R8 | g0/0/0 | 172.16.96.2/20 | 172.16.1.0/24 |
R8 | g0/0/1 | 78.1.1.1/24 | |
R9 | g0/0/0 | 78.1.1.2/24 | 172.16.2.0/24 |
二、实验步骤
1.配置 IP 地址
(1) ISP
[ISP]int g0/0/0
[ISP-GigabitEthernet0/0/0]ip add 12.1.1.1 24
(2) R2
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.1.1.2 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip add ip add 172.16.0.1 20
(3) R3
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip add 172.16.0.2 20
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip add 172.16.16.1 20
[R3-GigabitEthernet0/0/1]int g0/0/2
[R3-GigabitEthernet0/0/2]ip add 172.16.32.1 20
(4) R4
[R4]int g0/0/0
[R4-GigabitEthernet0/0/0]ip add 172.16.16.2 20
[R4-GigabitEthernet0/0/0]int g0/0/1
[R4-GigabitEthernet0/0/1]ip add 172.16.64.1 20
(5) R5
[R5]int g0/0/0
[R5-GigabitEthernet0/0/0]ip add 172.16.16.2 20
[R5-GigabitEthernet0/0/0]int g0/0/1
[R5-GigabitEthernet0/0/1]ip add 172.16.48.1 20
(6) R6
[R6]int g0/0/0
[R6-GigabitEthernet0/0/0]ip add 172.16.48.2 20
[R6-GigabitEthernet0/0/0]int g0/0/1
[R6-GigabitEthernet0/0/1]ip add 172.16.80.2 20
[R6-GigabitEthernet0/0/1]int g0/0/2
[R6-GigabitEthernet0/0/2]ip add 172.16.96.1 20
(7)R7
[R7]int g0/0/0
[R7-GigabitEthernet0/0/0]ip add 172.16.64.2 20
[R7-GigabitEthernet0/0/0]int g0/0/1
[R7-GigabitEthernet0/0/1]ip add 172.16.80.1 20
[R7]int LoopBack 0
[R7-LoopBack0]ip add 7.7.7.7 24
(8) R8
[R8]int g0/0/0
[R8-GigabitEthernet0/0/0]ip add 172.16.96.2 20
[R8-GigabitEthernet0/0/0]int g0/0/1
[R8-GigabitEthernet0/0/1]ip add 78.1.1.1 24
[R8]int LoopBack 0
[R8-LoopBack0]ip add 172.16.1.1 24
(9) R9
[R9]int g0/0/0
[R9-GigabitEthernet0/0/0]ip add 78.1.1.2 24
[R9]int LoopBack 0
[R9-LoopBack0]ip add 172.16.2.1 24
2.使用Rip配置路由协议
(1) R2
[R2]rip 1
[R2-rip-1]version 2
[R2-rip-1]network 172.16.0.0
(2) R3
[R3]rip 1
[R3-rip-1]version 2
[R3-rip-1]network 172.16.0.0
(3) R4
[R4]rip 1
[R4-rip-1]version 2
[R4-rip-1]network 172.16.0.0
(4)R5
[R5]rip 1
[R5-rip-1]version 2
[R5-rip-1]network 172.16.0.0
(5)R6
[R6]rip 1
[R6-rip-1]version 2
[R6-rip-1]network 172.16.0.0
(6)R7
[R7]rip 1
[R7-rip-1]version 2
[R7-rip-1]network 172.16.0.0
[R7-rip-1]network 7.0.0.0
(7)R8
[R8]rip 1
[R8-rip-1]version 1
[R8-rip-1]network 172.16.0.0
[R8-rip-1]network 78.0.0.0
[R8]int g0/0/0
[R8-GigabitEthernet0/0/0]rip version 2
(8)R9
[R9]rip 1
[R9-rip-1]version 1
[R9-rip-1]netw 172.16.0.0
[R9-rip-1]netw 78.0.0.0
以上步骤实现内网全网可达
3.在R2上进行NAT转换,达到外网全网可达
[R2]acl 2000
[R2-acl-basic-2000]rule permit source any
[R2-acl-basic-2000]quit
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]nat outbound 2000
[R2-GigabitEthernet0/0/0]quit
[R2]ip route-static 0.0.0.0 0 12.1.1.1 // 书写缺省路由
[R2-rip-1]default-route originate // 向内网下放缺省
ping R1 地址后验证得已实现全网可达
4.修改跳数
R2—>R3—>R5—>R6—>R7
[R3]acl 2000
[R3-acl-basic-2000]rule permit source 7.7.7.7 0.0.0.0
[R3]int g0/0/1
[R3-GigabitEthernet0/0/1]rip metricin 2000 4
5.开启远程登录
[R7]user-interface vty 0 4
[R7-ui-vty0-4]authentication-mode password
Please configure the login password (maximum length 16):123
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]nat static protocol tcp global 12.1.1.3 23 inside 7.7.7.7 23
从ISP远程访问R7
至此实验完成