小型企业局域网搭建(二)
一、核心层–配置内部网络
1. 配置三层交换机SWRoot
1.1 添加vlan并设置端口模式
Switch>en
Switch#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#host SWRoot
SWRoot(config)#vlan 10
SWRoot(config-vlan)#vlan 11
SWRoot(config-vlan)#vlan 12
SWRoot(config-vlan)#vlan 13
SWRoot(config-vlan)#vlan 14
SWRoot(config-vlan)#vlan 20
SWRoot(config-vlan)#vlan 21
SWRoot(config-vlan)#vlan 22
SWRoot(config-vlan)#vlan 23
SWRoot(config-vlan)#vlan 24
SWRoot(config-vlan)#vlan 30
SWRoot(config-vlan)#vlan 31
SWRoot(config-vlan)#vlan 32
SWRoot(config-vlan)#vlan 100
SWRoot(config-vlan)#exit
SWRoot(config)#int f0/1
SWRoot(config-if)#sw tr en do
SWRoot(config-if)#sw mo tr
SWRoot(config-if)#sw tr al vl al
SWRoot(config-if)#exit
SWRoot(config)#int range f0/23 - 24
SWRoot(config-if-range)#sw tr en do
SWRoot(config-if-range)#sw mo tr
SWRoot(config-if-range)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/24, changed state to up
SWRoot(config-if-range)#sw tr al vl al
SWRoot(config-if-range)#exit
1.2配置交换虚拟接口(SVI)地址
Switch>en
SWRoot#conf t
Enter configuration commands, one per line. End with CNTL/Z.
SWRoot(config)#int vlan 10
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan10, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan10, changed state to up
SWRoot(config-if)#ip address 192.168.1.28 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 11
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan11, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan11, changed state to up
SWRoot(config-if)#ip add 192.168.1.60 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 12
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan12, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan12, changed state to up
SWRoot(config-if)#ip add 192.168.1.92 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 13
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan13, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan13, changed state to up
SWRoot(config-if)#ip add 192.168.1.124 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 14
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan14, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan14, changed state to up
SWRoot(config-if)#ip add 192.168.1.156 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
// vlan20 - 24
SWRoot(config)#int vlan 20
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan20, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan20, changed state to up
SWRoot(config-if)#ip add 192.168.2.28 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 21
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan21, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan21, changed state to up
SWRoot(config-if)#ip add 192.168.2.60 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 22
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan22, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan22, changed state to up
SWRoot(config-if)#ip add 192.168.2.92 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 23
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan23, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan23, changed state to up
SWRoot(config-if)#ip add 192.168.2.124 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 24
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan24, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan24, changed state to up
SWRoot(config-if)#ip add 192.168.2.156 255.255.255.224
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
// vlan30 - 32
SWRoot(config)#int vlan 30
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan30, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan30, changed state to up
SWRoot(config-if)#ip add 192.168.3.60 255.255.255.192
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 31
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan31, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan31, changed state to up
SWRoot(config-if)#ip add 192.168.3.124 255.255.255.192
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
SWRoot(config)#int vlan 32
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan32, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan32, changed state to up
SWRoot(config-if)#ip add 192.168.3.188 255.255.255.192
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
// vlan 100
SWRoot(config)#int vlan 100
SWRoot(config-if)#
%LINK-5-CHANGED: Interface Vlan100, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan100, changed state to up
SWRoot(config-if)#ip add 100.100.100.254 255.255.255.0
SWRoot(config-if)#no shut
SWRoot(config-if)#exit
1.3 配置与路由器R0有关端口
Switch>en
SWRoot#conf t
Enter configuration commands, one per line. End with CNTL/Z.
SWRoot(config)#ip routing
SWRoot(config)#int G0/1
SWRoot(config-if)#no switchport
SWRoot(config-if)#ip address 12.1.1.1 255.255.255.252
1.4 访问控制列表ACL设置
这个必须要设置,为了控制各个vlan下电脑的IP通信权限。因为通过三层交换机的路由功能,可以使得所有不同vlan端口下的IP通信,但是实际情况下又需要限制部分IP通信,所以要进行ACL设置。
详见ACL设置这一篇博客
1.5 配置快速生成树
该功能在没有环路形成的时候可以不用
详见快速生成树这一篇博客
1.6 配置链路聚合
没有太多要求,可以不用,根据实际情况,需要高速带宽就设置。
详见链路聚合配置这一篇博客
2. 配置路由器R0
2.1 端口配置
Router>en
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#host Router0
Router0(config)#int G0/0
Router0(config-if)#ip add 200.1.1.1 255.255.255.0
Router0(config-if)#int G0/1
Router0(config-if)#ip add 12.1.1.2 255.255.255.252
Router0(config-if)#exit
2.2 ospf配置
该功能,是为了寻找最短通信路径,设置可以提高通信时的响应速度。
详见ospf配置这一篇博客