静态路由综合实验
1.拓扑图如下
2.实验要求如下
1.R6为isp,接口ip地址均为公有地址,该设备只能配置ip地址,之后不能再对其进行其他任何配置
2.R1-R6为局域网,私有IP地址为192.168.1.0/24,请合理分配
3.R1,R2,R4各有两个环回地址;R5,R6各有一个环回地址,所有路由器上的环回均代表连接用户的接口
4.R3下的两台pc通过DHCP自动获取ip地址
5.选路最佳,路由表尽量小,避免环路
6.R6TelnetR5的公有IP地址时候,实际登陆到R1上
7.R1-R5均可以访问R6的环回
8.R4与R5正常通过1000M链路,故障时通过100M链路
3.详细设计如下
先给路由器配置DHCP,之后完成对pc端分配IP的任务
[R3]int g0/0/2
[R3-GigabitEthernet0/0/2]ip address 192.168.1.97 27
[R3]dhcp enable
[R3]ip pool p1
[R3-ip-pool-p1]network 192.168.1.96 mask 27
[R3-ip-pool-p1]gateway-list 192.168.1.97
[R3-ip-pool-p1]dns-list 114.114.114.114
[R3-ip-pool-p1]q
[R3]int g0/0/02
[R3-GigabitEthernet0/0/2]dhcp select global
之后给其他两个接口配置IP
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip address 192.168.1.14 30
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip address 192.168.1.17 30
之后对其他路由器配置接口ip和环回IP
接下来给各个路由器配置缺省路由和静态路由同时给R4和R5之间将100M的优先级修改
[R1]ip route-static 0.0.0.0 0.0.0.0 192.168.1.2
[R1]ip route-static 0.0.0.0 0.0.0.0 192.168.1.14
[R1]ip route-static 192.168.1.64 27 192.168.1.2
[R1]ip route-static 192.168.1.128 27 192.168.1.2
[R1]ip route-static 192.168.1.160 27 192.168.1.2
[R1]ip route-static 192.168.1.128 27 192.168.1.14
[R1]ip route-static 192.168.1.160 27 192.168.1.14
[R1]ip route-static 192.168.1.96 27 192.168.1.14
[R1]ip route-static 192.168.1.0 30 192.168.1.2
[R1]ip route-static 192.168.1.4 30 192.168.1.2
[R1]ip route-static 192.168.1.20 30 192.168.1.2
[R1]ip route-static 192.168.1.24 30 192.168.1.2
[R1]ip route-static 192.168.1.12 30 192.168.1.14
[R1]ip route-static 192.168.1.16 30 192.168.1.14
[R1]ip route-static 192.168.1.20 30 192.168.1.14
[R1]ip route-static 192.168.1.24 30 192.168.1.14
[R2]ip route-static 0.0.0.0 0.0.0.0 192.168.1.6
[R2]ip route-static 192.168.1.32 27 192.168.1.1
[R2]ip route-static 192.168.1.96 27 192.168.1.1
[R2]ip route-static 192.168.1.12 30 192.168.1.1
[R2]ip route-static 192.168.1.4 30 192.168.1.6
[R2]ip route-static 192.168.1.16 30 192.168.1.6
[R2]ip route-static 192.168.1.20 30 192.168.1.6
[R2]ip route-static 192.168.1.24 30 192.168.1.6
[R2]ip route-static 192.168.1.128 27 192.168.1.6
[R2]ip route-static 192.168.1.160 27 192.168.1.6
[R3]ip route-static 192.168.1.0 30 192.168.1.13
[R3]ip route-static 192.168.1.32 27 192.168.1.13
[R3]ip route-static 192.168.1.64 27 192.168.1.13
[R3]ip route-static 192.168.1.4 30 192.168.1.18
[R3]ip route-static 192.168.1.64 27 192.168.1.18
[R3]ip route-static 192.168.1.128 27 192.168.1.18
[R3]ip route-static 192.168.1.160 27 192.168.1.18
[R3]ip route-static 192.168.1.20 30 192.168.1.18
[R3]ip route-static 192.168.1.24 30 192.168.1.18
[R4]ip route-static 0.0.0.0 0.0.0.0 192.168.1.22
[R4]ip route-static 0.0.0.0 0.0.0.0 192.168.1.26
[R4]ip route-static 192.168.1.0 30 192.168.1.5
[R4]ip route-static 192.168.1.32 27 192.168.1.5
[R4]ip route-static 192.168.1.64 27 192.168.1.5
[R4]ip route-static 192.168.1.96 27 192.168.1.17
[R4]ip route-static 192.168.1.32 27 192.168.1.17
[R4]ip route-static 192.168.1.12 30 192.168.1.17
[R4]ip route-static 192.168.1.160 27 192.168.1.22
[R4]ip route-static 192.168.1.160 27 192.168.1.26
[R5]ip route-static 192.168.1.128 27 192.168.1.21
[R5]ip route-static 192.168.1.128 27 192.168.1.25 preference 61
[R5]ip route-static 192.168.1.32 27 192.168.1.21
[R5]ip route-static 192.168.1.64 27 192.168.1.21
[R5]ip route-static 192.168.1.96 27 192.168.1.21
[R5]ip route-static 192.168.1.32 27 192.168.1.25 preference 61
[R5]ip route-static 192.168.1.64 27 192.168.1.25 preference 61
[R5]ip route-static 192.168.1.96 27 192.168.1.25 preference 61
[R5]ip route-static 192.168.1.0 30 192.168.1.21
[R5]ip route-static 192.168.1.4 30 192.168.1.21
[R5]ip route-static 192.168.1.12 30 192.168.1.21
[R5]ip route-static 192.168.1.16 30 192.168.1.21
[R5]ip route-static 192.168.1.0 30 192.168.1.25 preference 61
[R5]ip route-static 192.168.1.4 30 192.168.1.25 preference 61
[R5]ip route-static 192.168.1.12 30 192.168.1.25 preference 61
[R5]ip route-static 192.168.1.16 30 192.168.1.25 preference 61
给R1配置aaa进行telnet登陆
[R1]user-interface vty 0 4
[R1-ui-vty0-4]au
[R1-ui-vty0-4]authentication-mode aaa
[R1-ui-vty0-4]q
[R1]aaa
[R1-aaa]lo
[R1-aaa]local-user huawei p
[R1-aaa]local-user huawei password c
[R1-aaa]local-user huawei password cipher 123456
Info: Add a new user.
[R1-aaa]lo
[R1-aaa]local-user huawei pr
[R1-aaa]local-user huawei privilege le
[R1-aaa]local-user huawei privilege level 15
[R1-aaa]lo
[R1-aaa]local-user h
[R1-aaa]local-user huawei ser
[R1-aaa]local-user huawei service-type te
[R1-aaa]local-user huawei service-type telnet
给R5的0/0/1配置nat转换【此时R1-R4可以访问ISP的环回了】
[R5]acl 2000
[R5-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[R5]int g0/0/1
[R5-GigabitEthernet0/0/1]nat outbound 2000
给R5配置端口映射可以使ISPtelnetR1的服务器
[R5]int g0/0/1
[R5-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 23 inside 192.168.1.1 23
Warning:The port 23 is well-known port. If you continue it may cause function failure.
Are you sure to continue?[Y/N]:y
4.测试
ISP可以登陆R1的服务器
R3通过dhcp给pc端分配IP
R1可以访问ISP的环回这里就举一个为例子