网络综合实验实例(MSTP/LACP/VRRP/DHCP/NAT)
题目
需求
(1)MSTP+链路聚合LACP:
正常情况下各VLAN流量路径要求如下:
VLAN10:SW3->SW1->R1;
VLAN20:SW3->SW2->R1;
VLAN30:SW4->SW1->R1;
VLAN40:SW4->SW2->R1
使用dis stp brief 验证结果。
(2)VRRP:
正常情况下要求VLAN10、VLAN30的Master为SW1;
VLAN20、VLAN40的Master为SW2
使用dis vrrp 验证结果。
(3)DHCP:
R3为DHCP中继代理,R2为DHCP服务器,为PC5、PC6提供动态分配IP服务。
在PC5、PC6使用ipconfig 验证结果。
(4)NAT:
使用EasyIp进行转换使得Client1能够使用R1的外网口IP访问外网;
并使用NAT-Server使得Client1访问Server1的http服务时能够使用R3的g0/0/0的接口IP:8080端口进行访问
在R1使用display nat session all ,客户端访问http://23.0.0.1:8080 验证结果。
(5)所有终端能够网络互通
要求PC2能够ping通PC3和PC4;PC4能够ping通PC5和Server1
使用ping 验证结果。
实验步骤
1、MSTP+链路聚合LACP
R1
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sys R1
[R1]int g0/0/0
[R1-GigabitEthernet0/0/0]ip add 10.0.0.1 24
[R1-GigabitEthernet0/0/0]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 11.0.0.1 24
[R1-GigabitEthernet0/0/1]int g0/0/2
[R1-GigabitEthernet0/0/2]ip add 12.0.0.1 24
[R1-GigabitEthernet0/0/2]q
[R1]rip
[R1-rip-1]version 2
[R1-rip-1]undo summary
[R1-rip-1]net 10.0.0.0
[R1-rip-1]net 11.0.0.0
[R1-rip-1]net 12.0.0.0
[R1-rip-1]q
SW1
-----------基础配置--------------
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sys SW1
[SW1]v b 10 20 30 40 100
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW1]int g0/0/1
[SW1-GigabitEthernet0/0/1]port link-type trunk
[SW1-GigabitEthernet0/0/1]p t a v a
[SW1-GigabitEthernet0/0/1]int g0/0/2
[SW1-GigabitEthernet0/0/2]p l t
[SW1-GigabitEthernet0/0/2]p t a v a
[SW1-GigabitEthernet0/0/2]int g0/0/5
[SW1-GigabitEthernet0/0/5]p l a
[SW1-GigabitEthernet0/0/5]p d v 100
[SW1-GigabitEthernet0/0/5]q
[SW1]int vlan 10
[SW1-Vlanif10]ip add 192.168.10.10 24
[SW1-Vlanif10]int vlan 20
[SW1-Vlanif20]ip add 192.168.20.10 24
[SW1-Vlanif20]int vlan 30
[SW1-Vlanif30]ip add 192.168.30.10 24
[SW1-Vlanif20]int vlan 40
[SW1-Vlanif40]ip add 192.168.40.10 24
[SW1-Vlanif40]int vlan 100
[SW1-Vlanif100]ip add 10.0.0.10 24
[SW1-Vlanif100]q
-------------链路聚合--------------
[SW1]lacp priority 1000
[SW1]int eth-trunk 1
[SW1-Eth-Trunk1]bpdu enable
[SW1-Eth-Trunk1]mode lacp-static
[SW1-Eth-Trunk1]trunkport GigabitEthernet 0/0/3 to 0/0/4
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW1-Eth-Trunk1]max active-linknumber 2
[SW1-Eth-Trunk1]p l t
[SW1-Eth-Trunk1]p t a v a
[SW1-Eth-Trunk1]q
-----------MSTP配置------------
[SW1]stp mode mstp
[SW1]stp region-configuration
[SW1-mst-region]region-name huawei
[SW1-mst-region]revision-level 1
[SW1-mst-region]instance 1 vlan 10 30
[SW1-mst-region]instance 2 vlan 20 40
[SW1-mst-region]active region-configuration
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW1-mst-region]q
[SW1]stp instance 1 root primary
[SW1]stp instance 2 root secondary
SW2
--------基础配置-----------
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sys SW2
[SW2]v b 10 20 30 40 100
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW2]int g0/0/1
[SW2-GigabitEthernet0/0/1]p l t
[SW2-GigabitEthernet0/0/1]p t a v a
[SW2-GigabitEthernet0/0/1]int g0/0/2
[SW2-GigabitEthernet0/0/2]p l t
[SW2-GigabitEthernet0/0/2]p t a v a
[SW2-GigabitEthernet0/0/2]int g0/0/5
[SW2-GigabitEthernet0/0/5]p l a
[SW2-GigabitEthernet0/0/5]p d v 100
[SW2-GigabitEthernet0/0/5]q
[SW2]int vlan 10
[SW2-Vlanif10]ip add 192.168.10.20 24
[SW2-Vlanif10]int vlan 20
[SW2-Vlanif20]ip add 192.168.20.20 24
[SW2-Vlanif20]int vlan 30
[SW2-Vlanif30]ip add 192.168.30.20 24
[SW2-Vlanif30]int vlan 40
[SW2-Vlanif40]ip add 192.168.40.20 24
[SW2-Vlanif40]int vlan 100
[SW2-Vlanif100]ip add 11.0.0.20 24
[SW2-Vlanif100]q
--------链路聚合---------
[SW2]int eth-trunk 1
[SW2-Eth-Trunk1]bpdu enable
[SW2-Eth-Trunk1]mode lacp-static
[SW2-Eth-Trunk1]trunkport GigabitEthernet 0/0/3 to 0/0/4
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW2-Eth-Trunk1]max active-linknumber 2
[SW2-Eth-Trunk1]p l t
[SW2-Eth-Trunk1]p t a v a
[SW2-Eth-Trunk1]q
[SW2]dis trunkmembership eth-trunk 1
Trunk ID: 1
Used status: VALID
TYPE: ethernet
Working Mode : Static
Number Of Ports in Trunk = 2
Number Of Up Ports in Trunk = 2
Operate status: up
Interface GigabitEthernet0/0/3, valid, operate up, weight=1
Interface GigabitEthernet0/0/4, valid, operate up, weight=1
[SW2]
------------MSTP配置---------------
[SW2]stp mode mstp
[SW2]stp region-configuration
[SW2-mst-region]region-name huawei
[SW2-mst-region]revision-level 1
[SW2-mst-region]instance 1 vlan 10 30
[SW2-mst-region]instance 2 vlan 20 40
[SW2-mst-region]active region-configuration
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW2-mst-region]q
[SW2]stp instance 1 root secondary
[SW2]stp instance 2 root primary
SW3
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sys SW3
[SW3]v b 10 20 30 40
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW3]int e0/0/1
[SW3-Ethernet0/0/1]p l a
[SW3-Ethernet0/0/1]p d v 10
[SW3-Ethernet0/0/1]int e0/0/2
[SW3-Ethernet0/0/2]p l a
[SW3-Ethernet0/0/2]p d v 20
[SW3-Ethernet0/0/2]int e0/0/3
[SW3-Ethernet0/0/3]p l a
[SW3-Ethernet0/0/3]p d v 10
[SW3-Ethernet0/0/3]int g0/0/1
[SW3-GigabitEthernet0/0/1]p l t
[SW3-GigabitEthernet0/0/1]p t a v a
[SW3-GigabitEthernet0/0/1]int g0/0/2
[SW3-GigabitEthernet0/0/2]p l t
[SW3-GigabitEthernet0/0/2]p t a v a
[SW3-GigabitEthernet0/0/2]q
[SW3]stp mode mstp
[SW3]stp region-configuration
[SW3-mst-region]region-name huawei
[SW3-mst-region]revision-level 1
[SW3-mst-region]instance 1 vlan 10 30
[SW3-mst-region]instance 2 vlan 20 40
[SW3-mst-region]active region-configuration
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW3-mst-region]q
[SW3]
SW4
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sys SW4
[SW4]v b 10 20 30 40
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW4]int e0/0/1
[SW4-Ethernet0/0/1]p l a
[SW4-Ethernet0/0/1]p d v 30
[SW4-Ethernet0/0/1]int e0/0/2
[SW4-Ethernet0/0/2]p l a
[SW4-Ethernet0/0/2]p d v 40
[SW4-Ethernet0/0/2]int g0/0/1
[SW4-GigabitEthernet0/0/1]p l t
[SW4-GigabitEthernet0/0/1]p t a v a
[SW4-GigabitEthernet0/0/1]int g0/0/2
[SW4-GigabitEthernet0/0/2]p l t
[SW4-GigabitEthernet0/0/2]p t a v a
[SW4-GigabitEthernet0/0/2]q
[SW4]stp mode mstp
[SW4]stp region-configuration
[SW4-mst-region]region-name huawei
[SW4-mst-region]revision-level 1
[SW4-mst-region]instance 1 vlan 10 30
[SW4-mst-region]instance 2 vlan 20 40
[SW4-mst-region]active region-configuration
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW4-mst-region]q
PC配置
实验结果
2、VRRP
SW1
--------VRRP配置-------------
[SW1]int vlanif 10
[SW1-Vlanif10]vrrp vrid 1 virtual-ip 192.168.10.1
[SW1-Vlanif10]vrrp vrid 1 priority 120
[SW1-Vlanif10]vrrp vrid 1 preempt-mode timer delay 6
[SW1-Vlanif10]vrrp vrid 1 track interface g0/0/5 reduced 30
[SW1-Vlanif10]int v 20
[SW1-Vlanif20]vrrp vrid 1 virtual-ip 192.168.20.1
[SW1-Vlanif20]int v 30
[SW1-Vlanif30]vrrp vrid 1 virtual-ip 192.168.30.1
[SW1-Vlanif30]vrrp vrid 1 priority 120
[SW1-Vlanif30]vrrp vrid 1 preempt-mode timer delay 6
[SW1-Vlanif30]vrrp vrid 1 track interface g0/0/5 reduced 30
[SW1-Vlanif30]int v 40
[SW1-Vlanif40]vrrp vrid 1 virtual-ip 192.168.40.1
[SW1-Vlanif40]q
[SW1]
-----------三层交换----------------
[SW1]rip
[SW1-rip-1]version 2
[SW1-rip-1]undo summary
[SW1-rip-1]net 192.168.10.0
[SW1-rip-1]net 192.168.20.0
[SW1-rip-1]net 192.168.30.0
[SW1-rip-1]net 192.168.40.0
[SW1-rip-1]net 10.0.0.0
[SW1-rip-1]q
SW2
---------VRRP配置-------------
[SW2]int vlan 10
[SW2-Vlanif10]v v 1 v 192.168.10.1
[SW2-Vlanif10]int v 20
[SW2-Vlanif20]v v 1 v 192.168.20.1
[SW2-Vlanif20]vrrp v 1 priority 120
[SW2-Vlanif20]vrrp v 1 p t d 6
[SW2-Vlanif20]vrrp v 1 t int g0/0/5 r 30
[SW2-Vlanif20]int vlan 30
[SW2-Vlanif30]v v 1 v 192.168.30.1
[SW2-Vlanif30]int v 40
[SW2-Vlanif40]v v 1 v 192.168.40.1
[SW2-Vlanif40]vrrp v 1 priority 120
[SW2-Vlanif40]vrrp v 1 p t d 6
[SW2-Vlanif40]vrrp v 1 t int g0/0/5 r 30
[SW2-Vlanif40]q
------------三层交换-----------------
[SW2]rip
[SW2-rip-1]v 2
[SW2-rip-1]un summary
[SW2-rip-1]net 192.168.10.0
[SW2-rip-1]net 192.168.20.0
[SW2-rip-1]net 192.168.30.0
[SW2-rip-1]net 192.168.40.0
[SW2-rip-1]net 11.0.0.0
[SW2-rip-1]q
实验结果
3、DHCP
R2
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sys R2
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.0.0.2 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip add 23.0.0.2 24
[R2-GigabitEthernet0/0/1]q
[R2]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[R2]ip pool 1
Info: It's successful to create an IP address pool.
[R2-ip-pool-1]gateway-list 192.168.100.1
[R2-ip-pool-1]network 192.168.100.0 mask 24
[R2-ip-pool-1]dns-list 8.8.8.8
[R2-ip-pool-1]q
[R2]int g0/0/1
[R2-GigabitEthernet0/0/1]dhcp select global
[R2-GigabitEthernet0/0/1]q
[R2]rip
[R2-rip-1]version 2
[R2-rip-1]un summary
[R2-rip-1]net 12.0.0.0
[R2-rip-1]net 23.0.0.0
[R2-rip-1]q
[R2]
R3
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]un in en
Info: Information center is disabled.
[Huawei]sys R3
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip add 23.0.0.1 24
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip add 192.168.100.1 24
[R3-GigabitEthernet0/0/1]int g0/0/2
[R3-GigabitEthernet0/0/2]ip add 192.168.200.1 24
[R3-GigabitEthernet0/0/2]un sh
Info: Interface GigabitEthernet0/0/2 is not shutdown.
[R3-GigabitEthernet0/0/2]q
[R3]dhcp en
Info: The operation may take a few seconds. Please wait for a moment.done.
[R3]int g0/0/1
[R3-GigabitEthernet0/0/1]dhcp select relay
[R3-GigabitEthernet0/0/1]dhcp relay server-ip 23.0.0.2
[R3-GigabitEthernet0/0/1]q
[R3]rip
[R3-rip-1]version 2
[R3-rip-1]un su
[R3-rip-1]net 23.0.0.0
[R3-rip-1]net 192.168.100.0
[R3-rip-1]net 192.168.200.0
[R3-rip-1]q
[R3]
实验结果
4、NAT
R1
[R1]acl 3000
[R1-acl-adv-3000]rule permit ip source 192.168.10.0 0.0.0.255
[R1-acl-adv-3000]int g0/0/2
[R1-GigabitEthernet0/0/2]nat outbound 3000
R2
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]nat server protocol tcp global current-interface 8080 i
nside 192.168.200.200 80
server1
client1
实验结果
5、所有终端能够网络互通
结果
PC2能够ping通PC3和PC4
PC4能够ping通PC5和Server1