2022年金砖国家技能大赛-IT网络系统管理(完整版)
1-网络构建部分
任务二:实现集团、北京数据中心、分公司、办事处的网络互联互通。
拓扑图:
2-项目实施:
一、完成模拟器组网,按照拓扑图搭建及命令,过程略。
二、完成交换部分配置:
IDC2北京区域交换机
sysname IDC2-sw
int l1
ip add 172.16.252.1 255.255.255.255
un shut
int g 1/0/2
port link-mode router
ip add 172.16.254.1 255.255.255.252
un shut
vlan 10
port g 1/0/5
int vlan 10
ip add 172.16.10.1 255.255.255.0
un shut
vlan 20
port g 1/0/6
int vlan 20
ip add 172.16.20.1 255.255.255.0
un shut
vlan 30
port g 1/0/4
int vlan 30
ip add 172.16.30.1 255.255.255.0
un shut
vlan 40
port g 1/0/7
int vlan 40
ip add 172.16.40.1 255.255.255.0
un shut
vlan 50
port g 1/0/8
int vlan 50
ip add 172.16.50.1 255.255.255.0
un shut
vlan 60
port g 1/0/9
int vlan 60
ip add 172.16.60.1 255.255.255.0
un shut
*/聚合组,二层,负载分担
int br 1
link-agg mode dynamic
int g 1/0/3
port link-agg group 1
int br 1
port link-type trunk
port trunk permit vlan 20 30 40 50
link-agg load-sharing mode destination-mac
*/mtu
int g 1/0/2
mtu 1500
*/冗余备份
int vlan 20
vrrp vrid 20 virtual-ip 172.16.20.1
vrrp vrid 20 priority 254
int vlan 30
vrrp vird 30 virtual-ip 172.16.30.1
vrrp vrid 30 priorityt 254
int vlan 40
vrrp vrid 40 virtual-ip 172.16.40.1
vrrp vrid 40 priority 254
int vlan 50
vrrp vrid 50 virtual-ip 172.16.50.1
vrrp vrid 50 priority 254
quit
*/指定vrrp互通口
track 20 int br 1
track 30 int br 1
track 40 int br 1
track 50 int br 1
*/QOS
acl adv 3001
rule 0 IP permit source 172.16.20.0 0.0.0.255
quit
traffic classifier chanpin
if-match acl 3001
quit
traffic behavior_chanpin
car cir 50000 cbs 625000 pir 100000 cbs 102500
quit
qos policy car_chanpin
classfilter chanpin behavior behavior_chanpin
quit
qos vlan-policy car_chanpin vlan 20 inbound
qos vlan-policy car_chanpin vlan 20 outbound
*/mac绑定
mac-address static 0014-222c-aa69 int g 1/0/4 vlan 30
mac-address blackhole 00a0-fc00-583c vlan 30
mac-address interval 300
mac-address infor mode syslog
int g 1/0/9
mac-address info enable
*/ntp
clock timezone beijin add 8
clock protocol ntp
ntp-service enable
ntp-service unicast-server 172.16.100.1
*/ospf
ospf 1 router-id 172.16.252.1
lsa-gen 5
lsa-arri15
area 0
network 172.16.252.1 0.0.0.0
network 172.16.254.1 0.0.0.0
network 172.16.10.0 0.0.0.255
IDC1北京区域交换机
sysname IDC1-sw
int l1
ip add 172.16.252.2 255.255.255.255
un shut
int g 1/0/1
port link-mode router
ip add 172.16.254.5 255.2555.255.252
un shut
int g 1/0/2
port link-mode router
ip add 172.16.254.2 255.255.255.252
un shut
vlan 10
port g 1/0/5
int vlan 10
ip add 172.16.10.2 255.255.255.0
un shut
vlan 20
port g 1/0/6
int vlan 20
ip add 172.16.20.2 255.255.255.0
un shut
vlan 40
port g 1/0/7
int vlan 40
ip add 172.16.40.2 255.255.255.0
un shut
vlan 50
port g 1/0/8
int vlan 50
ip add 172.16.50.2 255.255.255.0
un shut
vlan 60
port g 1/0/9
int vlan 60
ip add 172.16.60.2 255.255.255.0
un shut
*/聚合组
int br 1
link-agg mode dynamic
int g 1/0/3
port link-agg group 1
int br 1
port link-type trunk
port trunk permit vlan 20 30 40 50
link-agg load-sharing mode destination-mac
*/mtu
int g 1/0/2
mtu 1500
*/冗余备份
int vlan 20
vrrp vrid 20 virtual-ip 172.16.20.1
int vlan 30
vrrp vird 30 virtual-ip 172.16.30.1
int vlan 40
vrrp vrid 40 virtual-ip 172.16.40.1
int vlan 50
vrrp vrid 50 virtual-ip 172.16.50.1
quit
*/指定vrrp互通口
track 20 int br 1
track 30 int br 1
track 40 int br 1
track 50 int br 1
*/ntp
clock timezone beijin add 8
clock protocol ntp
ntp-service enable
ntp-service unicast-server 172.16.100.1
*/ospf
ospf 1 router-id 172.16.252.2
lsa-gen 5
lsa-arr 15
area 0
network 172.16.252.2 0.0.0.0
network 172.16.254.5 0.0.0.0
network 172.16.254.2 0.0.0.0
network 172.16.20.0 0.0.0.255
network 172.16.50.0 0.0.0.255
三、完成路由配置:
集团路由器
sysname JT-router
IP自行配置
*/ospf
ospf 1 router-id 172.16.252.3
lsa-gen 5
lsa-arr 15
import-router ospf 12
area 0
network 172.16.252.3 0.0.0.0
network 172.16.254.12 0.0.0.0
network 172.16.254.6 0.0.0.0
ospf 12 router-id 172.16.252.3
lsa-gen 5
lsa-arr 15
import-router ospf 1
area 20
network 172.16.254.9 0.0.0.0
network 172.16.254.0 0.0.0.3
network 172.16.252.0 0.0.0.0
分公司路由器
sysname FGS-router
配置ip加ospf,详情参考上述
四、完成防火墙配置:
办事处防火墙
sysname BSC-firewall
配置IP、trust域、可以使用web配置
此处请咨询作者