如图:
配置如下:
[sw1]vlan batch 6 10 20
[sw1]int vlanif 10
[sw1-Vlanif10]ip add 192.168.10.250 24
[sw1-Vlanif10]vrrp vrid 10 virtual-ip 192.168.10.254
[sw1-Vlanif10]vrrp vrid 10 priority 200
[sw1-Vlanif10]int vlanif 20
[sw1-Vlanif20]ip add 192.168.20.250 24
[sw1-Vlanif20]vrrp vrid 20 virtual-ip 192.168.20.254
[sw1-Vlanif20]int g0/0/6
[sw1-GigabitEthernet0/0/6]port link access
[sw1-GigabitEthernet0/0/6]port default vlan 6
[sw1-GigabitEthernet0/0/6]q
[sw1]int vlanif 6
[sw1-Vlanif6]ip add 192.168.6.254 24
[sw1-Vlanif6]q
[sw1]int g0/0/13
[sw1-GigabitEthernet0/0/13]port link trunk
[sw1-GigabitEthernet0/0/13]port trunk allow-pass vlan all
[sw1-GigabitEthernet0/0/13]q
[sw1]vlan 11
[sw1-vlan11]q
[sw1]int vlanif 11
[sw1-Vlanif11]ip add 192.168.11.1 24
[sw1-Vlanif11]q
[sw1]int g0/0/1
[sw1-GigabitEthernet0/0/1]port link-ty access
[sw1-GigabitEthernet0/0/1]port default vlan 11
[sw1]ip route-static 88.1.1.0 24 192.168.11.2
[sw1]ip route-static 0.0.0.0 0 192.168.11.2
[sw2]vlan batch 6 10 20
[sw2]int vlanif 10
[sw2-Vlanif10]ip add 192.168.10.251 24
[sw2-Vlanif10]vrrp vrid 10 vi
[sw2-Vlanif10]vrrp vrid 10 virtual-ip 192.168.10.254
[sw2-Vlanif10]int vlanif 20
[sw2-Vlanif20]ip add 192.168.20.251 24
[sw2-Vlanif20]vrrp vrid 20 virtual-ip 192.168.20.254
[sw2-Vlanif20]vrrp vrid 20 priori
[sw2-Vlanif20]vrrp vrid 20 priority 200
[sw2-Vlanif20]q
[sw2]int g0/0/23
[sw2-GigabitEthernet0/0/23]port link-ty trunk
[sw2-GigabitEthernet0/0/23]port trunk allow-pass vlan all
[sw2-GigabitEthernet0/0/23]q
[sw2]vlan 12
[sw2-vlan12]q
[sw2]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link access
[sw2-GigabitEthernet0/0/2]port default vlan 12
[sw2-GigabitEthernet0/0/2]q
[sw2]ip route-static 88.1.1.0 24 192.168.12.2
[sw2]int vlanif 12
[sw2-Vlanif12]ip add 192.168.12.1 24
[sw2]ip route-static 0.0.0.0 0 192.168.12.2
[ar1]int g0/0/1
[ar1-GigabitEthernet0/0/1]ip add 192.168.11.2 24
[ar1-GigabitEthernet0/0/1]int g0/0/2
[ar1-GigabitEthernet0/0/2]ip add 192.168.12.2 24
[ar1-GigabitEthernet0/0/2]int g0/0/0
[ar1-GigabitEthernet0/0/0]ip add 88.1.1.1 24
[ar1-GigabitEthernet0/0/0]q
[ar1]ip route-static 0.0.0.0 0 88.1.1.2
[ar1]ip route-static 192.168.6.0 24 192.168.11.1
[ar1]ip route-static 192.168.10.0 24 192.168.11.1
[ar1]ip route-static 192.168.20.0 24 192.168.12.1
[ar1]int g0/0/0
[ar1-GigabitEthernet0/0/0]nat server pro
[ar1-GigabitEthernet0/0/0]nat server protocol tcp glo
[ar1-GigabitEthernet0/0/0]nat server protocol tcp global 88.1.1.3 21 inside 192.
168.6.6 21
[ar1-GigabitEthernet0/0/0]q
[ar1]int g0/0/0
[ar1-GigabitEthernet0/0/0]dis this
[V200R003C00]
interface GigabitEthernet0/0/0
ip address 88.1.1.1 255.255.255.0
nat server protocol tcp global 88.1.1.3 ftp inside 192.168.6.6
acl 2000
rule 5 permit source 192.168.10.0 0.0.0.255
rule 10 permit source 192.168.20.0 0.0.0.255
int g0/0/0
acl outbound 2000