老王说网络:网络资源共享汇总
https://docs.qq.com/sheet/DWXZiSGxiaVhxYU1F
☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝☝
设计思路:
某校园网分为4栋大楼
分别为行政楼、教学楼、实验楼、宿舍楼
分为接入区,核心区域,和外联区
接入:vlan透传、MSTP+VRRP,接入用户都自动获取ip
核心:OSPF、MSTP+VRRP、链路聚合、DHCP、ACL
外联区:NAT、OSPF、NAT映射
访问的限制:
有线有线网络都可以访问外网和dmz的DNS服务器
…
网段规划:
Vlan 10 192.168.10.0/24 行政楼
Vlan 20 192.168.20.0/24m 教学楼
Vlan 30 192.168.30.0/24 实验楼
Vlan 40 192.168.40.0/24 宿舍楼
Vlan100 10.10.100.0/24 有线管理网段
Vlan101 10.10.101.0/24 Office无线网段
密码设定:
FW:admin/admin@123
AC:admin/admin@123
Office:Office12345
接入交换机SW01:
sysname SW01
vlan batch 2 to 150
stp region-configuration
region-name huawei
instance 1 vlan 10 20 100 to 102
instance 2 vlan 30 40
active region-configuration
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Ethernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 to 102
stp edged-port enable
interface Ethernet0/0/2
port link-type access
port default vlan 10
stp edged-port enable
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
接入交换机SW02:
sysname SW02
vlan batch 2 to 150
stp region-configuration
region-name huawei
instance 1 vlan 10 20 100 to 102
instance 2 vlan 30 40
active region-configuration
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Ethernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 to 102
stp edged-port enable
interface Ethernet0/0/2
port link-type access
port default vlan 20
stp edged-port enable
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
接入交换机SW03:
sysname SW03
vlan batch 2 to 150
stp region-configuration
region-name huawei
instance 1 vlan 10 20 100 to 102
instance 2 vlan 30 40
active region-configuration
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Ethernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 to 102
stp edged-port enable
interface Ethernet0/0/2
port link-type access
port default vlan 30
stp edged-port enable
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
接入交换机SW04:
sysname SW04
vlan batch 2 to 150
stp region-configuration
region-name huawei
instance 1 vlan 10 20 100 to 102
instance 2 vlan 30 40
active region-configuration
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Ethernet0/0/1
port link-type trunk
port trunk pvid vlan 100
port trunk allow-pass vlan 100 to 102
stp edged-port enable
interface Ethernet0/0/2
port link-type access
port default vlan 40
stp edged-port enable
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
核心交换机core01:
sysname CORE01
vlan batch 2 to 150
stp instance 0 root primary
stp instance 1 root primary
stp instance 2 root secondary
dhcp enable
stp region-configuration
region-name huawei
instance 1 vlan 10 20 100 to 102
instance 2 vlan 30 40
active region-configuration
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Vlanif10
ip address 192.168.10.253 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.10.254
vrrp vrid 10 priority 120
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif20
ip address 192.168.20.253 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.254
vrrp vrid 20 priority 120
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif30
ip address 192.168.30.252 255.255.255.0
vrrp vrid 30 virtual-ip 192.168.30.254
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif40
ip address 192.168.40.252 255.255.255.0
vrrp vrid 40 virtual-ip 192.168.40.254
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif50
ip address 192.168.50.1 255.255.255.252
interface Vlanif100
ip address 10.10.100.253 255.255.255.0
vrrp vrid 100 virtual-ip 10.10.100.254
vrrp vrid 100 priority 120
dhcp select interface
interface Vlanif101
ip address 10.10.101.253 255.255.255.0
vrrp vrid 101 virtual-ip 10.10.101.254
vrrp vrid 101 priority 120
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Eth-Trunk1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/3
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/4
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/5
port link-type access
port default vlan 50
interface GigabitEthernet0/0/7
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/23
eth-trunk 1
interface GigabitEthernet0/0/24
eth-trunk 1
ospf 1
area 0.0.0.0
network 192.168.10.253 0.0.0.0
network 192.168.20.253 0.0.0.0
network 192.168.30.253 0.0.0.0
network 192.168.40.253 0.0.0.0
network 10.10.100.253 0.0.0.0
network 10.10.101.253 0.0.0.0
network 192.168.50.1 0.0.0.0
traffic-filter inbound acl 3000
核心交换机core02:
sysname CORE02
vlan batch 2 to 150
stp instance 0 root secondary
stp instance 1 root secondary
stp instance 2 root primary
dhcp enable
stp region-configuration
region-name huawei
instance 1 vlan 10 20 100 to 102
instance 2 vlan 30 40
active region-configuration
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Vlanif10
ip address 192.168.10.252 255.255.255.0
vrrp vrid 10 virtual-ip 192.168.10.254
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif20
ip address 192.168.20.252 255.255.255.0
vrrp vrid 20 virtual-ip 192.168.20.254
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif30
ip address 192.168.30.253 255.255.255.0
vrrp vrid 30 virtual-ip 192.168.30.254
vrrp vrid 30 priority 120
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif40
ip address 192.168.40.253 255.255.255.0
vrrp vrid 40 virtual-ip 192.168.40.254
vrrp vrid 40 priority 120
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Vlanif60
ip address 192.168.60.1 255.255.255.252
interface Vlanif100
ip address 10.10.100.252 255.255.255.0
vrrp vrid 100 virtual-ip 10.10.100.254
dhcp select interface
interface Vlanif101
ip address 10.10.101.252 255.255.255.0
vrrp vrid 101 virtual-ip 10.10.101.254
dhcp select interface
dhcp server dns-list 192.168.100.100 114.114.114.114
interface Eth-Trunk1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/3
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/4
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/5
port link-type trunk
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/7
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/23
eth-trunk 1
interface GigabitEthernet0/0/24
eth-trunk 1
ospf 1
area 0.0.0.0
network 0.0.0.0 255.255.255.255
到这里我们的交换机部分配置完成了!
无线控制器AC:
无线都是采用DHCP上线到无线控制器上的,比较简单方便
sysname AC
vlan batch 2 to 150
aaa
local-user admin password admin@123
local-user admin privilege level 15
local-user admin service-type http
interface Vlanif1
ip address 192.168.2.1 255.255.255.0
interface Vlanif100
ip address 10.10.100.1 255.255.255.0
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
ip route-static 0.0.0.0 0.0.0.0 10.10.100.254
capwap source interface vlanif100
wlan
traffic-profile name default
security-profile name Office
security wpa-wpa2 psk pass-phrase Office12345
ssid-profile name Office
ssid Office
vap-profile name Office
service-vlan vlan-id 101
ssid-profile Office
security-profile Office
serial-profile name preset-enjoyor-toeap
ap auth-mode no-auth
ap-group name default
radio 0
vap-profile Office wlan 1
radio 1
vap-profile Office wlan 1
radio 2
vap-profile Office wlan 1
ap-id 0 type-id 69 ap-mac 00e0-fc1c-4710 ap-sn 210235448310C05E827F
ap-id 1 type-id 69 ap-mac 00e0-fcc8-4c10 ap-sn 2102354483100B01047D
ap-id 2 type-id 69 ap-mac 00e0-fc7a-5f60 ap-sn 210235448310C254C64F
ap-id 3 type-id 69 ap-mac 00e0-fcd1-39a0 ap-sn 21023544831084215E48
provision-ap
防火墙FW1:
sysname FW1
ip address-set wired type object
address 0 192.168.10.0 mask 24
address 1 192.168.20.0 mask 24
address 2 192.168.30.0 mask 24
address 3 192.168.40.0 mask 24
ip address-set wlan type object
address 0 10.10.101.0 mask 24
address 1 10.10.102.0 mask 24
ip address-set 192.168.40.0/24 type object
address 0 192.168.40.0 mask 24
ip address-set 192.168.100.100/32 type object
address 0 192.168.100.100 mask 32
aaa
manager-user admin
password simple admin@123
service-type web terminal
level 15
interface GigabitEthernet0/0/0
undo shutdown
ip binding vpn-instance default
ip address 192.168.0.10 255.255.255.0
alias GE0/METH
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
interface GigabitEthernet1/0/0
undo shutdown
ip address 192.168.100.1 255.255.255.0
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
interface GigabitEthernet1/0/1
undo shutdown
ip address 192.168.50.2 255.255.255.252
service-manage ping permit
interface GigabitEthernet1/0/2
undo shutdown
ip address 192.168.60.2 255.255.255.252
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
interface GigabitEthernet1/0/4
undo shutdown
ip address 1.1.1.1 255.255.255.0
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
destination-nat address-group nat-http 0
section 1.1.1.1 1.1.1.1
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
add interface GigabitEthernet1/0/1
add interface GigabitEthernet1/0/2
firewall zone untrust
set priority 5
add interface GigabitEthernet1/0/4
firewall zone dmz
set priority 50
add interface GigabitEthernet1/0/0
ospf 1
default-route-advertise always
area 0.0.0.0
network 192.168.50.2 0.0.0.0
network 192.168.60.2 0.0.0.0
network 192.168.100.1 0.0.0.0
ip route-static 0.0.0.0 0.0.0.0 1.1.1.2
security-policy
rule name 1
action permit
nat-policy
rule name nat
source-zone untrust
destination-address address-set 192.168.100.100/32
service http
action destination-nat static port-to-port address-group nat-http 8282
rule name to-internet
source-zone trust
destination-zone untrust
source-address address-set wired
source-address address-set wlan
action source-nat easy-ip
nat server server global 1.1.1.3 inside 192.168.100.99 no-reverse
nat server server1 global 1.1.1.4 inside 192.168.100.101 no-reverse
DNS服务器配置截图:
FTp服务器配置截图:
HTTP服务器配置截图:
Clinent配置截图:
功能测试截图略