实验思路:
路由器配置ip地址
启动DHCP相关配置,确保PC可以自动获取IP地址
启动ospf
定制acl
相关配置命令
R1
sysname 1
dhcp enable
acl number 3000
rule 5 deny icmp source 192.168.1.29 0 destination 192.168.1.94 0 icmp-type echo
ip pool 1
gateway-list 192.168.1.1
network 192.168.1.0 mask 255.255.255.224
dns-list 114.114.114.114
aaa
local-user admin password cipher %
%
K8m.Nt84DZ}e#<0`8bmE3Uw}%
%
local-user admin service-type http
interface GigabitEthernet0/0/0
ip address 192.168.1.1 255.255.255.224
traffic-filter outbound acl 3000
dhcp select global
interface GigabitEthernet0/0/1
ip address 192.168.1.33 255.255.255.224
ospf 1 router-id 1.1.1.1
area 0.0.0.0
network 1.1.1.1 0.0.0.0
network 192.168.1.0 0.0.0.255
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
R2
sysname 2
dhcp enable
ip pool 2
gateway-list 192.168.1.65
network 192.168.1.64 mask 255.255.255.224
dns-list 114.114.114.114
aaa
local-user admin password cipher %
%
K8m.Nt84DZ}e#<0`8bmE3Uw}%
%
local-user admin service-type http
interface GigabitEthernet0/0/0
ip address 192.168.1.34 255.255.255.224
interface GigabitEthernet0/0/1
ip address 192.168.1.65 255.255.255.224
dhcp select global
interface GigabitEthernet0/0/2
ip address 192.168.1.97 255.255.255.224
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 2.2.2.2 0.0.0.0
network 192.168.1.0 0.0.0.255
R3
sysname 3
dhcp enable
acl number 3000
rule 5 deny ip source 192.168.1.30 0 destination 192.168.1.157 0
rule 10 deny icmp source 192.168.1.33 0 destination 192.168.1.98 0
ip pool 3
gateway-list 192.168.1.129
network 192.168.1.128 mask 255.255.255.224
dns-list 114.114.114.114
aaa
local-user 123 password cipher %
%
D;:wL)858QD\LPBXLxRBb;};%
%
local-user 123 privilege level 15
local-user 123 service-type telnet
local-user admin password cipher %
%
K8m.Nt84DZ}e#<0`8bmE3Uw}%
%
local-user admin service-type http
interface GigabitEthernet0/0/0
ip address 192.168.1.129 255.255.255.224
dhcp select global
interface GigabitEthernet0/0/1
ip address 192.168.1.98 255.255.255.224
traffic-filter inbound acl 3000
interface GigabitEthernet0/0/2
interface NULL0
ospf 1 router-id 3.3.3.3
area 0.0.0.0
network 3.3.3.3 0.0.0.0
network 192.168.1.0 0.0.0.255
pc1不能ping通pc6,可以ping通pc5
r1可以Telnet登录r3,但不能ping通r3
pc2不能ping通pc3,但pc3可以ping通pc2