1、 拓扑设计----地址规划
2、 拓扑搭建
3、 项目实施
(1)配ip
1)划分vlan
[sw1]vlan batch 2 to 3
[sw1]port-group group-member g0/0/1 to g0/0/2
[sw1-port-group]port link-type access
[sw1-port-group]port default vlan 2
[sw1]int g0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 3
[sw2]vlan batch 2 to 3
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type access
[sw2-GigabitEthernet0/0/1]port default vlan 2
[sw2-GigabitEthernet0/0/1]int g0/0/2
[sw2-GigabitEthernet0/0/2]port link-type access
[sw2-GigabitEthernet0/0/2]port default vlan 3
2)trunk干道
[sw1]int g0/0/4
[sw1-GigabitEthernet0/0/4]port link-type trunk
[sw1-GigabitEthernet0/0/4]port trunk allow-pass vlan all
[sw2]int g0/0/4
[sw2-GigabitEthernet0/0/4]port link-type trunk
[sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan all
3)给路由器配ip及创建子接口
[r1]int g0/0/1
[r1-GigabitEthernet0/0/1]ip address 192.168.1.1 30
[r2]int g0/0/0
[r2-GigabitEthernet0/0/0]ip address 192.168.1.2 30
[r2-GigabitEthernet0/0/1]ip address 12.1.1.1 24
[r3]int g0/0/0
[r3-GigabitEthernet0/0/0]ip address 12.1.1.2 24
[r3-GigabitEthernet0/0/0]int g0/0/2
[r3-GigabitEthernet0/0/2]ip address 1.1.1.1 24
子接口:
[r1]int g0/0/2.1
[r1-GigabitEthernet0/0/2.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/2.1]arp broadcast enable
[r1-GigabitEthernet0/0/2.1]ip address 192.168.1.65 27
[r1]int g0/0/2.2
[r1-GigabitEthernet0/0/2.2]dot1q termination vid 3
[r1-GigabitEthernet0/0/2.2]arp broadcast enable
[r1-GigabitEthernet0/0/2.2]ip address 192.168.1.97 27
[r2-GigabitEthernet0/0/0]int g0/0/2.1
[r2-GigabitEthernet0/0/2.1]dot1q termination vid 2
[r2-GigabitEthernet0/0/2.1]arp broadcast enable
[r2-GigabitEthernet0/0/2.1]ip address 192.168.1.129 27
[r2-GigabitEthernet0/0/2.1]int g0/0/2.2
[r2-GigabitEthernet0/0/2.2]dot1q termination vid 3
[r2-GigabitEthernet0/0/2.2]arp broadcast enable
[r2-GigabitEthernet0/0/2.2]ip address 192.168.1.161 27
4)使用dhcp自动获取ip
[r1]dhcp enable
[r1]ip pool vlan2
[r1-ip-pool-vlan2]network 192.168.1.64 mask 255.255.255.224
[r1-ip-pool-vlan2]gateway-list 192.168.1.65
[r1-ip-pool-vlan2]dns-list 114.114.114.114
[r1]ip pool vlan3
[r1-ip-pool-vlan3]network 192.168.1.96 mask 255.255.255.224
[r1-ip-pool-vlan3]gateway-list 192.168.1.97
[r1-ip-pool-vlan3]dns-list 114.114.114.114
[r1]int g0/0/2.1
[r1-GigabitEthernet0/0/2.1]dhcp select global
[r1-GigabitEthernet0/0/2.1]int g0/0/2.2
[r1-GigabitEthernet0/0/2.2]dhcp select global
[r2]dhcp enable
[r2]ip pool vlan2
[r2-ip-pool-vlan2]network 192.168.1.128 mask 255.255.255.224
[r2-ip-pool-vlan2]gateway-list 192.168.1.129
[r2-ip-pool-vlan2]dns-list 114.114.114.114
[r2]ip pool vlan3
[r2-ip-pool-vlan3]network 192.168.1.160 mask 255.255.255.224
[r2-ip-pool-vlan3]gateway-list 192.168.1.161
[r2-ip-pool-vlan3]dns-list 114.114.114.114
[r2]int g0/0/2.1
[r2-GigabitEthernet0/0/2.1]dhcp select global
[r2-GigabitEthernet0/0/2.1]int g0/0/2.2
[r2-GigabitEthernet0/0/2.2]dhcp select global
[pc1-GigabitEthernet0/0/0]ip address dhcp-alloc 把路由器当PC用,自动获取ip
(2)R1/2之间启ospf
中间网段为区域0,两路由器接口下面为区域1 2
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.1 0.0.0.0
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]network 192.168.1.65 0.0.0.0
[r1-ospf-1-area-0.0.0.1]network 192.168.1.97 0.0.0.0
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 192.168.1.2 0.0.0.0
[r2-ospf-1]area 2
[r2-ospf-1-area-0.0.0.2]network 192.168.1.129 0.0.0.0
[r2-ospf-1-area-0.0.0.2]network 192.168.1.161 0.0.0.0
做两个沉默接口:
[r2-ospf-1]silent-interface GigabitEthernet 0/0/2.1
[r2-ospf-1]silent-interface GigabitEthernet0/0/2.2
[r1-ospf-1]silent-interface g0/0/2.1
[r1-ospf-1]silent-interface g0/0/2.2
手工认证:
[r1-GigabitEthernet0/0/1]ospf authentication-mode md5 1 cipher 123456
[r2-GigabitEthernet0/0/0]ospf authentication-mode md5 1 cipher 123456
路由汇总:
[r1-ospf-1-area-0.0.0.0]abr-summary 192.168.1.64 255.255.255.192
[r2-ospf-1-area-0.0.0.2]abr-summary 192.168.1.128 255.255.255.192
(3)做telnet
R1:
[r1]aaa
[r1-aaa]local-user olx password cipher 123
[r1-aaa]local-user olx service-type telnet
[r1-aaa]local-user olx privilege level 15
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mode aaa
[r1]acl 3000
[r1-acl-adv-3000]rule deny tcp source 192.168.1.93 0 destination 192.168.1.65 0 destination-port eq 23
[r1-acl-adv-3000]rule deny tcp source 192.168.1.93 0 destination 192.168.1.97 0 destination-port eq 23
[r1-acl-adv-3000]rule deny tcp source 192.168.1.93 0 destination 192.168.1.1 0 destination-port eq 23
[r1-GigabitEthernet0/0/2.1]traffic-filter inbound acl 3000
(4)内网pc访问公网中的pc5
[r2]ospf 1
[r2-ospf-1]default-route-advertise always ospf边界路由器做个缺省
[r2]ip route-static 0.0.0.0 0 12.1.1.2 边界路由器自己要有缺省
1)做nat
[r2]acl 2000
[r2-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[r2-acl-basic-2000]q
[r2]int g0/0/1
[r2-GigabitEthernet0/0/1]nat outbound 2000
(5)做端口映射完成7、8问
[r2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 80 inside 192.168.1.100 80
Warning:The port 80 is well-known
port. If you continue it may cause function failure.
Are you sure to continue?[Y/N]:y
[r2-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 23 inside 192.168.1.1 23
Warning:The port 23 is well-known
port. If you continue it may cause function failure.
Are you sure to continue?[Y/N]:y
最后要在R1和R2上做两个空接口,避免环路