2023年网络系统管理-A模块-样题1
topo如下
地址规划
#S1
en
admin1234
admin1234
conf t
no int vlan 1
ho S1
vlan 10
name CAIWU
vlan 20
name XIAOSHOU
vlan 30
name YANFA
vlan 40
name SHICHANG
vlan 50
name AP
vlan 60
name Wireless
vlan 100
name Manage
int vlan 100
ip add 192.1.100.1/24
#S3
en
admin1234
admin1234
conf t
no int vlan 1
ho S3
vlan 10
name CAIWU
vlan 20
name XIAOSHOU
vlan 30
name YANFA
vlan 40
name SHICHANG
vlan 50
name AP
vlan 60
name Wireless
vlan 100
name Manage
int vlan 100
ip add 192.1.100.252/24
int vlan 10
ip add 192.1.10.252/24
int vlan 20
ip add 192.1.20.252/24
int vlan 30
ip add 192.1.30.252/24
int vlan 40
ip add 192.1.40.252/24
int vlan 50
ip add 192.1.50.252/24
int vlan 60
ip add 192.1.60.252/24
int g0/24
no sw
ip add 10.1.0.1/30
int loo 0
ip add 11.1.0.33/32
#S4
en
admin1234
admin1234
conf t
no int vlan 1
ho S4
vlan 10
name CAIWU
vlan 20
name XIAOSHOU
vlan 30
name YANFA
vlan 40
name SHICHANG
vlan 50
name AP
vlan 60
name Wireless
vlan 100
name Manage
int vlan 100
ip add 192.1.100.253/24
int vlan 10
ip add 192.1.10.253/24
int vlan 20
ip add 192.1.20.253/24
int vlan 30
ip add 192.1.30.253/24
int vlan 40
ip add 192.1.40.253/24
int vlan 50
ip add 192.1.50.253/24
int vlan 60
ip add 192.1.60.253/24
int g0/24
no sw
ip add 10.1.0.5/30
int loo 0
ip add 11.1.0.34/32
#AC1
en
conf t
ho AC1
vlan 100
name Manage
int loo 0
ip add 11.1.0.204/32
int vlan 100
ip add 194.1.100.2/24
#AC2
en
conf t
ho AC2
vlan 100
name Manage
int loo 0
ip add 11.1.0.205/32
int vlan 100
ip add 194.1.100.3/24
#S5
en
admin1234
admin1234
conf t
ho S5
vlan 100
name Manage
int vlan 100
ip add 194.1.100.254/24
int g0/24
no sw
ip add 40.1.0.1/30
int loo 0
ip add 11.1.0.5/32
#EG1
en
conf t
ho EG1
int g0/0
ip add 10.1.0.2 255.255.255.252
int g0/1
ip add 10.1.0.6 255.255.255.252
int g0/4
ip add 20.1.0.1 255.255.255.252
int loo 0
ip add 11.1.0.11 255.255.255.255
exit
specify interface gigabitEthernet 0/4 wan
end
write
reload
y
!
#EG2
en
conf t
ho EG2
int g0/0
ip add 10.1.0.14 255.255.255.252
int g0/1
ip add 10.1.0.18 255.255.255.252
int g0/4
ip add 30.1.0.1 255.255.255.252
int loo 0
ip add 11.1.0.12 255.255.255.255
exit
specify interface gigabitEthernet 0/4 wan
end
write
reload
y
!
#R1
en
conf t
ho R1
int g0/0
ip add 20.1.0.2 255.255.255.252
int g0/1
ip add 12.1.0.1 255.255.255.240
int g0/2
ip add 13.1.0.1 255.255.255.240
int loo 0
ip add 11.1.0.1 255.255.255.255
#R2
en
conf t
ho R2
int g0/0
ip add 30.1.0.2 255.255.255.252
int g0/1
ip add 12.1.0.2 255.255.255.240
int g0/2
ip add 23.1.0.2 255.255.255.240
int loo 0
ip add 11.1.0.2 255.255.255.255
#R3
en
conf t
ho R3
int g0/0
ip add 40.1.0.2 255.255.255.252
int g0/1
ip add 13.1.0.3 255.255.255.240
int g0/2
ip add 23.1.0.3 255.255.255.240
int loo 0
ip add 11.1.0.3 255.255.255.255
#S7
en
admin1234
admin1234
conf t
ho S7
no int vlan 1
vlan 10
name CAIWU
vlan 20
name XIAOSHOU
vlan 30
name YANFA
vlan 40
name SHICHANG
vlan 50
name AP
vlan 60
name Wireless
vlan 100
name Manage
int vlan 100
ip add 193.1.100.254/24
int vlan 10
ip add 193.1.10.254/24
int vlan 20
ip add 193.1.20.254/24
int vlan 30
ip add 193.1.30.254/24
int vlan 40
ip add 193.1.40.254/24
int vlan 50
ip add 193.1.50.254/24
int vlan 60
ip add 193.1.60.254/24
int g0/24
no sw
ip add 10.1.0.17/30
int loo 0
ip add 11.1.0.67/32
有线部分
端口ACCES划分
#S1
int r g0/1-4
sw mo ac
sw ac vlan 10
int r g0/5-8
sw mo ac
sw ac vlan 20
int r g0/9-12
sw mo ac
sw ac vlan 30
int r g0/13-16
sw mo ac
sw ac vlan 40
trunk修剪
#S3/S4
int r g0/21-22
port-group 1 mode active
int ag 1
sw mo tr
sw tr native vlan 100
sw tr all vlan on 10,20,30,40,50,60,100
int range g0/1,0/24
sw mo tr
sw tr native vlan 100
sw tr all vlan on 10,20,30,40,50,60,100
exit
#S1
int range g0/23-24
sw mo tr
sw tr native vlan 100
sw tr all vlan on 10,20,30,40,50,60,100
exit
int range g0/21-22
sw mo tr
sw tr na vlan 50
sw tr all vlan on 50,60
exit
#S5
int r g0/1-2
sw mo tr
sw tr nat vlan 100
sw tr all vlan on 100
#AC1/AC2
int g0/1
sw mo tr
sw tr na vlan 100
sw tr all vlan on 100
#S7
int g0/23
sw mo tr
sw tr na vlan 50
sw tr all vlan on 50,60
MST
#S3
span en
span mo mst
span mst conf
name test
rev 1
ins 1 vlan 10,20,50,60,100
ins 2 vlan 30,40
exit
span mst 1 pri 4096
span mst 2 pri 8192
#S4
span
span mo mst
span mst conf
name test
rev 1
ins 1 vlan 10,20,50,60,100
ins 2 vlan 30,40
exit
span mst 1 pri 8192
span mst 2 pri 4096
#S1
span
span mo mst
span mst conf
name test
rev 1
ins 1 vlan 10,20,50,60,100
ins 2 vlan 30,40
VRRP
#S3
int vlan 10
vrrp 10 ip 192.1.10.254
vrrp 10 pri 150
int vlan 20
vrrp 20 ip 192.1.20.254
vrrp 20 pri 150
int vlan 30
vrrp 30 ip 192.1.30.254
vrrp 30 pri 120
int vlan 40
vrrp 40 ip 192.1.40.254
vrrp 40 pri 120
int vlan 50
vrrp 50 ip 192.1.50.254
vrrp 50 pri 150
int vlan 60
vrrp 60 ip 192.1.60.254
vrrp 60 pri 150
int vlan 100
vrrp 100 ip 192.1.100.254
vrrp 100 pri 150
#S4
int vlan 10
vrrp 10 ip 192.1.10.254
vrrp 10 pri 120
int vlan 20
vrrp 20 ip 192.1.20.254
vrrp 20 pri 120
int vlan 30
vrrp 30 ip 192.1.30.254
vrrp 30 pri 150
int vlan 40
vrrp 40 ip 192.1.40.254
vrrp 40 pri 150
int vlan 50
vrrp 50 ip 192.1.50.254
vrrp 50 pri 120
int vlan 60
vrrp 60 ip 192.1.60.254
vrrp 60 pri 120
int vlan 100
vrrp 100 ip 192.1.100.254
vrrp 100 pri 120
OSPF
#S3
router ospf 10
net 10.1.0.0 0.0.0.3 a 0
redis conn metric-ty 1 sub
exit
int g0/24
ip ospf net point-to-point
#S4
router ospf 10
net 10.1.0.4 0.0.0.3 a 0
redis conn metric-ty 1 sub
exit
int g0/24
ip ospf net point-to-point
#EG1
router ospf 10
net 10.1.0.0 0.0.0.3 a 0
net 10.1.0.4 0.0.0.3 a 0
redis conn metric-ty 1 sub
default-information originate always metric-type 1
exit
int r g0/0-1
ip ospf net point-to-point
#S7
router ospf
net 10.1.0.16 0.0.0.3 a 0
redis conn metric-ty 1 sub
int g0/24
ip ospf net point-to-point
#EG2
router ospf
net 10.1.0.12 0.0.0.3 a 0
net 10.1.0.16 0.0.0.3 a 0
redis conn metric-ty 1 sub
default-information originate always metric-type 1
int g0/1
ip ospf net point-to-point
服务器区静态路由
#AC1/AC2
ip route 0.0.0.0 0.0.0.0 194.1.100.254
#S5
ip route 0.0.0.0 0.0.0.0 40.1.0.2
ip route 11.1.0.204 255.255.255.255 194.1.100.2
ip route 11.1.0.205 255.255.255.255 194.1.100.3
VRRPv6
#S3
int vlan 10
ipv6 enable
ipv6 add 2001:192:10::252/64
int vlan 20
ipv6 enable
ipv6 add 2001:192:20::252/64
int vlan 30
ipv6 enable
ipv6 add 2001:192:30::252/64
int vlan 40
ipv6 enable
ipv6 add 2001:192:40::252/64
int vlan 50
ipv6 enable
ipv6 add 2001:192:50::252/64
int vlan 60
ipv6 enable
ipv6 add 2001:192:60::252/64
int vlan 100
ipv6 enable
ipv6 add 2001:192:100::252/64
#S4
int vlan 10
ipv6 enable
ipv6 add 2001:192:10::253/64
int vlan 20
ipv6 enable
ipv6 add 2001:192:20::253/64
int vlan 30
ipv6 enable
ipv6 add 2001:192:30::253/64
int vlan 40
ipv6 enable
ipv6 add 2001:192:40::253/64
int vlan 50
ipv6 enable
ipv6 add 2001:192:50::253/64
int vlan 60
ipv6 enable
ipv6 add 2001:192:60::253/64
int vlan 100
ipv6 enable
ipv6 add 2001:192:100::253/64
#S3
int vlan 10
vrrp 10 ipv6 fe80::1
vrrp 10 ipv6 2001:192:10::254
vrrp ipv6 10 pri 150
vrrp ipv6 10 accept_mode
int vlan 20
vrrp 20 ipv6 fe80::1
vrrp 20 ipv6 2001:192:20::254
vrrp ipv6 20 pri 150
vrrp ipv6 20 accept_mode
int vlan 30
vrrp 30 ipv6 fe80::1
vrrp 30 ipv6 2001:192:30::254
vrrp ipv6 30 pri 120
vrrp ipv6 30 accept_mode
int vlan 40
vrrp 40 ipv6 fe80::1
vrrp 40 ipv6 2001:192:40::254
vrrp ipv6 40 pri 120
vrrp ipv6 40 accept_mode
int vlan 50
vrrp 50 ipv6 fe80::1
vrrp 50 ipv6 2001:192:50::254
vrrp ipv6 50 pri 150
vrrp ipv6 50 accept_mode
int vlan 60
vrrp 60 ipv6 fe80::1
vrrp 60 ipv6 2001:192:60::254
vrrp ipv6 60 pri 150
vrrp ipv6 60 accept_mode
int vlan 100
vrrp 100 ipv6 fe80::1
vrrp 100 ipv6 2001:192:100::254
vrrp ipv6 100 pri 150
vrrp ipv6 100 accept_mode
#S4
int vlan 10
vrrp 10 ipv6 fe80::1
vrrp 10 ipv6 2001:192:10::254
vrrp ipv6 10 pri 120
vrrp ipv6 10 accept_mode
int vlan 20
vrrp 20 ipv6 fe80::1
vrrp 20 ipv6 2001:192:20::254
vrrp ipv6 20 pri 120
vrrp ipv6 20 accept_mode
int vlan 30
vrrp 30 ipv6 fe80::1
vrrp 30 ipv6 2001:192:30::254
vrrp ipv6 30 pri 150
vrrp ipv6 30 accept_mode
int vlan 40
vrrp 40 ipv6 fe80::1
vrrp 40 ipv6 2001:192:40::254
vrrp ipv6 40 pri 150
vrrp ipv6 40 accept_mode
int vlan 50
vrrp 50 ipv6 fe80::1
vrrp 50 ipv6 2001:192:50::254
vrrp ipv6 50 pri 120
vrrp ipv6 50 accept_mode
int vlan 60
vrrp 60 ipv6 fe80::1
vrrp 60 ipv6 2001:192:60::254
vrrp ipv6 60 pri 120
vrrp ipv6 60 accept_mode
int vlan 100
vrrp 100 ipv6 fe80::1
vrrp 100 ipv6 2001:192:100::254
vrrp ipv6 100 pri 120
vrrp ipv6 100 accept_mode
互联网区域IGP互联
#R1
router ospf 20
net 12.1.0.0 0.0.0.15 a 0
net 13.1.0.0 0.0.0.15 a 0
net 11.1.0.1 0.0.0.0 a 0
int r g0/0-2
ip ospf net point-to-point
#R2
router ospf 20
net 12.1.0.0 0.0.0.15 a 0
net 23.1.0.0 0.0.0.15 a 0
net 11.1.0.2 0.0.0.0 a 0
int r g0/0-2
ip ospf net point-to-point
#R3
router ospf 20
net 13.1.0.0 0.0.0.15 a 0
net 23.1.0.0 0.0.0.15 a 0
net 11.1.0.3 0.0.0.0 a 0
int r g0/0-2
ip ospf net point-to-point
IBGP部署
#R1
ip route 20.1.0.0 255.255.0.0 null 0
router bgp 100
nei 11.1.0.2 remote-as 100
nei 11.1.0.3 remote-as 100
nei 11.1.0.2 up loo 0
nei 11.1.0.3 up loo 0
nei 11.1.0.2 next-hop-self
nei 11.1.0.3 next-hop-self
redis static
#R2
ip route 30.1.0.0 255.255.0.0 null 0
router bgp 100
nei 11.1.0.1 remote-as 100
nei 11.1.0.3 remote-as 100
nei 11.1.0.1 up loo 0
nei 11.1.0.3 up loo 0
nei 11.1.0.1 next-hop-self
nei 11.1.0.3 next-hop-self
redis static
#R3
ip route 11.1.0.204 255.255.255.255 40.1.0.1
ip route 11.1.0.205 255.255.255.255 40.1.0.1
ip route 40.1.0.0 255.255.0.0 null 0
router bgp 100
nei 11.1.0.1 remote-as 100
nei 11.1.0.2 remote-as 100
nei 11.1.0.1 up loo 0
nei 11.1.0.2 up loo 0
nei 11.1.0.1 next-hop-self
nei 11.1.0.2 next-hop-self
network 11.1.0.204 mask 255.255.255.255
network 11.1.0.205 mask 255.255.255.255
network 40.1.0.0 mask 255.255.0.0
为隔离部分终端用户间的二层互访,在交换机S1的Gi0/1-Gi0/10端口启用端口保护。
#S1
int r g0/1-10
sw protect
终端设备防环处理
#S1
int g0/1
spanning-tree portfast
spanning-tree bpduguard enable
exit
rldp enable
rldp port loop-detect shutdown-port
errdisable recovery interval 300
DHCP Relay
#S3/S4
service dhcp
ip helper-address 11.1.0.11
DHCP
#EG1
service dhcp
ip dhcp pool Pool_VLAN10
network 192.1.10.0 255.255.255.0
default-router 192.1.10.254
exit
DHCO Snooping
#S1
ip dhcp snooping
int r g0/23-24
ip dhcp snooping trust
出口网关配置
PAT
#EG1
int g0/0
ip nat inside
int g0/1
ip nat inside
int g0/4
ip nat outside
ip acc ex 110
permit ip 192.1.0.0 0.0.255.255 any
5 deny ip 192.1.0.0 0.0.255.255 193.1.0.0 0.0.255.255
exit
ip nat pool Pool_test prefix-length 24
address interface g0/4 match interface g0/4
ip nat inside source list 110 pool Pool_test overload
no ip nat inside source list 1 pool nat_pool overload
ip route 0.0.0.0 0.0.0.0 20.1.0.2
#EG2
int g0/0
ip nat inside
int g0/1
ip nat inside
int g0/4
ip nat outside
ip acc ex 110
permit ip 193.1.0.0 0.0.255.255 any
5 deny ip 193.1.0.0 0.0.255.255 192.1.0.0 0.0.255.255
exit
ip nat pool Pool_test prefix-length 24
address interface g0/4 match interface g0/4
ip nat inside source list 110 pool Pool_test overload
no ip nat inside source list 1 pool nat_pool overload
ip route 0.0.0.0 0.0.0.0 30.1.0.2
端口映射
ip nat inside source static tcp 11.1.0.34 22 20.1.0.1 22
IPSec
#EG1
acc 101 permit ip 192.1.0.0 0.0.255.255 193.1.0.0 0.0.255.255
cry isa poli 10
enc 3d
hash md5
auth pre
group 2
cryp isa key 0 123456 add 30.1.0.1
cry ipsec tran myset esp-3d esp-md5-h
exit
cry map mymap 10 ipsec-is
set peer 30.1.0.1
set tran myset
match add 101
exit
int g0/4
cry map mymap
#EG2
acc 101 permit ip 193.1.0.0 0.0.255.255 192.1.0.0 0.0.255.255
cry isa poli 10
enc 3d
hash md5
auth pre
group 2
exit
cryp isa key 0 123456 add 20.1.0.1
cry ipsec tran myset esp-3d esp-md5-h
exit
cry map mymap 10 ipsec-is
set peer 20.1.0.1
set tran myset
match add 101
exit
int g0/4
cry map mymap
无线网络配置
DHCP
#S3
server dhcp
ip dhcp pool Wireless
netw 192.1.60.0 255.255.255.0
default-router 192.1.60.254
exit
ip dhcp pool AP
netw 192.1.50.0 255.255.255.0
default-route 192.1.50.254
option 138 ip 11.1.0.204 11.1.0.208
#S7
server dhcp
ip dhcp pool Wireless
netw 193.1.60.0 255.255.255.0
default-router 193.1.60.254
exit
ip dhcp pool AP
netw 193.1.50.0 255.255.255.0
default-route 193.1.50.254
option 138 ip 11.1.0.204 11.1.0.208
配置Wlan-config、热备份
#AC1/AC2
show ap-config sum
AC1(config)#show ap-config summary
========= show ap status =========
Radio: Radio ID or Band: 2.4G = 1#, 5G = 2#
E = enabled, D = disabled, N = Not exist, V = Virtual AP
Current Sta number
Channel: * = Global
Power Level = Percent
Online AP number: 2
Offline AP number: 0
AP Name IP Address Mac Address Radio Radio Up/Off time State
---------------------------------------- --------------- -------------- ------------------- ------------------- ------------- -----
AP1 192.1.50.1 300d.9e8a.37c2 1 E 1 1* 100 2 E 0 157* 100 0:17:57:18 Run
3 E 0 44* 100 4 N - - -
AP2 192.1.50.2 300d.9e8a.3782 1 E 0 1* 100 2 E 0 149* 100 0:17:57:16 Run
3 E 1 36* 100 4 N - - -
AC2#show ap-config summary
========= show ap status =========
Radio: Radio ID or Band: 2.4G = 1#, 5G = 2#
E = enabled, D = disabled, N = Not exist, V = Virtual AP
Current Sta number
Channel: * = Global
Power Level = Percent
Online AP number: 1
Offline AP number: 0
AP Name IP Address Mac Address Radio Radio Up/Off time State
---------------------------------------- --------------- -------------- ------------------- ------------------- ------------- -----
AP3 193.1.50.1 300d.9e8a.382a 1 E 0 1* 100 2 E 0 157* 100 0:00:55:43 Run
3 E 0 44* 100 4 N - - -
此时AP全上线
#AC1/AC2
wlan-config 1 test-ZB
tunnel local
exit
ap-gr ZB
interf 1 60
exit
wlan-co 2 test-FB
tunnel local
exit
ap-gr FB
interf 2 60
wlan hot-ba xxx.xxx.xxx.xxx //主备CAPWAP隧道地址
conte 10
ap-grou ZB
ap-gr FB
priority level 7 //主AC键入
wlan hot-backup enable
AP加入组发布信号
根据实际情况
ap-config AP名称
ap-g AP组名