室验一:三层交换机下完成不同vlan间的PC双向互相通信。
实验二:再增加两个路由器,使AR9路由器下的PC能和所有PC双向互通。
环境拓扑:
实验一配置:
在交换机SW5进行VLAN的配置:
(1)创建vlan10和vlan20、vlan30
[SW5]vlan batch 10 20 30
[SW5]q
(2)进入接口,并规定为access链路、划分vlan隔离,
[SW5]int g0/0/1
[SW5-GigabitEthernet0/0/1]port link-type access
[SW5-GigabitEthernet0/0/1]port default vlan 10
[SW5]int g0/0/2
[SW5-GigabitEthernet0/0/2]port link-type access
[SW5-GigabitEthernet0/0/2]port default vlan 20
[SW5]int g0/0/3
[SW5-GigabitEthernet0/0/3]port link-type access
[SW5-GigabitEthernet0/0/3]port default vlan 30
(3)进入interface Vlanif接口配置网关
[SW5]int Vlanif 10
[SW5-Vlanif10]ip address 192.168.10.1 255.255.255.0
#
[SW5]int Vlanif 20
[SW5-Vlanif20]ip address 192.168.20.1 255.255.255.0
#
[SW5]int Vlanif 30
[SW5-Vlanif30]ip address 192.168.30.1 255.255.255.0
(4)进行PC配置
PC1-vlan10配置:192.168.10.10/24 GW 192.168.10.1
PC2-vlan20配置:192.168.20.20/24 GW 192.168.20.1
PC3-vlan30配置:192.168.30.30/24 GW 192.168.30.1
(5)验证:
配置查看:
[SW5]dis cu
[SW5]dis current-configuration
#
sysname SW5
#
vlan batch 10 20 30 40
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
ip address 192.168.10.1 255.255.255.0
#
interface Vlanif20
ip address 192.168.20.1 255.255.255.0
#
interface Vlanif30
ip address 192.168.30.1 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 20
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 30
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
二、实验二配置:增加AR8和AR9路由器后,实现所有PC之间互通。
在路由器AR8进行配置:
(1)进入接口,配置IP
[AR8]int g0/0/0
[AR8-GigabitEthernet0/0/0]ip address 10.10.10.1 255.255.255.128
[AR8]int g0/0/1
[AR8-GigabitEthernet0/0/1]ip address 10.10.10.253 255.255.255.128
在路由器AR9进行配置:
(1)进入接口,配置IP
[AR8]int g0/0/0
[AR8-GigabitEthernet0/0/0]ip address 192.168.40.1 255.255.255.0
[AR8]int g0/0/1
[AR8-GigabitEthernet0/0/1]ip address 10.10.10.252 255.255.255.128
在交换机SW5进行配置:
(1)进入int g0/0/4接口,并规定为access链路、划分vlan。
[SW5]int g0/0/4
[SW5-GigabitEthernet0/0/4]port link-type access
[SW5-GigabitEthernet0/0/4] port default vlan 40
[SW5-GigabitEthernet0/0/4] q
(2)进入interface Vlanif接口配置网关
[SW5]int Vlanif 40
[SW5-Vlanif40]ip address 10.10.10.10 255.255.255.128
路由添加配置:
交换机SW5路由配置:
[SW5]ip route-static 10.10.10.128 255.255.255.128 10.10.10.1
[SW5]ip route-static 192.168.40.0 255.255.255.0 10.10.10.1
或者直接配置默认路由:[SW5]ip route-static 0.0.0.0 0.0.0.0 10.10.10.1
路由器AR8路由配置:
[AR8]ip route-static 192.168.10.0 255.255.255.0 10.10.10.10
[AR8]ip route-static 192.168.20.0 255.255.255.0 10.10.10.10
[AR8]ip route-static 192.168.30.0 255.255.255.0 10.10.10.10
[AR8]ip route-static 192.168.40.0 255.255.255.0 10.10.10.252
路由器AR9路由配置:
[AR9]ip route-static 0.0.0.0 0.0.0.0 10.10.10.253
或者配置详细路由:
[AR9]ip route-static 10.10.10.0 25 10.10.10.253
[AR9]ip route-static 192.168.10.0 24 10.10.10.253
[AR9]ip route-static 192.168.20.0 24 10.10.10.253
[AR9]ip route-static 192.168.30.0 24 10.10.10.253
结果验证:
配置查看:
<AR8>dis cu
<AR8>dis current-configuration
[V200R003C00]
#
sysname AR8
#
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
#
clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
drop illegal-mac alarm
#
set cpu-usage threshold 80 restore 75
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-user admin service-type http
#
firewall zone Local
priority 15
#
interface GigabitEthernet0/0/0
ip address 10.10.10.1 255.255.255.128
#
interface GigabitEthernet0/0/1
ip address 10.10.10.253 255.255.255.128
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
ip route-static 192.168.10.0 255.255.255.0 10.10.10.10
ip route-static 192.168.20.0 255.255.255.0 10.10.10.10
ip route-static 192.168.30.0 255.255.255.0 10.10.10.10
ip route-static 192.168.40.0 255.255.255.0 10.10.10.252
#
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
#
wlan ac
#
return
[AR9]dis cu
[AR9]dis current-configuration
[V200R003C00]
#
sysname AR9
#
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
#
clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
drop illegal-mac alarm
#
set cpu-usage threshold 80 restore 75
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-user admin service-type http
#
firewall zone Local
priority 15
#
interface GigabitEthernet0/0/0
ip address 192.168.40.1 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 10.10.10.252 255.255.255.128
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
ip route-static 10.10.10.0 255.255.255.128 10.10.10.253
ip route-static 192.168.10.0 255.255.255.0 10.10.10.253
ip route-static 192.168.20.0 255.255.255.0 10.10.10.253
ip route-static 192.168.30.0 255.255.255.0 10.10.10.253
#
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
#
wlan ac
#
return
[SW5]dis current-configuration
#
sysname SW5
#
vlan batch 10 20 30 40
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
ip address 192.168.10.1 255.255.255.0
#
interface Vlanif20
ip address 192.168.20.1 255.255.255.0
#
interface Vlanif30
ip address 192.168.30.1 255.255.255.0
#
interface Vlanif40
ip address 10.10.10.10 255.255.255.128
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 10
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 20
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 30
#
interface GigabitEthernet0/0/4
port link-type access
port default vlan 40
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
ip route-static 10.10.10.128 255.255.255.128 10.10.10.1
ip route-static 192.168.40.0 255.255.255.0 10.10.10.1
#
user-interface con 0
user-interface vty 0 4
#
return
路由表查看:
[SW5]dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 12 Routes : 12
Destination/Mask Proto Pre Cost Flags NextHop Interface
10.10.10.0/25 Direct 0 0 D 10.10.10.10 Vlanif40
10.10.10.10/32 Direct 0 0 D 127.0.0.1 Vlanif40
10.10.10.128/25 Static 60 0 RD 10.10.10.1 Vlanif40
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.10.0/24 Direct 0 0 D 192.168.10.1 Vlanif10
192.168.10.1/32 Direct 0 0 D 127.0.0.1 Vlanif10
192.168.20.0/24 Direct 0 0 D 192.168.20.1 Vlanif20
192.168.20.1/32 Direct 0 0 D 127.0.0.1 Vlanif20
192.168.30.0/24 Direct 0 0 D 192.168.30.1 Vlanif30
192.168.30.1/32 Direct 0 0 D 127.0.0.1 Vlanif30
192.168.40.0/24 Static 60 0 RD 10.10.10.1 Vlanif40
[AR8]dis ip rou
[AR8]dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 14 Routes : 14
Destination/Mask Proto Pre Cost Flags NextHop Interface
10.10.10.0/25 Direct 0 0 D 10.10.10.1 GigabitEthernet
0/0/0
10.10.10.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
10.10.10.127/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
10.10.10.128/25 Direct 0 0 D 10.10.10.253 GigabitEthernet
0/0/1
10.10.10.253/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
10.10.10.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.10.0/24 Static 60 0 RD 10.10.10.10 GigabitEthernet
0/0/0
192.168.20.0/24 Static 60 0 RD 10.10.10.10 GigabitEthernet
0/0/0
192.168.30.0/24 Static 60 0 RD 10.10.10.10 GigabitEthernet
0/0/0
192.168.40.0/24 Static 60 0 RD 10.10.10.252 GigabitEthernet
0/0/1
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
[AR8]
[AR9]dis ip ro
[AR9]dis ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Tables: Public
Destinations : 14 Routes : 14
Destination/Mask Proto Pre Cost Flags NextHop Interface
10.10.10.0/25 Static 60 0 RD 10.10.10.253 GigabitEthernet
0/0/1
10.10.10.128/25 Direct 0 0 D 10.10.10.252 GigabitEthernet
0/0/1
10.10.10.252/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
10.10.10.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/1
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
192.168.10.0/24 Static 60 0 RD 10.10.10.253 GigabitEthernet
0/0/1
192.168.20.0/24 Static 60 0 RD 10.10.10.253 GigabitEthernet
0/0/1
192.168.30.0/24 Static 60 0 RD 10.10.10.253 GigabitEthernet
0/0/1
192.168.40.0/24 Direct 0 0 D 192.168.40.1 GigabitEthernet
0/0/0
192.168.40.1/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
192.168.40.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet
0/0/0
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
[AR9]