实验要求
拓扑分析
对192.168.1.0/24进行划分 分配出五个网段
在R1 R2启动ospf
因为pc1-pc4要自动获取IP地址 所以要配置DHCP
因为要求pc1不能Telnet R1 其他可以 所以要配置acl
pc1-pc4不能Telnet R1 且R2的公网接口只拥有一个公有ip 所以要配置easyIP
因为外部的client可以通过域名访问HTTPserver 所以要配置端口映射
根据要求8可得要配置端口映射
每台设备的配置及配置分析
LSW1
[sw1]vlan 2
[sw1]vlan 3
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1-GigabitEthernet0/0/2]p d v 2
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 2
[sw1-GigabitEthernet0/0/4]port link-type access
[sw1-GigabitEthernet0/0/4]port default vlan 3
[sw1-GigabitEthernet0/0/1]port link-type trunk
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan all(配置vlan)
LSW2
[sw2]vlan 2
[sw2]vlan 3
[sw2-GigabitEthernet0/0/2]port link-type access
[sw2-GigabitEthernet0/0/2]port default vlan 2
[sw2-GigabitEthernet0/0/3]port link-type access
[sw2-GigabitEthernet0/0/3]port default vlan 3
[sw2-GigabitEthernet0/0/1]port link-type trunk
[sw2-GigabitEthernet0/0/1]port trunk allow-pass vlan all(配置vlan)
AR1
[r1]dhcp enable
[r1]ip pool aa
[r1-ip-pool-aa]network 192.168.1.32 mask 27
[r1-ip-pool-aa]gateway-list 192.168.1.33
[r1-ip-pool-aa]dns-list 114.114.114.114
[r1-GigabitEthernet0/0/0.1]dhcp select global (配置DHCP)
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255(配置ospf)
[r1-aaa]local-user lzq privilege level 15 password cipher 123456
[r1-aaa]local-user lzq service-type telnet
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mode aaa(开启Telnet服务)
[r1]acl 3000
[r1-acl-adv-3000]rule deny tcp source 192.168.1.62 0.0.0.0 destination 192.168.1
.1 0.0.0.0 destination-port eq 23
[r1-acl-adv-3000]rule deny tcp source 192.168.1.62 0.0.0.0 destination 192.168.1
.33 0.0.0.0 destination-port eq 23
[r1-acl-adv-3000]rule deny tcp source 192.168.1.62 0.0.0.0 destination 192.168.1
.65 0.0.0.0 destination-port eq 23
[r1-GigabitEthernet0/0/0]traffic-filter inbound acl 3000(配置acl)
AR2
[r2]dhcp enable
[r2]ip pool aa
[r2-ip-pool-aa]network 192.168.1.96 mask 27
[r2-ip-pool-aa]gateway-list 192.168.1.97
[r2-ip-pool-aa]dns-list 114.114.114.114
[r2-GigabitEthernet0/0/0.1]dhcp select global
[r2]ip pool bb
[r2-ip-pool-bb]network 192.168.1.128 mask 27
[r2-ip-pool-bb]gateway-list 192.168.1.129
[r2-ip-pool-bb]dns-list 114.114.114.114
[r2-GigabitEthernet0/0/0.2]dhcp select global (配置DHCP)
[r2]ospf router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255(配置ospf)
[r2-ospf-1]default-route-advertise always (强制下发缺省信息)
[r2]acl 2000
[r2-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[r2-GigabitEthernet0/0/2]nat outbound 2000(配置easy IP)
[r2-GigabitEthernet0/0/2]nat server protocol tcp global current-interface 80 ins
ide 192.168.1.66 80
[r2-GigabitEthernet0/0/2]nat server protocol tcp global current-interface 23 ins
ide 192.168.1.1 23(配置nat)
实验结果验证