路由与交换技术期末上机考核

前言

这是一篇关于路由与交换技术期末考核的文章,我们是以机房上机的方式完成最终考核的。接下来,我会围绕期末考核的要求以及附上相关命令来进行介绍。注:本次内容纯属原创,仅供学习交流。

实验内容

拓扑图 如下:

说明 如下: 

设备  接口          IP连接设备接口IP
PC1Eth0/0/1192.168.10.10/24- -LSW2Eth0/0/1
PC2Eth0/0/1192.168.20.10/24- -LSW2Eth0/0/2
PC3Eth0/0/1192.168.30.10/24- -LSW3Eth0/0/3
PC4Eth0/0/1192.168.40.10/24- -LSW3Eth0/0/4
LSW1GE0/0/11- -LSW2GE0/0/1
LSW1GE0/0/12- -LSW2GE0/0/2
LSW1GE0/0/21- -LSW3GE0/0/1
LSW1GE0/0/22- -LSW3GE0/0/2
LSW1VLANIF1- -AR1GE0/0/1192.168.11.1/24
AR1GE0/0/2192.168.12.1/24- -AR2GE0/0/0192.168.12.2/24
AR2GE0/0/1192.168.23.2/24- -AR3GE0/0/2192.168.23.3/24
AR3GE0/0/1192.168.31.254/24- -Server1Eth0/0/0192.168.31.31/24

考核要求说明:

1.在交换机LSW1上创建VLAN10、VLAN20、VLAN30、VLAN40,并设置VLANIF10接口地址为192.168.10.254/24,VLANIF20接口地址为192.168.20.254/24,VLANIF30接口地址为192.168.30.254/24,VLANIF40接口地址为192.168.40.254/24。VLANIF1接口地址为192.168.11.11/24。

2.在交换机LSW2上创建VLAN10、VLAN20,并设置VLANIF10接口地址为192.168.10.253/24,VLANIF20接口地址为192.168.20.253/24。

3.在交换机LSW3上创建VLAN30、VLAN40,并设置VLANIF30接口地址为192.168.30.253/24,VLANIF40接口地址为192.168.40.253/24。

4.交换机LSW1与交换机LSW2之间完成MTSP协议配置,MST域名为HZU2021,VLAN 10映射为会话10,VLAN 20映射为会话20,LSW1作为VLAN10的主根桥,VLAN20的备份根桥;LSW2作为VLAN20的主根桥,VLAN10的备份根桥。

5.交换机LSW1与交换机LSW3之间完成链路聚合配置,Eth-Trunk编号为1,负载分担方式为源MAC地址与目的地址方式,实现流量在Eth-Trunk各成员接口间的负载分担。

6.在LSW1、AR1、AR2、AR3上做OSPF路由协议配置,进程号均为100,router-id分别为11.11.11.11、1.1.1.1、2.2.2.2、3.3.3.3,完成全网联通。

7.将LSW1交换机配置成DHCP服务器,创建4个地址池fv10、fv20、fv30、fv40,为VLAN10、VLAN20、VLAN30、VLAN40的主机分配IP地址。

8.在AR2上创建访问控制列表,编号为2021,规则步长为10,即10、20、30……;规划依次为:(1)限制vlan30、vlan40主机;(2)其它均允许;并将此列表用在AR2的G0/0/0端口上。


首先我们在进行操作时要先明确一个点,本次实验按照考核要求的步骤一步步来即可,无需在开启设备后进行主机IP的设置。后面DHCP配置部分会自动分配IP,此处对DHCP知识点还不熟悉的同学可查阅相关资料。


接下来,进行配置

分要求点配置

1.在交换机LSW1上创建VLAN10、VLAN20、VLAN30、VLAN40,并设置VLANIF10接口地址为192.168.10.254/24,VLANIF20接口地址为192.168.20.254/24,VLANIF30接口地址为192.168.30.254/24,VLANIF40接口地址为192.168.40.254/24。VLANIF1接口地址为192.168.11.11/24。

system-view
undo info-center enable
Sysname LSW1
Vlan batch 10 20 30 40
Interface vlanif1
ip address 192.168.11.11 24
Interface vlanif10
Ip address 192.168.10.254 24
Interface vlanif20
ip address 192.168.20.254 24
Interface vlanif30
Ip address 192.168.30.254 24
Interface valn40
Ip address 192.168.40.254 24
quit
Interface gigabitethernet0/0/11
Port link-type trunk
Port trunk allow-pass vlan all
quit
Interface gigabitethernet0/0/12
Port link-type trunk
Port trunk allow-pass vlan all
quit
Interface gigabitethernet0/0/23
Port link-type trunk
Port trunk allow-pass vlan all
quit

2.在交换机LSW2上创建VLAN10、VLAN20,并设置VLANIF10接口地址为192.168.10.253/24,VLANIF20接口地址为192.168.20.253/24。

system-view
undo info-center enable
Sysname LSW2
Vlan batch 10 20
Interface vlanif10
ip address 192.168.10.253 24
Interface vlanif20
Ip address 192.168.20.253 24
Interface ethernet0/0/1
Port link-type access
Port default vlan 10
Stp edged-port enable
quit
Interface ethernet0/0/2
Port link-type access
Port default vlan 20
Stp edged-port enable
quit
Interface gigabitethernet0/0/1
Port link-type trunk
Port trunk allow-pass vlan all
quit
Interface gigabitethernet0/0/2
Port link-type trunk
Port trunk allow-pass vlan all

3.在交换机LSW3上创建VLAN30、VLAN40,并设置VLANIF30接口地址为192.168.30.253/24,VLANIF40接口地址为192.168.40.253/24。

system-view
undo info-center enable
Sysname LSW3
Vlan batch 30 40
Interface vlanif30
ip address 192.168.30.253 24
Interface vlanif40
Ip address 192.168.40.253 24
Interface ethernet0/0/3
Port link-type access
Port default vlan 30
Stp edged-port enable
quit
Interface ethernet0/0/4
Port link-type access
Port default vlan 40
Stp edged-port enable
quit

4.交换机LSW1与交换机LSW2之间完成MTSP协议配置,MST域名为HZU2021,VLAN 10映射为会话10,VLAN 20映射为会话20,LSW1作为VLAN10的主根桥,VLAN20的备份根桥;LSW2作为VLAN20的主根桥,VLAN10的备份根桥。

  LSW1:

Stp enable
Stp mode mstp
stp region-configuration
region-name HZU2021
active region-configuration
instance 10 vlan 10 
instance 20 vlan 20
quit
stp instance 10 root primary 
stp instance 20 root secondary
quit

LSW2:

Stp enable
Stp mode mstp
stp region-configuration
region-name HZU2021
active region-configuration
instance 10 vlan 10 
instance 20 vlan 20
quit
stp instance 10 root secondary 
stp instance 20 root primary 

5.交换机LSW1与交换机LSW3之间完成链路聚合配置,Eth-Trunk编号为1,负载分担方式为源MAC地址与目的地址方式,实现流量在Eth-Trunk各成员接口间的负载分担。

LSW1:

Interface Eth-Trunk1
Port link-type trunk
Port trunk allow-pass vlan all
load-balance  src-dst-mac
quit
Interface gigabitethernet0/0/21
Eth-Trunk1
Interface gigabitethernet0/0/22
Eth-Trunk1
quit

LSW3:

Interface Eth-Trunk1
Port link-type trunk
Port trunk allow-pass vlan all
Load-balance src-dst-mac
Interface gigabitethernet0/0/1
Eth-Trunk1
Interface gigabitethernet0/0/2
Eth-Trunk1

6.在LSW1、AR1、AR2、AR3上做OSPF路由协议配置,进程号均为100,router-id分别为11.11.11.11、1.1.1.1、2.2.2.2、3.3.3.3,完成全网联通。

LSW1:

Ospf 100 router-id 11.11.11.11
Area 0
Net 192.168.11.0 0.0.0.255
Net 192.168.10.0 0.0.0.255
Net 192.168.20.0 0.0.0.255
Net 192.168.30.0 0.0.0.255
Net 192.168.40.0 0.0.0.255
quit

AR1:

System-view
Undo info-center enable
Sysname AR1
Interface g0/0/1 
Ip address 192.168.11.1 24
Interface g0/0/2
Ip address 192.168.12.1 24
quit
Ospf 100 router-id 1.1.1.1
Area 0
Net 192.168.11.0 0.0.0.255
Net 192.168.12.0 0.0.0.255
Quit

AR2:

System-view
Undo info-center enable
Sysname AR2
Interface g0/0/0 
Ip add 192.168.12.2 24
Interface g0/0/1
Ip add 192.168.23.2 24
quit
Ospf 100 router-id 2.2.2.2
Area 0
Net 192.168.12.0 0.0.0.255
Net 192.168.23.0 0.0.0.255
quit

AR3:

System-view
Undo info-center enable
Sysname AR3
Interface g0/0/2 
Ip add 192.168.23.3 24
Interface g0/0/1
Ip add 192.168.31.254 24
quit
Ospf 100 router-id 3.3.3.3
Area 0
Net 192.168.23.0 0.0.0.255
Net 192.168.31.0 0.0.0.255
quit

7.将LSW1交换机配置成DHCP服务器,创建4个地址池fv10、fv20、fv30、fv40,为VLAN10、VLAN20、VLAN30、VLAN40的主机分配IP地址。

Ip pool fv10
Gateway-list 192.168.10.254
Network 192.168.10.0 mask 24
Ip pool fv20
Gateway-list 192.168.20.254
Network 192.168.20.0 mask 24
Ip pool fv30
Gateway-list 192.168.30.254
Network 192.168.30.0 mask 24
Ip pool fv40
Gateway-list 192.168.40.254
Network 192.168.40.0 mask 24
quit
Dhcp enable
Interface vlanif10
Dhcp select global
Interface vlanif20
Dhcp select global
Interface vlanif30
Dhcp select global
Interface vlanif40
Dhcp select global

8.在AR2上创建访问控制列表,编号为2021,规则步长为10,即10、20、30……;规划依次为:(1)限制vlan30、vlan40主机;(2)其它均允许;并将此列表用在AR2的G0/0/0端口上。

acl number 2021
Rule 10 deny source 192.168.30.0 0.0.0.255
Rule 20 deny source 192.168.40.0 0.0.0.255
Rule 30 permit
quit
Interface g0/0/0
traffic-filter inbound acl 2021


完整命令:

LSW1:

system-view
undo info-center enable
Sysname LSW1
Vlan batch 10 20 30 40
Interface vlanif1
ip address 192.168.11.11 24
Interface vlanif10
Ip address 192.168.10.254 24
Interface vlanif20
ip address 192.168.20.254 24
Interface vlanif30
Ip address 192.168.30.254 24
Interface vlanif40
Ip address 192.168.40.254 24
quit
Interface gigabitethernet0/0/11
Port link-type trunk
Port trunk allow-pass vlan all
quit
Interface gigabitethernet0/0/12
Port link-type trunk
Port trunk allow-pass vlan all
quit
Interface gigabitethernet0/0/23
Port link-type trunk
Port trunk allow-pass vlan all
quit
Stp enable
Stp mode mstp
stp region-configuration
region-name HZU2021
active region-configuration
instance 10 vlan 10 
instance 20 vlan 20
quit
stp instance 10 root primary 
stp instance 20 root secondary
Interface Eth-Trunk1
Port link-type trunk
Port trunk allow-pass vlan all
load-balance  src-dst-mac
quit
Interface g0/0/21
Eth-Trunk1
Interface g0/0/22
Eth-Trunk1
quit
Ospf 100 router-id 11.11.11.11
Area 0
Net 192.168.11.0 0.0.0.255
Net 192.168.10.0 0.0.0.255
Net 192.168.20.0 0.0.0.255
Net 192.168.30.0 0.0.0.255
Net 192.168.40.0 0.0.0.255
quit
Ip pool fv10
Gateway-list 192.168.10.254
Network 192.168.10.0 mask 24
Ip pool fv20
Gateway-list 192.168.20.254
Network 192.168.20.0 mask 24
Ip pool fv30
Gateway-list 192.168.30.254
Network 192.168.30.0 mask 24
Ip pool fv40
Gateway-list 192.168.40.254
Network 192.168.40.0 mask 24
quit
Dhcp enable
Interface vlanif10
Dhcp select global
Interface vlanif20
Dhcp select global
Interface vlanif30
Dhcp select global
Interface vlanif40
Dhcp select global
quit

LSW2:

system-view
undo info-center enable
Sysname LSW2
Vlan batch 10 20
Interface vlanif10
ip address 192.168.10.253 24
Interface vlanif20
Ip address 192.168.20.253 24
Interface ethernet0/0/1
Port link-type access
Port default vlan 10
Stp edged-port enable
quit
Interface ethernet0/0/2
Port link-type access
Port default vlan 20
Stp edged-port enable
quit
Interface gigabitethernet0/0/1
Port link-type trunk
Port trunk allow-pass vlan all
quit
Interface gigabitethernet0/0/2
Port link-type trunk
Port trunk allow-pass vlan all
quit
Stp enable
Stp mode mstp
stp region-configuration
region-name HZU2021
active region-configuration
instance 10 vlan 10 
instance 20 vlan 20
quit
stp instance 10 root secondary 
stp instance 20 root primary 

LSW3:

system-view
undo info-center enable
Sysname LSW3
Vlan batch 30 40
Interface vlanif30
ip address 192.168.30.253 24
Interface vlanif40
Ip address 192.168.40.253 24
Interface ethernet0/0/3
Port link-type access
Port default vlan 30
Stp edged-port enable
quit
Interface ethernet0/0/4
Port link-type access
Port default vlan 40
Stp edged-port enable
quit
Interface Eth-Trunk1
Port link-type trunk
Port trunk allow-pass vlan all
Load-balance src-dst-mac
Interface g0/0/1
Eth-Trunk1
Interface g0/0/2
Eth-Trunk1

AR1:

System-view
Undo info-center enable
Sysname AR1
Interface g0/0/1 
Ip address 192.168.11.1 24
Interface g0/0/2
Ip address 192.168.12.1 24
quit
Ospf 100 router-id 1.1.1.1
Area 0
Net 192.168.11.0 0.0.0.255
Net 192.168.12.0 0.0.0.255
Quit

AR2:

System-view
Undo info-center enable
Sysname AR2
Interface g0/0/0 
Ip add 192.168.12.2 24
Interface g0/0/1
Ip add 192.168.23.2 24
quit
Ospf 100 router-id 2.2.2.2
Area 0
Net 192.168.12.0 0.0.0.255
Net 192.168.23.0 0.0.0.255
quit
acl number 2021
Rule 10 deny source 192.168.30.0 0.0.0.255
Rule 20 deny source 192.168.40.0 0.0.0.255
Rule 30 permit
quit
Interface g0/0/0
traffic-filter inbound acl 2021

AR3:

System-view
Undo info-center enable
Sysname AR3
Interface g0/0/2 
Ip add 192.168.23.3 24
Interface g0/0/1
Ip add 192.168.31.254 24
quit
Ospf 100 router-id 3.3.3.3
Area 0
Net 192.168.23.0 0.0.0.255
Net 192.168.31.0 0.0.0.255
quit

测试结果:

           首先查看DHCP为每台主机分配的ip地址,服务器再分别与四台主机的ip相ping,发现均可ping通。

注:由于作者能力有限,再加上隔了一段时间才再次执笔,文章中难免有很多遗漏与错误之处,恳请各位看者谅解并指正。

  • 4
    点赞
  • 50
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值