三层交换综合实验
搭建拓扑,分配ip
配置思路:eth-trunk trunk干道 VLAN STP SVI VRRP DHCP
Eth-trunk
Trunk干道
VLAN
Sw1-4创建VLAN2
Sw3-4连接pc的端口模式改为access,并将pc2 3划入VLAN2
STP
我们的目标是sw1 应该是组1的主根组2的备份根 , sw2应该是组2的主根组1的备份根,网关也应该在sw1和sw2上实现3合1:
然后再将连接电脑的接口设置为边缘接口,来提高效率
VRRP
Sw1
Sw2一样
Sw1:
Sw2
DHCP
[sw1]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[sw1]ip pool v1
Info:It's successful to create an IP address pool.
[sw1-ip-pool-v1]network 172.16.1.0 mask 25
[sw1-ip-pool-v1]gateway-list 172.16..1.126
[sw1-ip-pool-v1]dns
[sw1-ip-pool-v1]dns-list .114.114.114.114
[sw1-ip-pool-v1]q
[sw1]ip pool v2
Info:It's successful to create an IP address pool.
[sw1-ip-pool-v2]network 172.16.1.128 mask 25
[sw1-ip-pool-v2]dns-list 114.114.114.114
[sw1-ip-pool-v2]gateway-list 172.16.1.254
[sw1-ip-pool-v2]q
[sw1]int v 1
[sw1-Vlanif1]dhcp select global
[sw1-Vlanif1]int v 2
[sw1-Vlanif2]dhcp select global
Sw2一样
路由
这里华为模拟器有个问题就是 g0/0/5口undo portswitch后无法配置ip 正常是可以直接配ip的,所以这里只能用SVI模拟一个三层接口
[sw1]int g 0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 100
[sw1-GigabitEthernet0/0/1]int v 100
[sw1-Vlanif100]ip add 172.16.0.1 30
[sw2]int g 0/0/1
[sw2-GigabitEthernet0/0/1]port link-type access
[sw2-GigabitEthernet0/0/1]port default vlan 100
[sw2-GigabitEthernet0/0/1]int v 100
[sw2-Vlanif100]ip add 172.16.0.5 30
配置R1 R2的物理接口IP和环回,这里就不多说
内网上网
可以选择的方案有两种,一是直接静态路由,二是配置ospf,这里我选择用方案二,三层及以上为区域0 其他为区域1
R1
Sw1
Sw2
R1
此时再将底下两条路由汇聚成一条发上去
[sw1-ospf-1]
[sw1-ospf-1]area 1
[sw1-ospf-1-area-0.0.0.1]abr-summary 172.16.1.0 255.255.255.0
[sw2-ospf-1]
[sw2-ospf-1]area 1
[sw2-ospf-1-area-0.0.0.1]abr-summary 172.16.1.0 255.255.255.0
此时再看R1
此时这里有几个问题:每个SVI会每隔10秒向所有未堵塞的trunk干道和pc发hello包,因此下面的网络中会充斥着很多洪泛流量,所以我的解决方案是先沉默所有接口,再打开需要的接口
[sw1]ospf 1
[sw1-ospf-1]silent-interface all
[sw1-ospf-1]undo silent-interface GigabitEthernet 0/0/5
[sw1-ospf-1]undo silent-interface Eth-Trunk 0
[sw1-ospf-1]undo silent-interface Vlanif 1
[sw1-ospf-1]undo silent-interface Vlanif 100
Sw2一样
缺省
[r1]ip route-static 0.0.0.0 0 12.1.1.2
[r1-ospf-1]default-route-advertise
NAT
[r1]acl 2000
[r1-acl-basic-2000]rule p
[r1-acl-basic-2000]rule permit s
[r1-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r1-acl-basic-2000]q
[r1]int g 0/0/2
[r1-GigabitEthernet0/0/2]nat ou
[r1-GigabitEthernet0/0/2]nat outbound 2000