目录
要求
1.全网可达
2.拓扯中所需地址全部基于192.168.8.0/24划分所得3.静态路由(不许使用真他动态)
4.R8环回需要汇总
分析
1.子网划分--环回一个,左边四个路由器共用一个,vlan用一个,R9和R11一个,所以划分4个网段,四个网段再细化划分
2.回环的路由器需要做空接口,防止出现环路
3.100M,1000M,只需要把100M的优先级降低
4.R11做一个acl,允许所有流量通过
建立拓扑结构图
配置
1.vlan配置
SW1
<Huawei>sys
[Huawei]sysn sw1
[sw1]vlan batch 2 to 3
[sw1]int e0/0/3[sw1-Ethernet0/0/3]port l ac
[sw1-Ethernet0/0/3]port default vlan 2
[sw1-Ethernet0/0/3]int e0/0/4
[sw1-Ethernet0/0/4]port l ac
[sw1-Ethernet0/0/4]port de vlan 3
[sw1-Ethernet0/0/4]int e0/0/2
[sw1-Ethernet0/0/2]port link-type trunk //trunk通道
[sw1-Ethernet0/0/2]port trunk allow-pass vlan all //允许所有vlanSW2
[Huawei]sysn sw2
[sw2]interface e0/0/2
[sw2-Ethernet0/0/2]port li ac
[sw2-Ethernet0/0/2]port d vlan 2
[sw2-Ethernet0/0/2]int e0/0/3
[sw2-Ethernet0/0/3]port lin ac
[sw2-Ethernet0/0/3]port de vlan 3
[sw2-Ethernet0/0/3]int e0/0/1
[sw2-Ethernet0/0/1]port lin tru
[sw2-Ethernet0/0/1]port trunk allow-pass vlan allR3
<Huawei>sys
[Huawei]sysn r3
[r3]int g0/0/2.1
[r3-GigabitEthernet0/0/2.1]dot1q termination vid 2
[r3-GigabitEthernet0/0/2.1]ip add 192.168.0.195 27
[r3-GigabitEthernet0/0/2.1]arp broadcast enable
[r3-GigabitEthernet0/0/2.1]int g0/0/2.2
[r3-GigabitEthernet0/0/2.2]dot1q termination vid 3
[r3-GigabitEthernet0/0/2.2]ip add 192.168.0.227 27
[r3-GigabitEthernet0/0/2.2]arp broadcast enable
2.IP地址配置
R1
<Huawei>sys
[Huawei]sysn r1
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip add 192.168.0.1 28
[r1-GigabitEthernet0/0/0]int g0/0/1
[r1-GigabitEthernet0/0/1]ip add 192.168.0.33 28
//环回地址配置
[r1-GigabitEthernet0/0/1]int loo 0
[r1-LoopBack0]ip add 192.168.0.129 28
[r1-LoopBack0]int loo 1
[r1-LoopBack1]ip add 192.168.0.145 28
[r1-LoopBack1]int loo 2
[r1-LoopBack2]ip add 192.168.0.129 27
[r1]int loo 2
[r1-LoopBack2]ip add 192.168.0.161 27R2
<Huawei>sys
[Huawei]sysn r2
[r2]int g0/0/0
[r2-GigabitEthernet0/0/0]ip add 192.168.0.2 28
[r2-GigabitEthernet0/0/0]int g0/0/1
[r2-GigabitEthernet0/0/1]ip add 192.168.0.17 28R3
<r3>sys
[r3]int g0/0/0
[r3-GigabitEthernet0/0/0]ip add 192.168.0.34 28
[r3-GigabitEthernet0/0/0]int g0/0/1
[r3-GigabitEthernet0/0/1]ip add 192.168.0.49 28R4
<Huawei>sys
[Huawei]sysn r4
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip add 192.168.0.18 28
[r4-GigabitEthernet0/0/0]int g0/0/1
[r4-GigabitEthernet0/0/1]ip add 192.168.0.50 28
[r4-GigabitEthernet0/0/1]int e4/0/0
[r4-Ethernet4/0/0]ip add 192.168.0.97 27
[r4-Ethernet4/0/0]int g0/0/2
[r4-GigabitEthernet0/0/2]ip add 192.168.0.65 27R5
<Huawei>sys
[Huawei]sysn r5
[r5]int g0/0/1
[r5-GigabitEthernet0/0/1]ip add 192.168.0.98 27
[r5-GigabitEthernet0/0/1]int g0/0/0
[r5-GigabitEthernet0/0/0]ip add 192.168.0.66 27
[r5-GigabitEthernet0/0/0]int g0/0/2
[r5-GigabitEthernet0/0/2]ip add 100.1.1.2 24R6
<Huawei>sys
[Huawei]sysn r6
[r6]int g0/0/0
[r6-GigabitEthernet0/0/0]ip add 100.1.1.1 24PC1
PC2
PC3
PC4
3.静态路由配置
R1
<r1>sys
[r1]ip route-static 192.168.0.64 26 192.168.0.2
[r1]ip route-static 192.168.0.192 26 192.168.0.34
[r1]ip route-static 192.168.0.16 28 192.168.0.2
[r1]ip route-static 192.168.0.48 28 192.168.0.32
[r1]ip route-static 0.0.0.0 0 192.168.0.2 //缺省路由
[r1]ip route-static 192.168.0.128 26 NULL 0 //空接口R2
<r2>sys
[r2]ip route-static 192.168.0.32 28 192.168.0.1
[r2]ip route-static 192.168.0.48 28 192.168.0.18
[r2]ip route-static 192.168.0.128 26 192.168.0.1
[r2]ip route-static 192.168.0.192 26 192.168.0.1
[r2]ip route-static 192.168.0.64 26 192.168.0.18
[r2]ip route-static 0.0.0.0 0 192.168.0.18 //缺省路由R3
<r3>sys
[r3]ip route-static 192.168.0.0 28 192.168.0.33
[r3]ip route-static 192.168.0.16 28 192.168.0.50
[r3]ip route-static 192.168.0.128 26 192.168.0.33
[r3]ip route-static 192.168.0.64 26 192.168.0.50
[r3]ip route-static 0.0.0.0 0 192.168.0.50R4
<r4>sys
[r4]ip route-static 192.168.0.0 28 192.168.0.17
[r4]ip route-static 192.168.0.32 28 192.168.0.49
[r4]ip route-static 192.168.0.192 26 192.168.0.49
[r4]ip route-static 192.168.0.128 26 192.168.0.49
[r4]ip route-static 0.0.0.0 0 192.168.0.98 preference 80 //设置100M的优先级
[r4]ip route-static 0.0.0.0 0 192.168.0.66R5
[r5]ip route-static 192.168.0.0 26 192.168.0.97
[r5]ip route-static 192.168.0.128 26 192.168.0.97
[r5]ip route-static 192.168.0.192 26 192.168.0.97[r5]ip route-static 0.0.0.0 0 100.1.1.1
[r5]acl 2000 //ACL访问控制列表建立
[r5-acl-basic-2000]rule permit source any
[r5-acl-basic-2000]q
[r5]int g0/0/2
[r5-GigabitEthernet0/0/2]nat outbound 2000 //出接口选择ACL2000
验证
r1
这里就拿r1做验证,当然其他也可以
ping环回
ping vlan3的PC4
ping R6的接口