综合实验要求:
1、AR6理解为ISP设备,所连接的两个网段为公网;R1-R5构建为一个私有的局域网;
2、AR6上只能进行ip地址配置,之后不得对该路由器进行其他任何配置
3、公网范围IP地址已经指定,剩余R1-R5整个私网使用192.168.1.0/24进行合理分配
4、PC1/3为划分到VLAN2,PC2/4/HTTP 服务器划分到VLAN3;PC1-4通过DHCP自动获取ip地址;
5、所有路由器路由表应尽量控制减少,预防出现环路,所有选路均为最佳路径;R4与R5之间正常使用1000M链路,
1000M链路故障时自动切换到100m链路,整个网络仅使用静态路由协议;
6、PC1—PC4均可ping通PC5,同时PC5可以通过域名www.beixin.com来访问http服务器;
7、全网仅R1可以telnet登录R2
分析:
192.168.1.0/24划分为两个网段
192.168.1.0/25干路网段划分为:
192.168.1.0/30
192.168.1.4/30
192.168.1.8/30
192.168.1.12/30
192.168.1.16/30
192.168.1.20/30
192.168.1.128/25 r1 和 r3 vlan划分为:
192.168.1.128/26
192.168.1.128/27vlan2
192.168.1.160/27vlan3
192.168.1.192/26
192.168.1.192/27vlan2
192.168.1.224/27vlan3
配置sw1
[sw1]vlan batch 2 to 3
[sw1]interface g0/0/2
[sw1-GigabitEthernet0/0/2]port link-type access
[sw1GigabitEthernet0/0/2]port default vlan 2
[sw1]interface g0/0/3
[sw1-GigabitEthernet0/0/3]port l a
[sw1i-GigabitEthernet0/0/3]port default vlan 3
[sw1]interface g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type trunk
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan 2 to 3
配置sw2
[sw2]vlan batch 2 to 3
[sw2interface g0/0/1
[sw2-GigabitEthernet0/0/1]port l a
[sw2-port-group-de]port default vlan 2
[sw2]port-group group-member g0/0/2 to g0/0/3
[sw2-GigabitEthernet0/0/2]port l a
[sw2-GigabitEthernet0/0/2]port de vlan 3
[sw2]interface g0/0/4
[sw2-GigabitEthernet0/0/4]port link-type trunk
[sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 to 3
划分r1子接口
[r1]interface g0/0/2.1
[r1-GigabitEthernet0/0/2.1]dot1q termination vid 2
[r1-GigabitEthernet0/0/2.1]ip address 192.168.1.129 27
[r1-GigabitEthernet0/0/2.1]arp broadcast enable
[r1]int g0/0/2.2
[r1-GigabitEthernet0/0/2.2]dot1q termination vid 3
[r1-GigabitEthernet0/0/2.2]ip address 192.168.1.161 27
[r1-GigabitEthernet0/0/2.2]arp broadcast enable
[r1-GigabitEthernet0/0/2.2]q
启动DHCP
[r1]dhcp enable
[r1]ip pool 1
[r1-ip-pool-1]network 192.168.1.128 mask 27
[r1-ip-pool-1]gateway-list 192.168.1.129
[r1-ip-pool-1]dns-list 8.8.8.8
[r1]ip pool 2
[r1-ip-pool-2]network 192.168.1.160 mask 27
[r1-ip-pool-2]gateway-list 192.168.1.161
[r1-ip-pool-2]dns-list 8.8.8.8
[r1]interface g0/0/2.1
[r1-GigabitEthernet0/0/2.1]dhcp select global
[r1]int g0/0/2.2
[r1-GigabitEthernet0/0/2.2]dhcp select global
划分r3子接口
[r3]interface g0/0/2.1
[r3-GigabitEthernet0/0/2.1]dot1q termination vid 2
[r3-GigabitEthernet0/0/2.1]ip address 192.168.1.193 27
[r3-GigabitEthernet0/0/2.1]arp broadcast enable
[r3]interface g0/0/2.2
[r3-GigabitEthernet0/0/2.2]dot1q termination vid 3
[r3-GigabitEthernet0/0/2.2]ip address 192.168.1.225 27
启动DHCP
[r3]dhcp enable
[r3]ip pool 1
[r3-ip-pool-1]network 192.168.1.192 mask 27
[r3-ip-pool-1]gateway-list 192.168.1.193
[r3-ip-pool-1]dns-list 8.8.8.8
[r3]ip pool 2
[r3-ip-pool-2]network 192.168.1.224 mask 27
[r3-ip-pool-2]gateway-list 192.168.1.225[r2-ip-pool-2]dn
[r3-ip-pool-2]dns-list 8.8.8.8
[r3]interface g0/0/2.1
[r2-GigabitEthernet0/0/2.1]dhcp select global
[r3]interface g0/0/2.2
[r3-GigabitEthernet0/0/2.2]dhcp select global
r1配置IP
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip ad
[r1-GigabitEthernet0/0/0]ip address 192.168.1.1 30
[r1]int g0/0/1
[r1-GigabitEthernet0/0/1]ip address 192.168.1.9 30
r2配置IP
配置静态路由
r3配置ip
[r3]interface g0/0/0
[r3-GigabitEthernet0/0/0]ip address 192.168.1.10 30
[r3]int g0/0/1
[r3-GigabitEthernet0/0/1]ip address 192.168.1.13 30
配置静态路由
[r3]ip route-static 192.168.1.128 26 192.168.1.9
[r3]ip route-static 192.168.1.0 30 192.168.1.9
[r3]ip route-static 192.168.1.128 26 NULL 0
[r3]ip route-static 0.0.0.0 0 192.168.1.14
r4 配置ip
配置静态路由
[r4]ip route-static 0.0.0.0 0 192.168.1.22 preference 100
此命令为R4与R5之间正常使用1000M链路,1000M链路故障时自动切换到100m链路
r5配置ip
配置静态路由
边界路由器上配置汇总路由,汇通外网
r6配置ip
r2 telnet
实现仅允许 r1 telnet r2
给pc5、PAD、DNS手动添加IP
PC1—PC4均可ping通PC5
通过域名www.beixin.com来访问http服务器