目录
1.实验拓扑
2.实验需求
1,学校内部的HTTP客户端可以正常通过域名www.baidu.com访问到白度网络中的HTTP服务器
2,学校网络内部网段基于192.168.1.0/24划分,PC1可以正常访问3.3.3.0/24网段,但是PC2不允许访问3.3.3.3
3,学校内部路由使用静态路由,R1和R2之间两条链路进行浮动静态
4,运营商网络内部使用动态路由协议
5,AR1可以被telnet远程控制
3.实验需求分析
ip分配分层预留
1—>DNS
2—>VLAN,ACL
3—>静态路由,浮动静态
4—>动态路由协议,NAL
5—>Telnet
4.实验配置内容 (每一个设备的每一步操作)
ip分配分层预留
内网设置
R1
[R1-GigabitEthernet0/0/0]ip address 192.168.1.6 30
[R1-GigabitEthernet0/0/2]ip address 192.168.1.2 30
R2
[r2-GigabitEthernet0/0/2]ip address 192.168.1.1 30
[r2-GigabitEthernet0/0/1]ip address 192.168.1.5 30
[r2]int g0/0/0.2
[r2-GigabitEthernet0/0/0.2]dot1q termination vid 2
[r2-GigabitEthernet0/0/0.2]ip address 192.168.1.129 26
[r2-GigabitEthernet0/0/0.2]int g0/0/0.3
[r2-GigabitEthernet0/0/0.3]dot1q termination vid 3
[r2-GigabitEthernet0/0/0.3]ip address 192.168.1.193 26
R3:
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip address 13.0.0.3 24
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip address 34.0.0.3 24
[R3-GigabitEthernet0/0/1]int g0/0/2
[R3-GigabitEthernet0/0/2]ip address 35.0.0.3 24
R4:
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip address 34.0.0.4 24
[r4-GigabitEthernet0/0/0]int g0/0/1
[r4-GigabitEthernet0/0/1]ip address 100.1.1.254 24
R5:
[R5-GigabitEthernet0/0/0]ip address 35.0.0.5 24
[R5-GigabitEthernet0/0/0]int g0/0/1
[R5-GigabitEthernet0/0/1]ip address 56.0.0.5 24
R6:
[R6]int g0/0/0
[R6-GigabitEthernet0/0/0]ip address 56.0.0.6 24
lsw1
[Huawei]vlan batch 2 3
int g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type access
[Huawei-GigabitEthernet0/0/1]port default vlan 3
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type access
[Huawei-GigabitEthernet0/0/2]port default vlan 3
[Huawei-GigabitEthernet0/0/2]int g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type access
[Huawei-GigabitEthernet0/0/3]port default vlan 2
[Huawei-GigabitEthernet0/0/3]int g0/0/4
[Huawei-GigabitEthernet0/0/4]port link-type trunk
[Huawei-GigabitEthernet0/0/4]port trunk allow-pass vlan 2 3
http服务器
DHCP地址池
[r2]dhcp enable
[r2]ip pool vlan3
[r2-ip-pool-vlan3]network 192.168.1.128 mask 26 设置网关及掩码
[r2-ip-pool-vlan3]dns-list 100.1.1.1 设置DNS
[r2]int g0/0/0.3
[r2-GigabitEthernet0/0/0.3]dhcp select global 激活全局配置
[r2-GigabitEthernet0/0/0.3]arp broadcast enable --打开广播应答功能
[r2-GigabitEthernet0/0/0.2]arp broadcast enable
之后PC1和2就可以访问HTTP服务器了
PC访问R1
编辑缺省路由
R2
[r2]ip route-static 0.0.0.0 0 192.168.1.2
[r2]ip route-static 0.0.0.0 0 192.168.1.6 preference 61
R1
[R1]ip route-static 192.168.1.128 25( 192.168.1.1
[R1]ip route-static 192.168.1.128 25 192.168.1.5 preference 61
运营商网络:
IP配置
R1
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]ip address 13.0.0.1 24
R3
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]ip address 13.0.0.3 24
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip address 34.0.0.3 24
[R3-GigabitEthernet0/0/1]int g0/0/2
[R3-GigabitEthernet0/0/2]ip address 35.0.0.3 24
R3环回:
[R3]INT L 0
[R3-LoopBack0]ip address 3.3.3.3 24
R4:
[r4]int g0/0/0
[r4-GigabitEthernet0/0/0]ip address 34.0.0.4 24
[r4-GigabitEthernet0/0/1]ip address 100.1.1.254 24
R5:
[R5-GigabitEthernet0/0/0]ip address 35.0.0.5 24
[R5-GigabitEthernet0/0/0]int g0/0/1
[R5-GigabitEthernet0/0/1]ip address 56.0.0.5 24
内部网络设置:
R3:
[R3]rip 1
[R3-rip-1]verify-source
[R3-rip-1]version 2
[R3-rip-1]network 13.0.0.0
[R3-rip-1]network 34.0.0.0
[R3-rip-1]network 35.0.0.0
R4:
[r4]rip 1
[r4-rip-1]verify-source
[r4-rip-1]version 2
[r4-rip-1]network 34.0.0.0
[r4-rip-1]network 100.0.0.0
[r4-rip-1]network 100.1.1.0
R5:
[R5]RIP 1
[R5-rip-1]verify-source
[R5-rip-1]version 2
[R5-rip-1]network 35.0.0.0
[R5-rip-1]network 56.0.0.0
百度网络设置:
R6:
[R6]int g0/0/1
[R6-GigabitEthernet0/0/1]ip add
[R6-GigabitEthernet0/0/1]ip address 200.1.1.254 24
百度服务器:
DNS服务器:
内部就可以通讯了
区域互通:
缺省路由:
[R1]ip route-static 0.0.0.0 0 13.0.0.3
NAT:先抓流量,再做地址转换
[R1]acl 2000
[R1-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
设定一个nat的地址池包含公有IP地址
[R1]nat address-group 1 13.0.0.10 13.0.0.10
[R1]int g 0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000 address-group 1PC就可以连接3.3.3.3和DNS网络了
R6路由:
[R6]ip route-static 0.0.0.0 0 56.0.0.5,补充完后就可以连接DNS服务器
修改百度的http服务器地址:
配置R6的端口:
[R6]int g0/0/1
[R6-GigabitEthernet0/0/1]ip address 172.16.1.254 24
设置端口映射:
[R6]int g0/0/0
[R6-GigabitEthernet0/0/0]nat server protocol tcp global current-interface 80 ins
ide 172.16.1.1 80
设置NAT:
R6]acl 2000
[R6-acl-basic-2000]rule permit source 172.16.1.0 0.0.0.255
[R6]interface g0/0/0
[R6-GigabitEthernet0/0/0]nat outbound 2000
校园网服务器就可以访问百度服务器了
修改DNS和校园网服务器
可以连接了
拓展:
先删除原本设置的端口映射
[R6]interface g0/0/0
[R6-GigabitEthernet0/0/0]dis th
[R6-GigabitEthernet0/0/0]undo nat server protocol tcp global current-interface www inside 172.16.1.1 www
修改为:
[R6-GigabitEthernet0/0/0]nat server protocol tcp global current-interface 8080 i
nside 172.16.1.1 www
PC2不允许访问3.3.3.3
[r2]acl 3000
[r2-acl-adv-3000]rule deny ip source 192.16.1.253 0.0.0.0 destination 3.3.3.3 0
[r2]int g0/0/0.3
[r2-GigabitEthernet0/0/0.3]traffic-filter inbound acl 3000
AR1可以被telnet远程控制
aaa是认证授权计费
[R1]user-interface vty 0 4
[R1-ui-vty0-4]authentication-mode aaa
cipher密文文本形式保存
[R1]aaa
[R1-aaa]local-user huawei password cipher 123456
[R1-aaa]local-user huawei privilege level 15
修改服务类型:
[R1-aaa]local-user huawei service-type telnet