实验报告
一、拓扑信息
二、要求及分析
要求:
1.私网使用172.16.0.0/16网段进行划分
2.R1、R2、R3各存在两个环回接口充当用户网段
3.内网使用OSPF实现路由可达
4.R1和R3身上环回地址可以访问R6,但是R2的环回不可以访问R6,但是可以访问R5
5.R1和R6开启telnet服务,R6充当telnet客户端登录R1和R2,R5可以登录R1但是不能登录R2
6.实现全网可达
分析:
1.对172.16.0.0/16进行网段划分,再进行IP分配。
2.在私网中进行ospf配置,关联路由器中的回环和物理接口。
3.在边界路由器R4上使用NAT技术连通私网和公网的设备。
4.R1,R2,R6开启Telnet服务
5.在边界路由器R4上使用高级ACL添加规则,保证要求。
6.在R2的物理接口处配置高级ACL保证R5不能登录R2
三、配置
AR1
ip配置
[r1]int g 0/0/0
[r1-GigabitEthernet0/0/0]ip add 172.16.0.1 19
[r1-GigabitEthernet0/0/0]int l 0
[r1-LoopBack0]ip add 172.168.64.1 19
[r1-LoopBack0]int l 1
[r1-LoopBack1]ip add 172.168.96.1 19
OSPF
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]network 172.16.64.1 0.0.0.0
[r1-ospf-1-area-0.0.0.0]network 172.16.96.1 0.0.0.0
[r1-ospf-1-area-0.0.0.0]network 172.16.0.1 0.0.0.0
Telnet服务
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mode aaa
[r1-aaa]local-user huawei password cipher 123456
[r1-aaa]local-user huawei service-type telnet
[r1-aaa]local-user huawei privilege level 15
AR2
[r2]int g 0/0/0
[r2-GigabitEthernet0/0/0]ip add 172.16.0.2 19
[r2-GigabitEthernet0/0/0]int l 0
[r2-LoopBack0]ip add 172.16.128.1 19
[r2-LoopBack0]int l 1
[r2-LoopBack1]ip add 172.16.160.1 19
OSPF
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 172.16.128.1 0.0.0.0
[r2-ospf-1-area-0.0.0.0]network 172.16.160.1 0.0.0.0
[r2-ospf-1-area-0.0.0.0]network 172.16.0.2 0.0.0.0
Telnet服务
[r2]user-interface vty 0 4
[r2-ui-vty0-4]authentication-mode aaa
[r2-aaa]local-user huawei password cipher 123456
[r2-aaa]local-user huawei service-type telnet
[r2-aaa]local-user huawei privilege level 15
高级ACL
[r2]acl 3200
[r2-acl-adv-3200]rule deny tcp source 45.0.0.2 0 destination 172.16.0.2 0 destination-port eq 23
[r2-acl-adv-3200]int g 0/0/0
[r2-GigabitEthernet0/0/0]traffic-filter inbound acl 3200
AR3
[r3]int g 0/0/0
[r3-GigabitEthernet0/0/0]ip add 172.16.0.3 19
[r3-GigabitEthernet0/0/0]int l 0
[r3-LoopBack0]ip add 172.16.192.1 19
[r3-LoopBack0]int l 1
[r3-LoopBack1]ip add 172.16.224.1 19
OSPF
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 172.16.192.1 0.0.0.0
[r3-ospf-1-area-0.0.0.0]network 172.16.224.1 0.0.0.0
[r3-ospf-1-area-0.0.0.0]network 172.16.0.3 0.0.0.0
AR4
[r4]int g 0/0/0
[r4-GigabitEthernet0/0/0]ip add 172.16.32.2 19
[r4-GigabitEthernet0/0/0]int g 0/0/1
[r4-GigabitEthernet0/0/1]ip add 45.0.0.1 24
OSPF
[r4]ospf 1 router-id 4.4.4.4
[r4-ospf-1]area 0
[r4-ospf-1-area-0.0.0.0]network 172.16.32.2 0.0.0.0
静态路由
[r4]ip route-static 0.0.0.0 0 45.0.0.2
Easy-ip技术
[r4]acl 2000
[r4-acl-basic-2000]rule permit source 172.16.0.0 0.0.31.255
[r4-acl-basic-2000]rule permit source 172.16.32.0 0.0.31.255
[r4-acl-basic-2000]rule permit source 172.16.64.0 0.0.63.255
[r4-acl-basic-2000]rule permit source 172.16.128.0 0.0.63.255
[r4-acl-basic-2000]rule permit source 172.16.192.0 0.0.63.255
[r4-GigabitEthernet0/0/1]nat outbound 2000
高级ACL
[r4]acl 3000
[r4-acl-adv-3000]rule 5 permit ip source 172.16.64.1 0 destination 56.0.0.2 0
[r4-acl-adv-3000]rule 10 permit ip source 172.16.96.1 0 destination 56.0.0.2 0
[r4-acl-adv-3000]rule 15 permit ip source 172.16.192.1 0 destination 56.0.0.2 0
[r4-acl-adv-3000]rule 20 permit ip source 172.16.224.1 0 destination 56.0.0.2 0
[r4-acl-adv-3000]rule 25 deny ip source 172.16.128.1 0 destination 56.0.0.2 0
[r4-acl-adv-3000]rule 30 deny ip source 172.16.160.1 0 destination 56.0.0.2 0
[r4-acl-adv-3000]int g 0/0/0
[r4-GigabitEthernet0/0/0]traffic-filter inbound acl 3000
端口映射(可写可不写)
[r4]int g 0/0/1
[r4-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 10000
inside 172.16.0.1 23
[r4-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 20000
inside 172.16.0.2 23
AR5
[r5]int g 0/0/0
[r5-GigabitEthernet0/0/0]ip add 45.0.0.2 24
[r5]int g 0/0/1
[r5-GigabitEthernet0/0/1]ip add 56.0.0.1 24
AR6
[r6]int g 0/0/0
[r6-GigabitEthernet0/0/0]ip add 56.0.0.2 19
静态路由(可写可不写)
[r6]ip route-static 0.0.0.0 0 56.0.0.1