一、使用172.16.0.0/16划分网络
172.16.0.0 18
172.16.64.0 18
172.16.128.0 18
172.16.192.0 18
配IP
[Huawei]sys r7
[r7]interface g0/0/0
[r7-GigabitEthernet0/0/0]ip address 10.1.1.1 24
[r7]interface g0/0/1
[r7-GigabitEthernet0/0/1]ip address 11.1.1.1 24
[r7]interface LoopBack 0
[r7-LoopBack0]ip address 7.7.7.7 32
[Huawei]sys r6
[r6]interface g0/0/1
[r6-GigabitEthernet0/0/1]ip address 10.1.1.2 24
[r6]interface g0/0/0
[r6-GigabitEthernet0/0/0]ip address 172.16.64.2 18
[r6]interface LoopBack 0
[r6-LoopBack0]ip address 6.6.6.6 32
[Huawei]sys r1
[r1]interface g0/0/1
[r1-GigabitEthernet0/0/1]ip address 172.16.64.1 18
[r1]interface g0/0/0
[r1-GigabitEthernet0/0/0]ip address 172.168.0.1 18
[r1]interface LoopBack 0
[r1-LoopBack0]ip address 1.1.1.1 32
[Huawei]sys r2
[r2]interface g0/0/0
[r2-GigabitEthernet0/0/0]ip address 172.16.0.2 18
[r2]interface g0/0/1
[r2-GigabitEthernet0/0/1]ip address 192.16.128.1 18
[r2]interface LoopBack 0
[r2-LoopBack0]ip address 2.2.2.2 32
[Huawei]sys r8
[r8]interface g0/0/0
[r8-GigabitEthernet0/0/0]ip address 172.16.128.2 18
[r8]interface LoopBack 0
[r8-LoopBack0]ip address 8.8.8.8 32
[r8]interface g0/0/1.1
[r8-GigabitEthernet0/0/1.1]ip address 192.168.1.1 24
[r8]interface g0/0/1.2
[r8-GigabitEthernet0/0/1.2]ip address 192.168.2.1 24
[Huawei]sys r3
[r3]interface g0/0/0
[r3-GigabitEthernet0/0/0]ip address 172.16.0.3 18
[r3]interface g0/0/1
[r3-GigabitEthernet0/0/1]ip address 172.16.192.1 18
[r3]interface LoopBack 0
[r3-LoopBack0]ip address 3.3.3.3 32
[Huawei]sys r4
[r4]interface g0/0/0
[r4-GigabitEthernet0/0/0]ip address 172.16.192.2 18
[r4]interface g0/0/1.1
[r4-GigabitEthernet0/0/1.1]ip address 192.168.3.1 24
[r4]interface g0/0/1.2
[r4-GigabitEthernet0/0/1.2]ip address 192.168.4.1 24
[r4]interface LoopBack 0
[r4-LoopBack0]ip address 4.4.4.4 32
二、配ospf
[r6]ospf 1 router-id 6.6.6.6
[r6-ospf-1]area 1
[r6-ospf-1-area-0.0.0.1]network 6.6.6.6 0.0.0.0
[r6-ospf-1-area-0.0.0.1]network 172.16.64.2 0.0.0.0
[r1]ospf 1 router-id 1.1.1.1
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]network 172.16.64.1 0.0.0.0
[r1-ospf-1-area-0.0.0.1]network 1.1.1.1 0.0.0.0
[r1-ospf-1-area-0.0.0.1]area 0
[r1-ospf-1-area-0.0.0.0]network 172.16.0.1 0.0.0.0
[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]network 172.16.0.2 0.0.0.0
[r2-ospf-1-area-0.0.0.0]area 2
[r2-ospf-1-area-0.0.0.2]network 2.2.2.2 0.0.0.0
[r2-ospf-1-area-0.0.0.2]network 172.16.128.1 0.0.0.0
[r8]ospf 1 router-id 8.8.8.8
[r8-ospf-1]area 2
[r8-ospf-1-area-0.0.0.2]network 8.8.8.8 0.0.0.0
[r8-ospf-1-area-0.0.0.2]network 172.16.128.2 0.0.0.0
[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]network 172.16.0.3 0.0.0.0
[r3-ospf-1-area-0.0.0.0]area 3
[r3-ospf-1-area-0.0.0.3]network 3.3.3.3 0.0.0.0
[r3-ospf-1-area-0.0.0.3]network 172.16.192.1 0.0.0.0
[r4]ospf 1 router-id 4.4.4.4
[r4-ospf-1]area 3
[r4-ospf-1-area-0.0.0.3]network 172.16.192.2 0.0.0.0
[r4-ospf-1-area-0.0.0.3]network 4.4.4.4 0.0.0.0
保证更新安全明文
[r6]ospf 1
[r6-ospf-1]area 1
[r6-ospf-1-area-0.0.0.1]authentication-mode simple cipher 123
[r1]ospf 1
[r1-ospf-1]area 1
[r1-ospf-1-area-0.0.0.1]authentication-mode simple cipher 123
[r1]ospf 1
[r1-ospf-1]area 0
[r1-ospf-1-area-0.0.0.0]authentication-mode simple cipher 123
[r2]ospf 1
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]authentication-mode simple cipher 123
[r3]ospf 1
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]authentication-mode simple cipher 123
[r2]ospf 1
[r2-ospf-1]area 2
[r2-ospf-1-area-0.0.0.2]authentication-mode simple cipher 123
[r8]ospf 1
[r8-ospf-1]area 2
[r8-ospf-1-area-0.0.0.2]authentication-mode simple cipher 123
[r3]ospf 1
[r3-ospf-1]area 3
[r3-ospf-1-area-0.0.0.3]authentication-mode simple cipher 123
[r4]ospf 1
[r4-ospf-1]area 3
[r4-ospf-1-area-0.0.0.3]authentication-mode simple cipher 123
三、加快收敛速度
[r6-GigabitEthernet0/0/0]ospf timer hello 5
[r1-GigabitEthernet0/0/0]ospf timer hello 5
[r1-GigabitEthernet0/0/1]ospf timer hello 5
[r2-GigabitEthernet0/0/1]ospf timer hello 5
[r2-GigabitEthernet0/0/0]ospf timer hello 5
[r8-GigabitEthernet0/0/0]ospf timer hello 5
[r3-GigabitEthernet0/0/0]ospf timer hello 5
[r3-GigabitEthernet0/0/1]ospf timer hello 5
[r4-GigabitEthernet0/0/0]ospf timer hello 5
四、router1为DR没有BDR干涉选举
[r6-GigabitEthernet0/0/1]ospf dr-priority 0
[r2-GigabitEthernet0/0/0]ospf dr-priority 0
[r3-GigabitEthernet0/0/0]ospf dr-priority 0
五、pc2345自动获取ip地址,pc1为外网pc要求可以互相访问
[Huawei]vlan batch 2 3
[Huawei]interface e0/0/1
[Huawei-Ethernet0/0/1]port link-type trunk
[Huawei-Ethernet0/0/1]port trunk allow-pass vlan all
[Huawei]interface e0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 2
[Huawei]interface e0/0/3
[Huawei-Ethernet0/0/3]port link-type access
[Huawei-Ethernet0/0/3]port default vlan 3
[r8]dhcp enable
[r8]ip pool 1
[r8-ip-pool-1]network 192.168.1.0 mask 24
[r8-ip-pool-1]gateway-list 192.168.1.1
[r8-ip-pool-1]dns-list 8.8.8.8
[r8]ip pool 2
[r8-ip-pool-2]network 192.168.2.0 mask 24
[r8-ip-pool-2]gateway-list 192.168.2.1
[r8-ip-pool-2]dns-list 8.8.8.8
[r8]interface g0/0/1.1
[r8-GigabitEthernet0/0/1.1]dhcp select global
[r8-GigabitEthernet0/0/1.1]dot1q termination vid 2
[r8-GigabitEthernet0/0/1.1]arp broadcast enable
[r8]interface g0/0/1.2
[r8-GigabitEthernet0/0/1.2]dhcp select global
[r8-GigabitEthernet0/0/1.2]dot1q termination vid 3 [r8-GigabitEthernet0/0/1.2]arp broadcast enable
[Huawei]vlan batch 2 3
[Huawei]interface e0/0/1
[Huawei-Ethernet0/0/1]port link-type trunk
[Huawei-Ethernet0/0/1]port trunk allow-pass vlan all
[Huawei]interface e0/0/2
[Huawei-Ethernet0/0/2]port link-type access
[Huawei-Ethernet0/0/2]port default vlan 2
[Huawei]interface e0/0/3
[Huawei-Ethernet0/0/3]port link-type access
[Huawei-Ethernet0/0/3]port default vlan 3
[r4]dhcp enable
[r4]ip pool 3
[r4-ip-pool-3]network 192.168.3.0 mask 24
[r4-ip-pool-3]gateway-list 192.168.3.1
[r4-ip-pool-3]dns-list 8.8.8.8
[r4]ip pool 4
[r4-ip-pool-4]network 192.168.4.0 mask 24
[r4-ip-pool-4]gateway-list 192.168.4.1
[r4-ip-pool-4]dns-list 8.8.8.8
[r4]interface g0/0/1.1
[r4-GigabitEthernet0/0/1.1]dhcp select global
[r4-GigabitEthernet0/0/1.1]dot1q termination vid 2
[r4-GigabitEthernet0/0/1.1]arp broadcast enable
[r4]interface g0/0/1.2
[r4-GigabitEthernet0/0/1.2]dhcp select global
[r4-GigabitEthernet0/0/1.2]dot1q termination vid 3 [r4-GigabitEthernet0/0/1.2]arp broadcast enable
六、router7为运营商只能配置ip地址
[r7]ip pool 5
[r7-ip-pool-5]network 11.1.1.0 mask 24
[r7-ip-pool-5]gateway-list 11.1.1.1
[r7-ip-pool-5]dns-list 8.8.8.8
[r7-ip-pool-5]quit
[r7]interface g0/0/1
[r7-GigabitEthernet0/0/1]dhcp select global
七、pc4可以ping通router6但不能登录router6
[r6]acl 2000
[r6-acl-basic-2000]rule permit source any
[r6-acl-basic-2000]quit
[r6]interface g0/0/1
[r6-GigabitEthernet0/0/1]nat outbound 2000
[r6]user-interface vty 0 4
[r6-ui-vty0-4]authentication-mode password
Please configure the login password (maximum length 16):123
[r4]acl 3000
[r4-acl-adv-3000]rule deny tcp source 192.168.3.0 0.0.0.255 destination 172.16.64.2 0.0.0.0 destination-port eq 23
[r4-acl-adv-3000]quit
[r4]interface g0/0/1.1
[r4-GigabitEthernet0/0/1.1]traffic-filter inbound acl 3000
八、pc3可以ping通pc5但pc5不能ping通pc3
[r4]acl 3001
[r4-acl-adv-3001]rule deny icmp source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 icmp-type echo
[r4-acl-adv-3001]interface g0/0/1.2
[r4-GigabitEthernet0/0/1.2]traffic-filter inbound acl 3001
结果
The device is running!
<r4>display access-user
<r4>display accounting-scheme
<r4>display acl 3000
Advanced ACL3000,2 rules
Acl's step is 5
rule 5 deny iamp source 192.168.4.254 0 destination 192.168.2.254 0 icmp-type echo ( 5 matches)
rule l0 permit ip(1135 matches)
<r5>display acl all
Total quantity of nonempty ACL number is l
Basic ACL2000,1 rule
Aci's step is 5
rule 5 permit
<r5>display acl 2000
Basic ACL2000, l rule
Acl's step is 5
rule 5 permit