文章目录
1. NAT:
私网地址:
类地址 | 地址 | 表示方法 | 解释 |
---|---|---|---|
A | 10.0.0.0-10.255.255.255 | 10.0.0.0/8 | 16百万 |
B | 172.16.0.0-172.31.255.255 | 172.16.0.0/12 | 172.(00010000)——172.(00011111)1百万6000 |
C | 192.168.0.0-192.168.255.255 | 192.168.0.0/16 | 65535 |
内部本地地址/内部全局地址/外部全局地址/外部本地地址
静态NAT:公有地址 私有地址 1对1转换:
[Huawei]inter g0/0/1
[Huawei-GigabitEthernet0/0/1]nat static global 58.211.1.1 inside 192.168.1.1
静态NAT端口映射:公有地址+端口号 映射 私有地址+端口号:
[Huawei]inter g0/0/1
[Huawei-GigabitEthernet0/0/1]nat static protocol tcp global 58.211.1.3 23 inside 192.168.1.13 23
可从外部telnet
动态NAT:多对多 和 多对一
多对多转换:No-PAT
No-PAT:只转换源IP地址,不转换端口,拿完了多余的请求就会被拒绝掉
[Huawei]inter g0/0/1
[Huawei-GigabitEthernet0/0/1]dis this
[Huawei-GigabitEthernet0/0/1]undo nat static global 58.211.1.1 inside 192.168.1.1
[Huawei-GigabitEthernet0/0/1]undo nat static global 58.211.1.2 inside 192.168.1.2
[Huawei-GigabitEthernet0/0/1]undo nat static global 58.211.1.13 inside 192.168.1.3
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[Huawei]nat address-group 1 58.211.1.10 58.211.1.100
[Huawei]inter g0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2000 address-group 1 no-pat
多对一转换:PAT / Easy-IP
加上端口号,根据端口号区分内部主机
inter g0/0/0
[Huawei-GigabitEthernet0/0/1]un nat outbound 2000 address-group 1 no-pat
[Huawei]undo nat address-group 1
inter g0/0/0
[Huawei-GigabitEthernet0/0/0]nat outbound 2000
2.DHCP:
使用UDP协议,
客户端端口号68
服务器端口67
服务器67: 客户端68
<--------------- DHCPDiscover
DHCPOffer ---------------->
<--------------- DHCPRequest
DHCPACK ---------------->
基于接口地址池的DHCP:
以路由器接口所在网段作为地址池
[Huawei]inter g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 10.1.1.254 24
[Huawei]dhcp enable
[Huawei]inter g0/0/0
[Huawei-GigabitEthernet0/0/0]dhcp select interface 开启基于接口的地址池配置
[Huawei-GigabitEthernet0/0/0]dhcp server excluded-ip-address 10.1.1.1 10.1.1.10 排除一些地址
[Huawei-GigabitEthernet0/0/0]dhcp server lease day 1 hour 10 minute 30 配置租期
[Huawei-GigabitEthernet0/0/0]dhcp server dns-list 8.8.8.8 114.114.114.114 配置DNS
[Huawei]dis ip pool 查看分配情况
路由器端口获取IP地址:
[Huawei]dhcp enable
[Huawei]inter g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add dhcp-alloc
配置基于全局地址池的DHCP:
不管从哪个端口进来的请求包,都可以从全局地址池中取出一个给你分配
[Huawei]inter g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 10.1.1.254 24
[Huawei]dhcp e
[Huawei]ip pool net-10-1
[Huawei-ip-pool-net-10-1]network 10.1.1.0 mask 24 范围
[Huawei-ip-pool-net-10-1]gateway-list 10.1.1.254 网关
[Huawei-ip-pool-net-10-1]excluded-ip-address 10.1.1.1 10.1.1.10
[Huawei-ip-pool-net-10-1]dns-list 8.8.8.8
[Huawei-ip-pool-net-10-1]lease day 2 hour 8 minute 30
[Huawei-ip-pool-net-10-1]inter g0/0/0
[Huawei-GigabitEthernet0/0/0]dhcp select global 在接口下开启功能
PC>ipconfig /release
PC>ipconfig /renew
PC>ipconfig
DHCP 中继:
实现跨网段拿地址
DHCP服务器:
[Huawei]dhcp enable
[Huawei]ip pool net-20
[Huawei-ip-pool-net-20]network 20.1.1.0 mask 24
[Huawei-ip-pool-net-20]gateway-list 20.1.1.254
[Huawei-ip-pool-net-20]excluded-ip-address 20.1.1.1 20.1.1.10
[Huawei-ip-pool-net-20]dns-list 8.8.8.8
[Huawei-ip-pool-net-20]lease day 2
[Huawei-ip-pool-net-20]inter g0/0/2
[Huawei-GigabitEthernet0/0/2]dhcp select global
DHCP中继:
[Huawei]dhcp enable
[Huawei]inter g0/0/0
[Huawei-GigabitEthernet0/0/0]dhcp select relay
[Huawei-GigabitEthernet0/0/0]dhcp relay server-ip 12.1.1.1
3.VRRP:
VRRP:网关冗余协议/第1跳冗余协议,将两个或多个网关地址虚拟成一个地址,实现网关自动切换
而路由协议的优先级和cost:是第2跳冗余协议或负载均衡
组播地址:224.0.0.18
hello包:1s
hold time :3s
VRRP配在路由器的接口下:
[R2]inter g0/0/2
[R2-GigabitEthernet0/0/2]vrrp vrid 1 virtual-ip 10.1.1.250
[R2-GigabitEthernet0/0/2]vrrp vrid 1 priority 110 设置优先级,默认100
[R3]inter g0/0/2
[R3-GigabitEthernet0/0/2]vrrp vrid 1 virtual-ip 10.1.1.250
[R2]dis vrrp br 查看vrrp信息
[R3]dis vrrp
tracert 100.1.1.1
选举主/从网关:
①先看接口的优先级,大
②看接口的IP地址,大
抢占默认开启:
[R3-GigabitEthernet0/0/2]vrrp vrid 1 preempt-mode timer delay 10 10s内的网络问题不要抢占
[R3-GigabitEthernet0/0/2]vrrp vrid 1 preempt-mode disable 关闭抢占
验证:
[R3-GigabitEthernet0/0/2]vrrp vrid 1 authentication-mode md5 123456
[R2-GigabitEthernet0/0/2]vrrp vrid 1 authentication-mode md5 123456
配置多组VRRP实现负载均衡:
[R2]inter g0/0/2
[R2-GigabitEthernet0/0/2]vrrp vrid 2 virtual-ip 10.1.1.251
[R3-GigabitEthernet0/0/2]inter g0/0/2
[R3-GigabitEthernet0/0/2]vrrp vrid 2 virtual-ip 10.1.1.251
[R3-GigabitEthernet0/0/2]vrrp vrid 2 priority 110
监测上行口故障,有故障网关进行切换:
[R2]inter g0/0/2
[R2-GigabitEthernet0/0/2]vrrp vrid 1 track inter g0/0/0 reduced 20