一、实验拓扑
- 实验的技术有:
vlan的划分、vlan间的通信、静态路由、基本acl、easy-ip
- 实验要求:
VLAN之间进行通信
用easy-ip是内网访问外网
实验步骤:
LSW1交换机划分VLAN:
<Huawei>system-view //进入系统视图
[Huawei]undo info-center enable //关闭路由器输出信息
[Huawei]sysname LSW1 //修改设备名为LSW1
[LSW1]vlan batch 10 20 //创建 vlan 10 20
[LSW1]interface e0/0/1 //进入接口e0/0/1
[LSW1-Ethernet0/0/1]port link-type access //设置为 access模式
[LSW1-Ethernet0/0/1]port default vlan 10 //默认vlan为10
[LSW1-Ethernet0/0/1]undo shutdown //打开接口
[LSW1-Ethernet0/0/1]interface e0/0/2 //进入接口e0/0/2
[LSW1-Ethernet0/0/2]port link-type access //设置为access模式
[LSW1-Ethernet0/0/2]port default vlan 20 //默认vlan 为20
[LSW1-Ethernet0/0/2]undo shutdown //打开接口
[LSW1-Ethernet0/0/2]interface e0/0/3 //进入接口e0/0/3
[LSW1-Ethernet0/0/3]port link-type access //设置为access模式
[LSW1-Ethernet0/0/3]port default vlan 10 //设置默认vlan 为 10
[LSW1-Ethernet0/0/3]undo shutdown //打开接口
[LSW1-Ethernet0/0/3]interface g0/0/1 //进入接口g0/0/1
[LSW1-GigabitEthernet0/0/1]port link-type trunk //设置trunk模式
[LSW1-GigabitEthernet0/0/1]port trunk allow-pass vlan all 设置所有vlan允许通过
[LSW1-GigabitEthernet0/0/1]undo shutdown //开启端口
[LSW1-GigabitEthernet0/0/1]int g0/0/2 //进入接口g0/0/2
[LSW1-GigabitEthernet0/0/2]port link-type trunk //设置trunk 模式
[LSW1-GigabitEthernet0/0/2]port trunk allow-pass vlan all 设置所有vlan允许通过
[LSW1-GigabitEthernet0/0/2]undo shutdown //打开接口
[LSW1-GigabitEthernet0/0/2]quit //退出
LSW2交换机设置VLANIF
<Huawei>system-view //进入系统视图
[Huawei]undo info-center enable //关闭路由器输出信息
[Huawei]sysname LSW2 //修改设备名为 LSW2
[LSW2]vlan batch 10 20 100 //创建vlan 10 20 100
[LSW2]interface vlanif 10 //进入虚拟接口vlanif 10
[LSW2-Vlanif10]ip add 192.168.10.10 24 // 设置接口IP
[LSW2-Vlanif10]vrrp vrid 1 virtual-ip 192.168.10.1 //设置虚拟IP
[LSW2-Vlanif10]vrrp vrid 1 priority 120 //设置优先级120
[LSW2-Vlanif10]vrrp vrid 1 preempt-mode timer delay 5 //设置抢占时间5s
[LSW2-Vlanif10]vrrp vrid 1 track int g0/0/2 reduced 30 //监控上行接口
[LSW2-Vlanif10]vrrp vrid 1 track int g0/0/1 reduced 30 //监控下行接口
[LSW2-Vlanif10]di th //查看所有配置
#
interface Vlanif10
ip address 192.168.10.10 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.10.1
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 5
vrrp vrid 1 track interface GigabitEthernet0/0/2 reduced 30
vrrp vrid 1 track interface GigabitEthernet0/0/1 reduced 30
#
return
[LSW2-Vlanif10]quit
[LSW2]int vlanif 20 //进入虚拟接口vlanif 20
[LSW2-Vlanif20]ip add 192.168.20.20 24 //配置接口IP
[LSW2-Vlanif20]vrrp vrid 2 virtual-ip 192.168.20.1 //配置虚拟IP
[LSW2-Vlanif20]di th //查看配置
#
interface Vlanif20
ip address 192.168.20.20 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.20.1
#
return
[LSW2-Vlanif20]quit
[LSW2]interface g0/0/1 //进入接口g0/0/1
[LSW2-GigabitEthernet0/0/1]port link-type trunk //配置trunk模式
[LSW2-GigabitEthernet0/0/1]port trunk allow-pass vlan all //设置所有vlan允许通过
[LSW2-GigabitEthernet0/0/1]di th //查看配置
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
return
[LSW2-GigabitEthernet0/0/1]undo shutdown //启动接口
Info: Interface GigabitEthernet0/0/1 is not shutdown.
[LSW2-GigabitEthernet0/0/1]quit //返回
[LSW2]int vlanif 100 //进入虚拟接口vlanif100
[LSW2-Vlanif100]ip add 10.0.0.10 24 //设置接口IP
[LSW2-Vlanif100]quit //返回
[LSW2]interface g0/0/2 //进入g0/0/2接口
[LSW2-GigabitEthernet0/0/2]port link-type access //设置access模式
[LSW2-GigabitEthernet0/0/2]port default vlan 100 //设置默认 vlan100
[LSW2-GigabitEthernet0/0/2]undo shutdown //开启接口
[LSW2-GigabitEthernet0/0/2]di th //查看配置
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 100
#
return
[LSW2-GigabitEthernet0/0/2]q
[LSW2]ip route-static 0.0.0.0 0.0.0.0 10.0.0.1 //配置默认路由
LSW3交换机设置VLANIF
<Huawei>sys //进入系统视图
[Huawei]sysname LSW3 //修改设备名为 LSW3
[LSW3]undo info-center enable //关闭路由器输出信息
[LSW3]vlan batch 10 20 100 //创建vlan 10 20 100
[LSW3]int vlanif 10 //进入虚拟接口vlanif10
[LSW3-Vlanif10]ip add 192.168.10.20 24 //设置接口IP
[LSW3-Vlanif10]vrrp vrid 1 virtual-ip 192.168.10.1 //设置虚拟IP
[LSW3-Vlanif10]di th //查看接口
#
interface Vlanif10
ip address 192.168.10.20 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.10.1
#
return
[LSW3-Vlanif10]quit
[LSW3]int vlanif 20 //进入虚拟接口vlanif 20
[LSW3-Vlanif20]ip add 192.168.20.10 24 //设置接口IP
[LSW3-Vlanif20]vrrp vrid 2 virtual-ip 192.168.20.1 //设置虚拟IP
[LSW3-Vlanif20]vrrp vrid 2 priority 120 //设置优先级120
[LSW3-Vlanif20]vrrp vrid 2 preempt-mode timer delay 5 //设置抢占时间5s
[LSW3-Vlanif20]vrrp vrid 2 track int g0/0/2 reduced 30 //监控上行接口
[LSW3-Vlanif20]vrrp vrid 2 track int g0/0/1 reduced 30 //监控下行接口
[LSW3-Vlanif20]di th //查看命令
#
interface Vlanif20
ip address 192.168.20.10 255.255.255.0
vrrp vrid 2 virtual-ip 192.168.20.1
vrrp vrid 2 priority 120
vrrp vrid 2 preempt-mode timer delay 5
vrrp vrid 2 track interface GigabitEthernet0/0/2 reduced 30
vrrp vrid 2 track interface GigabitEthernet0/0/1 reduced 30
#
return
[LSW3-Vlanif20]quit
[LSW3]int vlanif 100 //进入虚拟接口vlanif 100
[LSW3-Vlanif100]ip add 11.0.0.20 24 //设置接口IP
[LSW3-Vlanif100]int g0/0/2 //进入接口g0/0/2
[LSW3-GigabitEthernet0/0/2]port link-type access //设置access模式
[LSW3-GigabitEthernet0/0/2]port default vlan 100 //默认vlan100
[LSW3-GigabitEthernet0/0/2]undo shutdown //开启接口
[LSW3-GigabitEthernet0/0/2]di th //查看配置
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 100
#
return
[LSW3-GigabitEthernet0/0/2]int g0/0/1 //进入g0/0/1接口
[LSW3-GigabitEthernet0/0/1]port link-type trunk //设置trunk模式
[LSW3-GigabitEthernet0/0/1]port trunk allow-pass vlan all //设置允许所有vlan通过
[LSW3-GigabitEthernet0/0/1]undo shutdown //开启端口
[LSW3-GigabitEthernet0/0/1]di th //查看端口
#
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#
return
[LSW3-GigabitEthernet0/0/1]q
[LSW3]ip route-static 0.0.0.0 0.0.0.0 11.0.0.1 //设置默认路由
测试PC1ping通PC2
然后进行路由器的配置
路由器R1的配置
<Huawei>sys //进入系统视图
[Huawei]undo info-center enable //关闭路由器输出信息
[Huawei]sysname R1 //修改设备名为 R1
[R1]int g0/0/0 //进入接口g0/0/0
[R1-GigabitEthernet0/0/0]ip add 11.0.0.1 24 //设置接口IP
[R1-GigabitEthernet0/0/0]undo shutdown //开启接口
[R1-GigabitEthernet0/0/0]int g0/0/1 //进入接口g0/0/1
[R1-GigabitEthernet0/0/1]ip add 10.0.0.1 24 //设置接口IP
[R1-GigabitEthernet0/0/1]undo shutdown //开启接口
[R1-GigabitEthernet0/0/1]int g0/0/2 //进入接口g0/0/2
[R1-GigabitEthernet0/0/2]ip add 12.0.0.1 24 //设置接口IP
[R1-GigabitEthernet0/0/2]undo shutdown //开启接口
[R1-GigabitEthernet0/0/2]q //退出
#设置静态路由
[R1]ip route-static 192.168.10.0 255.255.255.0 10.0.0.10
[R1]ip route-static 192.168.10.0 255.255.255.0 11.0.0.20 preference 70
[R1]ip route-static 192.168.20.0 255.255.255.0 11.0.0.20
[R1]ip route-static 192.168.20.0 255.255.255.0 10.0.0.10
[R1]ip route-static 192.168.100.0 255.255.255.0 12.0.0.2
[R1]ip route-static 192.168.200.0 255.255.255.0 12.0.0.2
路由器R2的配置
<Huawei>sys //进入系统视图
[Huawei]undo info-center enable //关闭路由器输出信息
[Huawei]sysname R2 //修改设备名
[R2]int g0/0/0 //进入接口g0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.0.0.2 24 //设置接口IP
[R2-GigabitEthernet0/0/0]undo shutdown //打开接口
[R2-GigabitEthernet0/0/0]int g0/0/1 //进入接口g0/0/1
[R2-GigabitEthernet0/0/1]ip add 23.0.0.1 24 //设置接口IP
[R2-GigabitEthernet0/0/1]undo shutdown //打开接口
[R2-GigabitEthernet0/0/1]q //退出
#设置静态路由
[R2]ip route-static 192.168.10.0 255.255.255.0 12.0.0.1
[R2]ip route-static 192.168.20.0 255.255.255.0 12.0.0.1
[R2]ip route-static 192.168.100.0 255.255.255.0 23.0.0.2
[R2]ip route-static 192.168.200.0 255.255.255.0 23.0.0.2
路由器R3的配置
<Huawei>sys //进入系统视图
[Huawei]undo info-center enable //关闭路由器输出信息
[Huawei]sysname R3 //修改设备名为 R3
[R3]int g0/0/0 //进入接口g0/0/0
[R3-GigabitEthernet0/0/0]ip add 23.0.0.2 24 //配置接口IP
[R3-GigabitEthernet0/0/0]undo shutdown //启动接口
[R3-GigabitEthernet0/0/0]q /退出/
[R3]int g0/0/1 //进入接口g0/0/1
[R3-GigabitEthernet0/0/1]ip add 192.168.100.1 24 //配置接口IP
[R3-GigabitEthernet0/0/1]undo shutdown //打开接口
[R3-GigabitEthernet0/0/1]int g0/0/2 //进入接口g0/0/2
[R3-GigabitEthernet0/0/2]ip add 192.168.200.1 24 //配置接口IP
[R3-GigabitEthernet0/0/2]undo shutdown //开启接口
[R3-GigabitEthernet0/0/2]q
配置静态路由
[R3]ip route-static 0.0.0.0 0.0.0.0 23.0.0.1
下一跳23.0.0.1
最后在R1上进行ACL和esay-ip的配置
[R1]acl 2000 //创建acl 2000
[R1-acl-basic-2000]rule permit source 192.168.10.0 0.0.0.255 //允许192.168.10.0网段IP地址通过
Easy-ip
[R1-acl-basic-2000]int g0/0/2 //进入g0/0/2接口
[R1-GigabitEthernet0/0/2]nat outbound 2000 //将acl配置的映射在这个接口上
[R1-GigabitEthernet0/0/2]quit //退出
[R1]dis nat outbound //查看nat映射表
NAT Outbound Information:
--------------------------------------------------------------------------
Interface Acl Address-group/IP/Interface Type
--------------------------------------------------------------------------
GigabitEthernet0/0/2 2000 12.0.0.1 easyip
--------------------------------------------------------------------------
Total : 1
最后测试PC去ping通PC3