一、三层交换主机:
1、建立VLAN:
vlan1 #(管理主VLAN)
vlan 10
vlan 20
vlan 30
2、业务网关:
interface Vlan-interface10
ip address 192.168.1.1 255.255.255.0
#interface Vlan-interface20
ip address 192.168.2.1 255.255.255.0
#interface Vlan-interface30
ip address 192.168.3.1 255.255.255.0
3、与路由器互联地址:
#交换机侧:
vlan 100
#interface Vlan-interface100
ip address 192.168.0.2 255.255.255.252
#路由器侧:
#interface ethernet1/0/1
ip address 192.168.0.2 255.255.255.252
4、交换机缺省路由:
ip route-static 0.0.0.0 0.0.0.0 192.168.0.1
二、路由器配置
1、向交换机的回程路由:
ip route-static 192.168.1.0 255.255.255.0 192.168.0.2
ip route-static 192.168.2.0 255.255.255.0 192.168.0.2
ip route-static 192.168.3.0 255.255.255.0 192.168.0.2
2、路由器缺省路由:
ip route-static 0.0.0.0 0.0.0.0 *.*.*.* (公网地址)
3、NAT转换:
acl number 2000
rule 0 permit
interface ethernet0/1
port link-mode route
nat outbound 2000
ip address *.*.*.* (公网地址)255.255.255.252
#
interface ethernet0/2
port link-mode route
ip address 192.168.0.1 255.255.255.252
对应设备:
交换机:华为S27、S37、S57…华三:S31、S36、S51、S55、S58、S75…
路由器:华为AR12/AR22/AR32/NE系列…
华为三层:MSR900/MSR20/MSR30/MSR50/SR系列