HCIP第一天实验
一、配置ip地址
有14个广播域,骨干链路6个广播域,主机位分4位作为网络位,共16个网段
192.168.1.0/24
192.168.1.0000 xxxx/28
192.168.1.0/31
192.168.1.0000 000 x/31
192.168.1.0000 001 x/31 R1-R2
192.168.1.0000 010 x/31 R2-R4
192.168.1.0000 011 x/31 R4-R5 1000M
192.168.1.0000 100 x/31 R4-R5 100M
192.168.1.0000 101 x/31 R4-R3
192.168.1.0000 110 x/31 R3-R1
192.168.1.0001 xxxx/28 R1L1
192.168.1.0010 xxxx/28 R1L2
192.168.1.0011 xxxx/28 R2L1
192.168.1.0100 xxxx/28 R2L2
192.168.1.0101 xxxx/28 R3
192.168.1.0110 xxxx/28 R4L1
192.168.1.0111 xxxx/28 R4L2
192.168.1.1000 xxxx/28 R5L1
5.5.5.0 /24 公网
5.5.5.1 /24 R5公网接口
6.6.6.6 /24 R6环回接口
二、配置DHCP
[r3]dhcp enable
[r3]ip pool 1
[r3-ip-pool-1]network 192.168.1.80 mask 28
[r3-ip-pool-1]gateway-list 192.168.1.81
[r3-ip-pool-1]dns-list 114.114.114.114 8.8.8.8
[r3-ip-pool-1]q
[r3]int g 0/0/2
[r3-GigabitEthernet0/0/2]dhcp select global
三、添加静态路由
[r1]ip route-static 192.168.1.4 31 192.168.1.3
[r1]ip route-static 192.168.1.10 31 192.168.1.12
[r1]ip route-static 192.168.1.6 31 192.168.1.3
[r1]ip route-static 192.168.1.6 31 192.168.1.12
[r1]ip route-static 192.168.1.8 31 192.168.1.3 preference 70
[r1]ip route-static 192.168.1.8 31 192.168.1.12 preference 70
[r1]ip route-static 192.168.1.80 28 192.168.1.12
[r1]ip route-static 0.0.0.0 0 192.168.1.3
[r2]ip route-static 192.168.1.12 31 192.168.1.2
[r2]ip route-static 192.168.1.10 31 192.168.1.5
[r2]ip route-static 192.168.1.80 28 192.168.1.5
[r2]ip route-static 192.168.1.80 28 192.168.1.2
[r2]ip route-static 192.168.1.6 31 192.168.1.5
[r2]ip route-static 192.168.1.8 31 192.168.1.5 preference 70
[r2]ip route-static 0.0.0.0 0 192.168.1.5
[r3]ip route-static 192.168.1.2 31 192.168.1.13
[r3]ip route-static 192.168.1.4 31 192.168.1.10
[r3]ip route-static 192.168.1.6 31 192.168.1.10
[r3]ip route-static 192.168.1.8 31 192.168.1.10 preference 70
[r3]ip route-static 0.0.0.0 0 192.168.1.10
[r4]ip route-static 192.168.1.2 31 192.168.1.4
[r4]ip route-static 192.168.1.12 31 192.168.1.11
[r4]ip route-static 192.168.1.80 28 192.168.1.11
[r4]ip route-static 0.0.0.0 0 192.168.1.7
[r4]ip route-static 0.0.0.0 0 192.168.1.9 preference 70
[r5]ip route-static 0.0.0.0 0.0.0.0 5.5.5.2
[r5]ip route-static 192.168.1.0 255.255.255.0 192.168.1.6
[r5]ip route-static 192.168.1.0 255.255.255.0 192.168.1.8 preference 70
三、配置虚拟接口
[r1]interface LoopBack 1
[r1-LoopBack1]ip address 192.168.1.17 255.255.255.240
[r1]interface LoopBack 2
[r1-LoopBack2]ip address 192.168.1.33 255.255.255.240
192.168.1.0001 xxxx/28 R1L1
192.168.1.0010 xxxx/28 R1L2
汇总后为192.168.1.0/26
配置空接口防环(R2,R4同理)
[r1]ip route-static 192.168.1.0 26 NULL 0
四、一对多NAT(私网访问外网必要步骤)
[r5]acl 2000
[r5-acl-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[r5]int g 0/0/1
[r5-GigabitEthernet0/0/1]nat outbound 2000
五、测试浮动路由
将1000M链路shutdown后
发现浮动静态路由没有弹上来还是走192.168.1.18这个路由,由于路由表进行递归查找导致这个问题,在递归查找时会查找到从192.168.1.0 24 NULL0这个空接口查找。
解决方法:
把原来的缺省路由删掉,改用带接口的缺省路由命令
[r4]undo ip route-static 0.0.0.0 0 192.168.1.7
[r4]ip route-static 0.0.0.0 0 GigabitEthernet 0/0/1 192.168.1.7
六、TELNET
[r1]aaa
[r1-aaa]local-user admin privilege level 15 password cipher 123456
[r1-aaa]local-user admin service-type telnet
[r1-aaa]q
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mode aaa
[r5-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 23 inside 192.168.1.2 23(前提是该接口应用acl2000已抓取流量并设置nat outbound 2000)