
1.要求:
(1)总部实现高可靠性设计,接入层断掉一根线或汇聚、核心设备故障都不能影响数据正常转发
(2)分部1人数较少,采用单臂路由互通
(3)总部、分部1、2之间都能访问互联网
(4)外网能够访问总部的HTTP server 和FTP server
(5)总部和两个分部之间通过DSVPN实现内网互通
2.总部配置
(1)创建vlan并加入接口,将核心交换机之间链路捆绑为e-trunk,确保任何一台故障时另一台能正常转发数据
LSW3vlan batch 10 20 30
LSW3int g0/0/3
LSW3-GigabitEthernet0/0/3port link-type access
LSW3-GigabitEthernet0/0/3port default vlan 10
LSW3-GigabitEthernet0/0/3int g0/0/1
LSW3-GigabitEthernet0/0/1port link-type trunk
LSW3-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20 30
LSW3-GigabitEthernet0/0/1int g0/0/2
LSW3-GigabitEthernet0/0/2port link-type trunk
LSW3-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 30
LSW4vlan batch 10 20 30
LSW4int g0/0/3
LSW4-GigabitEthernet0/0/3port link-type access
LSW4-GigabitEthernet0/0/3port default vlan 20
LSW4-GigabitEthernet0/0/3int g0/0/1
LSW4-GigabitEthernet0/0/1port link-type trunk
LSW4-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20 30
LSW4-GigabitEthernet0/0/1int g0/0/2
LSW4-GigabitEthernet0/0/2port link-type trunk
LSW4-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 30
LSW5vlan batch 10 20 30
LSW5int g0/0/3
LSW5-GigabitEthernet0/0/3port link-type access
LSW5-GigabitEthernet0/0/3port default vlan 30
LSW5-GigabitEthernet0/0/3int g0/0/1
LSW5-GigabitEthernet0/0/1port link-type trunk
LSW5-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20 30
LSW5-GigabitEthernet0/0/1int g0/0/2
LSW5-GigabitEthernet0/0/2port link-type trunk
LSW5-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 30
LSW1vlan batch 10 20 30 11 12
LSW1int g0/0/1
LSW1-GigabitEthernet0/0/1port link-type access
LSW1-GigabitEthernet0/0/1port default vlan 11
LSW1-GigabitEthernet0/0/1int g0/0/2
LSW1-GigabitEthernet0/0/2port link-type access
LSW1-GigabitEthernet0/0/2port default vlan 12
LSW1-GigabitEthernet0/0/2int g0/0/3
LSW1-GigabitEthernet0/0/3port link-type trunk
LSW1-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 30 11 12
LSW1-GigabitEthernet0/0/3int g0/0/4
LSW1-GigabitEthernet0/0/4port link-type trunk
LSW1-GigabitEthernet0/0/4port trunk allow-pass vlan 10 20 30 11 12 13 14
LSW1-GigabitEthernet0/0/4int g0/0/5
LSW1-GigabitEthernet0/0/5port link-type trunk
LSW1-GigabitEthernet0/0/5port trunk allow-pass vlan 10 20 30 11 12 13 14
LSW1-GigabitEthernet0/0/5quit
LSW1int Eth-Trunk 1
LSW1-Eth-Trunk1trunkport GigabitEthernet 0/0/6 to 0/0/7
LSW1-Eth-Trunk1port link-type trunk
LSW1-Eth-Trunk1port trunk allow-pass vlan 10 20 30 11 12 13 14
LSW2vlan batch 10 20 30 13 14
LSW2int g0/0/1
LSW2-GigabitEthernet0/0/1port link-type access
LSW2-GigabitEthernet0/0/1port default vlan 14
LSW2-GigabitEthernet0/0/1int g0/0/2
LSW2-GigabitEthernet0/0/2port link-type access
LSW2-GigabitEthernet0/0/2port default vlan 13
LSW2-GigabitEthernet0/0/2int g0/0/3
LSW2-GigabitEthernet0/0/3port link-type t
LSW2-GigabitEthernet0/0/3port link-type trunk
LSW2-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 30 11 12 13 14
LSW2-GigabitEthernet0/0/3int g0/0/4
LSW2-GigabitEthernet0/0/4port link-type trunk
LSW2-GigabitEthernet0/0/4port trunk allow-pass vlan 10 20 30 11 12 13 14
LSW2-GigabitEthernet0/0/4int g0/0/5
LSW2-GigabitEthernet0/0/5port link-type trunk
LSW2-GigabitEthernet0/0/5port trunk allow-pass vlan 10 20 30 11 12 13 14
LSW2-GigabitEthernet0/0/5quit
LSW2int Eth-Trunk 1
LSW2-Eth-Trunk1trunkport GigabitEthernet 0/0/6 to 0/0/7
LSW2-Eth-Trunk1port link-type trunk
LSW2-Eth-Trunk1port trunk allow-pass vlan 10 20 30 11 12 13 14


(2)配置MSTP破除环路:LSW1为vlan 10 20的根桥、vlan 30 的次根,LSW2为vlan 30的根桥、vlan 10 20的次根;将连接终端的接口配置为边缘端口
LSW1stp region-configuration
LSW1-mst-regionregion-name 1
LSW1-mst-regionrevision-level 1
LSW1-mst-regioninstance 1 vlan 10 20
LSW1-mst-regioninstance 2 vlan 30
LSW1-mst-regionactive region-configuration
LSW1stp instance 1 priority 0
LSW1stp instance 2 priority 4096

LSW2stp region-configuration
LSW2-mst-regionregion-name 1
LSW2-mst-regionrevision-level 1
LSW2-mst-regioninstance 1 vlan 10 20
LSW2-mst-regioninstance 2 vlan 30
LSW2-mst-regionactive region-configuration
LSW2stp instance 1 priority 4096
LSW2stp instance 2 priority 0

LSW3stp region-configuration
LSW3-mst-regionregion-name 1
LSW3-mst-regionrevision-level 1
LSW3-mst-regioninstance 1 vlan 10 20
LSW3-mst-regioninstance 2 vlan 30
LSW3-mst-regionactive region-configuration
LSW3-mst-regionquit
LSW4stp region-configuration
LSW4-mst-regionregion-name 1
LSW4-mst-regionrevision-level 1
LSW4-mst-regioninstance 1 vlan 10 20
LSW4-mst-regioninstance 2 vlan 30
LSW4-mst-regionactive region-configuration
LSW4-mst-regionquit
LSW5stp region-configuration
LSW5-mst-regionregion-name 1
LSW5-mst-regionrevision-level 1
LSW5-mst-regioninstance 1 vlan 10 20
LSW5-mst-regioninstance 2 vlan 30
LSW5-mst-regionactive region-configuration



LSW3int g0/0/3
LSW3-GigabitEthernet0/0/3stp edged-port enable
LSW4int g0/0/3
LSW4-GigabitEthernet0/0/3stp edged-port enable
LSW5int g0/0/3
LSW5-GigabitEthernet0/0/3stp edged-port enable
(3)配置vlan间路由,使内网互通:配置vrrp,LSW1为vlan 10 20的master、为vlan 30的backup,LSW2为vlan 10 20的backup、为vlan 30的master
LSW1int Vlanif 10
LSW1-Vlanif10ip add 10.1.1.1 24
LSW1-Vlanif10int Vlanif 20
LSW1-Vlanif20ip add 10.1.2.1 24
LSW1-Vlanif20int Vlanif 30
LSW1-Vlanif30ip add 10.1.3.1 24
LSW2int Vlanif 10
LSW2-Vlanif10ip add 10.1.1.2 24
LSW2-Vlanif10int Vlanif 20
LSW2-Vlanif20ip add 10.1.2.2 24
LSW2-Vlanif20int Vlanif 30
LSW2-Vlanif30ip add 10.1.3.2 24
LSW1int Vlanif 10
LSW1-Vlanif10vrrp vrid 1 virtual-ip 10.1.1.254
LSW1-Vlanif10vrrp vrid 1 priority 200
LSW1-Vlanif10vrrp vrid 1 preempt-mode timer delay 60
LSW1-Vlanif10vrrp vrid 1 track interface GigabitEthernet 0/0/1 reduced 120
LSW1int Vlanif 20
LSW1-Vlanif20vrrp vrid 2 virtual-ip 10.1.2.254
LSW1-Vlanif20vrrp vrid 2 priority 200
LSW1-Vlanif20vrrp vrid 2 preempt-mode timer delay 60
LSW1-Vlanif20vrrp vrid 2 track interface GigabitEthernet 0/0/1 reduced 120
LSW1int Vlanif 30
LSW1-Vlanif30vrrp vrid 3 virtual-ip 10.1.3.254
LSW2int Vlanif 10
LSW2-Vlanif10vrrp vrid 1 virtual-ip 10.1.1.254
LSW2-Vlanif10int Vlanif 20
LSW2-Vlanif20vrrp vrid 2 virtual-ip 10.1.2.254
LSW2-Vlanif20int Vlanif 30
LSW2-Vlanif30vrrp vrid 3 virtual-ip 10.1.3.254
LSW2-Vlanif30vrrp vrid 3 priority 200
LSW2-Vlanif30vrrp vrid 3 preempt-mode timer delay 60
LSW2-Vlanif30vrrp vrid 3 track interface GigabitEthernet 0/0/1 reduced 120






(4)配置三层互联接口
LSW1int Vlanif 11
LSW1-Vlanif11ip add 192.168.11.1 24
LSW1-Vlanif11int Vlanif 12
LSW1-Vlanif12ip add 192.168.12.1 24
LSW2int Vlanif 13
LSW2-Vlanif13ip add 192.168.13.2 24
LSW2-Vlanif13int Vlanif 14
LSW2-Vlanif14ip add 192.168.14.2 24
FW1firewall zone trust
FW1-zone-trustadd interface GigabitEthernet 1/0/2
FW1-zone-trustadd interface GigabitEthernet 1/0/0
FW1firewall zone untrust
FW1-zone-untrustadd interface GigabitEthernet 1/0/1
FW1-zone-untrustfirewall zone dmz
FW1-zone-dmzadd interface GigabitEthernet 1/0/3
FW1-zone-dmzadd interface GigabitEthernet 1/0/4
FW1int g1/0/1
FW1-GigabitEthernet1/0/1ip add 20.1.1.3 24
FW1-GigabitEthernet1/0/1int g1/0/0
FW1-GigabitEthernet1/0/0ip add 192.168.13.3 24
FW1-GigabitEthernet1/0/0int g1/0/2
FW1-GigabitEthernet1/0/2ip add 192.168.11.3 24
FW1-GigabitEthernet1/0/2int g1/0/3
FW1-GigabitEthernet1/0/3ip add 192.168.15.3 24
FW1-GigabitEthernet1/0/3int g1/0/4
FW1-GigabitEthernet1/0/4ip add 192.168.16.3 24

AR2int g0/0/0
AR2-GigabitEthernet0/0/0ip add 192.168.12.4 24
AR2-GigabitEthernet0/0/0int g0/0/1
AR2-GigabitEthernet0/0/1ip add 192.168.14.4 24
AR2-GigabitEthernet0/0/1int g0/0/2
AR2-GigabitEthernet0/0/2ip add 20.1.1.4 24
AR1int g4/0/0
AR1-GigabitEthernet4/0/0ip add 50.1.1.5 24
AR1-GigabitEthernet4/0/0int g0/0/1
AR1-GigabitEthernet0/0/1ip add 30.1.1.5 24
AR1-GigabitEthernet0/0/1int g0/0/2
AR1-GigabitEthernet0/0/2ip add 40.1.1.5 24
AR1-GigabitEthernet0/0/2int g0/0/0
AR1-GigabitEthernet0/0/0ip add 20.1.1.5 24
(5)配置DMZ区域
1)配置vlan
LSW10vlan batch 100 101
LSW10int g0/0/3
LSW10-GigabitEthernet0/0/3port link-type access
LSW10-GigabitEthernet0/0/3port default vlan 100
LSW10-GigabitEthernet0/0/3int g0/0/4
LSW10-GigabitEthernet0/0/4port link-type access
LSW10-GigabitEthernet0/0/4port default vlan 101
LSW10-GigabitEthernet0/0/4int g0/0/1
LSW10-GigabitEthernet0/0/1port link-type trunk
LSW10-GigabitEthernet0/0/1port trunk allow-pass vlan 100 101
LSW10-GigabitEthernet0/0/1int g0/0/2
LSW10-GigabitEthernet0/0/2port link-type trunk
LSW10-GigabitEthernet0/0/2port trunk allow-pass vlan 100 101
LSW8vlan batch 15 100 101
LSW8int g0/0/1
LSW8-GigabitEthernet0/0/1port link-type access
LSW8-GigabitEthernet0/0/1port default vlan 15
LSW8-GigabitEthernet0/0/1int g0/0/2
LSW8-GigabitEthernet0/0/2port link-type trunk
LSW8-GigabitEthernet0/0/2port trunk allow-pass vlan 15 100 101
LSW8-GigabitEthernet0/0/2quit
LSW8int Eth-Trunk 1
LSW8-Eth-Trunk1trunkport GigabitEthernet 0/0/3 to 0/0/4
LSW8-Eth-Trunk1port link-type trunk
LSW8-Eth-Trunk1port trunk allow-pass vlan 15 100 101
LSW9vlan batch 16 100 101
LSW9int g0/0/1
LSW9-GigabitEthernet0/0/1port link-type access
LSW9-GigabitEthernet0/0/1port default vlan 16
LSW9-GigabitEthernet0/0/1int g0/0/2
LSW9-GigabitEthernet0/0/2port link-type trunk
LSW9-GigabitEthernet0/0/2po
LSW9-GigabitEthernet0/0/2port trunk allow-pass vlan 16 100 101
LSW9-GigabitEthernet0/0/2quit
LSW9int Eth-Trunk 1
LSW9-Eth-Trunk1trunkport GigabitEthernet 0/0/3 to 0/0/4
LSW9-Eth-Trunk1port link-type trunk
LSW9-Eth-Trunk1port trunk allow-pass vlan 16 100 101
2)配置MSTP(要求vlan 100的根桥为LSW8,vlan 101的根桥为LSW9)
LSW10stp region-configuration
LSW10-mst-regionregion-name DMZ1
LSW10-mst-regionrevision-level 1
LSW10-mst-regioninstance 1 vlan 100
LSW10-mst-regioninstance 2 vlan 101
LSW10-mst-regionactive region-configuration
LSW8stp region-configuration
LSW8-mst-regionregion-name DMZ1
LSW8-mst-regionrevision-level 1
LSW8-mst-regioninstance 1 vlan 100
LSW8-mst-regioninstance 2 vlan 101
LSW8-mst-regionactive region-configuration
LSW9stp region-configuration
LSW9-mst-regionregion-name DMZ1
LSW9-mst-regionrevision-level 1
LSW9-mst-regioninstance 1 vlan 100
LSW9-mst-regioninstance 2 vlan 101
LSW9-mst-regionactive region-configuration
LSW8stp instance 1 priority 0
LSW8stp instance 2 priority 4096
LSW9stp instance 1 priority 4096
LSW9stp instance 2 priority 0

LSW10int g0/0/3
LSW10-GigabitEthernet0/0/3stp edged-port enable
LSW10-GigabitEthernet0/0/3int g0/0/4
LSW10-GigabitEthernet0/0/4stp edged-port enable
3)配置VLAN间路由
LSW8int Vlanif 15
LSW8-Vlanif15ip add 192.168.15.1 24
LSW8int Vlanif 100
LSW8-Vlanif100ip add 10.1.100.1 24
LSW8-Vlanif100int Vlanif 101
LSW8-Vlanif101ip add 10.1.101.1 24
LSW9int Vlanif 16
LSW9-Vlanif16ip add 192.168.16.2 24
LSW9int Vlanif 100
LSW9-Vlanif100ip add 10.1.100.2 24
LSW9-Vlanif100int Vlanif 101
LSW9-Vlanif101ip add 10.1.101.2 24
4)配置VRRP,保证链路备份
LSW8int Vlanif 100
LSW8-Vlanif100vrrp vrid 1 virtual-ip 10.1.100.254
LSW8-Vlanif100vrrp vrid 1 priority 200
LSW8-Vlanif100vrrp vrid 1 preempt-mode timer delay 60
LSW8-Vlanif100vrrp vrid 1 track interface g0/0/1 reduced 120
LSW8-Vlanif100quit
LSW8int Vlanif 101
LSW8-Vlanif101vrrp vrid 2 virtual-ip 10.1.101.254
LSW9int Vlanif 100
LSW9-Vlanif100vrrp vrid 1 virtual-ip 10.1.100.254
LSW9-Vlanif100int Vlanif 101
LSW9-Vlanif101vrrp vrid 2 virtual-ip 10.1.101.254
LSW9-Vlanif101vrrp vrid 2 preempt-mode timer delay 60
LSW9-Vlanif101vrrp vrid 2 priority 200
LSW9-Vlanif101vrrp vrid 2 track interface g0/0/1 reduced 120

(6)配置全网路由:将总部在OSFP的area 0区域,服务器在 area 1区域,分部1在area 2区域,分部2在area 3区域
1)配置OSPF
LSW1ospf 1 router-id 11.1.1.1
LSW1-ospf-1area 0
LSW1-ospf-1-area-0.0.0.0ne
LSW1-ospf-1-area-0.0.0.0network 10.1.1.0 0.0.0.255
LSW1-ospf-1-area-0.0.0.0network 10.1.2.0 0.0.0.255
LSW1-ospf-1-area-0.0.0.0network 10.1.3.0 0.0.0.255
LSW1-ospf-1-area-0.0.0.0network 192.168.11.0 0.0.0.255
LSW1-ospf-1-area-0.0.0.0network 192.168.12.0 0.0.0.255
LSW2ospf 1 router-id 22.1.1.1
LSW2-ospf-1area 0
LSW2-ospf-1-area-0.0.0.0network 10.1.1.0 0.0.0.255
LSW2-ospf-1-area-0.0.0.0network 10.1.2.0 0.0.0.255
LSW2-ospf-1-area-0.0.0.0network 10.1.3.0 0.0.0.255
LSW2-ospf-1-area-0.0.0.0network 192.168.13.0 0.0.0.255
LSW2-ospf-1-area-0.0.0.0network 192.168.14.0 0.0.0.255
FW1ospf router-id 33.1.1.1
FW1-ospf-1ospf 1
FW1-ospf-1area 0
FW1-ospf-1-area-0.0.0.0network 192.168.11.0 0.0.0.255
FW1-ospf-1-area-0.0.0.0network 192.168.13.0 0.0.0.255
FW1-ospf-1-area-0.0.0.0network 192.168.15.0 0.0.0.255
FW1-ospf-1-area-0.0.0.0network 192.168.16.0 0.0.0.255
AR2ospf router-id 44.1.1.1
AR2-ospf-1area 0
AR2-ospf-1-area-0.0.0.0network 192.168.12.0 0.0.0.255
AR2-ospf-1-area-0.0.0.0network 192.168.14.0 0.0.0.255
LSW8ospf router-id 111.1.1.1
LSW8-ospf-1area 0
LSW8-ospf-1-area-0.0.0.0network 192.168.15.0 0.0.0.255
LSW8-ospf-1-area-0.0.0.0area 1
LSW8-ospf-1-area-0.0.0.1network 10.1.100.0 0.0.0.255
LSW8-ospf-1-area-0.0.0.1network 10.1.101.0 0.0.0.255
LSW9ospf router-id 222.1.1.1
LSW9-ospf-1area 0
LSW9-ospf-1-area-0.0.0.0net
LSW9-ospf-1-area-0.0.0.0network 192.168.16.0 0.0.0.255
LSW9-ospf-1-area-0.0.0.0area 1
LSW9-ospf-1-area-0.0.0.1network 10.1.101.0 0.0.0.255
LSW9-ospf-1-area-0.0.0.1network 10.1.100.0 0.0.0.255
2)将vlanif接口静默
LSW1ospf 1
LSW1-ospf-1silent-interface Vlanif 10
LSW1-ospf-1silent-interface Vlanif 20
LSW1-ospf-1silent-interface Vlanif 30
LSW2ospf 1
LSW2-ospf-1silent-interface Vlanif 10
LSW2-ospf-1silent-interface Vlanif 20
LSW2-ospf-1silent-interface Vlanif 30
LSW8-ospf-1silent-interface Vlanif 100
LSW8-ospf-1silent-interface Vlanif 101
LSW9-ospf-1silent-interface Vlanif 100
LSW9-ospf-1silent-interface Vlanif 101

(7)配置trust到dmz的安全策略
FW1security-policy
FW1-policy-securityrule name t-to-dmz
FW1-policy-security-rule-t-to-dmzsource-zone trust
FW1-policy-security-rule-t-to-dmzsource-address 10.1.0.0 16
FW1-policy-security-rule-t-to-dmzdestination-zone dmz
FW1-policy-security-rule-t-to-dmzaction permit

(8)配置 NAT
FW1nat-policy
FW1-policy-natrule name to-ISP
FW1-policy-nat-rule-to-ISPsource-zone trust
FW1-policy-nat-rule-to-ISPdestination-zone untrust
FW1-policy-nat-rule-to-ISPsource-address 10.1.0.0 16
FW1-policy-nat-rule-to-ISPaction source-nat easy-ip
FW1security-policy
FW1-policy-securityrule name to-ISP
FW1-policy-security-rule-to-ISPsource-zone trust
FW1-policy-security-rule-to-ISPdestination-zone untrust
FW1-policy-security-rule-to-ISPsource-address 10.1.0.0 16
FW1-policy-security-rule-to-ISPaction permit
FW1ip route-static 0.0.0.0 0.0.0.0 20.1.1.5
FW1ospf 1
FW1-ospf-1default-route-advertise


(9)公网访问 dmz 区域的 http 服务和 FTP 服务:通过 nat-server 进行映射
FW1nat server protocol tcp global 20.1.1.100 80 inside 10.1.100.10 80
FW1nat server protocol tcp global 20.1.1.101 21 inside 10.1.101.10 21
FW1security-policy
FW1-policy-securityrule name u-to-dmz
FW1-policy-security-rule-u-to-dmzsource-zone untrust
FW1-policy-security-rule-u-to-dmzdestination-zone dmz
FW1-policy-security-rule-u-to-dmzdestination-address 10.1.100.10 32
FW1-policy-security-rule-u-to-dmzdestination-address 10.1.101.10 32
FW1-policy-security-rule-u-to-dmzaction permit


4.分部1的配置:单臂路由和NAT
(1)单臂路由配置
LSW11vlan batch 10 20
LSW11int g0/0/2
LSW11-GigabitEthernet0/0/2port link-type access
LSW11-GigabitEthernet0/0/2port default vlan 10
LSW11-GigabitEthernet0/0/2int g0/0/3
LSW11-GigabitEthernet0/0/3port link-type access
LSW11-GigabitEthernet0/0/3port default vlan 20
LSW11-GigabitEthernet0/0/3int g0/0/1
LSW11-GigabitEthernet0/0/1port link-type trunk
LSW11-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20
AR4int g0/0/1.10
AR4-GigabitEthernet0/0/1.10dot1q termination vid 10
AR4-GigabitEthernet0/0/1.10arp broadcast enable
AR4-GigabitEthernet0/0/1.10ip add 10.2.1.1 2
AR4-GigabitEthernet0/0/1.10int g0/0/1.20
AR4-GigabitEthernet0/0/1.20dot1q termination vid 20
AR4-GigabitEthernet0/0/1.20arp broadcast enable
AR4-GigabitEthernet0/0/1.20ip add 10.2.2.1 24
AR4int g0/0/0
AR4-GigabitEthernet0/0/0ip add 40.1.1.1 24
AR4ip route-static 0.0.0.0 0.0.0.0 40.1.1.5
AR4acl 2000
AR4-acl-basic-2000rule permit source 10.2.0.0 0.0.255.255
AR4-acl-basic-2000int g0/0/0
AR4-GigabitEthernet0/0/0nat outbound 2000

5.分部2的配置
(1)配置vlan
LSW13vlan batch 10 20 17
LSW13int g0/0/1
LSW13-GigabitEthernet0/0/1port link-type access
LSW13-GigabitEthernet0/0/1port default vlan 17
LSW13-GigabitEthernet0/0/1int g0/0/2
LSW13-GigabitEthernet0/0/2port link-type trunk
LSW13-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 17
LSW13-GigabitEthernet0/0/2int g0/0/3
LSW13-GigabitEthernet0/0/3port link-type trunk
LSW13-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 17
LSW13-GigabitEthernet0/0/3quit
LSW13int Eth-Trunk 1
LSW13-Eth-Trunk1trunkport GigabitEthernet 0/0/4 to 0/0/5
LSW13-Eth-Trunk1port link-type trunk
LSW13-Eth-Trunk1port trunk allow-pass vlan 10 20 17
LSW14vlan batch 10 20 18
LSW14int g0/0/1
LSW14-GigabitEthernet0/0/1port link-type access
LSW14-GigabitEthernet0/0/1port default vlan 18
LSW14-GigabitEthernet0/0/1int g0/0/2
LSW14-GigabitEthernet0/0/2port link-type trunk
LSW14-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20 18
LSW14-GigabitEthernet0/0/2int g0/0/3
LSW14-GigabitEthernet0/0/3port link-type trunk
LSW14-GigabitEthernet0/0/3port trunk allow-pass vlan 10 20 18
LSW14-GigabitEthernet0/0/3quit
LSW14int Eth-Trunk 1
LSW14-Eth-Trunk1trunkport GigabitEthernet 0/0/4 to 0/0/5
LSW14-Eth-Trunk1port link-type trunk
LSW14-Eth-Trunk1port trunk allow-pass vlan 10 20 18
LSW15vlan batch 10 20
LSW15int g0/0/3
LSW15-GigabitEthernet0/0/3port link-type access
LSW15-GigabitEthernet0/0/3port default vlan 10
LSW15-GigabitEthernet0/0/3int g0/0/1
LSW15-GigabitEthernet0/0/1port link-type trunk
LSW15-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20
LSW15-GigabitEthernet0/0/1int g0/0/2
LSW15-GigabitEthernet0/0/2port link-type trunk
LSW15-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20
LSW16vlan batch 10 20
LSW16int g0/0/3
LSW16-GigabitEthernet0/0/3port link-type access
LSW16-GigabitEthernet0/0/3port default vlan 20
LSW16-GigabitEthernet0/0/3int g0/0/1
LSW16-GigabitEthernet0/0/1port link-type trunk
LSW16-GigabitEthernet0/0/1port trunk allow-pass vlan 10 20
LSW16-GigabitEthernet0/0/1int g0/0/2
LSW16-GigabitEthernet0/0/2port link-type trunk
LSW16-GigabitEthernet0/0/2port trunk allow-pass vlan 10 20
(2)配置MSTP:LSW13为vlan 10的主根、vlan 20的次根,LSW14为vlan 20的主根、vlan 10的次根
LSW13stp region-configuration
LSW13-mst-regionregion-name FB2
LSW13-mst-regionrevision-level 1
LSW13-mst-regioninstance 1 vlan 10
LSW13-mst-regioninstance 2 vlan 20
LSW13-mst-regionactive region-configuration
LSW14stp region-configuration
LSW14-mst-regionregion-name FB2
LSW14-mst-regionrevision-level 1
LSW14-mst-regioninstance 1 vlan 10
LSW14-mst-regioninstance 2 vlan 20
LSW14-mst-regionactive region-configuration
LSW15stp region-configuration
LSW15-mst-regionregion-name FB2
LSW15-mst-regionrevision-level 1
LSW15-mst-regioninstance 1 vlan 10
LSW15-mst-regioninstance 2 vlan 20
LSW15-mst-regionactive region-configuration
LSW16stp region-configuration
LSW16-mst-regionregion-name FB2
LSW16-mst-regionrevision-level 1
LSW16-mst-regioninstance 1 vlan 10
LSW16-mst-regioninstance 2 vlan 20
LSW16-mst-regionactive region-configuration
LSW13stp instance 1 priority 0
LSW13stp instance 2 priority 4096
LSW14stp instance 1 priority 4096
LSW14stp instance 2 priority 0


LSW16-GigabitEthernet0/0/3stp edged-port enable
LSW15-GigabitEthernet0/0/3stp edged-port enable
(3)配置vlan间路由
LSW13int Vlanif 10
LSW13-Vlanif10ip add 10.3.1.1 24
LSW13-Vlanif10int Vlanif 20
LSW13-Vlanif20ip add 10.3.2.1 24
LSW13-Vlanif20int Vlanif 10
LSW13-Vlanif10vrrp vrid 1 virtual-ip 10.3.1.254
LSW13-Vlanif10vrrp vrid 1 priority 200
LSW13-Vlanif10vrrp vrid 1 preempt-mode timer delay 60
LSW13-Vlanif10vrrp vrid 1 track interface g0/0/1 reduced 120
LSW13-Vlanif10int Vlanif 20
LSW13-Vlanif20vrrp vrid 2 virtual-ip 10.3.2.254
LSW14int Vlanif 10
LSW14-Vlanif10ip add 10.3.1.2 24
LSW14-Vlanif10int Vlanif 20
LSW14-Vlanif20ip add 10.3.2.2 24
LSW14-Vlanif20vrrp vrid 2 virtual-ip 10.3.2.254
LSW14-Vlanif20vrrp vrid 2 priority 200
LSW14-Vlanif20vrrp vrid 2 preempt-mode timer delay 60
LSW14-Vlanif20vrrp vrid 2 track interface GigabitEthernet 0/0/1 reduced 120
LSW14-Vlanif20int Vlanif 10
LSW14-Vlanif10vrrp vrid 1 virtual-ip 10.3.1.254


(4)配置全网路由
LSW13int Vlanif 17
LSW13-Vlanif17ip add 192.168.17.1 24
LSW13-Vlanif17quit
LSW13ospf 1 router-id 17.1.1.1
LSW13-ospf-1area 2
LSW13-ospf-1-area-0.0.0.2ne
LSW13-ospf-1-area-0.0.0.2network 192.168.17.0 0.0.0.255
LSW13-ospf-1-area-0.0.0.2network 10.3.1.0 0.0.0.255
LSW13-ospf-1-area-0.0.0.2network 10.3.2.0 0.0.0.255
LSW13-ospf-1-area-0.0.0.2qui
LSW13-ospf-1silent-interface Vlanif 10
LSW13-ospf-1silent-interface Vlanif 20
LSW14int Vlanif 18
LSW14-Vlanif18ip add 192.168.18.1 24
LSW14-Vlanif18quit
LSW14ospf 1 router-id 18.1.1.1
LSW14-ospf-1area 2
LSW14-ospf-1-area-0.0.0.2network 10.3.1.0 0.0.0.255
LSW14-ospf-1-area-0.0.0.2network 10.3.2.0 0.0.0.255
LSW14-ospf-1-area-0.0.0.2network 192.168.18.0 0.0.0.255
LSW14-ospf-1-area-0.0.0.2quit
LSW14-ospf-1silent-interface Vlanif 10
LSW14-ospf-1silent-interface Vlanif 20
AR5int g0/0/1
AR5-GigabitEthernet0/0/1ip add 192.168.17.6 24
AR5-GigabitEthernet0/0/1int g0/0/2
AR5-GigabitEthernet0/0/2ip add 192.168.18.6 24
AR5-GigabitEthernet0/0/2int g0/0/0
AR5-GigabitEthernet0/0/0ip add 50.1.1.6 24
AR5ospf 1 router-id 55.1.1.1
AR5-ospf-1area 2
AR5-ospf-1-area-0.0.0.2network 192.168.17.0 0.0.0.255
AR5-ospf-1-area-0.0.0.2network 192.168.18.0 0.0.0.255
AR5ip route-static 0.0.0.0 0.0.0.0 50.1.1.5
AR5ospf 1
AR5-ospf-1default-route-advertise
(5)源NAT地址转换
AR5acl 2000
AR5-acl-basic-2000rule permit source 10.3.0.0 0.0.255.255
AR5int g0/0/0
AR5-GigabitEthernet0/0/0nat outbound 2000

6.总校分校DSVPN配置:AR2作为hub端,AR4、AR5作为spoke端,三个接口配置在172.1.1.0网段
AR2int Tunnel 0/0/0
AR2-Tunnel0/0/0tunnel-protocol gre p2mp
AR2-Tunnel0/0/0ip add 172.1.1.1 24
AR2-Tunnel0/0/0source GigabitEthernet 0/0/2
AR2-Tunnel0/0/0nhrp entry multicast dynamic
AR2-Tunnel0/0/0ospf dr-priority 255 //调整优先级至最大,使其成为 DR
AR4int Tunnel 0/0/0
AR4-Tunnel0/0/0tunnel-protocol gre p2mp
AR4-Tunnel0/0/0ip add 172.1.1.3 24
AR4-Tunnel0/0/0source GigabitEthernet 0/0/0
AR4-Tunnel0/0/0nhrp entry 172.1.1.1 20.1.1.4 register
AR4-Tunnel0/0/0ospf network-type broadcast
AR4-Tunnel0/0/0ospf dr-priority 0
AR5int Tunnel 0/0/0
AR5-Tunnel0/0/0tunnel-protocol gre p2mp
AR5-Tunnel0/0/0ip add 172.1.1.2 24
AR5-Tunnel0/0/0source GigabitEthernet 0/0/0
AR5-Tunnel0/0/0nhrp entry 172.1.1.1 20.1.1.4 register
AR5-Tunnel0/0/0ospf network-type broadcast
AR5-Tunnel0/0/0ospf dr-priority 0

AR2ospf 1
AR2-ospf-1area 0
AR2-ospf-1-area-0.0.0.0network 172.1.1.0 0.0.0.255
AR4ospf 1
AR4-ospf-1area 0
AR4-ospf-1-area-0.0.0.0network 172.1.1.0 0.0.0.255
AR5ospf 1
AR5-ospf-1area 0
AR5-ospf-1-area-0.0.0.0network 172.1.1.0 0.0.0.255