IP综合实验

要求:

1.内网地址172.16.0.0/16合理分配

2.SW1/2之间互为备份

3.VRRP/STP/VLAN/TRUNK均使用

一。配置交换机部分

eth-trunk 创建,划分vlan trunk STP SVI VRRP DHCP

1.配置eth-trunk进行绑定

SW1interface Eth-Trunk 0

SW1-Eth-Trunk0q

SW1int g0/0/2

SW1-GigabitEthernet0/0/2eth-trunk 0

SW1-GigabitEthernet0/0/2q

SW1int g0/0/3

SW1-GigabitEthernet0/0/3eth-trunk 0

SW2-Eth-Trunk0q

SW2int g0/0/2

SW2-GigabitEthernet0/0/2eth-trunk 0

SW2-GigabitEthernet0/0/2q

SW2int g0/0/3

SW2-GigabitEthernet0/0/3eth-trunk 0

2.创建vlan,划分接口类型

SW1vlan 2

SW1-vlan2q

SW1port-group group-member g0/0/4 to g0/0/5 Eth-Trunk 0

SW1-port-groupport link-type trunk

SW1-GigabitEthernet0/0/4port link-type trunk

SW1-GigabitEthernet0/0/5port link-type trunk

SW1-Eth-Trunk0port link-type trunk

SW1-port-groupport trunk allow-pass vlan 2

SW1-GigabitEthernet0/0/4port trunk allow-pass vlan 2

SW1-GigabitEthernet0/0/5port trunk allow-pass vlan 2

SW1-Eth-Trunk0port trunk allow-pass vlan 2

SW2vlan 2

SW2-vlan2q

SW2port-group group-member g0/0/4 to g0/0/5 Eth-Trunk 0

SW2-port-groupport link-type trunk

SW2-GigabitEthernet0/0/4port link-type trunk

SW2-GigabitEthernet0/0/5port link-type trunk

SW2-Eth-Trunk0port link-type trunk

SW2-port-groupport trunk allow-pass vlan 2

SW2-GigabitEthernet0/0/4port trunk allow-pass vlan 2

SW2-GigabitEthernet0/0/5port trunk allow-pass vlan 2

SW2-Eth-Trunk0port trunk allow-pass vlan 2

SW3vlan 2

SW3-vlan2q

SW3-Ethernet0/0/3int e0/0/4

SW3-Ethernet0/0/4port link-type access

SW3-Ethernet0/0/4port default vlan 2

SW3-Ethernet0/0/4q

SW3port-group group-member e0/0/1 to e0/0/2

SW3-port-groupport link-type trunk

SW3-Ethernet0/0/1port link-type trunk

SW3-Ethernet0/0/2port link-type trunk

SW3-port-groupport trunk allow-pass vlan 2

SW3-Ethernet0/0/1port trunk allow-pass vlan 2

SW3-Ethernet0/0/2port trunk allow-pass vlan 2

SW4vlan 2

SW4-vlan2q

SW4int e0/0/4

SW4-Ethernet0/0/4port link-type access

SW4-Ethernet0/0/4port default vlan 2

SW4-Ethernet0/0/4q

SW4port-group group-member e0/0/1 to e0/0/2

SW4-port-groupport link-type trunk

SW4-Ethernet0/0/1port link-type trunk

SW4-Ethernet0/0/2port link-type trunk

SW4-port-groupport trunk allow-pass vlan 2

SW4-Ethernet0/0/1port trunk allow-pass vlan 2

SW4-Ethernet0/0/2port trunk allow-pass vlan 2

3.配置生成树:

SW1stp region-configuration

SW1-mst-regionregion-name aa

SW1-mst-regioninstance 1 vlan 1

SW1-mst-regioninstance 2 vlan 2

SW1-mst-regionactive region-configuration

SW2stp region-configuration

SW2-mst-regioninstance 1 vlan 1

SW2-mst-regioninstance 2 vlan 2

SW2-mst-regionactive region-configuration

SW3stp region-configuration

SW3-mst-regionregion-name aa

SW3-mst-regioninstance 1 vlan 1

SW3-mst-regioninstance 2 vlan 2

SW3-mst-regionactive region-configuration

SW4stp region-configuration

SW4-mst-regionregion-name aa

SW4-mst-regioninstance 1 vlan 1

SW4-mst-regioninstance 2 vlan 2

SW4-mst-regionactive region-configuration

4.进行根和备份跟的确定:

SW1stp instance 1 root primary

SW1stp instance 2 root secondary

SW1stp instance 0 root primary

SW2stp instance 1 root secondary

SW2stp instance 2 root primary

SW2stp instance 0 root secondary

SW3port-group group-member e0/0/1 to e0/0/22(配置边缘接口进行优化)

SW3-port-groupstp edged-port enable

SW3int e0/0/3(修改WiFi接口优先级)

SW3-Ethernet0/0/3stp instance 0 port priority 16

5.配置ip地址SVI:

SW1int vlan 1

SW1-Vlanif1ip add 172.16.1.1 25

SW1int vlan 2

SW1-Vlanif2ip add 172.16.1.129 25

SW2int vlan 1

SW2-Vlanif1ip add 172.16.1.2 25

SW2int vlan 2

SW2-Vlanif2ip add 172.16.1.130 25

6.进行网关冗余VRRP:

SW1int vlan 1

SW1-Vlanif1vrrp vrid 1 virtual-ip 172.16.1.126

SW1-Vlanif1vrrp vrid 1 priority 110 (称为主ip)

SW1-Vlanif1vrrp vrid 1 track interface g0/0/1 reduced 20

SW2int vlan 1

SW2-Vlanif1vrrp vrid 1 virtual-ip 172.16.1.126

SW2int vlan 2

SW2-Vlanif2vrrp vrid 1 virtual-ip 172.16.1.254

SW2-Vlanif2vrrp vrid 1 priority 110

SW2-Vlanif2vrrp vrid 1 track int g0/0/1 reduced 20

SW1int vlan 2

SW1-Vlanif2vrrp vrid 1 virtual-ip 172.16.1.254

7.配置DHCP获取IP地址:

SW1dhcp enable

SW1ip pool v1

SW1-ip-pool-v1net 172.16.1.0 mask 25

SW1-ip-pool-v1gateway-list 172.16.1.126

SW1-ip-pool-v1dns-list 114.114.114.114

SW1-ip-pool-v1q

SW1ip pool v2

SW1-ip-pool-v2net 172.16.1.128 mask 25

SW1-ip-pool-v2gateway-list 172.16.1.254

SW1-ip-pool-v2dns-list 114.114.114.114

SW1-ip-pool-v2q

SW1int vlan 1

SW1-Vlanif1dhcp select global

SW1-Vlanif1int vlan 2

SW1-Vlanif2dhcp select global

SW2dhcp enable

SW2ip pool v1

Info:It's successful to create an IP address pool.

SW2-ip-pool-v1net 172.16.1.0 mask 25

SW2-ip-pool-v1gateway-list 172.16.1.126

SW2-ip-pool-v1dns-list 114.114.114.114

SW2-ip-pool-v1q

SW2ip pool v2

Info:It's successful to create an IP address pool.

SW2-ip-pool-v2net 172.16.1.128 mask 25

SW2-ip-pool-v2gateway-list 172.16.1.254

SW2-ip-pool-v2dns-list 114.114.114.114

SW2-ip-pool-v2q

SW2int vlan 1

SW2-Vlanif1dhcp select global

SW2-Vlanif1int vlan 2

SW2-Vlanif2dhcp select global

8.对于上层路由器进行连接

SW1vlan 99

SW1-GigabitEthernet0/0/2int g0/0/1

SW1-GigabitEthernet0/0/1port link-type access

SW1-GigabitEthernet0/0/1port default vlan 99

SW1int vlan 99

SW1-Vlanif99ip add 172.16.0.2 30

SW2vlan 99

SW2-vlan99int g0/0/1

SW2-GigabitEthernet0/0/1port link-type access

SW2-GigabitEthernet0/0/1port default vlan 99

SW2-GigabitEthernet0/0/1q

SW2int vlan 99

SW2-Vlanif99ip add 172.16.0.6 30

9.配置沉默接口:

SW1-ospf-1silent-interface all

SW1-ospf-1undo silent-interface GigabitEthernet 0/0/1

SW1-ospf-1undo silent-interface Vlanif 99

SW1-ospf-1undo silent-interface Eth-Trunk 0

SW1-ospf-1undo silent-interface Vlanif 1

SW2ospf 1

SW2-ospf-1silent-interface all

SW2-ospf-1undo silent-interface GigabitEthernet 0/0/1

SW2-ospf-1undo silent-interface Vlanif 99

SW2-ospf-1undo silent-interface Eth-Trunk 0

SW2-ospf-1undo silent-interface Vlanif 1

三。配置路由器部分:

1.配置ospf协议

R2ospf 1 router-id 2.2.2.2

R2-ospf-1area 0

R2-ospf-1-area-0.0.0.0net 172.16.0.0 0.0.0.255

SW1ospf 1 router-id 3.3.3.3

SW1-ospf-1area 0

SW1-ospf-1-area-0.0.0.0net 172.16.0.2 0.0.0.0

SW1-ospf-1area 1

SW1-ospf-1-area-0.0.0.1net 172.16.1.0 0.0.0.255

SW1-ospf-1-area-0.0.0.1

SW2ospf 1 router-id 4.4.4.4

SW2-ospf-1area 0

SW2-ospf-1-area-0.0.0.0net 172.16.0.6 0.0.0.0

SW2-ospf-1-area-0.0.0.0q

SW2-ospf-1area 1

SW2-ospf-1-area-0.0.0.1net 172.16.1.0 0.0.0.255

2.配置缺省路由

R2ip route-static 0.0.0.0 0 12.1.1.1

R2-ospf-1default-route-advertise

3.进行路由汇总:

SW1ospf 1

SW1-ospf-1area 1

SW1-ospf-1-area-0.0.0.1abr-summary 172.16.1.0 255.255.255.0

SW2ospf 1

SW2-ospf-1area 1

SW2-ospf-1-area-0.0.0.1abr-summary 172.16.1.0 255.255.255.0

4.防止路由黑洞

SW1ip route-static 172.16.1.0 24 NULL 0

SW2ip route-static 172.16.1.0 24 NULL 0

5.配置nat,进行上网:

R2acl 2000

R2-acl-basic-2000rule permit source 172.16.0.0 0.0.255.255

R2-acl-basic-2000q

R2int g0/0/0

R2-GigabitEthernet0/0/0nat outbound 2000

相关推荐
换个昵称都难1 小时前
webrtc 音频模块FEC模块
网络·音视频·webrtc
youngerwang2 小时前
【从搬运工到协处理器:网卡芯片架构、算法、验证与边缘演进深度剖析】
网络·算法·架构·芯片
智慧光迅AINOPOL4 小时前
校园在线巡课系统方案:督导全覆盖
网络·全光网解决方案·全光网·校园全光网·校园全光网解决方案
酉鬼女又兒5 小时前
零基础入门计算机网络:网络层核心任务、三大关键问题、两种服务类型与 TCP/IP 网际层协议体系全解析
服务器·网络·网络协议·tcp/ip·计算机网络·php·求职招聘
Urbano5 小时前
工装制作全流程科普:从面料到自动化生产
网络·人工智能
2401_868534785 小时前
网规笔记 | 真题解析:2018年11月软考网规-网络安全案例分析
网络
Gauss松鼠会5 小时前
【GaussDB】GaussDB重要通信参数汇总
服务器·网络·数据库·sql·性能优化·gaussdb·经验总结
超级无敌zhq6 小时前
后渗透痕迹清理:攻防对抗中的隐身术
网络·数据库·网络安全
“初生”6 小时前
Codex 桌面端新会话 5 次 Reconnecting 怎么办?HTTP/SSE 完美修复方案(2026最新)
网络·网络协议·http
m0_738120726 小时前
Docker 环境下 Vulfocus 靶场搭建全流程(附镜像源问题解决方案)
运维·服务器·网络·安全·docker·容器