IP综合实验

要求:

1.内网地址172.16.0.0/16合理分配

2.SW1/2之间互为备份

3.VRRP/STP/VLAN/TRUNK均使用

一。配置交换机部分

eth-trunk 创建,划分vlan trunk STP SVI VRRP DHCP

1.配置eth-trunk进行绑定

SW1interface Eth-Trunk 0

SW1-Eth-Trunk0q

SW1int g0/0/2

SW1-GigabitEthernet0/0/2eth-trunk 0

SW1-GigabitEthernet0/0/2q

SW1int g0/0/3

SW1-GigabitEthernet0/0/3eth-trunk 0

SW2-Eth-Trunk0q

SW2int g0/0/2

SW2-GigabitEthernet0/0/2eth-trunk 0

SW2-GigabitEthernet0/0/2q

SW2int g0/0/3

SW2-GigabitEthernet0/0/3eth-trunk 0

2.创建vlan,划分接口类型

SW1vlan 2

SW1-vlan2q

SW1port-group group-member g0/0/4 to g0/0/5 Eth-Trunk 0

SW1-port-groupport link-type trunk

SW1-GigabitEthernet0/0/4port link-type trunk

SW1-GigabitEthernet0/0/5port link-type trunk

SW1-Eth-Trunk0port link-type trunk

SW1-port-groupport trunk allow-pass vlan 2

SW1-GigabitEthernet0/0/4port trunk allow-pass vlan 2

SW1-GigabitEthernet0/0/5port trunk allow-pass vlan 2

SW1-Eth-Trunk0port trunk allow-pass vlan 2

SW2vlan 2

SW2-vlan2q

SW2port-group group-member g0/0/4 to g0/0/5 Eth-Trunk 0

SW2-port-groupport link-type trunk

SW2-GigabitEthernet0/0/4port link-type trunk

SW2-GigabitEthernet0/0/5port link-type trunk

SW2-Eth-Trunk0port link-type trunk

SW2-port-groupport trunk allow-pass vlan 2

SW2-GigabitEthernet0/0/4port trunk allow-pass vlan 2

SW2-GigabitEthernet0/0/5port trunk allow-pass vlan 2

SW2-Eth-Trunk0port trunk allow-pass vlan 2

SW3vlan 2

SW3-vlan2q

SW3-Ethernet0/0/3int e0/0/4

SW3-Ethernet0/0/4port link-type access

SW3-Ethernet0/0/4port default vlan 2

SW3-Ethernet0/0/4q

SW3port-group group-member e0/0/1 to e0/0/2

SW3-port-groupport link-type trunk

SW3-Ethernet0/0/1port link-type trunk

SW3-Ethernet0/0/2port link-type trunk

SW3-port-groupport trunk allow-pass vlan 2

SW3-Ethernet0/0/1port trunk allow-pass vlan 2

SW3-Ethernet0/0/2port trunk allow-pass vlan 2

SW4vlan 2

SW4-vlan2q

SW4int e0/0/4

SW4-Ethernet0/0/4port link-type access

SW4-Ethernet0/0/4port default vlan 2

SW4-Ethernet0/0/4q

SW4port-group group-member e0/0/1 to e0/0/2

SW4-port-groupport link-type trunk

SW4-Ethernet0/0/1port link-type trunk

SW4-Ethernet0/0/2port link-type trunk

SW4-port-groupport trunk allow-pass vlan 2

SW4-Ethernet0/0/1port trunk allow-pass vlan 2

SW4-Ethernet0/0/2port trunk allow-pass vlan 2

3.配置生成树:

SW1stp region-configuration

SW1-mst-regionregion-name aa

SW1-mst-regioninstance 1 vlan 1

SW1-mst-regioninstance 2 vlan 2

SW1-mst-regionactive region-configuration

SW2stp region-configuration

SW2-mst-regioninstance 1 vlan 1

SW2-mst-regioninstance 2 vlan 2

SW2-mst-regionactive region-configuration

SW3stp region-configuration

SW3-mst-regionregion-name aa

SW3-mst-regioninstance 1 vlan 1

SW3-mst-regioninstance 2 vlan 2

SW3-mst-regionactive region-configuration

SW4stp region-configuration

SW4-mst-regionregion-name aa

SW4-mst-regioninstance 1 vlan 1

SW4-mst-regioninstance 2 vlan 2

SW4-mst-regionactive region-configuration

4.进行根和备份跟的确定:

SW1stp instance 1 root primary

SW1stp instance 2 root secondary

SW1stp instance 0 root primary

SW2stp instance 1 root secondary

SW2stp instance 2 root primary

SW2stp instance 0 root secondary

SW3port-group group-member e0/0/1 to e0/0/22(配置边缘接口进行优化)

SW3-port-groupstp edged-port enable

SW3int e0/0/3(修改WiFi接口优先级)

SW3-Ethernet0/0/3stp instance 0 port priority 16

5.配置ip地址SVI:

SW1int vlan 1

SW1-Vlanif1ip add 172.16.1.1 25

SW1int vlan 2

SW1-Vlanif2ip add 172.16.1.129 25

SW2int vlan 1

SW2-Vlanif1ip add 172.16.1.2 25

SW2int vlan 2

SW2-Vlanif2ip add 172.16.1.130 25

6.进行网关冗余VRRP:

SW1int vlan 1

SW1-Vlanif1vrrp vrid 1 virtual-ip 172.16.1.126

SW1-Vlanif1vrrp vrid 1 priority 110 (称为主ip)

SW1-Vlanif1vrrp vrid 1 track interface g0/0/1 reduced 20

SW2int vlan 1

SW2-Vlanif1vrrp vrid 1 virtual-ip 172.16.1.126

SW2int vlan 2

SW2-Vlanif2vrrp vrid 1 virtual-ip 172.16.1.254

SW2-Vlanif2vrrp vrid 1 priority 110

SW2-Vlanif2vrrp vrid 1 track int g0/0/1 reduced 20

SW1int vlan 2

SW1-Vlanif2vrrp vrid 1 virtual-ip 172.16.1.254

7.配置DHCP获取IP地址:

SW1dhcp enable

SW1ip pool v1

SW1-ip-pool-v1net 172.16.1.0 mask 25

SW1-ip-pool-v1gateway-list 172.16.1.126

SW1-ip-pool-v1dns-list 114.114.114.114

SW1-ip-pool-v1q

SW1ip pool v2

SW1-ip-pool-v2net 172.16.1.128 mask 25

SW1-ip-pool-v2gateway-list 172.16.1.254

SW1-ip-pool-v2dns-list 114.114.114.114

SW1-ip-pool-v2q

SW1int vlan 1

SW1-Vlanif1dhcp select global

SW1-Vlanif1int vlan 2

SW1-Vlanif2dhcp select global

SW2dhcp enable

SW2ip pool v1

Info:It's successful to create an IP address pool.

SW2-ip-pool-v1net 172.16.1.0 mask 25

SW2-ip-pool-v1gateway-list 172.16.1.126

SW2-ip-pool-v1dns-list 114.114.114.114

SW2-ip-pool-v1q

SW2ip pool v2

Info:It's successful to create an IP address pool.

SW2-ip-pool-v2net 172.16.1.128 mask 25

SW2-ip-pool-v2gateway-list 172.16.1.254

SW2-ip-pool-v2dns-list 114.114.114.114

SW2-ip-pool-v2q

SW2int vlan 1

SW2-Vlanif1dhcp select global

SW2-Vlanif1int vlan 2

SW2-Vlanif2dhcp select global

8.对于上层路由器进行连接

SW1vlan 99

SW1-GigabitEthernet0/0/2int g0/0/1

SW1-GigabitEthernet0/0/1port link-type access

SW1-GigabitEthernet0/0/1port default vlan 99

SW1int vlan 99

SW1-Vlanif99ip add 172.16.0.2 30

SW2vlan 99

SW2-vlan99int g0/0/1

SW2-GigabitEthernet0/0/1port link-type access

SW2-GigabitEthernet0/0/1port default vlan 99

SW2-GigabitEthernet0/0/1q

SW2int vlan 99

SW2-Vlanif99ip add 172.16.0.6 30

9.配置沉默接口:

SW1-ospf-1silent-interface all

SW1-ospf-1undo silent-interface GigabitEthernet 0/0/1

SW1-ospf-1undo silent-interface Vlanif 99

SW1-ospf-1undo silent-interface Eth-Trunk 0

SW1-ospf-1undo silent-interface Vlanif 1

SW2ospf 1

SW2-ospf-1silent-interface all

SW2-ospf-1undo silent-interface GigabitEthernet 0/0/1

SW2-ospf-1undo silent-interface Vlanif 99

SW2-ospf-1undo silent-interface Eth-Trunk 0

SW2-ospf-1undo silent-interface Vlanif 1

三。配置路由器部分:

1.配置ospf协议

R2ospf 1 router-id 2.2.2.2

R2-ospf-1area 0

R2-ospf-1-area-0.0.0.0net 172.16.0.0 0.0.0.255

SW1ospf 1 router-id 3.3.3.3

SW1-ospf-1area 0

SW1-ospf-1-area-0.0.0.0net 172.16.0.2 0.0.0.0

SW1-ospf-1area 1

SW1-ospf-1-area-0.0.0.1net 172.16.1.0 0.0.0.255

SW1-ospf-1-area-0.0.0.1

SW2ospf 1 router-id 4.4.4.4

SW2-ospf-1area 0

SW2-ospf-1-area-0.0.0.0net 172.16.0.6 0.0.0.0

SW2-ospf-1-area-0.0.0.0q

SW2-ospf-1area 1

SW2-ospf-1-area-0.0.0.1net 172.16.1.0 0.0.0.255

2.配置缺省路由

R2ip route-static 0.0.0.0 0 12.1.1.1

R2-ospf-1default-route-advertise

3.进行路由汇总:

SW1ospf 1

SW1-ospf-1area 1

SW1-ospf-1-area-0.0.0.1abr-summary 172.16.1.0 255.255.255.0

SW2ospf 1

SW2-ospf-1area 1

SW2-ospf-1-area-0.0.0.1abr-summary 172.16.1.0 255.255.255.0

4.防止路由黑洞

SW1ip route-static 172.16.1.0 24 NULL 0

SW2ip route-static 172.16.1.0 24 NULL 0

5.配置nat,进行上网:

R2acl 2000

R2-acl-basic-2000rule permit source 172.16.0.0 0.0.255.255

R2-acl-basic-2000q

R2int g0/0/0

R2-GigabitEthernet0/0/0nat outbound 2000

相关推荐
北龙云海25 分钟前
案例分享 | 面向公网业务系统境内访问白名单配置实操方案
运维·网络·安全·网络安全·告警·数据泄露·入侵攻击
闲猫1 小时前
Spring AI对接Deepseek 使用Charles代理api.deepseek.com 拦截报文,查看Tool和Skill的本质
网络·网络协议·http
niaiheni3 小时前
Fastjson 1.2.83 “Gadget-Free“ RCE
网络·安全·web安全
意疏3 小时前
远程办公软件哪个安全性高?UU远程8项安全防线全覆盖
网络·安全
牛马之星4 小时前
气体涡轮流量计如何维护
网络·经验分享
MonolithIoT4 小时前
实战方案|设备备件无人值守仓库:连续化产线运维备件 7×24 小时数字化管控方案
运维·网络·数据库
三8445 小时前
BGP/GRE练习
网络
念恒123066 小时前
网络基础
linux·网络·c++
白山云北诗6 小时前
漏洞扫描+渗透测试:从资产摸底到风险验证,完成二次安全收口
网络·安全·web安全·渗透测试·漏洞扫描·ddos防护·cc防护
爱研究的小梁7 小时前
乾元通聚合路由及管理平台支持全面适配信创
网络·人工智能·信息与通信