实验任务
需要完成的任务如下。
(1)在总部和分公司相应交换机上完成 VLAN 相关配置,包括 VLAN 创建和端口划分、Trunk 配置、以太网通道配置和 MSTP 配置等。
(2)在总部和分公司的网络中完成 IP 地址配置,包括配置路由器接口的 IP 地址,为三层交换机创建 VLANIF 并配置 IP 地址,配置计算机和服务器的 IP 地址、子网掩码和网关。
(3)为总部核心交换机配置 VRRP,为主机提供冗余网关。
(4)配置 NAT,使总部和分公司的主机可以通过 SZ 路由器访问 Internet。
(5)测试以上所有直连链路的连通性。
(6)OSPF 区域划分:广州分公司和深圳总部网络划分到 OSPF Area 1 中,深圳总部和北京分公司网络划分到 OSPF Area 2 中,深圳总部网络划分到 OSPF Area 0 中,修改 OSPF 计算度量值参考带宽为 1000Mbit/s。路由器 SZ 的 Router ID 为 1.1.1.1,路由器 GZ 的 Router ID 为 2.2.2.2,路由器 BJ 的 Router ID 为 3.3.3.3,交换机 S1 的 Router ID 为 4.4.4.4,交换机 S2 的 Router ID 为 5.5.5.5,交换机 S5 的 Router ID 为 6.6.6.6,交换机 S6 的 Router ID 为 7.7.7.7。
(7)在深圳总部路由器上分别配置 OSPF Area 0、1 和 2 的 ABR 路由聚合,以便减少路由表大小,提高路由查找效率。
(8)为了减少向局域网发送不必要的 OSPF 更新,将分公司交换机适当接口配置为静默接口。
(9)为了提高网络安全性,在深圳总部到分公司的两条链路上配置 OSPF MD5 验证,在深圳总部的 OSPF Area 0 设备上配置 MD5 验证。
(10)在深圳总部和北京分公司的链路上,将接口发送 Hello 报文间隔改为 5s,Dead 时间改为 20s。
(11)将 Area 2 配置为完全末节区域。
(12)控制 DR 选举,使深圳总部路由器成为连接三层交换机 S1 和 S2 的相应网段的 DR。
(13)在深圳总部路由器上配置指向 ISP 的静态默认路由,并向 OSPF 网络注入默认路由。
(14)查看各路由器的 OSPF 邻居表、链路状态数据库和路由表,并进行网络连通性测试。
(15)保存配置文件,完成项目测试报告。
- 项目目的
通过本项目可以掌握如下知识点和技能点,同时积累项目经验。
(1)启动 OSPF 路由进程和启用参与 OSPF 协议接口的方法。
(2)配置 OSPF 计时器参数的方法。
(3)OSPF 计算度量值参考带宽的修改方法。
(4)修改 OSPF 接口优先级控制 DR 选举的方法。
(5)广播多路访问链路上 OSPF 的特征。
(6)基于链路和基于区域的 OSPF 验证的配置方法。
(7)区域间路由汇聚和向 OSPF 网络注入默认路由的方法。
(8)OSPF 不同路由器类型的功能和 OSPF LSA 的类型及特征。
(9)OSPF 链路状态数据库的特征和含义,以及 OSPF 第一类外部路由和第二类外部路由的区别。
(10)查看和调试 OSPF 协议相关信息的方法。
实验拓扑

SZ路由器配置
bash
#
sysname SZ
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher OOCM4m($F4ajUn1vMEIBNUw#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 172.16.12.1 255.255.255.252
ospf authentication-mode hmac-md5 1 cipher pFgcIB7-wIECB7Ie7'/)9\3#
#
interface GigabitEthernet0/0/1
ip address 192.168.12.1 255.255.255.252
ospf authentication-mode hmac-md5 1 cipher t-j(=lln<93@9_G-B0Y2H\b#
#
interface GigabitEthernet0/0/2
ip address 10.2.2.1 255.255.255.252
ospf dr-priority 2
#
interface GigabitEthernet0/0/3
ip address 10.2.3.1 255.255.255.252
ospf dr-priority 2
#
wlan
#
interface NULL0
#
ospf 1 router-id 1.1.1.1
default-route-advertise
bandwidth-reference 1000
area 0.0.0.0
abr-summary 10.1.12.0 255.255.252.0
authentication-mode hmac-md5 1 cipher :ZeeDxthRS939O4.`(ZG/\g#
network 10.2.3.1 0.0.0.0
network 10.2.2.1 0.0.0.0
area 0.0.0.1
abr-summary 172.16.8.0 255.255.252.0
network 172.16.12.1 0.0.0.0
area 0.0.0.2
abr-summary 192.168.2.0 255.255.254.0
network 192.168.12.1 0.0.0.0
stub no-summary
#
ip route-static 0.0.0.0 0.0.0.0 218.18.12.2
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
GZ路由器配置
bash
#
sysname GZ
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher +*X%D|%Wg7=H)H2[EInBTQO#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 172.16.12.2 255.255.255.252
ospf authentication-mode hmac-md5 1 cipher ;bXQ8>blpC3IF$':[285ua1#
#
interface GigabitEthernet0/0/1
ip address 172.16.6.1 255.255.255.252
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
ospf 1 router-id 2.2.2.2
bandwidth-reference 1000
area 0.0.0.1
network 172.16.12.2 0.0.0.0
network 172.16.6.1 0.0.0.0
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
BJ路由器配置
bash
#
sysname BJ
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher B3wPB^]SX$=H)H2[EInB3QO#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
ip address 192.168.6.1 255.255.255.252
#
interface GigabitEthernet0/0/1
ip address 192.168.12.2 255.255.255.252
ospf authentication-mode hmac-md5 1 cipher t-j(=lln<9ECB7Ie7'/)2`W#
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
ospf 1 router-id 3.3.3.3
bandwidth-reference 1000
area 0.0.0.2
network 192.168.12.2 0.0.0.0
network 192.168.6.1 0.0.0.0
stub
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
交换机S1配置
bash
#
sysname S1
#
vlan batch 12 to 15 100
#
stp instance 0 root primary
stp instance 1 root primary
stp instance 2 root secondary
stp bpdu-protection
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name RG1
instance 1 vlan 12 to 13
instance 2 vlan 14 to 15
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif12
ip address 10.1.12.252 255.255.255.0
vrrp vrid 1 virtual-ip 10.1.12.254
vrrp vrid 1 priority 120
vrrp vrid 1 preempt-mode timer delay 20
#
interface Vlanif13
ip address 10.1.13.252 255.255.255.0
vrrp vrid 2 virtual-ip 10.1.13.254
vrrp vrid 2 priority 120
vrrp vrid 2 preempt-mode timer delay 20
#
interface Vlanif14
ip address 10.1.14.252 255.255.255.0
vrrp vrid 3 virtual-ip 10.1.14.254
#
interface Vlanif15
ip address 10.1.15.252 255.255.255.0
vrrp vrid 4 virtual-ip 10.1.15.254
#
interface Vlanif100
ip address 10.2.2.2 255.255.255.252
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 100
stp edged-port enable
#
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
eth-trunk 1
#
interface GigabitEthernet0/0/24
eth-trunk 1
#
interface NULL0
#
ospf 1 router-id 4.4.4.4
bandwidth-reference 1000
area 0.0.0.0
authentication-mode hmac-md5 1 cipher {\Z8/"Rs$@sPddVIN=17BbZ#
network 10.2.2.2 0.0.0.0
network 10.1.12.252 0.0.0.0
network 10.1.13.252 0.0.0.0
network 10.1.14.252 0.0.0.0
network 10.1.15.252 0.0.0.0
#
user-interface con 0
user-interface vty 0 4
#
return
交换机S2配置
bash
#
sysname S2
#
vlan batch 12 to 15 200
#
stp instance 0 root secondary
stp instance 1 root secondary
stp instance 2 root primary
stp bpdu-protection
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name RG1
instance 1 vlan 12 to 13
instance 2 vlan 14 to 15
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif12
ip address 10.1.12.253 255.255.255.0
vrrp vrid 1 virtual-ip 10.1.12.254
#
interface Vlanif13
ip address 10.1.13.253 255.255.255.0
vrrp vrid 2 virtual-ip 10.1.13.254
#
interface Vlanif14
ip address 10.1.14.253 255.255.255.0
vrrp vrid 3 virtual-ip 10.1.14.254
vrrp vrid 3 priority 120
vrrp vrid 3 preempt-mode timer delay 20
#
interface Vlanif15
ip address 10.1.15.253 255.255.255.0
vrrp vrid 4 virtual-ip 10.1.15.254
vrrp vrid 4 priority 120
vrrp vrid 4 preempt-mode timer delay 20
#
interface Vlanif200
ip address 10.2.3.2 255.255.255.252
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 200
stp edged-port enable
#
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
eth-trunk 1
#
interface GigabitEthernet0/0/24
eth-trunk 1
#
interface NULL0
#
ospf 1 router-id 5.5.5.5
bandwidth-reference 1000
area 0.0.0.0
authentication-mode hmac-md5 1 cipher <`XfQyVFm)uqcXT}k'OI7bK#
network 10.2.3.2 0.0.0.0
network 10.1.12.253 0.0.0.0
network 10.1.13.253 0.0.0.0
network 10.1.14.253 0.0.0.0
network 10.1.15.253 0.0.0.0
#
user-interface con 0
user-interface vty 0 4
#
return
交换机S3配置
bash
#
sysname S3
#
vlan batch 12 to 15
#
stp bpdu-protection
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
stp region-configuration
region-name RG1
instance 1 vlan 12 to 13
instance 2 vlan 14 to 15
active region-configuration
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif12
#
interface Vlanif13
#
interface Vlanif14
#
interface Vlanif15
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 12
stp edged-port enable
#
interface GigabitEthernet0/0/4
port link-type access
port default vlan 13
stp edged-port enable
#
interface GigabitEthernet0/0/5
port link-type access
port default vlan 14
stp edged-port enable
#
interface GigabitEthernet0/0/6
port link-type access
port default vlan 15
stp edged-port enable
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return
交换机S5配置
bash
#
sysname S5
#
vlan batch 22 33 44 55 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif22
ip address 172.16.8.254 255.255.255.0
#
interface Vlanif33
ip address 172.16.9.254 255.255.255.0
#
interface Vlanif44
ip address 172.16.10.254 255.255.255.0
#
interface Vlanif55
ip address 172.16.11.254 255.255.255.0
#
interface Vlanif100
ip address 172.16.6.2 255.255.255.252
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 100
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
port link-type access
port default vlan 22
#
interface GigabitEthernet0/0/22
port link-type access
port default vlan 33
#
interface GigabitEthernet0/0/23
port link-type access
port default vlan 44
#
interface GigabitEthernet0/0/24
port link-type access
port default vlan 55
#
interface NULL0
#
ospf 1 router-id 6.6.6.6
silent-interface Vlanif22
silent-interface Vlanif33
silent-interface Vlanif44
silent-interface Vlanif55
bandwidth-reference 1000
area 0.0.0.1
network 172.16.6.2 0.0.0.0
network 172.16.8.254 0.0.0.0
network 172.16.9.254 0.0.0.0
network 172.16.10.254 0.0.0.0
network 172.16.11.254 0.0.0.0
#
user-interface con 0
user-interface vty 0 4
#
return
交换机S6配置
bash
#
sysname S6
#
vlan batch 100 222 333
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif100
ip address 192.168.6.2 255.255.255.252
#
interface Vlanif222
ip address 192.168.2.254 255.255.255.0
#
interface Vlanif333
ip address 192.168.3.254 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 100
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
port link-type access
port default vlan 222
#
interface GigabitEthernet0/0/24
port link-type access
port default vlan 333
#
interface NULL0
#
ospf 1 router-id 7.7.7.7
silent-interface Vlanif222
silent-interface Vlanif333
bandwidth-reference 1000
area 0.0.0.2
network 192.168.6.2 0.0.0.0
network 192.168.2.254 0.0.0.0
network 192.168.3.254 0.0.0.0
stub
#
user-interface con 0
user-interface vty 0 4
#
return
路由器R1配置
bash
#
sysname Huawei
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher cy9C$[HHtR=H)H2[EInB=QO#
local-user admin service-type http
#
firewall zone Local
priority 16
#
interface Ethernet0/0/0
ip address 218.18.12.2 255.255.255.252
#
interface Ethernet0/0/1
#
interface Serial0/0/0
link-protocol ppp
#
interface Serial0/0/1
link-protocol ppp
#
interface Serial0/0/2
link-protocol ppp
#
interface Serial0/0/3
link-protocol ppp
#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface GigabitEthernet0/0/3
#
wlan
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 218.18.12.1
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return