本次测试知识点有:VLAN 、端口聚合、STP、OSPF、默认路由、静态路由、HSRP、ACL、NAT、DHCP
Vlan
交换机0配置
Switch>en
Switch#conf t
Switch(config)#hostname SW0
SW0(config-if)#int f0/3
SW0(config-if)#switchport mode access
SW0(config-if)#switchport access vlan 10
交换机1配置
Switch>en
Switch#conf t
Switch(config)#hostname SW1
SW1(config-if)#int f0/3
SW1(config-if)#switchport mode access
SW1(config-if)#switchport access vlan 20
交换机2配置
Switch>en
Switch#conf t
Switch(config)#hostname SW2
SW2(config-if)#int f0/3
SW2(config-if)#switchport mode access
SW2(config-if)#switchport access vlan 30
交换机3配置
Switch>en
Switch#conf t
Switch(config)#hostname SW3
SW3(config-if)#int f0/3
SW3(config-if)#switchport mode access
SW3(config-if)#switchport access vlan 40
交换机4配置
Switch>enable
Switch#conf t
Switch(config)#hostname SW4
SW4(config)#vlan 50
SW4(config-vlan)#int ran f0/2-4
SW4(config-if-range)#switchport mode access
SW4(config-if-range)#switchport access vlan 50
多层交换机0配置
Switch>enable
Switch#conf t
Switch(config)#hostname SSW0
SSW0(config)#vlan 10
SSW0(config-vlan)#vlan 20
SSW0(config-vlan)#vlan 30
SSW0(config-vlan)#vlan 40
SSW0(config-vlan)#vlan 50
多层交换机1配置
Switch>enable
Switch#conf t
Switch(config)#hostname SSW1
SSW1(config)#vlan 10
SSW1(config-vlan)#vlan 20
SSW1(config-vlan)#vlan 30
SSW1(config-vlan)#vlan 40
端口聚合
交换机0配置
SW0(config)#int range f0/4-5
SW0(config-if-range)#switchport mode trunk
SW0(config-if-range)#channel-protocol lacp
SW0(config-if-range)#channel-group 1 mode ac
SW0(config-if-range)#int ran f0/6-7
SW0(config-if-range)#switchport mode trunk
SW0(config-if-range)#channel-protocol lacp
SW0(config-if-range)#channel-group 2 mode active
交换机1配置
SW1(config)#int range f0/6-7
SW1(config-if-range)#switchport mode trunk
SW1(config-if-range)#channel-protocol lacp
SW1(config-if-range)#channel-group 1 mode ac
SW1(config-if-range)#int ran f0/8-9
SW1(config-if-range)#switchport mode trunk
SW1(config-if-range)#channel-protocol lacp
SW1(config-if-range)#channel-group 2 mode active
交换机2配置
SW2(config)#int range f0/8-9
SW2(config-if-range)#switchport mode trunk
SW2(config-if-range)#channel-protocol lacp
SW2(config-if-range)#channel-group 1 mode ac
SW2(config-if-range)#int ran f0/10-11
SW2(config-if-range)#switchport mode trunk
SW2(config-if-range)#channel-protocol lacp
SW2(config-if-range)#channel-group 2 mode active
交换机3配置
SW2(config)#int range f0/10-11
SW2(config-if-range)#switchport mode trunk
SW2(config-if-range)#channel-protocol lacp
SW2(config-if-range)#channel-group 1 mode ac
SW2(config-if-range)#int ran f0/12-13
SW2(config-if-range)#switchport mode trunk
SW2(config-if-range)#channel-protocol lacp
SW2(config-if-range)#channel-group 2 mode active
交换机4配置
SW3(config)#int range f0/12-13
SW3(config-if-range)#switchport mode trunk
SW3(config-if-range)#channel-protocol lacp
SW3(config-if-range)#channel-group 1 mode ac
多层交换机0配置
SSW0(config)#int ran f0/4-5
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 1 mode active
SSW0(config)#int ran f0/6-7
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 2 mode active
SSW0(config)#int ran f0/8-9
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 3 mode active
SSW0(config)#int ran f0/10-11
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 4 mode active
SSW0(config)#int ran f0/2-3
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 5 mode active
SSW0(config)#int ran f0/12-13
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 6 mode active
多层交换机1配置
SSW0(config)#int ran f0/6-7
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 1 mode active
SSW0(config)#int ran f0/8-9
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 2 mode active
SSW0(config)#int ran f0/10-11
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 3 mode active
SSW0(config)#int ran f0/12-13
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 4 mode active
SSW0(config)#int ran f0/2-3
SSW0(config-if-range)#switchport trunk encapsulation dot1q
SSW0(config-if-range)#switchport mode trunk
SSW0(config-if-range)#channel-protocol lacp
SSW0(config-if-range)#channel-group 5 mode active
STP
多层交换机0配置
SSW0(config)#spanning-tree mode rapid-pvst //快速生成树协议
SSW0(config)#spanning-tree vlan 10,20,50 root primary //vlan 10,20,30为主
SSW0(config)#spanning-tree vlan 30,40 root secondary //vlan 30,40为辅
多层交换机1配置
SSW0(config)#spanning-tree mode rapid-pvst //快速生成树协议
SSW0(config)#spanning-tree vlan 30,40 root primary //vlan 30,40为主
SSW0(config)#spanning-tree vlan 10,20 root secondary //vlan 10,20为辅
HSRP
多层交换机0配置
SSW0(config)#int vlan 10
SSW0(config-if)#ip address 192.168.10.252 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 10 ip 192.168.10.254 //配置虚拟网关
SSW0(config-if)#standby 10 priority 200 //优先级200
SSW0(config-if)#standby 10 preempt //抢占
SSW0(config)#int vlan 20
SSW0(config-if)#ip address 192.168.20.252 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 20 ip 192.168.20.254 //配置虚拟网关
SSW0(config-if)#standby 20 priority 200 //优先级200
SSW0(config-if)#standby 20 preempt //抢占
SSW0(config)#int vlan 30
SSW0(config-if)#ip address 192.168.30.252 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 30 ip 192.168.30.254 //配置虚拟网关
SSW0(config-if)#standby 30 priority 195 //优先级195
SSW0(config-if)#standby 30 preempt //抢占
SSW0(config)#int vlan 40
SSW0(config-if)#ip address 192.168.40.252 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 40 ip 192.168.40.254 //配置虚拟网关
SSW0(config-if)#standby 40 priority 195 //优先级195
SSW0(config-if)#standby 40 preempt //抢占
SSW0(config)#int vlan 50
SSW0(config-if)#ip address 192.168.50.254 255.255.255.0 //配置网关
多层交换机1配置
SSW0(config)#int vlan 10
SSW0(config-if)#ip address 192.168.10.253 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 10 ip 192.168.10.254 //配置虚拟网关
SSW0(config-if)#standby 10 priority 195 //优先级195
SSW0(config-if)#standby 10 preempt //抢占
SSW0(config)#int vlan 20
SSW0(config-if)#ip address 192.168.20.253 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 20 ip 192.168.20.254 //配置虚拟网关
SSW0(config-if)#standby 20 priority 195 //优先级195
SSW0(config-if)#standby 20 preempt //抢占
SSW0(config)#int vlan 30
SSW0(config-if)#ip address 192.168.30.253 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 30 ip 192.168.30.254 //配置虚拟网关
SSW0(config-if)#standby 30 priority 200 //优先级200
SSW0(config-if)#standby 30 preempt //抢占
SSW0(config)#int vlan 40
SSW0(config-if)#ip address 192.168.40.253 255.255.255.0 //配置真实IP
SSW0(config-if)#standby 40 ip 192.168.40.254 //配置虚拟网关
SSW0(config-if)#standby 40 priority 200 //优先级200
SSW0(config-if)#standby 40 preempt //抢占
交换和路由配置IP
先配置IP
多层交换机0配置
SSW0(config)#ip routing
SSW0(config)#int f0/1
SSW0(config-if)#no switchport
SSW0(config-if)#ip address 10.0.0.2 255.255.255.0
SSW0(config-if)#no shutdown
多层交换机1配置
SSW1(config)#ip routing
SSW1(config)#int f0/1
SSW1(config-if)#no switchport
SSW1(config-if)#ip address 20.0.0.2 255.255.255.0
SSW1(config-if)#no shutdown
路由器0配置
R1(config)#int g0/0
R1(config-if)#ip address 10.0.0.1 255.255.255.0
R1(config-if)#no shutdown
R1(config-if)#int g0/1
R1(config-if)#ip address 20.0.0.1 255.255.255.0
R1(config-if)#no shutdown
R1(config-if)int g0/2
R1(config-if)#ip address 202.96.209.1 255.255.255.0
R1(config-if)#no shutdown
路由器1配置
R2(config)#int g0/0
R2(config-if)#ip address 202.96.209.2 255.255.255.0
R2(config-if)#no shutdown
R2(config)#int g0/1
R2(config-if)#ip address 8.8.8.1 255.255.255.0
R2(config-if)#no shutdown
OSPF
多层交换机0配置
SSW0(config)#router ospf 100
SSW0(config-router)#network 192.168.10.0 0.0.0.255 area 0
SSW0(config-router)#network 192.168.20.0 0.0.0.255 area 0
SSW0(config-router)#network 192.168.30.0 0.0.0.255 area 0
SSW0(config-router)#network 192.168.40.0 0.0.0.255 area 0
SSW0(config-router)#network 192.168.50.0 0.0.0.255 area 0
SSW0(config-router)#network 10.0.0.0 0.0.0.255 area 0
多层交换机1配置
SSW1(config)#router ospf 100
SSW1(config-router)#network 192.168.10.0 0.0.0.255 area 0
SSW1(config-router)#network 192.168.20.0 0.0.0.255 area 0
SSW1(config-router)#network 192.168.30.0 0.0.0.255 area 0
SSW1(config-router)#network 192.168.40.0 0.0.0.255 area 0
SSW1(config-router)#network 192.168.50.0 0.0.0.255 area 0
SSW1(config-router)#network 20.0.0.0 0.0.0.255 area 0
或者
SSW1(config-router)#network 192.168.0.0 0.0.255.255 area 0
路由器0配置
R1(config)#router ospf 100
R1(config-router)#network 10.0.0.0 255.255.255.0 area 0
R1(config-router)#network 20.0.0.0 255.255.255.0 area 0
R1(config-router)#network 202.96.209.0 255.255.255.0 area 0
默认路由
多层交换机0配置
SSW0(config)#ip route 0.0.0.0 0.0.0.0 10.0.0.1
多层交换机1配置
SSW1(config)#ip route 0.0.0.0 0.0.0.0 20.0.0.1
路由器1配置
R1(config)#ip route 0.0.0.0 0.0.0.0 202.96.209.2
路由器2配置
R2(config)#ip route 0.0.0.0 0.0.0.0 202.96.209.1
DHCP
//路由器当DHCP服务器
//路由器0配置DHCP服务器
R1(config)#ip dhcp pool vlan10
R1(dhcp-config)#default-router 192.168.10.254
R1(dhcp-config)#network 192.168.10.0 255.255.255.0
R1(dhcp-config)#domain-name mumawu.com
R1(dhcp-config)#dns-server 192.168.50.2
R1(config)#ip dhcp pool vlan20
R1(dhcp-config)#default-router 192.168.20.254
R1(dhcp-config)#network 192.168.20.0 255.255.255.0
R1(dhcp-config)#domain-name mumawu.com
R1(dhcp-config)#dns-server 192.168.50.2
R1(config)#ip dhcp pool vlan30
R1(dhcp-config)#default-router 192.168.30.254
R1(dhcp-config)#network 192.168.30.0 255.255.255.0
R1(dhcp-config)#domain-name mumawu.com
R1(dhcp-config)#dns-server 192.168.50.2
R1(config)#ip dhcp pool vlan40
R1(dhcp-config)#default-router 192.168.40.254
R1(dhcp-config)#network 192.168.40.0 255.255.255.0
R1(dhcp-config)#domain-name mumawu.com
R1(dhcp-config)#dns-server 192.168.50.2
//排除地址
R1(config)#ip dhcp excluded-address 192.168.10.250 192.168.10.254
R1(config)#ip dhcp excluded-address 192.168.20.250 192.168.20.254
R1(config)#ip dhcp excluded-address 192.168.30.250 192.168.30.254
R1(config)#ip dhcp excluded-address 192.168.40.250 192.168.40.254
多层交换机0配置中继
SSW0(config)#int vlan 10
SSW0(config-if)#ip helper-address 10.0.0.1
SSW0(config)#int vlan 20
SSW0(config-if)#ip helper-address 10.0.0.1
SSW0(config)#int vlan 30
SSW0(config-if)#ip helper-address 10.0.0.1
SSW0(config)#int vlan 40
SSW0(config-if)#ip helper-address 10.0.0.1
多层交换机1配置中继
SSW0(config)#int vlan 10
SSW0(config-if)#ip helper-address 20.0.0.1
SSW0(config)#int vlan 20
SSW0(config-if)#ip helper-address 20.0.0.1
SSW0(config)#int vlan 30
SSW0(config-if)#ip helper-address 20.0.0.1
SSW0(config)#int vlan 40
SSW0(config-if)#ip helper-address 20.0.0.1
如果有DHCP服务器的话直接执行中继命令即可,IP指向DHCP服务器IP
NAT
//内部访问外部单IP
R1(config)#access-list 10 deny 192.168.30.0 0.0.0.255
R1(config)#ip nat inside source list 10 interface g0/2 overload
R1(config)#interface g0/0
R1(config-if)#ip nat inside
R1(config-if)#int g0/1
R1(config-if)#ip nat inside
R1(config-if)#int g0/2
R1(config-if)#ip nat outside
//内部访问外部多IP
//内部访问外部多IP
R1(config)#access-list 10 permit 192.168.10.0 0.0.0.255
R1(config)#access-list 10 permit 192.168.20.0 0.0.0.255
R1(config)#ip nat pool nattest 202.96.209.3 202.96.209.10 netmask 255.255.255.0 //定义名为 nattest的地址池
R1(config)#ip nat inside source list 10 pool nattest //应用地址池
R1(config)#int g0/0
R1(config-if)#ip nat inside
R1(config-if)#int g0/1
R1(config-if)#ip nat inside
R1(config-if)#int g0/2
R1(config-if)#ip nat outside
//外部访问内部静态NAT
R1(config)#ip nat inside source static tcp 192.168.50.3 80 202.96.209.10 80 //把内部服务器80端口转换为公网IP80端口
ACL
ACL标准
//控制30和40网段禁止访问外部服务器
R1(config)#access-list 20 deny 192.168.30.0 0.0.0.255
R1(config)#access-list 20 deny 192.168.40.0 0.0.0.255
R1(config)#access-list 20 permit any
R1(config)#int g0/2
R1(config-if)#ip access-group 20 out //设置为路由出方向接口
ACL扩展
R1(config)#access-list 110 Permit Tcp 192.168.20.0 0.0.0.255 192.168.50.0 0.0.0.255 eq 80 //允许20网段访问50网段WEB服务
R1(config)#access-list 110 deny ip 192.168.20.0 0.0.0.255 192.168.30.0 0.0.0.255 //拒绝 20网段访问30网段
*******注意顺序很重要,他是从上到下匹配到任何一个就不往下执行,所以把允许的写到上面。
//自定义ACL
R1(config)#ip access-list extended testacl //定义一个名字为 testacl的ACL
R1(config-ext-nacl)#10 permit tcp 192.168.10.0 0.0.0.255 192.168.40.0 0.0.0.255 eq 21
R1(config-ext-nacl)#20 permit tcp 192.168.20.0 0.0.0.255 192.168.30.0 0.0.0.255 eq 80
R1(config-ext-nacl)#30 deny ip 192.168.10.0 0.0.0.255 192.168.40.0 0.0.0.255
R1(config-ext-nacl)#40 deny ip 192.168.20.0 0.0.0.255 192.168.30.0 0.0.0.255
R1(config-ext-nacl)#50 permit ip any any
//删除单个规则
R1(config)#ip access-list extended testacl //进入ACL
R1(config-ext-nacl)#no 30 deny ip 192.168.10.0 0.0.0.255 192.168.40.0 0.0.0.255
© 版权声明
THE END
暂无评论内容