'''SW1設定trunk介面模式'''
en
conf t
host SW1
intrange f0/1-4
switchport trunk encapsulation dot1q
sw m t
exit
'''SW2設定trunk介面模式'''
en
conf t
host SW2
intrange f0/1-4
switchport trunk encapsulation dot1q
sw m t
exit
'''SW3設定trunk介面模式'''
en
conf t
ho SW3
intrange f0/3-4
sw m t
exit
'''SW4設定trunk介面模式'''
en
conf t
ho SW4
int f0/3
sw m t
exit
int f0/4
sw m t
exit
'''SW5設定trunk介面模式'''
en
conf t
ho SW5
int f0/3
sw m t
exit
int f0/4
sw m t
exit
'''檢視設定結果'''
do show vlan #如果介面成功設定為trunk,則不會在vlan表中顯示。
第1.2步 設定VTP域及建立VLAN型別
設定VTP可以在2個核心交換機或3個二層交換機中設定。
建立VLAN需要一個個建立。
'''SW1設定VTP域及建立VLAN型別'''
en
conf t
vtp domain qq
vlan 10
exit
vlan 20
exit
vlan 30
exit
vlan 40
exit
vlan 50
exit
'''檢視設定結果'''
do show vlan #檢查各個交換機是否成功根據VTP生成所需VLAN
第1.3步 劃分介面至對應VLAN
對於二層交換機,需要將每個介面按VLAN分類設定。
'''為SW3劃分介面至相應VLAN'''
en
conf t
int f0/1
sw ac vlan 10int f0/2
sw ac vlan 20
exit
'''為SW4劃分介面至相應VLAN'''
en
conf t
int f0/1
sw ac vlan 30int f0/2
sw ac vlan 40
exit
'''為SW5劃分介面至相應VLAN'''
en
conf t
int f0/1
sw ac vlan 50int f0/2
sw ac vlan 50
exit
'''檢視設定結果'''
do show vlan #檢查各個交換機是否成功根據VTP生成所需VLAN
'''為SW1建立虛擬介面設定IP並設定DHCP中繼'''
en
conf t
ip routing
int vlan 10
no shut
ip add 192.168.1.252255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 20
no shut
ip add 192.168.2.252255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 30
no shut
ip add 192.168.3.252255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 40
no shut
ip add 192.168.4.252255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 50
no shut
ip add 192.168.5.252255.255.255.0
ip helper-address 192.168.5.1
exit
'''為SW1升級介面為三級介面並設定IP'''
en
conf t
int f0/5
no switchport
no shut
ip add 192.168.100.1255.255.255.0
exit
int f0/6
no switchport
no shut
ip add 192.168.102.1255.255.255.0
exit
int f0/7
no switchport
no shut
ip add 192.168.106.1255.255.255.0
exit
'''為SW2建立虛擬介面設定IP並設定DHCP中繼'''
en
conf t
ip routing
int vlan 10
no shut
ip add 192.168.1.253255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 20
no shut
ip add 192.168.2.253255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 30
no shut
ip add 192.168.3.253255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 40
no shut
ip add 192.168.4.253255.255.255.0
ip helper-address 192.168.5.1
exit
int vlan 50
no shut
ip add 192.168.5.253255.255.255.0
ip helper-address 192.168.5.1
exit
'''為SW2升級介面為三級介面並設定IP'''
en
conf t
int f0/5
no switchport
no shut
ip add 192.168.101.1255.255.255.0
exit
int f0/6
no switchport
no shut
ip add 192.168.103.1255.255.255.0
exit
int f0/7
no switchport
no shut
ip add 192.168.107.1255.255.255.0
exit
'''檢視設定結果'''
show ip int b #檢查各個vlan及實體介面IP
'''為SW1建立HSRP熱備份'''
en
conf t
int vlan 10
stan 10 ip 192.168.1.254
stan 10 prior 200
stan 10 preempt
stan 10 track f0/5
stan 10 track f0/6
exit
int vlan 20
stan 20 ip 192.168.2.254
stan 20 prior 200
stan 20 preempt
stan 20 track f0/5
stan 20 track f0/6
exit
int vlan 30
stan 30 ip 192.168.3.254
stan 30 prior 200
stan 30 preempt
stan 30 track f0/5
stan 30 track f0/6
exit
int vlan 40
stan 40 ip 192.168.4.254
stan 40 prior 200
stan 40 preempt
stan 40 track f0/5
stan 40 track f0/6
exit
int vlan 50
stan 50 ip 192.168.5.254
stan 50 prior 195
stan 50 preempt
stan 50 track f0/5
stan 50 track f0/6
exit
'''為SW2建立HSRP熱備份'''
en
conf t
int vlan 10
stan 10 ip 192.168.1.254
stan 10 prior 195
stan 10 preempt
stan 10 track f0/5
stan 10 track f0/6
exit
int vlan 20
stan 20 ip 192.168.2.254
stan 20 prior 195
stan 20 preempt
stan 20 track f0/5
stan 20 track f0/6
exit
int vlan 30
stan 30 ip 192.168.3.254
stan 30 prior 195
stan 30 preempt
stan 30 track f0/5
stan 30 track f0/6
exit
int vlan 40
stan 40 ip 192.168.4.254
stan 40 prior 195
stan 40 preempt
stan 40 track f0/5
stan 40 track f0/6
exit
int vlan 50
stan 50 ip 192.168.5.254
stan 50 prior 200
stan 50 preempt
stan 50 track f0/5
stan 50 track f0/6
exit
'''檢視設定結果'''
show standby breif #檢視HSRP設定結果,斷線測試優先順序需要在後續路由器設定後'''ping測試'''
手動為PC1與PC2設定IP,測試兩個VLAN間能否正常通訊。
在PT6.0版本此處ping不通,因為模擬平臺存在bug,在8.0版本可以ping通。
第1.6步 路由器設定IP
根據網路規劃,對路由器每個介面設定IP。
'''為R1介面設定IP'''
en
conf t
ho R1
int f0/0
no shut
ip add 192.168.100.2255.255.255.0
exit
int f0/1
no shut
ip add 192.168.101.2255.255.255.0
exit
int f1/0
no shut
ip add 100.1.1.1255.255.255.0
exit
'''為R2介面設定IP'''
en
conf t
ho R2
int f0/0
no shut
ip add 192.168.102.2255.255.255.0
exit
int f0/1
no shut
ip add 192.168.103.2255.255.255.0
exit
int f1/0
no shut
ip add 101.1.1.1255.255.255.0
exit
'''為R3介面設定IP'''
en
conf t
ho R3
int f0/0
no shut
ip add 192.168.104.2255.255.255.0
exit
int f0/1
no shut
ip add 192.168.105.2255.255.255.0
exit
int f1/0
no shut
ip add 192.168.106.2255.255.255.0
exit
int f1/1
no shut
ip add 192.168.107.2255.255.255.0
exit
'''為R4介面設定IP'''
en
conf t
ho R4
int f0/0
no shut
ip add 192.168.6.254255.255.255.0
exit
int f0/1
no shut
ip add 192.168.104.1255.255.255.0
exit
'''為R5介面設定IP'''
en
conf t
ho R5
int f0/0
no shut
ip add 192.168.7.254255.255.255.0
exit
int f0/1
no shut
ip add 192.168.105.1255.255.255.0
exit
'''為R6介面設定IP'''
en
conf t
ho R6
int f0/0
no shut
ip add 100.1.1.2255.255.255.0
exit
int f0/1
no shut
ip add 101.1.1.2255.255.255.0
exit
int f1/0
no shut
ip add 102.1.1.254255.255.255.0
exit
int f1/1
no shut
ip add 103.1.1.2255.255.255.0
exit
'''為R7介面設定IP'''
en
conf t
ho R7
int f0/0
no shut
ip add 103.1.1.1255.255.255.0
exit
int f0/1
no shut
ip add 10.1.1.254255.255.255.0
exit
'''檢視設定結果'''
show standby breif #斷線測試優先順序需要在後續路由器設定後
第1.7步 路由器設定路由表
由於為採用RIP動態路由設定時,容易形成優先順序相同的路徑,本實驗採用靜態路由表設定的方式進行。
對於路由表條目優先順序,靜態路由>動態路由>預設路由。
建議先使用show ip router 檢視直連路由表有哪些,在進行設定。
'''為SW1設定靜態路由表'''
en
conf t
ip route 192.168.6.0255.255.255.0192.168.106.2
ip route 192.168.7.0255.255.255.0192.168.106.2
ip route 192.168.104.0255.255.255.0192.168.106.2
ip route 192.168.105.0255.255.255.0192.168.106.2
ip route 0.0.0.00.0.0.0192.168.100.2
ip route 0.0.0.00.0.0.0192.168.102.22'''為SW2設定靜態路由表'''
en
conf t
ip route 192.168.6.0255.255.255.0192.168.107.2
ip route 192.168.7.0255.255.255.0192.168.107.2
ip route 192.168.104.0255.255.255.0192.168.107.2
ip route 192.168.105.0255.255.255.0192.168.107.2
ip route 0.0.0.00.0.0.0192.168.101.2
ip route 0.0.0.00.0.0.0192.168.103.22'''為R3設定RIP靜態路由表'''
en
conf t
ip route 192.168.6.0255.255.255.0192.168.104.1
ip route 192.168.7.0255.255.255.0192.168.105.1
ip route 0.0.0.00.0.0.0192.168.106.1
ip route 0.0.0.00.0.0.0192.168.107.12'''為R4設定預設路由表'''
en
conf t
ip route 0.0.0.00.0.0.0192.168.104.2'''為R5設定靜態路由表'''
en
conf t
ip route 0.0.0.00.0.0.0192.168.105.2'''檢視設定結果'''
show ip router #檢視路由表是否收斂'''ping測試'''
手動為PC1與PC6設定IP,測試總部與分部間能否正常通訊。
'''為R1設定靜態路由表'''
en
conf t
ip route 0.0.0.00.0.0.0100.1.1.2
ip route 192.168.1.0255.255.255.0192.168.100.1
ip route 192.168.2.0255.255.255.0192.168.100.1
ip route 192.168.3.0255.255.255.0192.168.100.1
ip route 192.168.4.0255.255.255.0192.168.100.1
ip route 192.168.5.0255.255.255.0192.168.100.1
ip route 192.168.6.0255.255.255.0192.168.100.1
ip route 192.168.7.0255.255.255.0192.168.100.1
ip route 192.168.104.0255.255.255.0192.168.100.1
ip route 192.168.105.0255.255.255.0192.168.100.1
ip route 192.168.106.0255.255.255.0192.168.100.1
ip route 192.168.107.0255.255.255.0192.168.100.1
ip route 192.168.1.0255.255.255.0192.168.101.12
ip route 192.168.2.0255.255.255.0192.168.101.12
ip route 192.168.3.0255.255.255.0192.168.101.12
ip route 192.168.4.0255.255.255.0192.168.101.12
ip route 192.168.5.0255.255.255.0192.168.101.12
ip route 192.168.6.0255.255.255.0192.168.101.12
ip route 192.168.7.0255.255.255.0192.168.101.12
ip route 192.168.104.0255.255.255.0192.168.101.12
ip route 192.168.105.0255.255.255.0192.168.101.12
ip route 192.168.106.0255.255.255.0192.168.101.12
ip route 192.168.107.0255.255.255.0192.168.101.12'''為R2設定靜態路由表'''
en
conf t
ip route 0.0.0.00.0.0.0101.1.1.2
ip route 192.168.1.0255.255.255.0192.168.103.1
ip route 192.168.2.0255.255.255.0192.168.103.1
ip route 192.168.3.0255.255.255.0192.168.103.1
ip route 192.168.4.0255.255.255.0192.168.103.1
ip route 192.168.5.0255.255.255.0192.168.103.1
ip route 192.168.6.0255.255.255.0192.168.103.1
ip route 192.168.7.0255.255.255.0192.168.103.1
ip route 192.168.104.0255.255.255.0192.168.103.1
ip route 192.168.105.0255.255.255.0192.168.103.1
ip route 192.168.106.0255.255.255.0192.168.103.1
ip route 192.168.107.0255.255.255.0192.168.103.1
ip route 192.168.1.0255.255.255.0192.168.102.12
ip route 192.168.2.0255.255.255.0192.168.102.12
ip route 192.168.3.0255.255.255.0192.168.102.12
ip route 192.168.4.0255.255.255.0192.168.102.12
ip route 192.168.5.0255.255.255.0192.168.102.12
ip route 192.168.6.0255.255.255.0192.168.102.12
ip route 192.168.7.0255.255.255.0192.168.102.12
ip route 192.168.104.0255.255.255.0192.168.102.12
ip route 192.168.105.0255.255.255.0192.168.102.12
ip route 192.168.106.0255.255.255.0192.168.102.12
ip route 192.168.107.0255.255.255.0192.168.102.12'''為R6設定靜態路由表'''
en
conf t
ip route 0.0.0.00.0.0.0103.1.1.1'''為R7設定靜態路由表'''
en
conf t
ip route 0.0.0.00.0.0.0103.1.1.2'''檢視設定結果'''
show ip router #檢視路由表是否收斂'''ping測試'''
測試PC1是否能ping通R1、R2介面上的IP。
測試PC8是否能ping通R1、R2外介面上的IP。
第2.2步 為總路由介面設定NAT轉換表
根據路由器R1、R2上介面的內外網方向進行定義,f0/0、f0/1是內網介面,f1/0是外網介面。
'''為R1設定NAT轉換表,設定內網網段規則並應用於外網介面上'''
en
conf t
int f0/0
ip nat inside
exit
int f0/1
ip nat inside
exit
int f1/0
ip nat outside
exit
acc 1 permit 192.168.0.00.0.255.255
ip nat inside source list1int f1/0 overload
'''為R2設定NAT轉換表,設定內網網段規則並應用於外網介面上'''
en
conf t
int f0/0
ip nat inside
exit
int f0/1
ip nat inside
exit
int f1/0
ip nat outside
exit
acc 1 permit 192.168.0.00.0.255.255
ip nat inside source list1int f1/0 overload
'''ping測試'''
測試PC1是否能ping通PC8介面上的IP。
'''為R1設定ACL'''
en
conf t
ip access-list extended deny-to-internet
deny ip 192.168.6.00.255.255.255any
deny ip 192.168.7.00.255.255.255any
petmit ip anyany
exit
int f1/0
ip access-group deny-to-internet out
exit
'''為R2設定NAT轉換表,設定內網網段規則並應用於外網介面上'''
en
conf t
ip access-list extended deny-to-internet
deny ip 192.168.6.00.255.255.255any
deny ip 192.168.7.00.255.255.255any
petmit ip anyany
exit
int f1/0
ip access-group deny-to-internet out
exit
'''ping測試'''
成功阻止分部上網。