实验要求
实验分析
配置思路
交换
eth-trunk > 创建vlan > trunk干道> 接口划分vlan > STP > SVI > VRRP > DHCP
路由
实验拓扑
实验步骤
一.eth-trunk的配置
SW1:
[sw1]int Eth-Trunk 0 ----创建虚拟接口
[sw1-Eth-Trunk0]int g0/0/23 ---将接口划入虚拟接口
[sw1-GigabitEthernet0/0/23]eth-trunk 0
[sw1-GigabitEthernet0/0/23]int g0/0/24
[sw1-GigabitEthernet0/0/24]e
[sw1-GigabitEthernet0/0/24]eth-trunk 0
SW2:
[sw2]int Eth-Trunk 0
[sw2-Eth-Trunk0]int g0/0/23
[sw2-GigabitEthernet0/0/23]e
[sw2-GigabitEthernet0/0/23]eth-trunk 0
[sw2-GigabitEthernet0/0/23]int g0/0/24
[sw2-GigabitEthernet0/0/24]e
[sw2-GigabitEthernet0/0/24]eth-trunk 0
二.创建VLAN,划分vlan,配置Trunk干道
SW1:
[sw1]port-group group-member GigabitEthernet 0/0/2 GigabitEthernet 0/0/3 Eth-Trunk 0
[sw1-port-group]port link-type trunk
[sw1-port-group]port trunk allow-pass vlan all
SW2:
[sw2]port-group group-member GigabitEthernet 0/0/2 GigabitEthernet 0/0/3 Eth-Trunk 0
[sw2-port-group]port link-type trunk
[sw2-port-group]port trunk allow-pass vlan all
SW3:
[sw3]vlan 2
[sw3]port-group group-member GigabitEthernet 0/0/1 GigabitEthernet 0/0/2
[sw3-port-group]port link-type trunk
[sw3-port-group]port trunk allow-pass vlan 2
[sw3]int e0/0/2
[sw3-Ethernet0/0/2]port link-type access
[sw3-Ethernet0/0/2]port default vlan 2
[sw3-Ethernet0/0/2]stp edged-port enable
[sw3-Ethernet0/0/2]int e0/0/1
[sw3-Ethernet0/0/1]stp edged-port enable
SW4:
[sw4]vlan 2
[sw4]port-group group-member GigabitEthernet 0/0/1 GigabitEthernet 0/0/2
[sw4-port-group]port link-type trunk
[sw4-port-group]port trunk allow-pass vlan 2
[sw4]int e0/0/2
[sw4-Ethernet0/0/2]port link-type access
[sw4-Ethernet0/0/2]port default vlan 2
[sw3-Ethernet0/0/2]stp edged-port enable
[sw3-Ethernet0/0/2]int e0/0/1
[sw3-Ethernet0/0/1]stp edged-port enable
三.STP配置
SW1 —— SW4
stp region-configuration ---进入MSTP组
region-name a ---创建名字,但其他交换机配置名必须一致
instance 1 vlan 1 ---将VLAN按需求放入对应instance中
instance 2 vlan 2
active region-configuration ---激活MST域的配置
[sw1]stp instance 1 root primary ---将instan 1作为SW1的主根
[sw1]stp instance 2 root secondary ---将instan 2作为SW1的备份根
[sw2]stp instance 1 root secondary ---将instan 1作为SW2的备份根
[sw2]stp instance 2 root primary ---将instan 2作为SW2的主根
四.配置SVI和VRRP
SW1:
[sw1]interface Vlan 1
[sw1-Vlanif1]ip address 172.16.1.1 25 ---SVI配置
[sw1-Vlanif1]vrrp vrid 1 virtual-ip 172.16.1.126 ---激活VRRP,配置虚拟网关
[sw1-Vlanif1]vrrp vrid 1 priority 110 ---修改优先级
[sw1-Vlanif1]vrrp vrid 1 track interface GigabitEthernet 0/0/1 reduced 50 ---上行链路追踪,如果上行的端口发送故障,则将网关接口的VRRP优先级降低50(默认降低10)
[sw1]interface Vlan 2
[sw1-Vlanif2]ip address 172.16.1.129 25
[sw1-Vlanif2]vrrp vrid 1 virtual-ip 172.16.1.254
SW2:
[sw2]interface Vlan 1
[sw2-Vlanif1]ip address 172.16.1.2 25
[sw2-Vlanif1]vrrp vrid 1 virtual-ip 172.16.1.126
[sw2]interface Vlan 2
[sw2-Vlanif2]ip address 172.16.1.130 25
[sw2-Vlanif2]vrrp vrid 1 virtual-ip 172.16.1.254
[sw2-Vlanif2]vrrp vrid 1 priority 110
[sw2-Vlanif2]vrrp vrid 1 track interface GigabitEthernet 0/0/1 reduced 50
五、配置DHCP
[sw1]dhcp enable
[sw1]ip pool v1
[sw1-ip-pool-v1]network 172.16.1.0 mask 25
[sw1-ip-pool-v1]gateway-list 172.16.1.126
[sw1-ip-pool-v1]q
[sw1]ip pool v2
[sw1-ip-pool-v2]network 172.16.1.128 mask 25
[sw1-ip-pool-v2]gateway-list 172.16.1.254
[sw1]int Vlanif 1
[sw1-Vlanif1]dhcp select global
[sw1-Vlanif1]q
[sw1]int Vlanif 2
[sw1-Vlanif2]dhcp select global
SW2:
[sw2]dhcp enable
[sw2]ip pool v1
[sw2-ip-pool-v1]network 172.16.1.0 mask 25
[sw2-ip-pool-v1]gateway-list 172.16.1.126
[sw2-ip-pool-v1]q
[sw2]ip pool v2
[sw2-ip-pool-v2]network 172.16.1.128 mask 25
[sw2-ip-pool-v2]gateway-list 172.16.1.254
[sw2]int Vlanif 1
[sw2-Vlanif1]dhcp select global
[sw2-Vlanif1]q
[sw2]int Vlanif 2
[sw2-Vlanif2]dhcp select global
六.路由配置
R1
R2
交换机上IP配置,需要虚拟接口
SW1:
[sw1]vlan 100
[sw1-vlan100]q
[sw1]int Vlanif 100
[sw1-Vlanif100]ip address 172.16.0.2 30
[sw1]int g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access
[sw1-GigabitEthernet0/0/1]port default vlan 100
SW2:
[sw2]vlan 100
[sw2-vlan100]q
[sw2]int Vlanif 100
[sw2-Vlanif100]ip address 172.16.0.6 30
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type access
[sw2-GigabitEthernet0/0/1]port default vlan 100
这里选择动态路由RIP
[r1]rip
[r1-rip-1]v 2
[r1-rip-1]network 172.16.0.0
[r1-rip-1]default-route originate
[sw1]rip
[sw1-rip-1]v 2
[sw1-rip-1]network 172.16.0.0
[sw2]rip
[sw2-rip-1]v 2
[sw2-rip-1]network 172.16.0.0
NAT
NAT地址转换使私网通公网
[r1]ip route-static 0.0.0.0 0 12.0.0.2
[r1]acl 2000
[r1-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r1-acl-basic-2000]q
[r1]int g 0/0/0
[r1-GigabitEthernet0/0/0]nat outbound 2000
实验验证