一、拓扑结构
二、配置交换机
封装端口
[SW1]vlan batch 10 20 //添加vlan网段
[SW1]int e0/0/1
[SW1-Ethernet0/0/1]port link-type access
[SW1-Ethernet0/0/1]port default vlan 10
[SW1-Ethernet0/0/1]int e0/0/2
[SW1-Ethernet0/0/2]port link-type 20
[SW1-Ethernet0/0/2]port default vlan 20
[SW1-Ethernet0/0/2]int e0/0/3
[SW1-Ethernet0/0/3]port link-type access
[SW1-Ethernet0/0/3]port default vlan 10
[SW1-Ethernet0/0/3]int e0/0/4
[SW1-Ethernet0/0/4]port link-type access
[SW1-Ethernet0/0/4]port default vlan 20
[SW1-Ethernet0/0/4]int e0/0/5
[SW1-Ethernet0/0/5]port link-type trunk
[SW1-Ethernet0/0/5]port trunk allow-pass vlan all
[SW1-Ethernet0/0/5]quit
[SW1]display ip int brief //查看ip信息表
三、配置AR1
配置ip地址,子接口
[R1]int g0/0/0.10 //配置子接口
[R1-GigabitEthernet0/0/0.10]dotlq termination vid 10
[R1-GigabitEthernet0/0/0.10]ip address 192.168.10.1 24 //配置ip地址
[R1-GigabitEthernet0/0/0.10]arp broadcast enable
[R1-GigabitEthernet0/0/0.10]int g0/0/0.20
[R1-GigabitEthernet0/0/0.20]dotlq termination vid 20
[R1-GigabitEthernet0/0/0.20]ip address 192.168.20.1 24
[R1-GigabitEthernet0/0/0.20]arp broadcast enable
[R1-GigabitEthernet0/0/0.20]int g0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.0.1 24
[R1-GigabitEthernet0/0/1]quit
[R1]
配置默认网关
[R1]ip route-static 0.0.0.0 0 10.0.0.2
配置ACL
[R1]acl number 3000
[R1-acl-adv-3000]rule 5 permit icmp source any
[R1-acl-adv-3000]rule 5 deny icmp source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
[R1-acl-adv-3000]quit
[R1]int g0/0/0 //激活端口
[R1-GigabitEthernet0/0/0]traffic-filter inbound acl 3000
[R1-GigabitEthernet0/0/0]quit
[R1]acl number 3001
[R1-acl-adv-3001]rule 5 deny tcp source 10.0.0.1 0 destination 11.0.0.2 0 destination-port eq 80
[R1-acl-adv-3001]quit
[R1]int g0/0/1
[R1-GigabitEthernet0/0/1]traffic-filter outbound acl 3001
[R1-GigabitEthernet0/0/0]quit
[R1]dis current-configuration //查看信息表
四、配置AR2
配置ip地址和默认网关
[R2]int g0/0/0
[R2-GigabitEthernet0/0/0]ip add 10.0.0.2 24
[R2-GigabitEthernet0/0/0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip add 11.0.0.1 24
[R2-GigabitEthernet0/0/1]quit
[R2]ip route-static 0.0.0.0 0 10.0.0.1
五、服务器
六、结果
PC1 ping PC2 不通 抓包结果如下
R1 ping 服务器 无tcp 包