题目
要求
- R6为isp,接口IP地址均为公有地址;该设备只能配置IP地址,之后不能再对其进行其他任何配置;
- R1-R5为局域网,私有IP地址192.168.1./24,请合理分配;
- R1,R2,R4,各有两个环回地址;R5,R6各有一个环回地址;所有路由器上环回均代表连接用户的接口:
- R3下的两台PC通过DHCP自动获取P地址;
- 选路最佳,路由表尽量小,避免环路;
- R1-R5均可以访问R6的环回;
- R6通过telnet 登录R5的公有IP地址时,实际登陆到R1上;
- R4与R5正常通过1000M链路,故障时通过100M链路;
分析及其配置
一、划分广播域
题目中将R1-R5都划分为私网,公用有个IP段(192.168.1./24)。由于R1-R5之间一共有14个广播域,所以需要对其进行子网划分。
192.168.1.0/24
192.168.1.0000 0000 ---- 0
192.168.1.0001 0000 ---- 16
192.168.1.0010 0000 ---- 32
192.168.1.0011 0000 ---- 48
192.168.1.0100 0000 ---- 64
192.168.1.0101 0000 ---- 80
192.168.1.0110 0000 ---- 96
192.168.1.0111 0000 ---- 112
192.168.1.1000 0000 ---- 128
192.168.1.1001 0000 ---- 144
192.168.1.1010 0000 ---- 160
192.168.1.1011 0000 ---- 176
192.168.1.1100 0000 ---- 192
192.168.1.1101 0000 ---- 208
多出两个
192.168.1.1110 0000 ---- 224
192.168.1.1111 0000 ---- 240
结果如图:
二、配置接口IP和换回地址
R1
[r1-GigabitEthernet0/0/0]ip address 192.168.1.33 255.255.255.240
[r1-GigabitEthernet0/0/1]ip address 192.168.1.18 255.255.255.240
[r1-LoopBack1]ip address 192.168.1.113 255.255.255.240
[r1-LoopBack2]ip address 192.168.1.129 255.255.255.240
R2
[r2-GigabitEthernet0/0/0]ip address 192.168.1.34 255.255.255.240
[r2-GigabitEthernet0/0/1]ip address 192.168.1.49 255.255.255.240
[r2-LoopBack1]ip address 192.168.1.145 255.255.255.240
[r2-LoopBack2]ip address 192.168.1.161 255.255.255.240
R3
[r3-GigabitEthernet0/0/0]ip address 192.168.1.1 255.255.255.240
[r3-GigabitEthernet0/0/1]ip address 192.168.1.17 255.255.255.240
[r3-GigabitEthernet0/0/2]ip address 192.168.1.66 255.255.255.240
R4
[r4-GigabitEthernet0/0/0]ip address 192.168.1.50 255.255.255.240
[r4-GigabitEthernet0/0/1]ip address 192.168.1.65 255.255.255.240
[r4-GigabitEthernet0/0/2]ip address 192.168.1.97 255.255.255.240
[r4-GigabitEthernet4/0/0]ip address 192.168.1.81 255.255.255.240
[r4-LoopBack1]ip address 192.168.1.177 255.255.255.240
[r4-LoopBack2]ip address 192.168.1.193 255.255.255.240
R5
[r5-GigabitEthernet0/0/0]ip address 192.168.1.98 255.255.255.240
[r5-GigabitEthernet0/0/1]ip address 192.168.1.82 255.255.255.240
[r5-GigabitEthernet0/0/2]ip address 12.0.0.1 255.255.255.0
[r5-LoopBack1]ip address 192.168.1.209 255.255.255.240
R6
[r6-GigabitEthernet0/0/0]ip address 12.0.0.2 255.255.255.0
[r6-LoopBack]ip address 1.1.1.1 255.255.255.0
三、配置R3的DHCP
[r1]dhcp enable
[r1]ip pool aa
[r1-ip-pool-aa]network 192.168.1.0 mask 28
[r1-ip-pool-aa]gateway-list 192.168.1.1
[r1-ip-pool-aa]dns-list 114.114.114.114
[r1-GigabitEthernet0/0/0]dhcp select global
四、配置静态路由
R1
[r1]ip route-static 0.0.0.0 0.0.0.0 192.168.1.34
[r1]ip route-static 0.0.0.0 0.0.0.0 192.168.1.17
[r1]ip route-static 192.168.1.0 255.255.255.240 192.168.1.17
[r1]ip route-static 192.168.1.48 255.255.255.240 192.168.1.34
[r1]ip route-static 192.168.1.64 255.255.255.240 192.168.1.17
[r1]ip route-static 192.168.1.144 255.255.255.240 192.168.1.34
[r1]ip route-static 192.168.1.160 255.255.255.240 192.168.1.34
R2
[r2]ip route-static 0.0.0.0 0.0.0.0 192.168.1.50
[r2]ip route-static 192.168.1.0 255.255.255.240 192.168.1.33
[r2]ip route-static 192.168.1.16 255.255.255.240 192.168.1.33
[r2]ip route-static 192.168.1.112 255.255.255.240 192.168.1.33
[r2]ip route-static 192.168.1.128 255.255.255.240 192.168.1.33
R3
[r3]ip route-static 0.0.0.0 0.0.0.0 192.168.1.65
[r3]ip route-static 192.168.1.32 255.255.255.240 192.168.1.18
[r3]ip route-static 192.168.1.112 255.255.255.240 192.168.1.18
[r3]ip route-static 192.168.1.128 255.255.255.240 192.168.1.18
[r3]ip route-static 192.168.1.144 255.255.255.240 192.168.1.18
[r3]ip route-static 192.168.1.160 255.255.255.240 192.168.1.18
R4
[r4]ip route-static 0.0.0.0 0.0.0.0 192.168.1.82
[r4]ip route-static 0.0.0.0 0.0.0.0 192.168.1.98 preference 61
[r4]ip route-static 192.168.1.0 255.255.255.240 192.168.1.66
R5
[r5]ip route-static 0.0.0.0 0.0.0.0 12.0.0.2
[r5]ip route-static 192.168.0.0 255.255.0.0 NULL0
[r5]ip route-static 192.168.1.0 255.255.255.0 192.168.1.81
[r5]ip route-static 192.168.1.0 255.255.255.0 192.168.1.97 preference 61
五、配置R5上的NAT
[r5-GigabitEthernet0/0/2]nat static global 12.0.0.3 inside 192.168.1.33
[r5]nat address-group 0 12.0.0.4 12.0.0.8
[r5]acl 2000
[r5-acl-basic-2000]rule permit source 192.168.0.0 0.0.255.255
[r5-GigabitEthernet0/0/2]nat outbound 2000 address-group 0 no-pat
六、配置Telent
[r1]aaa
[r1-aaa]
[r1-aaa]local-user xiaozhang privilege level 15 password cipher 123456
[r1-aaa]local-user xiaozhang service-type telnet
[r1]user-interface vty 0 4
[r1-ui-vty0-4]authentication-mode aaa
测试
PC>ping 1.1.1.1
Ping 1.1.1.1: 32 data bytes, Press Ctrl_C to break
From 1.1.1.1: bytes=32 seq=1 ttl=252 time=63 ms
From 1.1.1.1: bytes=32 seq=2 ttl=252 time=47 ms
From 1.1.1.1: bytes=32 seq=3 ttl=252 time=62 ms
From 1.1.1.1: bytes=32 seq=4 ttl=252 time=47 ms
From 1.1.1.1: bytes=32 seq=5 ttl=252 time=47 ms
--- 1.1.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 47/53/63 ms
PC>ping 192.168.1.145
Ping 192.168.1.145: 32 data bytes, Press Ctrl_C to break
From 192.168.1.145: bytes=32 seq=1 ttl=253 time=47 ms
From 192.168.1.145: bytes=32 seq=2 ttl=253 time=31 ms
From 192.168.1.145: bytes=32 seq=3 ttl=253 time=47 ms
From 192.168.1.145: bytes=32 seq=4 ttl=253 time=31 ms
From 192.168.1.145: bytes=32 seq=5 ttl=253 time=31 ms
--- 192.168.1.145 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/37/47 ms
<r6>telnet 12.0.0.3
Press CTRL_] to quit telnet mode
Trying 12.0.0.3 ...
Connected to 12.0.0.3 ...
Login authentication
Username:xiaozhang
Password:
<r1>
<r1>