实验5 综合实验
第一部分 实验介绍
1关于本实验
公司有两个建筑,分别为库房和办公楼。
公司的网络中,由4台路由器组成骨干网,运行OSPF协议,区域0。
其中AR1为办公楼到骨干网出口路由器,AR2为库房到骨干网出口路由器,AR4为数据中心到骨干网出口路由器,AR3为公司方向互联网的出口。
公司内网络各个区域的功能需求如下:
(1)数据中心
地理位置在办公楼内。数据中心所有的服务器均使用固定IP地址,通过交换机与AR4连接。本实验仅模拟其中1台服务器,IP地址为172.18.29.253/22,需要被公司内所有电脑访问,但是不能访问互联网。
(2)库房
库房内的PC和终端通过3台交换机连接,各个PC以DHCP的方式从AR2获取IP地址,且所有PC不可访问互联网。
(3)办公楼
办公楼分若干区域,每个区域划分为1个VLAN,各个VLAN间不允许互相访问。办公楼内的PC均已DHCP的方式从AR1获取IP地址,可以访问互联网。办公楼一楼和二楼分别用1台汇聚交换机连接,且这两台交换机之间用链路聚合协议相连。
2 实验目标
掌握企业网络的基本需求
掌握骨干网路由器之间的配置
通过团队协作完成全部配置
3实验拓扑
4实验所需资源与地址规划
4.1实验所需资源
2台交换机(支持华为Version 5.110版镜像的华为S3700或同类交换机,或使用华为eNSP模拟器3.9及以上版本)
9台交换机(支持华为Version 5.110版镜像的华为S5700或同类交换机,或使用华为eNSP模拟器3.9及以上版本)
5台路由器(支持华为Version 5.130版镜像的华为AR2200或同类路由器,或使用华为ESP模拟器3.9及以上版本)
LSW-2F的配置:
<Huawei>sy
[Huawei]vlan batch 201 205
[Huawei]int g0/0/4
[Huawei-GigabitEthernet0/0/4]port link-type hybrid
[Huawei-GigabitEthernet0/0/4]port hybrid pvid vlan 201
[Huawei-GigabitEthernet0/0/4]port hybrid untagged vlan 201
[Huawei-GigabitEthernet0/0/4]int g0/0/5
[Huawei-GigabitEthernet0/0/5]port link-type hybrid
[Huawei-GigabitEthernet0/0/5]port hybrid pvid vlan 201
[Huawei-GigabitEthernet0/0/5]port hybrid untagged vlan 201
[Huawei-GigabitEthernet0/0/5]int g0/0/06
[Huawei-GigabitEthernet0/0/6]port link-type hybrid
[Huawei-GigabitEthernet0/0/6]port hybrid pvid vlan 205
[Huawei-GigabitEthernet0/0/6]port hybrid untagged vlan 205
[Huawei-GigabitEthernet0/0/6]q
[Huawei]int Eth-Trunk 1
[Huawei-Eth-Trunk1]mode lacp-static
[Huawei-Eth-Trunk1]max active-linknumber 2
[Huawei-Eth-Trunk1]trunkport GigabitEthernet 0/0/1 to 0/0/3
[Huawei-Eth-Trunk1]port link-type trunk
[Huawei-Eth-Trunk1]port trunk allow-pass vlan 201 205
LSW-1F的配置:
<Huawei>sy
[Huawei]vlan batch 201 205 101 103
[Huawei]int g0/0/04
[Huawei-GigabitEthernet0/0/4]port link-type hybrid
[Huawei-GigabitEthernet0/0/4]port hybrid pvid vlan 101
[Huawei-GigabitEthernet0/0/4]port hybrid untagged vlan 101
[Huawei-GigabitEthernet0/0/4]int g0/0/5
[Huawei-GigabitEthernet0/0/5]port link-type hybrid
[Huawei-GigabitEthernet0/0/5]port hybrid pvid vlan 103
[Huawei-GigabitEthernet0/0/5]port hybrid untagged vlan 103
[Huawei-GigabitEthernet0/0/5]q
[Huawei]int Eth-Trunk 1
[Huawei-Eth-Trunk1]mode lacp-static
[Huawei-Eth-Trunk1]max active-linknumber 2
[Huawei-Eth-Trunk1]trunkport GigabitEthernet 0/0/1 to 0/0/3
[Huawei-Eth-Trunk1]port link-type trunk
[Huawei-Eth-Trunk1]port trunk allow-pass vlan 201 205
[Huawei-Eth-Trunk1]q
[Huawei]int g0/0/24
[Huawei-GigabitEthernet0/0/24]port link-type hybrid
[Huawei-GigabitEthernet0/0/24]port hybrid untagged vlan 201 205 101 103
AR1:
<ISPRouter>sy
[ISPRouter]rou id 1.1.1.1
[ISPRouter]ospf 1
[ISPRouter-ospf-1]a 0
[ISPRouter-ospf-1-area-0.0.0.0]q
[ISPRouter-ospf-1]q
[ISPRouter]dhcp enable
[ISPRouter]int g0/0/0
[ISPRouter-GigabitEthernet0/0/0]ip add 172.19.79.254 22
[ISPRouter-GigabitEthernet0/0/0]dhcp select interface
[ISPRouter-GigabitEthernet0/0/0]q
[ISPRouter]
[ISPRouter]int g0/0/01
[ISPRouter-GigabitEthernet0/0/1]ip add 14.1.1.1 24
[ISPRouter-GigabitEthernet0/0/1]o e 1 a 0
[ISPRouter-GigabitEthernet0/0/1]int g0/0/02
[ISPRouter-GigabitEthernet0/0/2]ip add 13.1.1.1 24
[ISPRouter-GigabitEthernet0/0/2]o e 1 a 0
[ISPRouter-GigabitEthernet0/0/2]q
[ISPRouter]acl 2000
[ISPRouter-acl-basic-2000]rule 5 permit source 172.19.79.254 0.0.3.255
[ISPRouter-acl-basic-2000]q
[ISPRouter]int g0/0/01
[ISPRouter-GigabitEthernet0/0/1]nat outbound 2000
[ISPRouter-GigabitEthernet0/0/1]q
[ISPRouter]int g0/0/2
[ISPRouter-GigabitEthernet0/0/2]nat outbound 2000
[ISPRouter-GigabitEthernet0/0/2]q
AR2:
<Huawei>sy
[Huawei]rou id 2.2.2.2
[Huawei]ospf 1
[Huawei-ospf-1]a 0
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]dhcp enable
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 24.1.1.2 24
[Huawei-GigabitEthernet0/0/0]o e 1 a 0
[Huawei-GigabitEthernet0/0/0]int g0/0/01
[Huawei-GigabitEthernet0/0/1]ip add 23.1.1.2 24
[Huawei-GigabitEthernet0/0/1]o e 1 a 0
[Huawei-GigabitEthernet0/0/1]int g0/0/02
[Huawei-GigabitEthernet0/0/2]ip add 192.19.79.254 24
[Huawei-GigabitEthernet0/0/2]dhcp select interface
[Huawei-GigabitEthernet0/0/2]o e 1 a 0
[Huawei-GigabitEthernet0/0/2]q
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 5 permit source 192.19.79.0 0.0.0.255
[Huawei-acl-basic-2000]q
[Huawei]acl 2001
[Huawei-acl-basic-2001]rule 5 deny source 192.19.79.0 0.0.0.255
[Huawei-acl-basic-2001]q
[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]nat outbound 2001
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]nat outbound 2000
AR3:
<Huawei>sy
[Huawei]rou id 3.3.3.3
[Huawei]ospf 1
[Huawei-ospf-1]a 0
[Huawei-ospf-1-area-0.0.0.0]
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]int g0/0/01
[Huawei-GigabitEthernet0/0/1]ip add 23.1.1.3 24
[Huawei-GigabitEthernet0/0/1]o e 1 a 0
[Huawei-GigabitEthernet0/0/1]q
[Huawei]int g0/0/2
[Huawei-GigabitEthernet0/0/2]ip add 13.1.1.3 24
[Huawei-GigabitEthernet0/0/2]o e 1 a 0
[Huawei-GigabitEthernet0/0/2]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 61.11.32.121 16
[Huawei-GigabitEthernet0/0/0]q
[Huawei]ip route-static 0.0.0.0 0 61.11.32.254
[Huawei]ip route-static 8.8.8.8 32 61.11.32.254
[Huawei]ospf 1
[Huawei-ospf-1]import-route static
[Huawei-ospf-1]q
[Huawei]acl
[Huawei]acl 2000
[Huawei-acl-basic-2000]rule 5 permit source 13.1.1.1 0.0.0.255
[Huawei-acl-basic-2000]rule 10 deny source 0.0.0.0 255.255.255.255
[Huawei-acl-basic-2000]q
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]traffic-filter outbound acl 2000
AR4:
<Huawei>sy
[Huawei]ospf 1
[Huawei-ospf-1]a 0
[Huawei-ospf-1-area-0.0.0.0]q
[Huawei-ospf-1]q
[Huawei]int g0/0/02
[Huawei-GigabitEthernet0/0/2]ip add 172.18.29.253
[Huawei-GigabitEthernet0/0/2]ip add 172.18.29.254 22
[Huawei-GigabitEthernet0/0/2]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 24.1.1.4 24
[Huawei-GigabitEthernet0/0/0]o e 1 a 0
[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip add 14.1.1.4 24
[Huawei-GigabitEthernet0/0/1]o e 1 a 0
R1:
<Huawei>sy
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 61.11.32.254 16
[Huawei-GigabitEthernet0/0/0]int loo 0
[Huawei-LoopBack0]ip add 8.8.8.8 32
[Huawei-LoopBack0]q
[Huawei]ip route-static 0.0.0.0 0 61.11.32.121