ImageVerifierCode 换一换
格式:DOCX , 页数:16 ,大小:59.44KB ,
资源ID:15808202      下载积分:5 金币
快捷下载
登录下载
邮箱/手机:
温馨提示:
快捷下载时,用户名和密码都是您填写的邮箱或者手机号,方便查询和重复下载(系统自动生成)。 如填写123,账号就是123,密码也是123。
特别说明:
请自助下载,系统不会自动发送文件的哦; 如果您已付费,想二次下载,请登录后访问:我的下载记录
支付方式: 支付宝    微信支付   
验证码:   换一换

加入VIP,免费下载
 

温馨提示:由于个人手机设置不同,如果发现不能下载,请复制以下地址【https://www.bingdoc.com/d-15808202.html】到电脑端继续下载(重复下载不扣费)。

已注册用户请登录:
账号:
密码:
验证码:   换一换
  忘记密码?
三方登录: 微信登录   QQ登录  

下载须知

1: 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。
2: 试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。
3: 文件的所有权益归上传用户所有。
4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
5. 本站仅提供交流平台,并不能对任何下载内容负责。
6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

版权提示 | 免责声明

本文(网络配置.docx)为本站会员(b****6)主动上传,冰点文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知冰点文库(发送邮件至service@bingdoc.com或直接QQ联系客服),我们立即给予删除!

网络配置.docx

1、网络配置网络拓扑图一、保证全网互通11、使直连互通(192.168.1.1-192.168.1.2)RT1配置:为路由配置ip地址:RT1int G0/0/1RT1-GigabitEthernet0/0/1ip add 192.168.1.1 24RT1-GigabitEthernet0/0/1int G0/0/2RT1-GigabitEthernet0/0/2ip add 192.168.3.1 24SW1配置:为交换机配置IP地址(交换机的地址需要在先换分vlan然后在vlan中配置)划分Vlan:SW1vlan 1000SW1-vlan1000vlan 1001SW1-vlan1001v

2、lan 10SW1-vlan10vlan 20SW1-vlan20vlan 30进入Vlan配置IP地址:Vlan1000:SW1int vlan 1000SW1-Vlan-interface1000ip add 192.168.1.2 24Vlan1001:SW1int vlan 1001SW1-Vlan-interface1001ip add 192.168.2.1 24使Vlan属于某个端口:SW1int E0/4/0SW1-Ethernet0/4/0port access vlan 1000测试结果:SW1-Ethernet0/4/0ping -a 192.168.1.2 192.16

3、8.1.1 PING 192.168.1.1: 56 data bytes, press CTRL_C to break Reply from 192.168.1.1: bytes=56 Sequence=1 ttl=255 time=44 ms Reply from 192.168.1.1: bytes=56 Sequence=2 ttl=255 time=5 ms Reply from 192.168.1.1: bytes=56 Sequence=3 ttl=255 time=15 ms Reply from 192.168.1.1: bytes=56 Sequence=4 ttl=255

4、 time=20 ms Reply from 192.168.1.1: bytes=56 Sequence=5 ttl=255 time=15 ms - 192.168.1.1 ping statistics - 5 packet(s) transmitted 5 packet(s) received 0.00% packet lossround-trip min/avg/max = 5/19/44 ms12、使直连互通(192.168.3.1-192.168.3.2)SW2配置:划分VlanSW2vlan 1000SW2-vlan1000vlan 1001SW2-vlan1001vlan 1

5、0SW2-vlan10vlan 20SW2-vlan20vlan 30进入Vlan配置IP地址:Vlan1000:SW2-vlan30int vlan 1000SW2-Vlan-interface1000ip add 192.168.3.2 24Vlan1001:SW2-Vlan-interface1000int vlan 1001SW2-Vlan-interface1001ip add 192.168.2.2 24使Vlan属于某个端口:SW2-Ethernet0/4/0port access vlan 1000测试结果:SW2-Ethernet0/4/0ping -a 192.168.3.

6、2 192.168.3.1 PING 192.168.3.1: 56 data bytes, press CTRL_C to break Reply from 192.168.3.1: bytes=56 Sequence=1 ttl=255 time=50 ms Reply from 192.168.3.1: bytes=56 Sequence=2 ttl=255 time=24 ms Reply from 192.168.3.1: bytes=56 Sequence=3 ttl=255 time=30 ms Reply from 192.168.3.1: bytes=56 Sequence=

7、4 ttl=255 time=4 ms Reply from 192.168.3.1: bytes=56 Sequence=5 ttl=255 time=20 ms - 192.168.3.1 ping statistics - 5 packet(s) transmitted 5 packet(s) received 0.00% packet lossround-trip min/avg/max = 4/25/50 ms13、链路聚合(192.168.2.1-192.168.2.2)SW1配置:SW1int Bridge-Aggregation 1SW1int E0/4/2SW1-Ethern

8、et0/4/2port link-aggregation group 1SW1-Ethernet0/4/2int e0/4/1SW1-Ethernet0/4/1port link-aggregation group 1SW1int Bridge-Aggregation 1SW1-Bridge-Aggregation1port link-type trunkSW1-Bridge-Aggregation1port trunk permit vlan 1001SW2配置:SW2interface Bridge-Aggregation 1SW2int E0/4/1SW2-Ethernet0/4/1po

9、rt link-aggregation group 1SW2-Ethernet0/4/1int E0/4/2SW2-Ethernet0/4/2port link-aggregation group 1SW2int Bridge-Aggregation 1SW2-Bridge-Aggregation1port link-type trunk SW2-Bridge-Aggregation1port trunk permit vlan 1001测试结果:SW1-Bridge-Aggregation1ping -a 192.168.2.1 192.168.2.2 PING 192.168.2.2: 5

10、6 data bytes, press CTRL_C to break Reply from 192.168.2.2: bytes=56 Sequence=1 ttl=255 time=340 ms Reply from 192.168.2.2: bytes=56 Sequence=2 ttl=255 time=174 ms Reply from 192.168.2.2: bytes=56 Sequence=3 ttl=255 time=174 ms Reply from 192.168.2.2: bytes=56 Sequence=4 ttl=255 time=154 ms Request

11、time out - 192.168.2.2 ping statistics - 5 packet(s) transmitted 4 packet(s) received 20.00% packet lossround-trip min/avg/max = 154/210/340 ms1.4、将Vlan 10、Vlan 20、Vlan 30设置到相应端口:SW1配置:SW1int vlan 10 SW1-Vlan-interface10ip add 10.0.0.1 24SW1-Vlan-interface20int vlan 30 SW1-Vlan-interface30ip add 30.

12、0.0.1 24SW1-Vlan-interface30int E0/4/3 SW1-Ethernet0/4/3port access vlan 30SW1-Ethernet0/4/3int E0/4/4 SW1-Ethernet0/4/4port access vlan 10SW2配置:SW2int vlan 20SW2-Vlan-interface20ip add 20.0.0.1 24SW2-Vlan-interface20int E0/4/3SW2-Ethernet0/4/3port access vlan 201.5、设置OSPF:SW1:SW1ospf 1SW1-ospf-1are

13、a 0SW1-ospf-1-area-0.0.0.0network 192.168.1.0 0.0.0.255SW1-ospf-1-area-0.0.0.0network 192.168.2.0 0.0.0.255SW1-ospf-1-area-0.0.0.0network 10.0.0.0 0.0.0.255 SW1-ospf-1-area-0.0.0.0network 30.0.0.0 0.0.0.255查看配置SW1-ospf-1-area-0.0.0.0dis th# area 0.0.0.0 network 192.168.1.0 0.0.0.255 network 192.168.

14、2.0 0.0.0.255 network 10.0.0.0 0.0.0.255 network 30.0.0.0 0.0.0.255#SW1-ospf-1-area-0.0.0.0dis ospf peer OSPF Process 1 with Router ID 192.168.2.1 Neighbor Brief Information Area: 0.0.0.0 Router ID Address Pri Dead-Time Interface State 192.168.3.1 192.168.1.1 1 28 Vlan1000 Full/DR 192.168.3.2 192.16

15、8.2.2 1 36 Vlan1001 Full/BDRSW2:SW2ospf 1SW2-ospf-1area 0SW2-ospf-1-area-0.0.0.0network 192.168.3.0 0.0.0.255SW2-ospf-1-area-0.0.0.0network 192.168.2.0 0.0.0.255查看配置:SW2-ospf-1-area-0.0.0.0dis th# area 0.0.0.0 network 192.168.3.0 0.0.0.255 network 192.168.2.0 0.0.0.255 network 20.0.0.0 0.0.0.255#SW2

16、-ospf-1-area-0.0.0.0dis ospf peer OSPF Process 1 with Router ID 192.168.3.2 Neighbor Brief Information Area: 0.0.0.0 Router ID Address Pri Dead-Time Interface State 192.168.3.1 192.168.3.1 1 36 Vlan1000 Full/DR 192.168.2.1 192.168.2.1 1 30 Vlan1001 Full/DRSW2-ospf-1-area-0.0.0.0dis ip routing-table

17、Routing Tables: Public Destinations : 7 Routes : 8Destination/Mask Proto Pre Cost NextHop Interface127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0192.168.1.0/24 OSPF 10 2 192.168.3.1 Vlan1000 OSPF 10 2 192.168.2.1 Vlan1001192.168.2.0/24 Direct 0 0 192.168.2.2 Vlan10

18、01192.168.2.2/32 Direct 0 0 127.0.0.1 InLoop0192.168.3.0/24 Direct 0 0 192.168.3.2 Vlan1000192.168.3.2/32 Direct 0 0 127.0.0.1 InLoop0测试结果:SW2-Ethernet0/4/3ping -a 20.0.0.1 30.0.0.1 PING 30.0.0.1: 56 data bytes, press CTRL_C to break Reply from 30.0.0.1: bytes=56 Sequence=1 ttl=255 time=130 ms Reply

19、 from 30.0.0.1: bytes=56 Sequence=2 ttl=255 time=155 ms Reply from 30.0.0.1: bytes=56 Sequence=3 ttl=255 time=164 ms Reply from 30.0.0.1: bytes=56 Sequence=4 ttl=255 time=185 ms Reply from 30.0.0.1: bytes=56 Sequence=5 ttl=255 time=164 ms - 30.0.0.1 ping statistics - 5 packet(s) transmitted 5 packet

20、(s) received 0.00% packet lossround-trip min/avg/max = 130/159/185 msRT1:RT1ospf 1RT1-ospf-1area 0RT1-ospf-1-area-0.0.0.0network 192.168.1.0 0.0.0.255RT1-ospf-1-area-0.0.0.0network 192.168.3.0 0.0.0.255二、接入外网2.1、设置ACL:RT1:为RT1添加IP地址:RT1-GigabitEthernet0/0/0ip add 14.0.0.1 24为RT1设置ACLRT1acl number 20

21、00RT1-acl-basic-2000rule permit source 10.0.0.1 0.0.0.255RT1-acl-basic-2000rule permit source 20.0.0.1 0.0.0.255RT1-acl-basic-2000int G0/0/0RT1-GigabitEthernet0/0/0nat outbound 20002.2、设置静态路由 SW1:SW1ip route-static 14.0.0.0 255.255.255.0 192.168.1.1测试结果:SW1ping -a 10.0.0.1 14.0.0.2 PING 14.0.0.2: 56

22、 data bytes, press CTRL_C to break Reply from 14.0.0.2: bytes=56 Sequence=1 ttl=254 time=40 ms Reply from 14.0.0.2: bytes=56 Sequence=2 ttl=254 time=30 ms Reply from 14.0.0.2: bytes=56 Sequence=3 ttl=254 time=5 ms Reply from 14.0.0.2: bytes=56 Sequence=4 ttl=254 time=30 ms Reply from 14.0.0.2: bytes

23、=56 Sequence=5 ttl=254 time=5 ms - 14.0.0.2 ping statistics - 5 packet(s) transmitted 5 packet(s) received 0.00% packet loss round-trip min/avg/max = 5/22/40 msSW2:SW2ip route-static 14.0.0.0 255.255.255.0 192.168.3.1测试结果:SW2ping -a 20.0.0.1 14.0.0.2 PING 14.0.0.2: 56 data bytes, press CTRL_C to bre

24、ak Reply from 14.0.0.2: bytes=56 Sequence=1 ttl=254 time=4 ms Reply from 14.0.0.2: bytes=56 Sequence=2 ttl=254 time=15 ms Reply from 14.0.0.2: bytes=56 Sequence=3 ttl=254 time=30 ms Reply from 14.0.0.2: bytes=56 Sequence=4 ttl=254 time=24 ms Reply from 14.0.0.2: bytes=56 Sequence=5 ttl=254 time=30 m

25、s - 14.0.0.2 ping statistics - 5 packet(s) transmitted 5 packet(s) received 0.00% packet lossround-trip min/avg/max = 4/20/30 ms2.3、为RT2配置IP地址RT2int G0/0/0RT2-GigabitEthernet0/0/0ip add 14.0.0.2 24三、公网互通TR1:RT1int G0/0/3RT1-GigabitEthernet0/0/3ip add 12.0.0.1 24RT1ip route-static 23.0.0.0 255.255.25

26、5.0 12.0.0.2RT3:建IP地址:RT3int G0/0/0RT3-GigabitEthernet0/0/0ip add 12.0.0.2 24RT3-GigabitEthernet0/0/0int G0/0/1RT3-GigabitEthernet0/0/1ip add 23.0.0.2 24RT4:RT4int G0/0/0RT4-GigabitEthernet0/0/0ip add 23.0.0.3 24RT4-GigabitEthernet0/0/0int G0/0/1RT4-GigabitEthernet0/0/1ip add 40.0.0.1 24RT4-GigabitE

27、thernet0/0/1quRT4ip route-static 12.0.0.1 255.255.255.0 23.0.0.2测试结果:RT1ping -a 12.0.0.1 23.0.0.3 PING 23.0.0.3: 56 data bytes, press CTRL_C to break Reply from 23.0.0.3: bytes=56 Sequence=1 ttl=254 time=21 ms Request time out Request time out Reply from 23.0.0.3: bytes=56 Sequence=4 ttl=254 time=10

28、 ms Reply from 23.0.0.3: bytes=56 Sequence=5 ttl=254 time=10 ms - 23.0.0.3 ping statistics - 5 packet(s) transmitted 3 packet(s) received 40.00% packet loss round-trip min/avg/max = 10/13/21 ms四、建IPSEC、VPN建立ipsec和VPNRT4创建aclRT4acl number 3000RT4-acl-adv-3000rule permit ip source 40.0.0.0 0.0.0.255 d

29、estination 30.0.0.0 0.0.0.255创建ipsec proposal(安全提议)RT4ipsec proposal r1RT4-ipsec-proposal-r1transform espRT4-ipsec-proposal-r1esp authentication-algorithm sha1RT4-ipsec-proposal-r1esp encryption-algorithm 3desRT4-ipsec-proposal-r1encapsulation-mode tunnel创建ikeRT4ike peer r3RT4-ike-peer-r3pre-shared-

30、key 123RT4-ike-peer-r3remote-address 12.0.0.1创建ips policy(创建IP安全策略)RT4ips policy 1 10 isakmpRT4-ipsec-policy-isakmp-1-10security acl 3000RT4-ipsec-policy-isakmp-1-10ike-peer r3RT4-ipsec-policy-isakmp-1-10proposal r1将安全策略应用到指定端口RT4int g0/0/0RT4-GigabitEthernet0/0/0ipsec policy 1RT1:创建aclRT1acl number 3000RT1-acl-adv-3000rule permit ip source 30.0.0.0 0.0.0.255 destination 40.0.0.0 0.0.0.255创建ipsec proposal(安全提议)RT1

copyright@ 2008-2023 冰点文库 网站版权所有

经营许可证编号:鄂ICP备19020893号-2