H3C综合实验:基于OSPF,DHCP,PPP等协议的小型企业网络构建
一 . 实验拓扑
实验需求
1.按照图示配置 |P 地址Q
2.SW1 和 SW2 之间的直连链路配置链路聚合
3.公司内部业务网段为 Vlan10 和 Van20:Vlan10 是市场部,Van20 是技术部,要求对 Vlana 进行命名以便识别:PC1属于 Vlan10,PC2属于 Vlan20,Vlan30 用于 SW1和 SW2 建立 OSPF 邻居:Vlan111 为 SW1 和 R1 的互联 Vlan,Vlan222 为 SW2 和 R2 的互联 Vlan
4.所有交换机相连的端口配置为 Trunk,允许相关流量通过
5.交换机连接 PC 的端口配置为边缘端口
6.在 SW1 上配置 DHCP 服务,为 Van10 和 Van20 的 PC 动态分配 IP 地址、网关和 DNS 地址;要求 Vlan10 的网关是192.168.1.252,Vlan20 的网关是192.168.2.253
7.按图示分区域配置 OSPF 实现公司内部网络全网互通,ABR 的环回口宣告进骨干区域:业务网段不允许出现协议报文
8.R1 上配置默认路由指向互联网,并引入到 OSPF
9.R1 通过双线连接到互联网,配置 PPP-MP,并配置双向 chap 验证
10.配置 EASY IP,只有业务网段 和 的数据流可以通过 R1 访问互联网192.168.1.0/24 192.168.2.0/2411.R1 开启 TELNET 远程管理,使用用户kami1登录,密码 123456.com,只允许技术部远程管理 R1
二.实验步骤
1.如图所示配置IP
R1:
[H3C]SYSN R1
[R1]INT G0/0
[R1-GigabitEthernet0/0]IP AD 10.0.0.5 30
[R1-GigabitEthernet0/0]INT G0/1
[R1-GigabitEthernet0/1]IP AD 10.0.0.1 30
[R1-GigabitEthernet0/1]INT G0/2
[R1-GigabitEthernet0/2]INT LO0
[R1-LoopBack0]IP AD 10.1.1.1 32
R2:
[R2]INT G0/0
[R2-GigabitEthernet0/0]IP AD 10.0.0.9 30
[R2-GigabitEthernet0/0]INT G0/1
[R2-GigabitEthernet0/1]IP AD 10.0.0.18 30
[R2-GigabitEthernet0/1]INT G0/2
[R2-GigabitEthernet0/2]IP AD 10.0.0.2 30
[R2-GigabitEthernet0/2]INT LO0
[R2-LoopBack0]IP AD 10.1.1.2 32
R3:
[R3]INT G0/0
[R3-GigabitEthernet0/0]IP AD 10.0.0.13 30
[R3-GigabitEthernet0/0]INT G0/1
[R3-GigabitEthernet0/1]IP AD 10.0.0.17 30
[R3-GigabitEthernet0/1]INT G0/2
[R3-GigabitEthernet0/2]IP AD 192.168.3.254 24
[R3-GigabitEthernet0/2]INT LO0
[R3-LoopBack0]IP AD 10.1.1.3 32
SW1:
[SW1]VLAN 10
[SW1-vlan10]VLAN 20
[SW1-vlan20]VLAN 30
[SW1-vlan30]VLAN 111
[SW1-vlan111]INT VLAN 10
[SW1-Vlan-interface10]IP AD 192.168.1.252 24
[SW1-Vlan-interface10]INT VLAN 20
[SW1-Vlan-interface20]IP AD 192.168.2.252 24
[SW1-Vlan-interface20]INT VLAN 30
[SW1-Vlan-interface30]IP AD 10.1.2.1 30
[SW1-Vlan-interface30]INT VLAN 111
[SW1-Vlan-interface111]IP AD 10.0.0.6 30
[SW1-Vlan-interface111]INT LO0
[SW1-LoopBack0]IP AD 10.1.1.11 32
SW2:
[SW2]VLAN 10
[SW2-vlan10]VLAN 20
[SW2-vlan20]VLAN 30
[SW2-vlan30]VLAN 222
[SW2-vlan222]INT VLAN 10
[SW2-Vlan-interface10]IP AD 192.168.1.253 24
[SW2-Vlan-interface10]INT VLAN 20
[SW2-Vlan-interface20]IP AD 192.168.2.253 24
[SW2-Vlan-interface20]INT VLAN 30
[SW2-Vlan-interface30]IP AD 10.1.2.2 30
[SW2-Vlan-interface30]INT VLAN 222
[SW2-Vlan-interface222]IP AD 10.0.0.10 30
[SW2-Vlan-interface222]INT LO0
2.SW1 和 SW2 之间的直连链路配置链路聚合
SW1:
[SW1]int Bridge-Aggregation 1
[SW1-Bridge-Aggregation1]quit
[SW1]int g1/0/1
[SW1-GigabitEthernet1/0/1]port link-aggregation group 1
[SW1]int g1/0/2
[SW1-GigabitEthernet1/0/2]port link-aggregation group 1
SW2:
[SW2]int Bridge-Aggregation 1
[SW2-Bridge-Aggregation1]quit
[SW2]int g1/0/1
[SW2-GigabitEthernet1/0/1]port link-aggregation group 1
[SW2]int g1/0/2
[SW2-GigabitEthernet1/0/2]port link-aggregation group 1
3.划分VLAN
SW3:
[SW3]vlan 10
[SW3-vlan10]port g1/0/3
[SW3-vlan10]vlan 20
[SW3-vlan20]port g1/0/4
SW1:
[SW1-vlan10]vlan 111
[SW1-vlan111]port g1/0/4
SW2:
[SW2]vlan 222
[SW2-vlan222]port g1/0/4
4.所有交换机相连的端口配置为 Trunk,允许相关流量通过
SW1:
[SW1]int Bridge-Aggregation 1
[SW1-Bridge-Aggregation1]port link-type trunk
[SW1-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW1-Bridge-Aggregation1]int g1/0/3
[SW1-GigabitEthernet1/0/3]port link-type trunk
[SW1-GigabitEthernet1/0/3]port trunk permit vlan 10 20
SW2:
[SW2]int Bridge-Aggregation 1
[SW2-Bridge-Aggregation1]port link-type trunk
[SW2-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW2-Bridge-Aggregation1]int g1/0/3
[SW2-GigabitEthernet1/0/3]port link-type trunk
[SW2-GigabitEthernet1/0/3]port trunk permit vlan 10 20
SW3:
[SW3]int g1/0/1
[SW3-GigabitEthernet1/0/1]port link-type trunk
[SW3-GigabitEthernet1/0/1]port trunk permit vlan 10 20
[SW3-GigabitEthernet1/0/1]int g1/0/2
[SW3-GigabitEthernet1/0/2]port link-type trunk
[SW3-GigabitEthernet1/0/2]port trunk permit vlan 10 20
5.交换机连接 PC 的端口配置为边缘端口
[SW3-GigabitEthernet1/0/2]int g1/0/3
[SW3-GigabitEthernet1/0/3]stp edged-port
[SW3-GigabitEthernet1/0/3]int g1/0/4
[SW3-GigabitEthernet1/0/4]stp edged-port
6.在 SW1 上配置 DHCP 服务
SW1:
[SW1]dhcp enable
[SW1]dhcp server ip-pool 1
[SW1-dhcp-pool-1]gateway-list 192.168.1.252
[SW1-dhcp-pool-1]network 192.168.1.0 24
[SW1-dhcp-pool-1]quit
[SW1]dhcp server ip-pool 2
[SW1-dhcp-pool-2]gateway-list 192.168.2.253
[SW1-dhcp-pool-2]network 192.168.2.0 24
7.按图示分区域配置 OSPF
R1:
[R1]ospf 1 router-id 10.1.1.1
[R1-ospf-1]are 0
[R1-ospf-1-area-0.0.0.0]net 10.0.0.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]net 10.0.0.14 0.0.0.0
[R1-ospf-1-area-0.0.0.0]net 10.1.1.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]are 1
[R1-ospf-1-area-0.0.0.1]net 10.0.0.5 0.0.0.0
R2:
[R2]ospf 1 router-id 10.1.1.2
[R2-ospf-1]are 1
[R2-ospf-1-area-0.0.0.1]net 10.0.0.9 0.0.0.0
[R2-ospf-1-area-0.0.0.1]are 0
[R2-ospf-1-area-0.0.0.0]net 10.0.0.18 0.0.0.0
[R2-ospf-1-area-0.0.0.0]net 10.0.0.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]network 10.1.1.2 0.0.0.0
R3:
[R3]ospf 1 router-id 10.1.1.3
[R3-ospf-1]are 0
[R3-ospf-1-area-0.0.0.0]net 10.0.0.13 0.0.0.0
[R3-ospf-1-area-0.0.0.0]net 10.0.0.17 0.0.0.0
[R3-ospf-1-area-0.0.0.0]net 192.168.3.254 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 10.1.1.3 0.0.0.0
SW1:
[SW1]ospf 1
[SW1-ospf-1]are 1
[SW1-ospf-1-area-0.0.0.1]net 192.168.1.0 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]net 192.168.2.0 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]net 10.1.2.1 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]net 10.0.0.6 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]net 10.1.1.11 0.0.0.0
SW2:
[SW2]ospf 1
[SW2-ospf-1]are 1
[SW2-ospf-1-area-0.0.0.1]net 192.168.1.0 0.0.0.255
[SW2-ospf-1-area-0.0.0.1]net 192.168.2.0 0.0.0.255
[SW2-ospf-1-area-0.0.0.1]net 10.1.2.2 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]net 10.0.0.10 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]net 10.1.1.12 0.0.0.0
业务网段不允许出现协议报文
SW1:
[SW1-ospf-1]silent-interface vlan 10
[SW1-ospf-1]silent-interface vlan 20
SW2:
[SW2-ospf-1]silent-interface vlan 10
[SW2-ospf-1]silent-interface vlan 20
8.R1 上配置默认路由指向互联网,并引入到 OSPF
R1:
[R1]ip route-static 0.0.0.0 0 202.100.1.1
[R1]ospf 1
[R1-ospf-1]default-route-advertise
R1 通过双线连接到互联网,配置 PPP-MP,并配置双向 chap 验证
R1:
[R1]int MP-group 1
[R1-MP-group1]
[R1]local-user kami class network
[R1-luser-network-kami]password simple 123456
[R1-luser-network-kami]service-type ppp
[R1-luser-network-kami]quit
[R1]int s1/0
[R1-Serial1/0]ppp mp MP-group 1
[R1-Serial1/0]ppp chap user kami
[R1-Serial1/0]int s2/0
[R1-Serial2/0]ppp mp MP-group 1
[R1-Serial2/0]ppp chap user kami
INTERNET:
[INTERNET]int MP-group 1
[INTERNET-MP-group1]quit
[INTERNET]local-user kami
[INTERNET-luser-manage-kami]quit
[INTERNET]local-user kami class network
[INTERNET-luser-network-kami]password simple 123456
[INTERNET-luser-network-kami]service-type ppp
[INTERNET-luser-network-kami]int s1/0
[INTERNET-Serial1/0]ppp mp MP-group 1
[INTERNET-Serial1/0]ppp chap user kami
[INTERNET-Serial1/0]int s2/0
[INTERNET-Serial2/0]ppp mp MP-group 1
[INTERNET-Serial2/0]ppp chap user kami
10.配置 EASY IP
R1:
[R1]acl basic 2000
[R1-acl-ipv4-basic-2000]rule permit source 192.168.1.0 0.0.0.255
[R1-acl-ipv4-basic-2000]rule permit source 192.168.2.0 0.0.0.255
[R1-acl-ipv4-basic-2000]quit
[R1]int MP-group 1
[R1-MP-group1]nat outbound 2000
开启 TELNET 远程管理,使用用户kami1登录,密码 123456.com,只允许技术部远程管理 R1
R1:开启telnet服务
[R1]telnet server enable
[R1]local-user kami1 class manage
[R1-luser-manage-kami1]password simple 123456.com
[R1-luser-manage-kami1]authorization-attribute user-role level-15
[R1-luser-manage-kami1]service-type telnet
[R1]user-int vty 0 4
[R1-line-vty0-4]authentication-mode sc
R1:配置高级ACL
[R1]acl advanced 3000
[R1-acl-ipv4-adv-3000]rule permit tcp source 192.168.2.0 0.0.0.255
[R1-acl-ipv4-adv-3000]rule deny tcp
[R1-acl-ipv4-adv-3000]quit
[R1]int range g0/0 to g0/2
[R1-if-range]packet-filter 3000 inbound
三.测试
全网互通
PC1ping
PC1TELNET登录
PC2TELNET登录
PC3TELNET登录