H3C综合实验:基于OSPF,DHCP,PPP等协议的小型企业网络构建

H3C综合实验:基于OSPF,DHCP,PPP等协议的小型企业网络构建

一 . 实验拓扑

在这里插入图片描述

实验需求

1.按照图示配置 |P 地址Q
2.SW1 和 SW2 之间的直连链路配置链路聚合
3.公司内部业务网段为 Vlan10 和 Van20:Vlan10 是市场部,Van20 是技术部,要求对 Vlana 进行命名以便识别:PC1属于 Vlan10,PC2属于 Vlan20,Vlan30 用于 SW1和 SW2 建立 OSPF 邻居:Vlan111 为 SW1 和 R1 的互联 Vlan,Vlan222 为 SW2 和 R2 的互联 Vlan
4.所有交换机相连的端口配置为 Trunk,允许相关流量通过
5.交换机连接 PC 的端口配置为边缘端口
6.在 SW1 上配置 DHCP 服务,为 Van10 和 Van20 的 PC 动态分配 IP 地址、网关和 DNS 地址;要求 Vlan10 的网关是192.168.1.252,Vlan20 的网关是192.168.2.253
7.按图示分区域配置 OSPF 实现公司内部网络全网互通,ABR 的环回口宣告进骨干区域:业务网段不允许出现协议报文
8.R1 上配置默认路由指向互联网,并引入到 OSPF
9.R1 通过双线连接到互联网,配置 PPP-MP,并配置双向 chap 验证
10.配置 EASY IP,只有业务网段 和 的数据流可以通过 R1 访问互联网192.168.1.0/24 192.168.2.0/2411.R1 开启 TELNET 远程管理,使用用户kami1登录,密码 123456.com,只允许技术部远程管理 R1

二.实验步骤

1.如图所示配置IP

R1:

[H3C]SYSN R1
[R1]INT G0/0
[R1-GigabitEthernet0/0]IP AD 10.0.0.5 30
[R1-GigabitEthernet0/0]INT G0/1
[R1-GigabitEthernet0/1]IP AD 10.0.0.1 30
[R1-GigabitEthernet0/1]INT G0/2
[R1-GigabitEthernet0/2]INT LO0
[R1-LoopBack0]IP AD 10.1.1.1 32

R2:

[R2]INT G0/0
[R2-GigabitEthernet0/0]IP AD 10.0.0.9 30
[R2-GigabitEthernet0/0]INT G0/1
[R2-GigabitEthernet0/1]IP AD 10.0.0.18 30
[R2-GigabitEthernet0/1]INT G0/2
[R2-GigabitEthernet0/2]IP AD 10.0.0.2 30
[R2-GigabitEthernet0/2]INT LO0
[R2-LoopBack0]IP AD 10.1.1.2 32

R3:

[R3]INT G0/0
[R3-GigabitEthernet0/0]IP AD 10.0.0.13 30
[R3-GigabitEthernet0/0]INT G0/1
[R3-GigabitEthernet0/1]IP AD 10.0.0.17 30
[R3-GigabitEthernet0/1]INT G0/2
[R3-GigabitEthernet0/2]IP AD 192.168.3.254 24
[R3-GigabitEthernet0/2]INT LO0
[R3-LoopBack0]IP AD 10.1.1.3 32

SW1:

[SW1]VLAN  10
[SW1-vlan10]VLAN 20
[SW1-vlan20]VLAN 30
[SW1-vlan30]VLAN 111
[SW1-vlan111]INT VLAN 10
[SW1-Vlan-interface10]IP AD 192.168.1.252 24
[SW1-Vlan-interface10]INT VLAN 20
[SW1-Vlan-interface20]IP AD 192.168.2.252 24
[SW1-Vlan-interface20]INT VLAN 30
[SW1-Vlan-interface30]IP AD 10.1.2.1 30
[SW1-Vlan-interface30]INT VLAN 111
[SW1-Vlan-interface111]IP AD 10.0.0.6 30
[SW1-Vlan-interface111]INT LO0
[SW1-LoopBack0]IP AD 10.1.1.11 32

SW2:

[SW2]VLAN 10
[SW2-vlan10]VLAN 20
[SW2-vlan20]VLAN 30
[SW2-vlan30]VLAN 222
[SW2-vlan222]INT VLAN 10
[SW2-Vlan-interface10]IP AD 192.168.1.253 24
[SW2-Vlan-interface10]INT VLAN 20
[SW2-Vlan-interface20]IP AD 192.168.2.253 24
[SW2-Vlan-interface20]INT VLAN 30
[SW2-Vlan-interface30]IP AD 10.1.2.2 30
[SW2-Vlan-interface30]INT VLAN 222
[SW2-Vlan-interface222]IP AD 10.0.0.10 30
[SW2-Vlan-interface222]INT LO0

2.SW1 和 SW2 之间的直连链路配置链路聚合

SW1:

[SW1]int Bridge-Aggregation 1
[SW1-Bridge-Aggregation1]quit
[SW1]int g1/0/1
[SW1-GigabitEthernet1/0/1]port link-aggregation group 1
[SW1]int g1/0/2
[SW1-GigabitEthernet1/0/2]port link-aggregation group 1

SW2:

[SW2]int Bridge-Aggregation 1
[SW2-Bridge-Aggregation1]quit
[SW2]int g1/0/1
[SW2-GigabitEthernet1/0/1]port link-aggregation group 1
[SW2]int g1/0/2
[SW2-GigabitEthernet1/0/2]port link-aggregation group 1

3.划分VLAN

SW3:

[SW3]vlan 10
[SW3-vlan10]port g1/0/3
[SW3-vlan10]vlan 20
[SW3-vlan20]port g1/0/4

SW1:

[SW1-vlan10]vlan 111
[SW1-vlan111]port g1/0/4

SW2:

[SW2]vlan 222
[SW2-vlan222]port g1/0/4

4.所有交换机相连的端口配置为 Trunk,允许相关流量通过

SW1:

[SW1]int Bridge-Aggregation 1
[SW1-Bridge-Aggregation1]port link-type  trunk 
[SW1-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW1-Bridge-Aggregation1]int g1/0/3
[SW1-GigabitEthernet1/0/3]port link-type trunk 
[SW1-GigabitEthernet1/0/3]port trunk permit vlan 10 20

SW2:

[SW2]int Bridge-Aggregation 1
[SW2-Bridge-Aggregation1]port link-type trunk 
[SW2-Bridge-Aggregation1]port trunk permit vlan 10 20 30
[SW2-Bridge-Aggregation1]int g1/0/3
[SW2-GigabitEthernet1/0/3]port link-type trunk 
[SW2-GigabitEthernet1/0/3]port trunk permit vlan 10 20

SW3:

[SW3]int g1/0/1
[SW3-GigabitEthernet1/0/1]port link-type trunk 
[SW3-GigabitEthernet1/0/1]port trunk permit vlan 10 20
[SW3-GigabitEthernet1/0/1]int g1/0/2
[SW3-GigabitEthernet1/0/2]port link-type trunk 
[SW3-GigabitEthernet1/0/2]port trunk permit vlan 10 20

5.交换机连接 PC 的端口配置为边缘端口

[SW3-GigabitEthernet1/0/2]int g1/0/3
[SW3-GigabitEthernet1/0/3]stp edged-port
[SW3-GigabitEthernet1/0/3]int g1/0/4
[SW3-GigabitEthernet1/0/4]stp edged-port

6.在 SW1 上配置 DHCP 服务

SW1:

[SW1]dhcp enable 
[SW1]dhcp server ip-pool 1
[SW1-dhcp-pool-1]gateway-list 192.168.1.252
[SW1-dhcp-pool-1]network 192.168.1.0 24
[SW1-dhcp-pool-1]quit
[SW1]dhcp server ip-pool 2
[SW1-dhcp-pool-2]gateway-list 192.168.2.253
[SW1-dhcp-pool-2]network 192.168.2.0 24

7.按图示分区域配置 OSPF

R1:

[R1]ospf 1 router-id 10.1.1.1
[R1-ospf-1]are 0
[R1-ospf-1-area-0.0.0.0]net 10.0.0.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]net 10.0.0.14 0.0.0.0
[R1-ospf-1-area-0.0.0.0]net 10.1.1.1 0.0.0.0
[R1-ospf-1-area-0.0.0.0]are 1
[R1-ospf-1-area-0.0.0.1]net 10.0.0.5 0.0.0.0

R2:

[R2]ospf 1 router-id 10.1.1.2
[R2-ospf-1]are 1
[R2-ospf-1-area-0.0.0.1]net 10.0.0.9 0.0.0.0
[R2-ospf-1-area-0.0.0.1]are 0
[R2-ospf-1-area-0.0.0.0]net 10.0.0.18 0.0.0.0
[R2-ospf-1-area-0.0.0.0]net 10.0.0.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]network 10.1.1.2 0.0.0.0

R3:

[R3]ospf 1 router-id 10.1.1.3
[R3-ospf-1]are 0
[R3-ospf-1-area-0.0.0.0]net 10.0.0.13 0.0.0.0
[R3-ospf-1-area-0.0.0.0]net 10.0.0.17 0.0.0.0
[R3-ospf-1-area-0.0.0.0]net 192.168.3.254 0.0.0.255
[R3-ospf-1-area-0.0.0.0]network 10.1.1.3 0.0.0.0

SW1:

[SW1]ospf 1
[SW1-ospf-1]are 1
[SW1-ospf-1-area-0.0.0.1]net 192.168.1.0 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]net 192.168.2.0 0.0.0.255
[SW1-ospf-1-area-0.0.0.1]net 10.1.2.1 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]net 10.0.0.6 0.0.0.0
[SW1-ospf-1-area-0.0.0.1]net 10.1.1.11 0.0.0.0

SW2:

[SW2]ospf 1
[SW2-ospf-1]are 1
[SW2-ospf-1-area-0.0.0.1]net 192.168.1.0 0.0.0.255
[SW2-ospf-1-area-0.0.0.1]net 192.168.2.0 0.0.0.255
[SW2-ospf-1-area-0.0.0.1]net 10.1.2.2 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]net 10.0.0.10 0.0.0.0
[SW2-ospf-1-area-0.0.0.1]net 10.1.1.12 0.0.0.0

业务网段不允许出现协议报文

SW1:

[SW1-ospf-1]silent-interface vlan 10
[SW1-ospf-1]silent-interface vlan 20

SW2:

[SW2-ospf-1]silent-interface vlan 10
[SW2-ospf-1]silent-interface vlan 20

8.R1 上配置默认路由指向互联网,并引入到 OSPF

R1:

[R1]ip route-static 0.0.0.0 0 202.100.1.1
[R1]ospf 1
[R1-ospf-1]default-route-advertise

R1 通过双线连接到互联网,配置 PPP-MP,并配置双向 chap 验证

R1:

[R1]int MP-group 1
[R1-MP-group1]
[R1]local-user kami class network 
[R1-luser-network-kami]password simple 123456
[R1-luser-network-kami]service-type ppp
[R1-luser-network-kami]quit
[R1]int s1/0
[R1-Serial1/0]ppp mp MP-group 1
[R1-Serial1/0]ppp chap user kami
[R1-Serial1/0]int s2/0
[R1-Serial2/0]ppp mp MP-group 1
[R1-Serial2/0]ppp chap user kami

INTERNET:

[INTERNET]int MP-group 1
[INTERNET-MP-group1]quit
[INTERNET]local-user kami
[INTERNET-luser-manage-kami]quit
[INTERNET]local-user kami class network 
[INTERNET-luser-network-kami]password simple 123456
[INTERNET-luser-network-kami]service-type ppp
[INTERNET-luser-network-kami]int s1/0
[INTERNET-Serial1/0]ppp mp MP-group 1
[INTERNET-Serial1/0]ppp chap user kami
[INTERNET-Serial1/0]int s2/0
[INTERNET-Serial2/0]ppp mp MP-group 1
[INTERNET-Serial2/0]ppp chap user kami

10.配置 EASY IP

R1:

[R1]acl basic 2000
[R1-acl-ipv4-basic-2000]rule permit source  192.168.1.0 0.0.0.255
[R1-acl-ipv4-basic-2000]rule permit source  192.168.2.0 0.0.0.255
[R1-acl-ipv4-basic-2000]quit
[R1]int MP-group 1
[R1-MP-group1]nat outbound 2000

开启 TELNET 远程管理,使用用户kami1登录,密码 123456.com,只允许技术部远程管理 R1

R1:开启telnet服务

[R1]telnet server enable 
[R1]local-user kami1 class manage 
[R1-luser-manage-kami1]password simple 123456.com
[R1-luser-manage-kami1]authorization-attribute user-role level-15
[R1-luser-manage-kami1]service-type telnet 
[R1]user-int vty 0 4
[R1-line-vty0-4]authentication-mode sc

R1:配置高级ACL

[R1]acl advanced 3000
[R1-acl-ipv4-adv-3000]rule permit tcp source 192.168.2.0 0.0.0.255
[R1-acl-ipv4-adv-3000]rule deny tcp
[R1-acl-ipv4-adv-3000]quit
[R1]int range g0/0 to g0/2
[R1-if-range]packet-filter 3000 inbound 
三.测试

全网互通

PC1ping

在这里插入图片描述

在这里插入图片描述

在这里插入图片描述

PC1TELNET登录
在这里插入图片描述

PC2TELNET登录
在这里插入图片描述

PC3TELNET登录

在这里插入图片描述

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值