网络系统集成基础(实验学时)——实验四

题目要求:

实验内容:

1、熟悉路由器的配置管理(附文档路由器的介绍PPT)
2、静态路由实验,建立拓扑pc1>>R1>>R2>>R3>>pc2,使pc1与pc2能相互通信。
3、为实验二公司网络配置路由器,使内部网络可以访问Internet。
4、将内网服务器80端口映射出去,允许外网用户访问

实验报告:

要求独立完成,报告需包含模拟器配置文件
分别使用华为模拟器和思科模拟器完成

思科

1、熟悉路由器的配置管理(附文档路由器的介绍PPT)

  1. 路由器是连接网络的重要设备,它能将多个网络连接起来,实现不同网络之间的通信。路由器主要由硬件和软件两部分组成,硬件包括CPU、RAM、Flash等,软件如思科的IOS、华为的VRP等。
  2. 路由器的核心功能是根据数据包的目标IP地址,通过查找路由表,确定数据包的下一跳,并将其从相应的接口转发出去。路由表可以通过直连路由、静态路由和动态路由等方式生成。
  3. 配置路由器时,需要熟悉各种工作模式,如用户模式(查看信息)、特权模式(调试排错)、全局配置模式(进行全局配置)和接口配置模式(配置各接口)等。
  4. 常用的路由器配置命令包括:查看路由器信息(show)、配置路由器名称(hostname)、设置接口IP地址(ip address)、配置静态路由(ip route)、配置时钟频率(clock rate)等。
  5. 路由器支持多种线缆类型,如同轴电缆、双绞线、光纤等。选择线缆时需要考虑带宽、距离和成本等因素。
  6. 路由器的接口类型多样,如以太网接口、异步/同步串行接口、Console/AUX接口等。不同接口的配置和线缆要求不同。
  7. 路由器的存储设备包括RAM(运行时存储)、NVRAM(启动配置)、Flash(IOS镜像)和ROM(硬件自检和引导)等。
  8. 可通过Console口(参数为9600、8、N、1)、AUX口、Telnet(23端口)、SSH(22端口)等方式管理路由器。远程管理需要合理的安全策略。
  9. 了解路由器常见的问题和故障排除方法,如接口down、线缆问题、配置错误、软硬件冲突等,可通过ping、traceroute、show等命令定位问题。
  10. 路由器是网络的核心设备,掌握路由器的原理、组成、配置和管理,是网络工程师必备的技能。

思科是全球领先的网络设备供应商,其路由器产品以性能稳定、功能强大而闻名。下面我们重点介绍思科路由器的相关知识。思科路由器采用Cisco IOS(互联网络操作系统)软件,提供了丰富的功能和灵活的配置选项。Cisco IOS支持CLI(命令行界面)和图形化管理,适合不同的用户需求。思科路由器的型号命名遵循一定的规则,如19xx、29xx、39xx等系列,代表了不同的性能和应用场景。选择路由器型号时,需要考虑吞吐量、接口数量、可扩展性等因素。

在硬件组成方面,思科路由器typically包括CPU、RAM、Flash、NVRAM等部件,分别承担处理、存储、引导等功能。合理的硬件配置对于路由器的性能至关重要。思科路由器支持多种接口类型,如FastEthernet、Ethernet、Serial等。这些接口使用RJ45、DB60等不同的连接器和线缆。配置接口时,需要了解接口的工作模式(如DTE/DCE)和物理特性。管理思科路由器的常见方式包括Console口(通过RJ45转DB9串口线)、AUX口、Telnet和SSH等。Console口一般用于本地配置调试,AUX用于拨号,Telnet和SSH则用于远程管理。

配置思科路由器时,需要熟悉Cisco IOS的命令行界面。常用的配置命令包括enable(进入特权模式)、configure terminal(进入全局配置)、interface(进入接口配置)等。在路由配置方面,思科路由器支持静态路由和动态路由协议(如RIP、OSPF、EIGRP等)。通过ip route命令可以配置静态路由,network和router等命令用于启用动态路由。安全性是配置思科路由器需要关注的重点。可以通过设置密码(如enable secret)、配置SSH(ip ssh version 2)、启用AAA认证(aaa new-model)等措施,加强路由器的安全防护。

管理思科路由器还需要进行系统维护,如备份配置(copy running-config startup-config)、升级IOS(copy tftp flash)、查看日志(show logging)等。当思科路由器出现故障时,可以使用ping、traceroute、show等命令进行排查。通过分析接口状态、路由表、CPU利用率等指标,可以定位和解决大部分问题。思科路由器凭借其优异的性能和丰富的功能,在网络领域占据着重要的地位。深入学习和实践思科路由器的配置与管理,对于提升网络技能大有裨益。

2、静态路由实验,建立拓扑pc1>>R1>>R2>>R3>>pc2,使pc1与pc2能相互通信。

根据您提供的拓扑图,我使用10开头的IP地址重新规划:

设备IP配置:

  • PC-PT (PC0): 10.1.1.2/30,网关10.1.1.1
  • Router0:

    • Fa0/0: 10.1.1.1/30
    • Se2/0: 10.1.2.1/30
  • Router-PT:

    • Se2/0: 10.1.2.2/30
    • Se3/0: 10.1.3.1/30
  • Router2:

    • Fa0/0: 10.1.3.3/30
    • Se3/0: 10.1.3.2/30
  • PC-PT (PC1): 10.1.3.4/30,网关10.1.3.3

路由器IP

R0

Router>en
Router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#hostname r0
r0(config)#int f0/0
r0(config-if)#ip addr 10.1.1.1 255.255.255.0
r0(config-if)#no shut


r0(config-if)#int s2/0
r0(config-if)#ip addr 10.1.2.1 255.255.255.0
r0(config-if)#no shut

R1

Router>en
Router#conf t
  Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#hostname r1
r1(config)#int s2/0
r1(config-if)#ip addr 10.1.2.2 255.255.255.0
r1(config-if)#no shut


r1(config-if)#int s3/0
r1(config-if)#ip addr 10.1.3.1 255.255.255.0
r1(config-if)#no shut

R2:


Router>en
Router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#hostname r2
r2(config)#int s2/0
r2(config-if)#ip addr 10.1.3.2 255.255.255.0
r2(config-if)#no shut

r2(config-if)#int f0/0
r2(config-if)#ip addr 10.1.4.1 255.255.255.0
r2(config-if)#no shut

设备接口IP地址子网掩码
PC0NIC10.1.1.10255.255.255.0
PC1NIC10.1.4.10255.255.255.0
r0f0/010.1.1.1255.255.255.0
s2/010.1.2.1255.255.255.0
r1s2/010.1.2.2255.255.255.0
s3/010.1.3.1255.255.255.0
r2s2/010.1.3.2255.255.255.0
f0/010.1.4.1255.255.255.0

pc1

PC2

配置静态路由

设备接口IP地址子网掩码
PC0NIC10.1.1.10255.255.255.0
PC1NIC10.1.4.10255.255.255.0
r0f0/010.1.1.1255.255.255.0
s2/010.1.2.1255.255.255.0
r1s2/010.1.2.2255.255.255.0
s3/010.1.3.1255.255.255.0
r2s2/010.1.3.2255.255.255.0
f0/010.1.4.1255.255.255.0
r0(config)#ip route 10.1.3.0 255.255.255.0 10.1.2.2
r0(config)#ip route 10.1.4.0 255.255.255.0 10.1.2.2

r1(config)#ip route 10.1.1.0 255.255.255.0 10.1.2.1
r1(config)#ip route 10.1.4.0 255.255.255.0 10.1.3.2

r2(config)#ip route 10.1.1.0 255.255.255.0 10.1.3.1
r2(config)#ip route 10.1.2.0 255.255.255.0 10.1.3.1
r0(config)#do show ip route static
     10.0.0.0/24 is subnetted, 4 subnets
S       10.1.3.0 [1/0] via 10.1.2.2
S       10.1.4.0 [1/0] via 10.1.2.2


r1(config)#do show ip route static
     10.0.0.0/24 is subnetted, 4 subnets
S       10.1.1.0 [1/0] via 10.1.2.1
S       10.1.4.0 [1/0] via 10.1.3.2


r2#show ip route 
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
       i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
       * - candidate default, U - per-user static route, o - ODR
       P - periodic downloaded static route

Gateway of last resort is not set

     10.0.0.0/24 is subnetted, 4 subnets
S       10.1.1.0 [1/0] via 10.1.3.1
S       10.1.2.0 [1/0] via 10.1.3.1
C       10.1.3.0 is directly connected, Serial2/0
C       10.1.4.0 is directly connected, FastEthernet0/0
r2#

测试

PC>tracert 10.1.4.10

Tracing route to 10.1.4.10 over a maximum of 30 hops: 

  1   0 ms      0 ms      0 ms      10.1.1.1
  2   0 ms      4 ms      0 ms      10.1.2.2
  3   1 ms      0 ms      1 ms      10.1.3.2
  4   *         2 ms      4 ms      10.1.4.10

Trace complete.

PC>ping 10.1.4.10

Pinging 10.1.4.10 with 32 bytes of data:

Reply from 10.1.4.10: bytes=32 time=7ms TTL=125

Ping statistics for 10.1.4.10:
    Packets: Sent = 1, Received = 1, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 7ms, Maximum = 7ms, Average = 7ms

3、为实验二公司网络配置路由器,使内部网络可以访问Internet。

一个新的拓扑,当做公网

  • 202.194.222.4/32
  • 202.194.222.1/32

R0

r0>en
r0#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
r0(config)#ip route 0.0.0.0 0.0.0.0 Serial2/0
r0(config)#
r0(config)#do show ip route

R1:

r1(config)#int fa0/0
r1(config-if)#ip addr 10.1.5.1 255.255.255.0
r1(config-if)#no shut
r1(config)#ip route 0.0.0.0 0.0.0.0 fa0/0

右上角路由

Router>en
Router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#hostname intelnet
intelnet(config)#int fa1/0
intelnet(config-if)#ip addr 10.1.5.2 255.255.255.0
intelnet(config-if)#no shut

intelnet(config-if)#int f0/0
intelnet(config-if)#ip addr 202.194.222.1 255.255.255.0
intelnet(config-if)#no shut

intelnet(config-if)#ip route 10.1.1.0 255.255.255.0 10.1.5.1
intelnet(config)#ip route 10.1.4.0 255.255.255.0 10.1.5.1

R2

r2(config)#ip route 0.0.0.0 0.0.0.0 se2/0

测试

PC>ping 202.194.222.4

Pinging 202.194.222.4 with 32 bytes of data:

Reply from 202.194.222.4: bytes=32 time=6ms TTL=125
Reply from 202.194.222.4: bytes=32 time=4ms TTL=125
Reply from 202.194.222.4: bytes=32 time=2ms TTL=125
Reply from 202.194.222.4: bytes=32 time=4ms TTL=125

Ping statistics for 202.194.222.4:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 2ms, Maximum = 6ms, Average = 4ms

PC>

4、将内网服务器80端口映射出去,

内网服务器

拓扑这样子:

intelnet(config)#access-list 1 permit 10.1.1.0 0.0.0.255
intelnet(config)#access-list 1 permit 10.1.4.0 0.0.0.255
intelnet(config)#int fa1/0
intelnet(config-if)#ip nat inside
intelnet(config-if)#exit

intelnet(config)#int fa0/0
intelnet(config-if)#ip nat outside
intelnet(config-if)#exit
intelnet(config)#ip nat inside source list 1 interface FastEthernet0/0 overload
intelnet(config)#ip nat inside source static tcp 10.1.4.250 80 202.194.222.1 8080

测试一下,打开浏览器:

http://202.194.222.1:8080
可以正常访问。

5、模拟器配置文件

r0

r0#copy running-config startup-config 
Destination filename [startup-config]? 
Building configuration...
[OK]
r0#show run
r0#show running-config 
Building configuration...

Current configuration : 758 bytes
!
version 12.2
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname r0
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
 ip address 10.1.1.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet1/0
 no ip address
 duplex auto
 speed auto
 shutdown
!
interface Serial2/0
 ip address 10.1.2.1 255.255.255.0
!
interface Serial3/0
 no ip address
 shutdown
!
interface FastEthernet4/0
 no ip address
 shutdown
!
interface FastEthernet5/0
 no ip address
 shutdown
!
ip classless
ip route 10.1.3.0 255.255.255.0 10.1.2.2 
ip route 10.1.4.0 255.255.255.0 10.1.2.2 
ip route 0.0.0.0 0.0.0.0 Serial2/0 
!
!
!
!
!
!
!
line con 0
!
line aux 0
!
line vty 0 4
 login
!
!
!
end

r1

r1#copy running-config startup-config 
Destination filename [startup-config]? 
Building configuration...
[OK]
r1#show ru
r1#show running-config 
Building configuration...

Current configuration : 868 bytes
!
version 12.2
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname r1
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
 ip address 10.1.5.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet1/0
 no ip address
 duplex auto
 speed auto
 shutdown
!
interface Serial2/0
 ip address 10.1.2.2 255.255.255.0
!
interface Serial3/0
 ip address 10.1.3.1 255.255.255.0
!
interface FastEthernet4/0
 no ip address
 shutdown
!
interface FastEthernet5/0
 no ip address
 shutdown
!
ip classless
ip route 10.1.1.0 255.255.255.0 10.1.2.1 
ip route 10.1.4.0 255.255.255.0 10.1.3.2 
ip route 10.1.1.0 255.255.255.0 202.194.222.2 
ip route 10.4.1.0 255.255.255.0 202.194.222.2 
ip route 0.0.0.0 0.0.0.0 FastEthernet0/0 
!
!
!
!
!
!
!
line con 0
!
line aux 0
!
line vty 0 4
 login
!
!
!
end


r1#

r2

r2#copy running-config startup-config 
Destination filename [startup-config]? 
Building configuration...
[OK]
r2#show ru
r2#show running-config 
Building configuration...

Current configuration : 758 bytes
!
version 12.2
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname r2
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
 ip address 10.1.4.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet1/0
 no ip address
 duplex auto
 speed auto
 shutdown
!
interface Serial2/0
 ip address 10.1.3.2 255.255.255.0
!
interface Serial3/0
 no ip address
 shutdown
!
interface FastEthernet4/0
 no ip address
 shutdown
!
interface FastEthernet5/0
 no ip address
 shutdown
!
ip classless
ip route 10.1.1.0 255.255.255.0 10.1.3.1 
ip route 10.1.2.0 255.255.255.0 10.1.3.1 
ip route 0.0.0.0 0.0.0.0 Serial2/0 
!
!
!
!
!
!
!
line con 0
!
line aux 0
!
line vty 0 4
 login
!
!
!
end


r2#

r3

intelnet#copy running-config startup-config 
Destination filename [startup-config]? 
Building configuration...
[OK]
intelnet#show ru
intelnet#show running-config 
Building configuration...

Current configuration : 1015 bytes
!
version 12.2
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname intelnet
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
 ip address 202.194.222.1 255.255.255.0
 ip nat outside
 duplex auto
 speed auto
!
interface FastEthernet1/0
 ip address 10.1.5.2 255.255.255.0
 ip nat inside
 duplex auto
 speed auto
!
interface Serial2/0
 no ip address
 shutdown
!
interface Serial3/0
 no ip address
 shutdown
!
interface FastEthernet4/0
 no ip address
 shutdown
!
interface FastEthernet5/0
 no ip address
 shutdown
!
ip nat inside source list 1 interface FastEthernet0/0 overload
ip nat inside source static tcp 10.1.4.250 80 202.194.222.1 8080 
ip classless
ip route 10.1.1.0 255.255.255.0 10.1.5.1 
ip route 10.4.1.0 255.255.255.0 10.1.5.1 
ip route 10.1.4.0 255.255.255.0 10.1.5.1 
!
!
access-list 1 permit 10.1.1.0 0.0.0.255
access-list 1 permit 10.1.4.0 0.0.0.255
!
!
!
!
!
line con 0
!
line aux 0
!
line vty 0 4
 login
!
!
!
end


intelnet#
intelnet#

华为

1、熟悉路由器的配置管理(附文档路由器的介绍PPT)

华为是中国乃至全球的网络设备巨头之一,其路由器产品以性价比高、功能全面而备受青睐。下面我们就来详细了解一下华为路由器的相关知识。

华为路由器采用VRP(Versatile Routing Platform)操作系统,该系统基于Linux内核开发,提供了强大的网络功能和友好的配置管理界面。VRP支持命令行和Web界面配置,满足不同用户的需求。

华为路由器的命名方式通常以AR(Access Router)、NE(Network Engine)等字母开头,后面跟数字表示系列和型号,如AR系列、NE系列等。不同系列的路由器在性能、接口、功耗等方面有所差异,可根据实际需求选择。

从硬件结构看,华为路由器一般包括主控板(MPU)、业务板(LPU)、交换网板(SFU)、电源板(PWR)等部件。其中,MPU负责路由计算和管理,LPU提供业务接口,SFU实现数据交换,PWR供给系统电源。

华为路由器支持丰富的接口类型,如以太网接口(Ethernet)、广域网接口(WAN)、串行接口(Serial)等。不同接口使用RJ45、SFP、RS232等连接器,传输介质包括双绞线、光纤、同轴电缆等。

管理华为路由器的方式有多种,如Console口(通过Console线缆)、Telnet(23端口)、SSH(22端口)、Web(80端口)等。日常配置一般使用Console口,远程管理则用Telnet/SSH/Web,注意网络和安全设置。

配置华为路由器时,需要熟悉VRP的命令行界面。常见命令包括system-view(进入系统视图)、interface(进入接口视图)、display(查看信息)、save(保存配置)等。

华为路由器支持多种路由协议,如静态路由、RIP、OSPF、ISIS、BGP等。配置静态路由使用ip route-static命令,动态路由则在相应的路由视图下进行。

安全性是华为路由器配置的重中之重。基本措施包括设置用户名密码(aaa)、启用SSH(ssh server enable)、配置ACL(acl number)等。对于关键路由器,还需要部署防火墙、VPN等安全业务。

维护华为路由器需要掌握一些常用操作,如软件升级(upgrade)、配置备份(backup configuration)、日志查看(display current-configuration)、调试开关(debugging)等。

华为路由器出现故障时,参考以下思路排查:

  1. 检查物理连接,如接口线缆、模块、电源等是否正常。
  2. 确认接口配置,如IP地址、子网掩码、接口状态等。
  3. 查看路由表,分析路由协议、路由条目是否合理。
  4. 观察CPU、内存等资源利用率,判断是否过载。
  5. 使用ping、tracert等工具,测试网络连通性。
  6. 对比配置文件,查找配置差异或错误。
  7. 翻阅系统日志,获取告警、错误等重要信息。

华为路由器以其优异的性能、灵活的扩展性和极高的性价比,在企业网和运营商网广泛应用。系统学习华为路由器的原理、配置和维护,对于提高网络管理水平大有裨益。作为网络人,掌握华为路由器的"武功秘籍",定能在职场立于不败之地。

2、静态路由实验,建立拓扑pc1>>R1>>R2>>R3>>pc2,使pc1与pc2能相互通信。

它有bug,用就用最高级的那个路由器。

用这个路由器:

拓扑图:

配置命令

R1:

[Huawei]int e0/0/0
[Huawei-Ethernet0/0/0]ip addr 192.168.1.1 24

[Huawei]int e0/0/1  
[Huawei-Ethernet0/0/1]ip addr 10.1.1.1 24
[Huawei]ip route-static 192.168.2.0 24 10.1.1.2

[Huawei]dis ip routing-table

R2:

<Huawei>sys
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 10.1.1.2 24

[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 10.2.2.2 24


[Huawei-GigabitEthernet0/0/1]quit
[Huawei]ip route-static 192.168.1.0 24 10.1.1.1
[Huawei]ip route-static 192.168.2.0 24 10.2.2.3  
[Huawei]dis ip int brief


[Huawei]ping 192.168.2.1 (成功)
[Huawei]ping 192.168.1.1 (成功)

R3:

<Huawei>sys
[Huawei]int e0/0/0
[Huawei-Ethernet0/0/0]ip addr 10.2.2.3 24
[Huawei-Ethernet0/0/0]int e0/0/1
[Huawei-Ethernet0/0/1]ip addr 192.168.2.1 24
[Huawei-Ethernet0/0/1]quit
[Huawei]ip route-static 192.168.1.0 24 10.2.2.2
[Huawei]dis ip int brief
Interface                         IP Address/Mask      Physical   Protocol  
Ethernet0/0/0                     10.2.2.3/24          up         up        
Ethernet0/0/1                     192.168.2.1/24       up         up        
GigabitEthernet0/0/0              unassigned           down       down      
GigabitEthernet0/0/1              unassigned           down       down      
GigabitEthernet0/0/2              unassigned           down       down      
GigabitEthernet0/0/3              unassigned           down       down      
NULL0                             unassigned           up         up(s)     
Serial0/0/0                       unassigned           down       down      
Serial0/0/1                       unassigned           down       down      
Serial0/0/2                       unassigned           down       down      
Serial0/0/3                       unassigned           down       down      

可以ping通

这个也是:

3、为实验二公司网络配置路由器,使内部网络可以访问Internet。

请直接跳转到[☆新的拓扑图]章节,蓝屏了。拓扑图重新画的。

R2

[Huawei]ip route-static 0.0.0.0 0.0.0.0 10.11.11.6
[Huawei-GigabitEthernet0/0/2]ip addr 10.11.11.2 24

R6

<Huawei>sys
  Enter system view, return user view with Ctrl+Z.
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 10.11.11.6 24

[Huawei-GigabitEthernet0/0/0]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 202.194.222.1 24

目前AR2可以访问202.194.222.4(intelnet)

划分VLAN

拓扑结构:

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]int vlan    
[Huawei]int Vlanif 
[Huawei]int Vlanif 10
Error: The VLAN does not exist.
[Huawei]vlan 10
[Huawei-vlan10]vlan 20
[Huawei-vlan20]vlan 30
[Huawei-vlan30]int vl    
[Huawei-vlan30]int vlanif 10
[Huawei-Vlanif10]ip addr 192.168.10.1 24
[Huawei-Vlanif10]int vl    
[Huawei-Vlanif10]int vlanif 20
[Huawei-Vlanif20]ip addr 192.168.20.1 24
[Huawei-Vlanif20]int vlanif 30
[Huawei-Vlanif30]ip addr 192.168.30.1 24
Enter system view, return user view with Ctrl+Z.
[Huawei]vlan 10
[Huawei-vlan10]vlan 20
[Huawei-vlan20]
Jun  5 2024 10:22:42-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 5, th
e change loop count is 0, and the maximum number of records is 4095.

服务器配置IP

划分VLAN到端口

[Huawei-vlan30]int e0/0/2
[Huawei-Ethernet0/0/2]pro    
[Huawei-Ethernet0/0/2]port    
[Huawei-Ethernet0/0/2]port link-type access 
[Huawei-Ethernet0/0/2]
Jun  5 2024 10:25:42-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 7, th
e change loop count is 0, and the maximum number of records is 4095.port default
 vlan 10
[Huawei-Ethernet0/0/2]port default vlan 10
[Huawei-Ethernet0/0/2]
Jun  5 2024 10:25:52-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 8, th
e change loop count is 0, and the maximum number of records is 4095.port default
 vlan 10
[Huawei-Ethernet0/0/2]
[Huawei-Ethernet0/0/2]int e0/0/3
[Huawei-Ethernet0/0/3]port link-type access
[Huawei-Ethernet0/0/3]int e0/0/3
Jun  5 2024 10:26:02-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 9, th
e change loop count is 0, and the maximum number of recordport default vlan 20
[Huawei-Ethernet0/0/3]
[Huawei-Ethernet0/0/3]
[Huawei-Ethernet0/0/3]port default vlan 20
[Huawei-Ethernet0/0/3]
Jun  5 2024 10:26:12-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 10, t
he change loop count is 0, and the maximum number of records is 4095.

vlan划分

[Huawei]vlan 10
[Huawei-vlan10]vlan 20
[Huawei-vlan20]vlan 30
[Huawei-vlan30]
Jun  5 2024 10:23:13-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 6, th
e change loop count is 0, and the maximum number of records is 4095.
[Huawei-vlan30]
[Huawei-vlan30]
[Huawei-vlan30]int e0/0/1
[Huawei-Ethernet0/0/1]port link    
[Huawei-Ethernet0/0/1]port link-t    
[Huawei-Ethernet0/0/1]port link-type tr    
[Huawei-Ethernet0/0/1]port link-type trunk 
[Huawei-Ethernet0/0/1]int e0/0/2
[Huawei-Ethernet0/0/2]por
Jun  5 2024 10:28:03-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 7, th
e change loop count is 0, and the maximum number of records is 4095.t
                           ^
Error:Incomplete command found at '^' position.
[Huawei-Ethernet0/0/2]port link    
[Huawei-Ethernet0/0/2]port link-t    
[Huawei-Ethernet0/0/2]port link-type tr    
[Huawei-Ethernet0/0/2]port link-type acc    
[Huawei-Ethernet0/0/2]port link-type access 
[Huawei-Ethernet0/0/2]
Jun  5 2024 10:28:13-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 8, th
e change loop count is 0, and the maximum number of records is 4095.
[Huawei-Ethernet0/0/2]
[Huawei-Ethernet0/0/2]port default vlan 30
[Huawei-Ethernet0/0/2]
Jun  5 2024 10:28:43-08:00 Huawei DS/4/DATASYNC_CFGCHANGE:OID 1.3.6.1.4.1.2011.5
.25.191.3.1 configurations have been changed. The current change number is 9, th
e change loop count is 0, and the maximum number of records is 4095.

核心交换机

[Huawei-vlan30]int g0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]int g0/0/2
[Huawei-GigabitEthernet0/0/2]port link-type trunk
[Huawei-GigabitEthernet0/0/2]int g0/0/3
[Huawei-GigabitEthernet0/0/3]port link-type trunk
[Huawei-GigabitEthernet0/0/3]

[Huawei-GigabitEthernet0/0/1.10]int g0/0/1.20
[Huawei-GigabitEthernet0/0/1.20]ip addr 192.168.20.1 24
[Huawei-GigabitEthernet0/0/1.20]dot1q termination vid 20
Jun  5 2024 10:55:51-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[2]:The line protocol
 IP on the interface GigabitEthernet0/0/1.20 has entered the UP state. 
[Huawei-GigabitEthernet0/0/1.20]int g0/0/1.30
[Huawei-GigabitEthernet0/0/1.30]ip addr 192.168.30.1 24
[Huawei-GigabitEthernet0/0/1.30]dot1q termination vid 30


后面电脑突然蓝屏重启了,没有保存文件
后面电脑突然蓝屏重启了,没有保存文件
后面电脑突然蓝屏重启了,没有保存文件

☆新的拓扑图

简单模拟一下

路由器:

<Huawei>sys
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip addr 10.22.22.1 24

[Huawei]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip addr 202.194.222.1 24 #公网IP


[Huawei]ip route-static 192.168.10.0 24 10.22.22.2
[Huawei]ip route-static 192.168.20.0 24 10.22.22.2
[Huawei]ip route-static 192.168.30.0 24 10.22.22.2

三层交换机

[Huawei-GigabitEthernet0/0/1]quit
[Huawei]undo inf    
[Huawei]undo info-center en    
[Huawei]undo info-center enable 
Info: Information center is disabled.
[Huawei]vlan b 10 20 30
Info: This operation may take a few seconds. Please wait for a moment...done.
[Huawei]vlan b 10 20 30 100
Info: This operation may take a few seconds. Please wait for a moment...done.
[Huawei]int vlanif10
[Huawei-Vlanif10]ip addr 192.168.10.1 24
[Huawei-Vlanif10]int vlanif20
[Huawei-Vlanif20]ip addr 192.168.20.1 24
[Huawei-Vlanif20]int vlanif30
[Huawei-Vlanif30]ip addr 192.168.30.1 24
[Huawei-Vlanif30]int vlanif100
[Huawei-Vlanif100]ip addr 10.22.22.2 24
[Huawei-Vlanif100]int g0/0/3
[Huawei-GigabitEthernet0/0/3]p l a
[Huawei-GigabitEthernet0/0/3]p d v 100
[Huawei-GigabitEthernet0/0/3]un sh
Info: Interface GigabitEthernet0/0/3 is not shutdown.
[Huawei-GigabitEthernet0/0/3]q
[Huawei]ip route-static 0.0.0.0 0.0.0.0 10.22.22.2
Error: The next-hop address is invalid.
[Huawei]ip route-static 0.0.0.0 0.0.0.0 10.22.22.1
[Huawei]

[Huawei]int g 0/0/1
[Huawei-GigabitEthernet0/0/1]p l t
[Huawei-GigabitEthernet0/0/1]p t a v a

二层交换机

[Huawei]int e0/0/3
[Huawei-Ethernet0/0/3]p l t #port link-type trunk 
[Huawei-Ethernet0/0/3]p t a v a #port trunk allow-pass vlan all 
[Huawei-Ethernet0/0/3]un sh

[Huawei]int e0/0/1
[Huawei-Ethernet0/0/1]p l a
[Huawei-Ethernet0/0/1]p d v 30
[Huawei-Ethernet0/0/1]int e0/0/2
[Huawei-Ethernet0/0/2]p l a
[Huawei-Ethernet0/0/2]p d v 30
[Huawei-Ethernet0/0/2]un sh

拓扑图:

内网互通

内网互通2

互通WAN IP:

外网访问:

4、将内网服务器80端口映射出去,

int e0/0/1
[Huawei-GigabitEthernet0/0/1]nat server protocol tcp global current-interface 80 inside 192.168.30.250 80

启动http服务器

测试:

网页可以打开。

5、模拟器配置文件

LSW2

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]display current-configuration 
#
sysname Huawei
#
undo info-center enable
#
vlan batch 10 20
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default
 domain default_admin
 local-user admin password simple admin
 local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Ethernet0/0/1
 port link-type access
 port default vlan 10
#
interface Ethernet0/0/2
 port link-type access
 port default vlan 20
#
interface Ethernet0/0/3
 port link-type trunk
 port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/4
#
interface Ethernet0/0/5
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return

[Huawei]
[Huawei]

LSW3

<Huawei>
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]dis cu    
[Huawei]dis current-configuration 
#
sysname Huawei
#
undo info-center enable
#
vlan batch 10 20 30
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default
 domain default_admin
 local-user admin password simple admin
 local-user admin service-type http
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Ethernet0/0/1
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/2
 port link-type access
 port default vlan 30
#
interface Ethernet0/0/3
 port link-type trunk
 port trunk allow-pass vlan 2 to 4094
#
interface Ethernet0/0/4
#
interface Ethernet0/0/5
#
interface Ethernet0/0/6
#
interface Ethernet0/0/7
#
interface Ethernet0/0/8
#
interface Ethernet0/0/9
#
interface Ethernet0/0/10
#
interface Ethernet0/0/11
#
interface Ethernet0/0/12
#
interface Ethernet0/0/13
#
interface Ethernet0/0/14
#
interface Ethernet0/0/15
#
interface Ethernet0/0/16
#
interface Ethernet0/0/17
#
interface Ethernet0/0/18
#
interface Ethernet0/0/19
#
interface Ethernet0/0/20
#
interface Ethernet0/0/21
#
interface Ethernet0/0/22
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return

[Huawei]

LSW1


<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]dis cu    
[Huawei]dis current-configuration 
#
sysname Huawei
#
undo info-center enable
#
vlan batch 10 20 30 100
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default
 domain default_admin
 local-user admin password simple admin
 local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
 ip address 192.168.10.1 255.255.255.0
#
interface Vlanif20
 ip address 192.168.20.1 255.255.255.0
#
interface Vlanif30
 ip address 192.168.30.1 255.255.255.0
#
interface Vlanif100
 ip address 10.22.22.2 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
 port link-type trunk
 port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/2
 port link-type trunk
 port trunk allow-pass vlan 2 to 4094
#
interface GigabitEthernet0/0/3
 port link-type access
 port default vlan 100
#
interface GigabitEthernet0/0/4
#
interface GigabitEthernet0/0/5
#
interface GigabitEthernet0/0/6
#
interface GigabitEthernet0/0/7
#
interface GigabitEthernet0/0/8
#
interface GigabitEthernet0/0/9
#
interface GigabitEthernet0/0/10
#
interface GigabitEthernet0/0/11
#
interface GigabitEthernet0/0/12
#
interface GigabitEthernet0/0/13
#
interface GigabitEthernet0/0/14
#
interface GigabitEthernet0/0/15
#
interface GigabitEthernet0/0/16
#
interface GigabitEthernet0/0/17
#
interface GigabitEthernet0/0/18
#
interface GigabitEthernet0/0/19
#
interface GigabitEthernet0/0/20
#
interface GigabitEthernet0/0/21
#
interface GigabitEthernet0/0/22
#
interface GigabitEthernet0/0/23
#
interface GigabitEthernet0/0/24
#
interface NULL0
#
ip route-static 0.0.0.0 0.0.0.0 10.22.22.1
#
user-interface con 0
user-interface vty 0 4
#
return

[Huawei]
[Huawei]
[Huawei]
[Huawei]
[Huawei]
[Huawei]

AR1

<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]dis cu    
[Huawei]dis current-configuration 
[V200R003C00]
#
 snmp-agent local-engineid 800007DB03000000000000
 snmp-agent 
#
 clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
 drop illegal-mac alarm
#
 undo info-center enable
#
 set cpu-usage threshold 80 restore 75
#
acl number 2000  
 rule 5 permit source 192.168.30.250 0 
#
aaa 
 authentication-scheme default
 authorization-scheme default
 accounting-scheme default
 domain default 
 domain default_admin 
 local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
 local-user admin service-type http
#
firewall zone Local
 priority 15
#
interface GigabitEthernet0/0/0
 ip address 10.22.22.1 255.255.255.0 
#
interface GigabitEthernet0/0/1
 ip address 202.194.222.1 255.255.255.0 
 nat server protocol tcp global current-interface www inside 192.168.30.250 www
#
interface GigabitEthernet0/0/2
#
interface NULL0
#
ip route-static 192.168.10.0 255.255.255.0 10.22.22.2
ip route-static 192.168.20.0 255.255.255.0 10.22.22.2
ip route-static 192.168.30.0 255.255.255.0 10.22.22.2
#
user-interface con 0
 authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
#
wlan ac
#
return
[Huawei]
[Huawei]
[Huawei]

失效:一些失效的过程

拓扑图:

PC1: 192.168.1.10/24
PC5: 192.168.2.10/24
PC2: 192.168.10.22/24
PC3: 192.168.20.22/24 
PC4: 192.168.30.22/24
LSW1: 192.168.30.10/24
LSW2: 192.168.30.11/24  
Server1: 192.168.30.250/24
Server2: 202.194.222.4/24

路由器

设备接口IP地址子网掩码
R1Ethernet0/0/0192.168.1.1255.255.255.0
R1Ethernet0/0/110.1.1.1255.255.255.0
R2Ethernet0/0/010.1.1.2255.255.255.0
R2Ethernet0/0/110.1.2.2255.255.255.0
R3Ethernet0/0/010.1.2.3255.255.255.0
R3Ethernet0/0/110.1.5.3255.255.255.0
R3GigabitEthernet0/0/0192.168.100.1255.255.255.0
R3GigabitEthernet0/0/1192.168.2.1255.255.255.0
R4Ethernet0/0/010.1.5.4255.255.255.0
R4Ethernet0/0/1202.194.222.1255.255.255.0

配置IP

PC1

PC5

SERVER2

PC2:

PC3:

路由器配置IP(

R1:

<Huawei>sys
[Huawei]sysname r1
[r1]int e0/0/0
[r1-Ethernet0/0/0]ip addr 192.168.1.1 24
[r1]int e0/0/1
[r1-Ethernet0/0/1]ip addr 10.1.1.1 24

R2:

<Huawei>sys
  Enter system view, return user view with Ctrl+Z.
[Huawei]sysname r2
[r2]int e0/0/0
[r2-Ethernet0/0/0]ip addr 10.1.1.2 24

[r2-Ethernet0/0/0]int e0/0/1
[r2-Ethernet0/0/1]ip addr 10.1.2.2 24

R3:

[Huawei]int e0/0/0
[Huawei-Ethernet0/0/0]ip addr 10.1.2.3 24

[Huawei-Ethernet0/0/0]int e0/0/1
[Huawei-Ethernet0/0/1]ip addr 10.1.5.3 24

[Huawei-Ethernet0/0/1]sysname r3

[r3]int g0/0/1
[r3-GigabitEthernet0/0/1]ip addr 192.168.2.1 24

[r3-GigabitEthernet0/0/1]int g0/0/0
[r3-GigabitEthernet0/0/0]ip addr 192.168.100.1 24


[r3-GigabitEthernet0/0/0]dis ip int brief
Interface                         IP Address/Mask      Physical   Protocol  
Ethernet0/0/0                     10.1.2.3/24          up         up        
Ethernet0/0/1                     10.1.5.3/24          up         up        
GigabitEthernet0/0/0              192.168.100.1/24     up         up        
GigabitEthernet0/0/1              192.168.2.1/24       up         up        
GigabitEthernet0/0/2              unassigned           down       down  

R4:

<Huawei>sys
  Enter system view, return user view with Ctrl+Z.
[Huawei]int e0/0/0
[Huawei-Ethernet0/0/0]ip addr 10.1.5.4 24
[Huawei-Ethernet0/0/0]sysname r4

[r4]int e0/0/1
[r4-Ethernet0/0/1]ip addr 202.194.222.1 24

配置静态路由

[r1]ip route-static 192.168.2.0 24 10.1.1.2


[r2]ip route-static 192.168.1.0 24 10.1.1.1
[r2]ip route-static 192.168.2.0 24 10.1.2.3


[r3]ip route-static 192.168.1.0 24 10.1.3.2
<PC1>ping 192.168.2.10
<PC5>ping 192.168.1.10

0xff:文件下载

  1. 思科
    https://p.dabbit.net/blog/pic_bed/sharex/_pn-2024-06-04-18-35-43_Tragopan_Giant_Bowed.rar

  1. 华为

https://p.dabbit.net/blog/pic_bed/sharex/_pn-2024-06-05-17-31-09_Robin_Slateblue_Fair.7z

最后修改:2024 年 06 月 05 日
如果觉得我的文章对你有用,请随意赞赏