题目:
 
操作:
 
1.进行VLAN划分以及配置DHCP服务
 以R1为例:
 [Huawei]interface GigabitEthernet0/0/1.1
 [Huawei-GigabitEthernet0/0/1.1]ip address 192.168.1.65 27
 [Huawei-GigabitEthernet0/0/1.1]q
 [Huawei]interface GigabitEthernet 0/0/1.2
 [Huawei-GigabitEthernet0/0/1.2]ip address 192.168.1.97 27
 划分VLAN
 [Huawei]vlan 2
 [Huawei-vlan2]vlan 3
 [Huawei-vlan3]q
 [Huawei]interface Ethernet 0/0/2
 [Huawei-Ethernet0/0/2]port link-type access
 [Huawei-Ethernet0/0/2]port default vlan 2
 [Huawei]interface Ethernet 0/0/3
 [Huawei-Ethernet0/0/3]port link-type access
 [Huawei-Ethernet0/0/3]port default vlan 2
 [Huawei]interface Ethernet 0/0/4
 [Huawei-Ethernet0/0/4]port link-type access
 [Huawei-Ethernet0/0/4]port default vlan 3
 [Huawei]dhcp enable
 [Huawei]ip pool a
 [Huawei-ip-pool-a]network 192.168.1.64 mask 27
 [Huawei-ip-pool-a]gateway-list 192.168.1.65
 [Huawei-ip-pool-a]dns-list 114.114.114.114 8.8.8.8
 [Huawei]ip pool b
 [Huawei-ip-pool-a]network 192.168.1.96 mask 27
 [Huawei-ip-pool-a]gateway-list 192.168.1.97
 [Huawei-ip-pool-a]dns-list 114.114.114.114 8.8.8.8
 开启服务:
 [Huawei]interface GigabitEthernet0/0/1.1
 [Huawei-GigabitEthernet0/0/1.1]dhcp select global
 [Huawei]interface GigabitEthernet0/0/1.2
 [Huawei-GigabitEthernet0/0/1.2]dhcp select global
 2.启动ospf协议
 R1上配置:
 [Huawei]ospf 1 router-id 192.168.1.1
 [Huawei-ospf-1]area 0
 [Huawei-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
 R2上配置:
 [R2]ospf 1 router-id 192.168.1.129
 [R2-ospf-1]area 0
 [R2-ospf-1-area-0.0.0.0]network 192.168.1.0 0.0.0.255
 配置trunk干道:
 [LSW1]interface Ethernet 0/0/1
 [LSW1-Ethernet0/0/1]port link-type trunk
 [LSW1-Ethernet0/0/1]port trunk allow-pass vlan all
 [LSW2]interface GigabitEthernet 0/0/1
 [LSW2-GigabitEthernet0/0/1]port link-type trunk
 [LSW2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
 3.在路由器R1,R2上设置telnet登录;
 [r1]aaa
 [r1-aaa]local-user abc privilege level 15 password cipher 123456
 [r1-aaa]local-user abc service-type telnet
 [r1]user-interface vty 0 4
 [r1-ui-vty0-4]authentication-mode aaa
 [r2]aaa
 [r2-aaa]local-user cba privilege level 15 password cipher 123456
 [r2-aaa]local-user cba service-type telnet
 [r2]user-interface vty 0 4
 [r2-ui-vty0-4]authentication-mode aaa
 R1上设置策略:
 [r1-acl-adv-3001]rule deny tcp source 192.168.1.93 0 destination 192.168.1.1 0 destination-port eq 23
 [r1-acl-adv-3001]rule deny tcp source 192.168.1.93 0 destination 192.168.1.65 0 destination-port eq 23
 [r1-acl-adv-3001]rule deny tcp source 192.168.1.93 0 destination 192.168.1.97 0 destination-port eq 23
 调用该命令
 [r1-GigabitEthernet0/0/1]traffic-filter inbound acl 3000
 4.通过公有IP12.1.1.1使得PC1-PC4可以访问PC5 :
 [r2-acl-basic-2000]rule permit source 192.168.0.0 0.0.255.255
 [r2]interface GigabitEthernet 0/0/2
 [r2-GigabitEthernet0/0/2]nat outbound 2000
 [r2]ip route-static 0.0.0.0 0.0.0.0 1.1.1.0
 即PC1-PC4可以访问PC5
测试成功










