1: 根据拓扑图配置,并且配置vl加入物理端口 sw2: sys un in en vl 4 int vl 4 ip add 10.0.4.254 24 int e0/0/1 port link-type trunk port trunk allow-pass vlan all port trunk pvid vlan 4
sw2: sys un in en vl 6 int vl 6 ip add 10.0.6.254 24 int e0/0/1 p link-t t p t a v a p t p v 6
r1: sys un in en int g0/0/1 ip addr 10.0.4.1 24 int g0/0/0 ip addr 192.168.169.2 24
r2: sys un in en int g0/0/1 ip addr 10.0.6.1 24 int g0/0/0 ip addr 192.168.169.3 24
4: a1配置acl,进行nat,允许转换源ip10.0.4.254去访问192.168.169.3的23端口 允许转换源ip为10.0.4.0的网段 a2配置acl,进行nat,允许转换10.0.6.0的网段
a1: sys ?? ??? ? acl 3000 rule permit tcp sou 10.0.4.254 0 des 192.168.169.3 des eq 23 rule permit ip sou 10.0.4.0 0.0.0.255 des any a2: sys acl 2000 rule permit sou 10.0.6.0 0.0.0.255 5: r1配置nat地址池,将相应的acl张贴在对应的物理端口上,将r3配置telnet服务器 s1: sys ip route-s 0.0.0.0 0.0.0.0 10.0.4.1 s2: sys ip route-s 0.0.0.0 0.0.0.0 10.0.6.1 r1: sys nat add 1 192.168.169.20 192.168.169.23 int g0/0/0 nat out 3000 add 1 r2: int g0/0/0 nat out 2000 q telnet server enbale user-interface vty 0 4 auth password 123.com q s1: sys telnet 192.168.169.3
1: 按照拓扑图配置 r1: sys un in en int lo 0 ip addr 10.0.1.1 24 int g0/0/0 ip addr 10.0.123.1 24
r2: sys un in en int lo 0 ip addr 10.0.2.2 24 int g0/0/0 ip addr 10.0.123.2 24
r3: sys un in en int lo 0 ip addr 10.0.3.3 24 int g0/0/0 ip addr 10.0.123.3 24 验证网络连通性 r3: ping 10.0.123.1
配置单区域ospf,区域为0 ,进程为1,并配置区域认证(密码huawei) 声明接口的时候采用0.0.0.0 router-id手动配置 r1: sys ospf 1 rout 1.1.1.1 a 0 auth si huawei network 10.0.1.1 0.0.0.0 network 10.0.123.1 0.0.0.0
r2: sys ospf 1 route 2.2.2.2 auth si huawei network 10.0.2.2 0.0.0.0 network 10.0.123.2 0.0.0.0
r3: sys ospf 1 route 3.3.3.3 auth si huawei network 10.0.3.3.3 0.0.0.0 network 10.0.123.3 0.0.0.0
修改ospf的cost,r1修改为20 r3修改为10 r1: int g0/0/0 ospf cost 20
r2: int g0/0/0 ospf cost 10
配置r1的g0/0/0接口为不发送hello包(silent-interface) r1: ospf 1 silent g0/0/0
单臂路由注意 trunk口要允许vlan 这是与思科不一样的 port trunk allow-pass vlan 10 20 路由器虚拟子接口要开启arp广播? arp broadcast enable
流程 pc机配ip 配网关 交换机 配置与pc连接的口为access口 配置与路由连接的为trunk口允许trunk口通过vlan 20 30(记得save) int ethernet 0/0/1 port link-type access port default vlan 10
int ethernet0/0/2 port link-type access port default vlan 20
int ethernet 0/0/0 port link-type trunk port trunk allow-pass vlan 10 20
路由器去接口去子接口 配置ip sys sys r1 int g0/0/0.1 dot1q termination vid 10 ip addr 192.168.10.1 24 arp broadcast enable
int g0/0/0.2 dot1q termination vid 20 ip addr 192.168.20.1 24 arp broadcast enable
华为防火墙(无二层配置access trunk) 路由配ip 路由表 防火墙配ip 路由表 配置安装策略全允许 sys sys fw1 security-policy default action permit 相应端口(ip)配置允许所有服务 int g1/0/0 ip addr 192.168.30.1 24 service-manage all permit int g1/0/1 ip addr 192.168.20.1 24 service-manage all permit 加入相应安全区(trust) firewall zone trust add interface g1/0/0 add interface g1/0/1
|