网络实习参考解答_第1页
网络实习参考解答_第2页
已阅读5页,还剩5页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、、网络功能描述图1某公司网络拓扑结构图某企业的网络拓朴如图1所示,总公司网络中使用了两台三层交换机Switch-A和Switch-B提供内部网络的互联,使用一台二层交换机Switch-A作为服务器的接入,网络边缘采用一台路由器Router-A用于连接到分公司,总公司网络运行的是动态路由协议OSPF总公司路由器与分公司路由器Router-B点对点连接,并且封装的是PPP协议,为了安全考虑两台路由器需要使用CHAP验证机制。所有设备之间连接拓扑如图1,各设备连接接口及接口地址规划如表1所示。题目中未说明的密码均设置为123。二、配置要求1组网及网络设备配置基本要求:(1)正确制作10根网线并按拓朴

2、图要求将设备正确连接。(2)根据拓扑图命名交换机和路由器名称。(3)按要求连接设备并正确配置路由器和交换机的接口IP。技术要求:1)三层路由:1. 合理的部署网络设备、PC和服务器的IP地址(见附表)2. 主公司内网用OSPF实现网络的互通,网络的出口使用默认路由实现内网所有节点都可以访问internet.3. 主公司通过三层交换机实现不同vlan间的通信。说明:OSPF使用processID:1。 OSPF勺network语句使用基于接口网段的通告 所有服务器属于vian30。PC1属于vian10,PC3属于vian20。 两台三层交换机均部署相同的SVI。2)二层部署:4. 内网所有交换

3、区块均开启的生成树协议(RSTP,设置Switch-A为生成树的根桥。5. 二层交换机和三层交换机之间的互联链路启用端口聚合,实现链路带宽的提升。连接RB的serial口链路使用ppp封装,并启用chap。说明:通过设置Switch-A的优先级为4096的方式实现根桥选举。 所有trunk口都启用基于的中继圭寸装协议。 链路聚合启用基于lacp模式下的active模式,在聚合的接口下开启trunk。 chap是同双向认证方式。对于RA:.usernameRouter-Bpassword123;RB.:usernameRouter-Apassword123;安全管理:7. 在两台二层交换机上部署

4、端口安全实现:最大连接数量为:1;违例的惩罚措施:把接口置为errordisable状态对于两台服务器使用mac地址绑定确保服务器的安全8. 通过ACL100限制公司内部vian10和vian20所有PC所在网段到所有服务器的访问。(在SW-B1部署在vian30出站调用)9. 使用PAT实现内网到外网的地址访问(基于端口映射,中间调用ACL10),使用静态的NAT把对应的服务器的web服务发布到internet。10. 为所有网络设备部署teinet服务方面管理员管理网络设备11. 想办法实现分公司可以访问总公司linux-ser上的web服务。说明:enable的密码设置为:ruijie。

5、 telnet使用线下密码认证的方式实现,密码为123。 Switch-C和Swich-B不要部署telnet(也可以所谓拓展尝试,提示必须三层可达才可telnet)附表:设备接口及地址命名一览表设备型号接口IP地址备注Router-AS2/0时钟频率:64000F0/0F1/0Router-BS2/0F0/0Switch-AF0/1F0/2Trunk口F0/23Trunk口聚合链路F0/24Vlan10Vlan20Vlan30Switch-BF0/1F0/2Trunk口F0/23Trunk口聚合链路F0/24Vlan10Vlan20Vlan30Switch-CF0/1连接WIN-SerF0/

6、11连接Linux-SerF0/23Trunk口聚合连路F0/24Switch-DF0/1连接pc3F0/11连接pc3F0/23Trunk口聚合链路F0/24WIN-SerLinux-SerWeb服务在此服务器上PC1PC2PC3设备配置文件导出hostnameRouter-A!enablepasswordruijie!usernameRouter-Bpassword0123!interfaceFastEthernetO/OipnatinsideduplexautospeedautointerfaceFastEthernet1/0ipnatinsideduplexautospeedauto!

7、interfaceSerial2/0encapsulationppppppauthenticationchapipnatoutsideclockrate64000!routerospf1log-adjacency-changesdefault-informationoriginate!ipnatinsidesourcelist10interfaceSerial2/0overloadipclassless!nocdprunlinecon0!lineaux0!linevty04password123login!end!hostnameRouter-B!enablepasswordruijie!us

8、ernameRouter-Apassword0123!interfaceFastEthernet0/0ipnatinsideduplexautospeedauto!interfaceFastEthernet1/0noipaddressduplexautospeedautoshutdowninterfaceSerial2/0encapsulationppppppauthenticationchapipnatoutside!ipnatinsidesourcelist10interfaceSerial2/0overloadipclassless!nocdprun!linecon0!lineaux0!

9、linevty04password123login!endhostnameSwitch-A!enablepasswordruijie!iprouting!spanning-treemoderapid-pvstspanning-treevlan1,10,20,30priority4096!interfaceFastEthernet0/1noswitchportduplexautospeedauto!interfaceFastEthernet0/2switchporttrunkencapsulationdot1qswitchportmodetrunk!interfaceFastEthernet0/

10、23channel-group1modeactiveswitchporttrunkencapsulationdot1qswitchportmodetrunkinterfaceFastEthernetO/24channel-group1modeactiveswitchporttrunkencapsulationdot1qswitchportmodetrunk!interfacePort-channel1switchporttrunkencapsulationdot1qswitchportmodetrunk!interfaceVlan10!interfaceVlan20!interfaceVlan

11、30!routerospf1log-adjacency-changes!ipclassless!linecon0!lineaux0!linevty04password123login!endhostnameSwitch-B!enablepasswordruijie!iprouting!spanning-treemoderapid-pvst!interfaceFastEthernet0/1noswitchportduplexautospeedautointerfaceFastEthernet0/2switchporttrunkencapsulationdotlqswitchportmodetru

12、nk!interfaceFastEthernetO/23channel-group1modeactiveswitchporttrunkencapsulationdot1qswitchportmodetrunk!interfaceFastEthernetO/24channel-group1modeactiveswitchporttrunkencapsulationdot1qswitchportmodetrunk!interfacePort-channel1switchporttrunkencapsulationdot1qswitchportmodetrunk!interfaceVlan1noip

13、addressshutdown!interfaceVlan10!interfaceVlan20!interfaceVlan30ipaccess-group100out!routerospf1log-adjacency-changes!ipclassless!access-list100permitipanyany!linecon0!lineaux0!linevty04password123loginendhostnameSwitch-Cenablepasswordruijie!spanning-treemoderapid-pvst!interfaceFastEthernetO/1switchp

14、ortaccessvlan30switchportmodeaccessswitchportport-security!interfaceFastEthernetO/11switchportaccessvlan30switchportmodeaccessswitchportport-security!interfaceFastEthernetO/23channel-group1modeactiveswitchportmodetrunk!interfaceFastEthernetO/24channel-group1modeactiveswitchportmodetrunk!interfacePor

15、t-channel1switchportmodetrunk!linecon0!linevty04nologinlinevty515login!endhostnameSwitch-D!enablepasswordruijie!spanning-treemoderapid-pvst!interfaceFastEthernet0/1switchportaccessvlan10switchportmodeaccessswitchportport-securityinterfaceFastEthernet0/11switchportaccessvlan20switchportmodeaccessswit

16、chportport-security!interfaceFastEthernet0/23channel-group1modeactiveswitchportmodetrunk!interfaceFastEthernet0/24channel-group1modeactiveswitchportmodetrunk!interfacePort-channel1switchportmodetrunk!linecon0!linevty04nologinlinevty515login!end实验注意点一、思科和锐捷命令去有区别之处(CiscoPacketTracer和真机命令不同之处)A.关于端口聚合

17、(二层)A. Cisco:(cisco叫Ether-channel,会继承物理接口属性因此聚合接口不用启用trunk)interfacerangeFastEthernet0/23-24channel-group1modeactiveswitchporttrunkencapsulationdot1q(三层交换机需要这条命令)switchportmodetrunkinterfacePort-channel1switchporttrunkencapsulationdot1q(可选命令,PT计分软件此命令计分)switchportmodetrunkB. 锐捷:(cisco叫端口聚合,不会继承物理接口属

18、性因次聚合接口一定要启用trunk)interfacerangeFastEthernet0/23-FastEthernet0/24port-group3interfacePort-channel1switchporttrunkencapsulationdot1q(三层交换机需要这条命令)switchportmodetrunk注释:当然锐捷这种方案并不是传统意义上的LACP。B.关于生成树a)Cisco:(又叫PVSTP或者PVRSTP:个vlan对应一个生成树域)spanning-treemoderapid-pvstspanning-treevlan1,10,20,30priority4096b)锐捷:(又叫CST:基于所有vlan

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

最新文档

评论

0/150

提交评论