目录
一、实验题目
二、实验思路
2.1 拓扑设计(IP地址规划)
2.2 实施
2.3 维护
2.4 升级
涉及知识点:
配置顺序:
三、实验步骤
3.1 建立eth-trunk
3.2 建立vlan
3.3 划入vlan
3.4 trunk干道
3.5 STP生成树协议
3.6 调整边缘接口
3.7 配置SVI
3.8 VRRP---网关冗余
3.9 启动DHCP
3.10 联通三层
3.11 启动OSPF协议
3.12 撰写ACL表
3.13 配置公网
四、测试
PC端获取IP:
PC端pingLSP环回:
一、实验题目

实验要求:
1,内网IP地址172.16.0.0/16合理分配
2,SW1/2之间互为备份
3,VRRP/STP/VLAN/TRUNK均使用
4,所有PC通过DHCP获取IP地址

二、实验思路
2.1 拓扑设计(IP地址规划)
内网依据172.16.0.0/16划分,使用172.16.0.0/24即可,两个骨干链路172.16.0.0/30 172.16.0.4/30
vlan1:172.16.1.0/25 vlan2:172.16.1.128/25
R1-R2网段:12.1.1.0/24 LSP环回:1.1.1.0/24
2.2 实施
拓扑的搭建
配置
交换---拓扑搭建
底层---所有节点拥有合法IP地址
路由---全网可达
策略(优化,规则,安全)
测试
排错
2.3 维护
2.4 升级
涉及知识点:
交换---eth-trunk STP SVI vlan(创建、划分) trunk DHCP VRRP(网关冗余)
配置顺序:
eth-trunk 创建vlan、划分vlan trunk STP SVI VRRP DHCP
三、实验步骤
3.1 建立eth-trunk
SW1:
[sw1]int Eth-Trunk 0
[sw1-Eth-Trunk0]int g0/0/2
[sw1-GigabitEthernet0/0/2]eth-trunk 0
[sw1-GigabitEthernet0/0/2]int g0/0/3
[sw1-GigabitEthernet0/0/3]eth-trunk 0
[sw1-GigabitEthernet0/0/3]q
SW2:
[sw2]int Eth-Trunk 0
[sw2-Eth-Trunk0]int g0/0/2
[sw2-GigabitEthernet0/0/2]eth-trunk 0
[sw2-GigabitEthernet0/0/2]int g0/0/3
[sw2-GigabitEthernet0/0/3]eth-trunk 0
[sw2-GigabitEthernet0/0/3]q3.2 建立vlan
SW1:
[sw1]vlan 2
[sw1-vlan2]q
SW2:
[sw2]vlan 2
[sw2-vlan2]q
SW3:
[sw3]vlan 2
[sw3-vlan2]q
SW4:
[sw4]vlan 2
[sw4-vlan2]q3.3 划入vlan
SW3:
[sw3]int e0/0/4
[sw3-Ethernet0/0/4]port link-type access 
[sw3-Ethernet0/0/4]port default vlan 2
[sw3-Ethernet0/0/4]q
SW4:
[sw4]int e0/0/4
[sw4-Ethernet0/0/4]port link-type access 
[sw4-Ethernet0/0/4]port default vlan 2
[sw4-Ethernet0/0/4]q
3.4 trunk干道
SW1:
[sw1]port-group  group-member Eth-Trunk 0 g0/0/4 to g0/0/5
[sw1-port-group]port link-type trunk 
[sw1-Eth-Trunk0]port link-type trunk 
[sw1-GigabitEthernet0/0/4]port link-type trunk 
[sw1-GigabitEthernet0/0/5]port link-type trunk 
[sw1-port-group]port trunk allow-pass vlan 2
[sw1-Eth-Trunk0]port trunk allow-pass vlan 2
[sw1-GigabitEthernet0/0/4]port trunk allow-pass vlan 2
[sw1-GigabitEthernet0/0/5]port trunk allow-pass vlan 2
[sw1-port-group]q
SW2:
[sw2]port-group group-member Eth-Trunk 0 g0/0/4 to g0/0/5
[sw2-port-group]port link-type trunk 
[sw2-Eth-Trunk0]port link-type trunk 
[sw2-GigabitEthernet0/0/4]port link-type trunk 
[sw2-GigabitEthernet0/0/5]port link-type trunk 
[sw2-port-group]port trunk allow-pass vlan 2
[sw2-Eth-Trunk0]port trunk allow-pass vlan 2
[sw2-GigabitEthernet0/0/4]port trunk allow-pass vlan 2
[sw2-GigabitEthernet0/0/5]port trunk allow-pass vlan 2
[sw2-port-group]q
SW3:
[sw3]port-group group-member e0/0/1 to e0/0/2
[sw3-port-group]port link-type trunk 
[sw3-Ethernet0/0/1]port link-type trunk 
[sw3-Ethernet0/0/2]port link-type trunk 
[sw3-port-group]port trunk allow-pass vlan 2
[sw3-Ethernet0/0/1]port trunk allow-pass vlan 2
[sw3-Ethernet0/0/2]port trunk allow-pass vlan 2
[sw3-port-group]q
SW4:
[sw4]port-group group-member e0/0/1 to e0/0/2
[sw4-port-group]port link-type trunk 
[sw4-Ethernet0/0/1]port link-type trunk 
[sw4-Ethernet0/0/2]port link-type trunk 
[sw4-port-group]port trunk allow-pass vlan 2
[sw4-Ethernet0/0/1]port trunk allow-pass vlan 2
[sw4-Ethernet0/0/2]port trunk allow-pass vlan 2
[sw4-port-group]q
3.5 STP生成树协议
SW1:
[sw1]stp mode mstp
[sw1]stp edged-port
[sw1]stp enable
[sw1]stp region-configuration 
[sw1-mst-region]region-name a
[sw1-mst-region]instance 1 vlan 1
[sw1-mst-region]instance 2 vlan 2
[sw1-mst-region]active region-configuration 
SW2:
[sw2]stp mode mstp
[sw2]stp edged-port
[sw2]stp enable
[sw2]stp region-configuration 
[sw2-mst-region]region-name a
[sw2-mst-region]instance 1 vlan 1
[sw2-mst-region]instance 2 vlan 2
[sw2-mst-region]active region-configuration 
SW3:
[sw3]stp mode mstp 
[sw3]stp edged-port
[sw3]stp enable
[sw3]stp region-configuration 
[sw3-mst-region]region-name a
[sw3-mst-region]instance 1 vlan 1
[sw3-mst-region]instance 2 vlan 2
[sw3-mst-region]active region-configuration 
SW4:
[sw4]stp mode mstp
[sw4]stp edged-port
[sw4]stp enable
[sw4]stp region-configuration 
[sw4-mst-region]region-name a
[sw4-mst-region]instance 1 vlan 1
[sw4-mst-region]instance 2 vlan 2
[sw4-mst-region]active region-configuration 
3.6 调整边缘接口
SW3:
[sw3]int e0/0/3
[sw3-Ethernet0/0/3]stp edged-port enable 
[sw3-Ethernet0/0/3]int e0/0/4
[sw3-Ethernet0/0/4]stp edged-port enable 
SW4:
[sw4]port-group group-member e0/0/3 to e0/0/4
[sw4-port-group]stp edged-port enable 
[sw4-Ethernet0/0/3]stp edged-port enable 
[sw4-Ethernet0/0/4]stp edged-port enable 
3.7 配置SVI
SW1:
[sw1]int vlan 1
[sw1-Vlanif1]ip add 172.16.1.1 25
[sw1-Vlanif1]int vlan 2
[sw1-Vlanif2]ip add 172.16.1.129 25
SW2:
[sw2]int vlan 1                    
[sw2-Vlanif1]ip add 172.16.1.2 25
[sw2-Vlanif1]int vlan 2
[sw2-Vlanif2]ip add 172.16.1.130 25
3.8 VRRP---网关冗余
SW1:
[sw1]int vlan 1
[sw1-Vlanif1]ip add 172.16.1.1 25
[sw1-Vlanif1]int vlan 2
[sw1-Vlanif2]ip add 172.16.1.129 25
[sw1-Vlanif1]vrrp vrid 1 virtual-ip 172.16.1.126
[sw1-Vlanif1]vrrp vrid 1 priority 105
[sw1-Vlanif1]vrrp vrid 1 track interface g0/0/1 reduced 10
[sw1-Vlanif1]int vlan 2
[sw1-Vlanif2]vrrp vrid 1 virtual-ip 172.16.1.254
SW2:
[sw2-Vlanif1]vrrp vrid 1 virtual-ip 172.16.1.126
[sw2-Vlanif1]int vlan 2
[sw2-Vlanif2]vrrp vrid 1 virtual-ip 172.16.1.254
[sw2-Vlanif2]vrrp vrid 1 priority 105  
[sw2-Vlanif2]vrrp vrid 1 track int g0/0/1 reduce 10
3.9 启动DHCP
SW1:
[sw1]dhcp enable 
[sw1]ip pool v1
[sw1-ip-pool-v1]network 172.16.1.0 mask 25
[sw1-ip-pool-v1]gateway-list 172.16.1.126
[sw1-ip-pool-v1]dns-list 114.114.114.114 8.8.8.8
[sw1-ip-pool-v1]q
[sw1]int vlan 1
[sw1-Vlanif1]dhcp select global 
[sw1-Vlanif1]int vlan 2
[sw1-Vlanif2]dhcp select global 
[sw1-Vlanif2]ip pool v2
[sw1-ip-pool-v2]network 172.16.1.128 mask 25  
[sw1-ip-pool-v2]gateway-list 172.16.1.
[sw1-ip-pool-v2]dns-list 114.114.114.114 8.8.8.8
SW2:
[sw2]dhcp enable 
[sw2]ip pool v1
[sw2-ip-pool-v1]network 172.16.1.0 mask 25
[sw2-ip-pool-v1]gateway-list 172.16.1.126
[sw2-ip-pool-v1]dns-list 114.114.114.114 8.8.8.8
[sw2-ip-pool-v1]q
[sw2]int vlan 1
[sw2-Vlanif1]dhcp select global 
[sw2-Vlanif1]int vlan 2
[sw2-Vlanif2]dhcp select global 
[sw2-Vlanif2]ip pool v2
Info:It's successful to create an IP address pool.
[sw2-ip-pool-v2]network 172.16.1.128 mask 25
[sw2-ip-pool-v2]gateway-list 172.16.1.254
[sw2-ip-pool-v2]dns-list 114.114.114.114 8.8.8.8
3.10 联通三层
R1:
[r1]int g0/0/0
[r1-GigabitEthernet0/0/0]ip add 12.1.1.1 24
[r1-GigabitEthernet0/0/0]int g0/0/1
[r1-GigabitEthernet0/0/1]ip add 172.16.0.1 30
[r1-GigabitEthernet0/0/1]int g0/0/2
[r1-GigabitEthernet0/0/2]ip add 172.16.0.5 30
[r1-GigabitEthernet0/0/2]q
SW1:
[sw1-Vlanif100]
[sw1-Vlanif100]ip add 172.16.0.2 30
[sw1-vlan100]int g0/0/1
[sw1-GigabitEthernet0/0/1]port link-type access 
[sw1-GigabitEthernet0/0/1]port default vlan 100
[sw1-GigabitEthernet0/0/1]q
SW2:
[sw2]int vlan 100
[sw2-Vlanif100]
[sw2-Vlanif100]ip add 172.16.0.6 30
[sw2]int g0/0/1
[sw2-GigabitEthernet0/0/1]port link-type access 
[sw2-GigabitEthernet0/0/1]port default vlan 100
[sw2-GigabitEthernet0/0/1]q
3.11 启动OSPF协议
R1:
[r1]ospf 1 router-id 11.11.11.11
[r1-ospf-1]a 0
[r1-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[r1]ip route-static 0.0.0.0 0 12.1.1.2
SW1:
[sw1]ospf 1 router-id 1.1.1.1
[sw1-ospf-1]a 0
[sw1-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[sw1-ospf-1]silent-interface all
[sw1-ospf-1]undo silent-interface vlanif 100
[sw1-ospf-1]undo silent-interface Eth-Trunk 0 //沉默接口
SW2:
[sw2]ospf 1 router-id 2.2.2.2
[sw2-ospf-1]a 0
[sw2-ospf-1-area-0.0.0.0]network 172.16.0.0 0.0.255.255
[sw2-ospf-1]silent-interface all
[sw2-ospf-1]undo silent-interface vlanif 1
[sw2-ospf-1]undo silent-interface Eth-Trunk 0 //沉默接口
3.12 撰写ACL表
R1:
[r1]acl 2000
[r1-acl-basic-2000]
[r1-acl-basic-2000]rule permit source 172.16.0.0 0.0.255.255
[r1-acl-basic-2000]int g0/0/0
[r1-GigabitEthernet0/0/0]nat outbound 20003.13 配置公网
LSP:
[lsp]int g0/0/0
[lsp-GigabitEthernet0/0/0]ip add 12.1.1.2 24
[lsp-GigabitEthernet0/0/0]int lo0
[lsp-LoopBack0]ip add 1.1.1.1 24四、测试
PC端获取IP:




PC端pingLSP环回:




















