• NAT+ACL+mstp小综合


    三、实验一相关知识点

    1,实验:NAT 综合实验

    2,拓扑

    3,需求:

    1),实现VLAN20 的除了20这台主机以外所有主机上网访问外网
    2),实现VLAN30 的主机为奇数电脑上网
    3),实现内网VLAN10 的内网服务器 可以被外网client1 访问,公有地址为200.1.1.10
    4),访问外网要求使用最节省IP地址的方案

    4,  配置思路

    1),配置终端信息

    2),配置二层交换

    -创建VLAN

    -配置access

    3),配置路由器

    -配置基本IP地址

    -配置路由-静态路由

    4),配置NAT 设备

    -实现内网访问外网

    -easyIP

    -实现外网访问内网

    -nat server  200.1.1.10

    5),验证测试

    5,配置步骤

    1. [sw1]vlan batch 10 20 30 100
    2. [sw1]dis vlan
    3. [sw1]interface g0/0/1
    4. [sw1-GigabitEthernet0/0/1]port link-type access
    5. [sw1-GigabitEthernet0/0/1]port default vlan 10
    6. [sw1-GigabitEthernet0/0/1]q
    7. [sw1]int g0/0/4
    8. [sw1-GigabitEthernet0/0/4]port link-type access
    9. [sw1-GigabitEthernet0/0/4]port default vlan 20
    10. [sw1-GigabitEthernet0/0/4]q
    11. [sw1]int g0/0/2
    12. [sw1-GigabitEthernet0/0/2]port link-type access
    13. [sw1-GigabitEthernet0/0/2]port default vlan 30
    14. [sw1-GigabitEthernet0/0/2]q
    15. [sw1]int g0/0/3
    16. [sw1-GigabitEthernet0/0/3]port link-type access
    17. [sw1-GigabitEthernet0/0/3]port default vlan 100
    18. [sw1-GigabitEthernet0/0/3]q
    19. [sw1]interface Vlanif 10
    20. [sw1-Vlanif10]ip add 192.168.10.254 24
    21. [sw1-Vlanif10]q
    22. [sw1]interface Vlanif 20
    23. [sw1-Vlanif20]ip add 192.168.20.254 24
    24. [sw1-Vlanif20]q
    25. [sw1]int Vlanif 30
    26. [sw1-Vlanif30]ip add 192.168.30.254 24
    27. [sw1-Vlanif30]q
    28. [sw1]int Vlanif 100
    29. [sw1-Vlanif100]ip add 192.168.100.2 24
    30. [sw1-Vlanif100]q
    31. [sw1]dis ip int brief
    32. [sw1]ip route-static 0.0.0.0 0 192.168.100.1
    33. [NAT]ip route-static 0.0.0.0 0 200.1.1.2
    34. [NAT]ip route-static 192.168.10.0 24 192.168.100.2
    35. [NAT]ip route-static 192.168.20.0 24 192.168.100.2
    36. [NAT]ip route-static 192.168.30.0 24 192.168.100.2

    通配符 :   0表示严格检查、匹配  

    1表示任意匹配,忽略检查

    192.168.30.0 段  匹配奇数    —最后一位为1 ,指的是主机位我只检查最后 一位即可,最有一位用0匹配。前面几位用1匹配

    192.168.30.1    192.168.30. 0000000  1

    192.168.30.3    192.168.30. 0000001  1

    192.168.30.5     192.168.30.0000010  1

    192.168.30.7     192.168. 30.0000011  1

    192.168.30.9     192.168.30 .0000100   1       0.0.0.11111110      0.0.0.254

    192.168.30.1                                                                                0.0.0.254

    1. [NAT]acl 2000
    2. [NAT-acl-basic-2000]rule deny source 192.168.20.20 0.0.0.0
    3. [NAT-acl-basic-2000]rule permit source 192.168.20.0 0.0.0.255
    4. [NAT-acl-basic-2000]rule permit source 192.168.30.1 0.0.0.254
    5. [NAT-acl-basic-2000]rule permit source any //不可以配置,否则偶数也放行啦
    6. [NAT]int g0/0/1
    7. [NAT-GigabitEthernet0/0/1]nat outbound 2000
    8. [NAT]acl 2000
    9. [NAT-acl-basic-2000]rule deny source any
    10. [NAT-acl-basic-2000]dis th
    11. rule 5 deny source 192.168.20.20 0
    12. rule 10 permit source 192.168.20.0 0.0.0.255
    13. rule 15 permit source 192.168.30.1 0.0.0.254
    14. rule 20 permit
    15. rule 25 deny
    16. [NAT-acl-basic-2000]undo rule 20
    17. [NAT-acl-basic-2000]dis th
    18. rule 5 deny source 192.168.20.20 0
    19. rule 10 permit source 192.168.20.0 0.0.0.255
    20. rule 15 permit source 192.168.30.1 0.0.0.254
    21. rule 25 deny

    验证:  在客户端 更改 奇数偶数地址 ,进行验证。

    实验:一阶段最终测试:VLAN +三层交换+链路聚合+MSTP+ACL+NAT+静态路由+DHCP+Telnet

    1,需求:

    1,实现VLAN20 的除了20这台主机以外所有主机上网访问外网
    2,实现VLAN30 的主机为奇数电脑上网
    3,实现内网VLAN10 的内网服务器 可以被外网client1 访问,公有地址为200.1.1.10
    4,访问外网要求使用最节省IP地址的方案
    5,在SW1和SW2 完成增强带宽的操作 ,同时在SW3和SW1上 也完成增强链路带宽的操作,尽量节省成本
    6,实现内网的终端在进行数据通信的时候,要求走最优的路径
    7,内网各个网段的主机通过DHCP服务器自动获取IP地址信息,将保留的地址进行排除
    8, 在ISP 上实现远程登录内网SW1 的Telnet服务

    2,拓扑

    3,配置思路

    1,配置终端信息   10

    2,配置二层交换   10

    -创建VLAN

    -配置access

    -配置trunk

    -配置链路聚合 10

    -配置MSTP     10

    3,配置路由器     10

    -配置基本IP地址

    -配置路由-静态路由

    4,配置NAT 设备

    -实现内网访问外网 10

    -easyIP

    -实现外网访问内网

    -nat server  200.1.1.10

    WEB       10

    TELNET    10                   

    5,配置DHCP服务器   20

    6,验证测试

    4,配置步骤:

    1)创建VLAN

    1. [SW1]vlan batch 10 20 30 100
    2. [SW2]vlan batch 10 20 30 100
    3. [sw3]vlan batch 10 20 30 100
    4. 2)配置access
    5. [SW1]int g0/0/3
    6. [SW1-GigabitEthernet0/0/3]port link-type access
    7. [SW1-GigabitEthernet0/0/3]port default vlan 100
    8. [SW2]int g0/0/2
    9. [SW2-GigabitEthernet0/0/2]port link-type access
    10. [SW2-GigabitEthernet0/0/2]port default vlan 10
    11. [sw3]int g0/0/1
    12. [sw3-GigabitEthernet0/0/1]port link-type access
    13. [sw3-GigabitEthernet0/0/1]port default vlan 20
    14. [sw3-GigabitEthernet0/0/1]q
    15. [sw3]int g0/0/4
    16. [sw3-GigabitEthernet0/0/4]port link-type access
    17. [sw3-GigabitEthernet0/0/4]port default vlan 30
    18. 3)配置链路聚合+trunk
    19. [SW1]interface Eth-Trunk 1
    20. [SW1-Eth-Trunk1]mode lacp-static
    21. [SW1-Eth-Trunk1]trunkport g0/0/1
    22. [SW1-Eth-Trunk1]trunkport g0/0/5
    23. [SW1-Eth-Trunk1]port link-type trunk
    24. [SW1-Eth-Trunk1]port trunk allow-pass vlan all
    25. [SW1-Eth-Trunk1]q
    26. [SW1]interface Eth-Trunk 2
    27. [SW1-Eth-Trunk2]mode lacp-static
    28. [SW1-Eth-Trunk2]trunkport g0/0/2
    29. [SW1-Eth-Trunk2]trunkport g0/0/6
    30. [SW1-Eth-Trunk2]p l t
    31. [SW1-Eth-Trunk2]p t a v a
    32. [SW2]int Eth-Trunk 1
    33. [SW2-Eth-Trunk1]mode lacp-static
    34. [SW2-Eth-Trunk1]trunkport g0/0/1
    35. [SW2-Eth-Trunk1]trunkport g0/0/5
    36. [SW2-Eth-Trunk1]port l t
    37. [SW2-Eth-Trunk1]p t a v a
    38. [SW2-Eth-Trunk1]q
    39. [SW2]int g0/0/3
    40. [SW2-GigabitEthernet0/0/3]p l t
    41. [SW2-GigabitEthernet0/0/3]p t a v a
    42. [sw3]int Eth-Trunk 2
    43. [sw3-Eth-Trunk2]mode lacp-static
    44. [sw3-Eth-Trunk2]trunkport g0/0/2
    45. [sw3-Eth-Trunk2]trunkport g0/0/6
    46. [sw3-Eth-Trunk2]p l t
    47. [sw3-Eth-Trunk2]p t a v a
    48. [sw3-Eth-Trunk2]q
    49. [sw3]int g0/0/3
    50. [sw3-GigabitEthernet0/0/3]p l t
    51. [sw3-GigabitEthernet0/0/3]p t a v a
    52. 4)配置MSTP SW1/SW2/SW3
    53. stp region-configuration
    54. region-name HCIP
    55. instance 1 vlan 10
    56. instance 2 vlan 20 30
    57. active region-configuration
    58. [SW2]stp instance 1 priority 4096
    59. [sw3]stp instance 2 priority 4096
    60. 5)配置路由器IP地址 、静态路由
    61. [SW1]interface Vlanif 10
    62. [SW1-Vlanif10]ip add 192.168.10.254 24
    63. [SW1-Vlanif10]q
    64. [SW1]interface Vlanif 20
    65. [SW1-Vlanif20]ip add 192.168.20.254 24
    66. [SW1-Vlanif20]q
    67. [SW1]int Vlanif 30
    68. [SW1-Vlanif30]ip add 192.168.30.254 24
    69. [SW1-Vlanif30]q
    70. [SW1]int Vlanif 100
    71. [SW1-Vlanif100]ip add 192.168.100.2 24
    72. [SW1-Vlanif100]q
    73. [SW1]ip route-static 0.0.0.0 0 192.168.100.1
    74. [NAT]int g0/0/0
    75. [NAT-GigabitEthernet0/0/0]ip add 192.168.100.1 24
    76. [NAT-GigabitEthernet0/0/0]q
    77. [NAT]int g0/0/1
    78. [NAT-GigabitEthernet0/0/1]ip add 200.1.1.1 24
    79. [NAT-GigabitEthernet0/0/1]q
    80. [NAT]ip route-static 0.0.0.0 0 200.1.1.2
    81. [NAT]ip route-static 192.168.10.0 24 192.168.100.2
    82. [NAT]ip route-static 192.168.20.0 24 192.168.100.2
    83. [NAT]ip route-static 192.168.30.0 24 192.168.100.2
    84. 6)配置easyIP
    85. [NAT]acl 2000
    86. [NAT-acl-basic-2000]rule deny source 192.168.20.20 0
    87. [NAT-acl-basic-2000]rule permit source 192.168.20.0 0.0.0.255
    88. [NAT-acl-basic-2000]rule permit source 192.168.30.1 0.0.0.254
    89. [NAT-acl-basic-2000]q
    90. [NAT]int g0/0/1
    91. [NAT-GigabitEthernet0/0/1]nat outbound 2000
    92. 7)配置NAT SERVER
    93. [SW1]telnet server enable
    94. [SW1]user-interface vty 0 4
    95. [SW1-ui-vty0-4]authentication-mode aaa
    96. [SW1-ui-vty0-4]protocol inbound all
    97. [SW1-ui-vty0-4]q
    98. [SW1]aaa
    99. [SW1-aaa]local-user wy password cipher suibian
    100. [SW1-aaa]local-user wy service-type telnet
    101. [SW1-aaa]local-user wy privilege level 15
    102. [NAT]int g0/0/1
    103. [NAT-GigabitEthernet0/0/1]nat outbound 2000
    104. [NAT-GigabitEthernet0/0/1]nat server protocol tcp global 200.1.1.10 80 inside 192.168.10.1 80
    105. [NAT-GigabitEthernet0/0/1]nat server protocol tcp global 200.1.1.10 23 inside 192.168.100.2 23
    106. 8)配置DHCP服务器
    107. [SW1]dhcp enable
    108. [SW1]ip pool vlan10
    109. [SW1-ip-pool-vlan10]network 192.168.10.0 mask 24
    110. [SW1-ip-pool-vlan10]gateway-list 192.168.10.254
    111. [SW1-ip-pool-vlan10]dns-list 1.1.1.1
    112. [SW1-ip-pool-vlan10]lease day 10
    113. [SW1-ip-pool-vlan10]q
    114. [SW1]interface Vlanif 10
    115. [SW1-Vlanif10]dhcp select global
    116. [SW1-Vlanif10]q
    117. [SW1]ip pool vlan20
    118. [SW1-ip-pool-vlan20]network 192.168.20.0 mask 24
    119. [SW1-ip-pool-vlan20]gateway-list 192.168.20.254
    120. [SW1-ip-pool-vlan20]dns-list 2.2.2.2
    121. [SW1-ip-pool-vlan20]excluded-ip-address 192.168.20.20
    122. [SW1-ip-pool-vlan20]lease day 0 hour 6
    123. [SW1-ip-pool-vlan20]q
    124. [SW1]interface Vlanif 20
    125. [SW1-Vlanif20]dhcp select global
    126. [SW1-Vlanif20]q
    127. [SW1]ip pool vlan30
    128. [SW1-ip-pool-vlan30]network 192.168.30.0 mask 24
    129. [SW1-ip-pool-vlan30]gateway-list 192.168.30.254
    130. [SW1-ip-pool-vlan30]dns-list 6.6.6.6
    131. [SW1-ip-pool-vlan30]q
    132. [SW1]int Vlanif 30
    133. [SW1-Vlanif30]dhcp select global

      更多资源------>黑凤梨 (zhangwujistudy) - Gitee.com

  • 相关阅读:
    Clickhouse 实现 MaterializedPostgreSQL
    解决使用gets(getchar)函数无法输入字符(字符串)和scanf_s函数显示缺少“scanf_s”整型参数的问题
    工业路由器和家用路由器的区别?
    Anaconda虚拟环境下打开jupyter notebook
    【消息队列】MQ02——Kafka
    Vue3 数据响应式原理:Proxy和Reflect
    一张图进阶 RocketMQ - 消息发送
    让Maven在你这里得心应手
    Vue 2与Vue 3生命周期钩子的对比分析
    uni-app 5小时快速入门 15 uni-app语法(下)
  • 原文地址:https://blog.csdn.net/qq_65225435/article/details/133515073