ra的相关配置: 配置IP地址; 配置ospf、ripv2路由协议,配置路由重分发,使全网互通; rb的相关配置: 配置IP地址; 配置ospf路由协议、静态路由或路由重分发,使全网互通; 配置NAT,内网中的vlan10、vlan20能够通过地址池(88.1.1.3~88.1.1.5/28)访问互联网;内网中的vlan30、vlan40能够通过地址池(88.1.1.6~88.1.1.8/28)访问互联网;只将FTP、WEB服务发布到互联网上,其公网IP地址为88.1.1.10; Sa的相关配置: 配置IP地址、配置vlan信息; 配置RIPv2路由协议,使全网互通; 不允许vlan10与vlan20互访,其他不受限制; Sb的相关配置: 配置IP地址、配置vlan信息; 配置ospf路由协议,使全网互通; 不允许vlan30、vlan40互访,其他不受限制; 将接口fa0/2-10加入到vlan30中,把接口fa0/13-20加入到vlan40中; 二层交换机的相关配置: 配置vlan信息; 将接口fa0/1-5加入到vlan10中,将接口fa0/6-9加入到vlan20中; 配置端口安全功能,每个接口接入的最大连接数为2,如果违规则关闭接口。
时间: 2023-10-30 17:07:07 浏览: 118
ra的配置:
1. 配置IP地址:
```
interface GigabitEthernet0/0
ip address 192.168.1.1 255.255.255.0
!
```
2. 配置ospf、ripv2路由协议,配置路由重分发,使全网互通:
```
router ospf 1
network 192.168.1.0 0.0.0.255 area 0
redistribute rip subnets
!
router rip
version 2
network 192.168.1.0
redistribute ospf 1 metric 3
!
```
rb的配置:
1. 配置IP地址:
```
interface GigabitEthernet0/0
ip address 192.168.1.2 255.255.255.0
!
```
2. 配置ospf路由协议、静态路由或路由重分发,使全网互通:
```
router ospf 1
network 192.168.1.0 0.0.0.255 area 0
!
```
3. 配置NAT,内网中的vlan10、vlan20能够通过地址池(88.1.1.3~88.1.1.5/28)访问互联网;内网中的vlan30、vlan40能够通过地址池(88.1.1.6~88.1.1.8/28)访问互联网;只将FTP、WEB服务发布到互联网上,其公网IP地址为88.1.1.10:
```
interface GigabitEthernet0/1
ip nat outside
!
interface Vlan10
ip address 192.168.10.1 255.255.255.0
ip nat inside
!
interface Vlan20
ip address 192.168.20.1 255.255.255.0
ip nat inside
!
interface Vlan30
ip address 192.168.30.1 255.255.255.0
ip nat inside
!
interface Vlan40
ip address 192.168.40.1 255.255.255.0
ip nat inside
!
ip nat pool pool1 88.1.1.3 88.1.1.5 netmask 255.255.255.240
ip nat pool pool2 88.1.1.6 88.1.1.8 netmask 255.255.255.240
access-list 101 permit tcp any any eq ftp
access-list 101 permit tcp any any eq www
ip nat inside source list 101 pool pool1
ip nat inside source list 101 pool pool2
ip nat inside source static tcp 192.168.10.10 21 88.1.1.10 21
ip nat inside source static tcp 192.168.20.10 80 88.1.1.10 80
```
Sa的配置:
1. 配置IP地址、配置vlan信息:
```
interface GigabitEthernet0/0
switchport mode trunk
!
interface GigabitEthernet0/1
switchport access vlan 10
!
interface GigabitEthernet0/2
switchport access vlan 20
!
interface Vlan10
ip address 192.168.10.2 255.255.255.0
!
interface Vlan20
ip address 192.168.20.2 255.255.255.0
!
```
2. 配置RIPv2路由协议,使全网互通;不允许vlan10与vlan20互访,其他不受限制:
```
router rip
version 2
network 192.168.10.0
network 192.168.20.0
!
interface Vlan10
ip access-group 101 in
!
interface Vlan20
ip access-group 102 in
!
access-list 101 deny ip any 192.168.20.0 0.0.0.255
access-list 101 permit ip any any
access-list 102 deny ip any 192.168.10.0 0.0.0.255
access-list 102 permit ip any any
```
Sb的配置:
1. 配置IP地址、配置vlan信息:
```
interface GigabitEthernet0/0
switchport mode trunk
!
interface GigabitEthernet0/1
switchport access vlan 30
!
interface GigabitEthernet0/2
switchport access vlan 40
!
interface Vlan30
ip address 192.168.30.2 255.255.255.0
!
interface Vlan40
ip address 192.168.40.2 255.255.255.0
!
```
2. 配置ospf路由协议,使全网互通;不允许vlan30、vlan40互访,其他不受限制:
```
router ospf 1
network 192.168.30.0 0.0.0.255 area 0
network 192.168.40.0 0.0.0.255 area 0
!
interface Vlan30
ip access-group 101 in
!
interface Vlan40
ip access-group 102 in
!
access-list 101 deny ip any 192.168.40.0 0.0.0.255
access-list 101 permit ip any any
access-list 102 deny ip any 192.168.30.0 0.0.0.255
access-list 102 permit ip any any
```
二层交换机的配置:
1. 配置vlan信息:
```
vlan 10
name VLAN10
!
vlan 20
name VLAN20
!
interface FastEthernet0/1
switchport mode access
switchport access vlan 10
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/2
switchport mode access
switchport access vlan 10
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/3
switchport mode access
switchport access vlan 10
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/4
switchport mode access
switchport access vlan 10
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/5
switchport mode access
switchport access vlan 10
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/6
switchport mode access
switchport access vlan 20
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/7
switchport mode access
switchport access vlan 20
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/8
switchport mode access
switchport access vlan 20
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/9
switchport mode access
switchport access vlan 20
switchport port-security maximum 2
switchport port-security violation shutdown
!
interface FastEthernet0/10
switchport mode access
switchport access vlan 20
switchport port-security maximum 2
switchport port-security violation shutdown
!
```
注意:端口安全功能可能会影响连通性,如果需要测试连通性,可以将其注释掉。
阅读全文