编写一个涵盖ospf协议、rip协议、 stp技术, acl技术,vlan划分,ipv6,eigrp协议,dhcp技术,nat技术, aaa技术,该拓扑图请将两个pc机连接二层交换机,另外两个pc机连接二层交换机 ,两个二层交换机与一个三层交换机连接, 该三层交换机与左侧路由器连接,左侧路由器与中间路由器连接,中间的路由器与右侧路由器连接,右侧路由器连接一个三层交换机,三层交换机连接两个二层交换机,两个二层交换机各连接两个pc机,写出每个设备接口的ip地址,必须实现不同协议的交叉互通,及所有设备进行SSH登录,还要体现二、三层的安全保护,请写出配置命令
时间: 2023-07-16 10:14:39 浏览: 105
网络常用配置命令,包括dhcp,ospf,rip,以及常用的命令
拓扑图如下:
```
+-----------+ +-------------+ +-----------+
| PC1 | | PC2 | | PC3 |
| | | | | |
+---+---+---+ +---+---+---+ +---+---+---+
| | | | | |
| | | | | |
| | | | | |
+---+---+---+ +---+---+---+ +---+---+---+
| SW1 | | SW2 | | SW3 |
| | | | | |
+---+---+---+ +---+---+---+ +---+---+---+
| | | | | |
| +------------------------+ +------------------------+ |
| |
| |
| |
+---+---+---+ |
| R1 | |
| | |
+---+---+---+ |
| |
| |
| |
+---+---+---+ |
| R2 | |
| | |
+---+---+---+ |
| |
| |
| |
+---+---+---+ |
| R3 | |
| | |
+---+---+---+ |
| |
| |
| |
+---+---+---+ +---+---+---+ +---+---+---+
| SW4 | | SW5 | | PC4 |
| | | | | |
+---+---+---+ +---+---+---+ +---+---+---+
| | | | | |
| | | | | |
| | | | | |
+---+---+---+ +---+---+---+ +---+---+---+
| PC5 | | PC6 | | PC7 |
| | | | | |
+-----------+ +-------------+ +-----------+
```
为了简化配置,我们假设所有设备的管理VLAN都是VLAN 1,所有设备的SSH用户名密码均为admin/admin。
下面给出每个设备接口的IP地址及配置命令:
## R1
```
interface GigabitEthernet0/0
ip address 192.168.1.1 255.255.255.0
duplex auto
speed auto
!
interface GigabitEthernet0/1
ip address 10.0.1.1 255.255.255.0
duplex auto
speed auto
!
interface GigabitEthernet0/2
ip address 10.0.2.1 255.255.255.0
duplex auto
speed auto
!
router ospf 1
network 10.0.1.0 0.0.0.255 area 0
network 10.0.2.0 0.0.0.255 area 0
network 192.168.1.0 0.0.0.255 area 0
!
router rip
network 192.168.1.0
!
ipv6 unicast-routing
ipv6 router ospf 1
router-id 1.1.1.1
network 2001:db8:1::/64 area 0
network 2001:db8:2::/64 area 0
!
ipv6 dhcp pool IPv6_POOL
address prefix 2001:db8:1:1::/64 lifetime infinite infinite
domain-name example.com
dns-server 2001:db8:1::1
!
ip dhcp pool DHCP_POOL
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1
dns-server 8.8.8.8
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
```
## R2
```
interface GigabitEthernet0/0
ip address 10.0.1.2 255.255.255.0
duplex auto
speed auto
!
interface GigabitEthernet0/1
ip address 10.0.3.1 255.255.255.0
duplex auto
speed auto
!
interface GigabitEthernet0/2
ip address 10.0.4.1 255.255.255.0
duplex auto
speed auto
!
router ospf 1
network 10.0.1.0 0.0.0.255 area 0
network 10.0.3.0 0.0.0.255 area 0
network 10.0.4.0 0.0.0.255 area 0
!
router eigrp 2
network 10.0.1.0 0.0.0.255
network 10.0.3.0 0.0.0.255
network 10.0.4.0 0.0.0.255
!
ipv6 unicast-routing
ipv6 router ospf 1
router-id 2.2.2.2
network 2001:db8:2::/64 area 0
!
ip dhcp excluded-address 10.0.3.1 10.0.3.10
ip dhcp excluded-address 10.0.4.1 10.0.4.10
!
ip dhcp pool DHCP_POOL1
network 10.0.3.0 255.255.255.0
default-router 10.0.3.1
dns-server 8.8.8.8
!
ip dhcp pool DHCP_POOL2
network 10.0.4.0 255.255.255.0
default-router 10.0.4.1
dns-server 8.8.8.8
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
```
## R3
```
interface GigabitEthernet0/0
ip address 192.168.2.1 255.255.255.0
duplex auto
speed auto
!
interface GigabitEthernet0/1
ip address 10.0.2.2 255.255.255.0
duplex auto
speed auto
!
interface GigabitEthernet0/2
ip address 10.0.5.1 255.255.255.0
duplex auto
speed auto
!
router ospf 1
network 10.0.2.0 0.0.0.255 area 0
network 10.0.5.0 0.0.0.255 area 0
network 192.168.2.0 0.0.0.255 area 0
!
router rip
network 192.168.2.0
!
ipv6 unicast-routing
ipv6 router ospf 1
router-id 3.3.3.3
network 2001:db8:3::/64 area 0
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
```
## SW1
```
vlan 10
name MANAGEMENT
vlan 20
name USERS
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
ip address 192.168.1.2 255.255.255.0
!
interface Vlan20
ip address 10.0.1.3 255.255.255.0
!
interface FastEthernet0/1
switchport mode access
switchport access vlan 10
!
interface FastEthernet0/2
switchport mode access
switchport access vlan 20
!
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
spanning-tree mode rapid-pvst
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
!
```
## SW2
```
vlan 10
name MANAGEMENT
vlan 30
name SERVERS
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
ip address 10.0.1.4 255.255.255.0
!
interface Vlan30
ip address 10.0.3.2 255.255.255.0
!
interface FastEthernet0/1
switchport mode access
switchport access vlan 10
!
interface FastEthernet0/2
switchport mode access
switchport access vlan 30
!
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
spanning-tree mode rapid-pvst
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
!
```
## SW3
```
vlan 10
name MANAGEMENT
vlan 40
name GUESTS
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
ip address 192.168.2.2 255.255.255.0
!
interface Vlan40
ip address 10.0.4.2 255.255.255.0
!
interface FastEthernet0/1
switchport mode access
switchport access vlan 10
!
interface FastEthernet0/2
switchport mode access
switchport access vlan 40
!
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
spanning-tree mode rapid-pvst
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
!
```
## SW4
```
vlan 50
name MANAGEMENT
vlan 60
name USERS
!
interface Vlan1
no ip address
shutdown
!
interface Vlan50
ip address 10.0.5.2 255.255.255.0
!
interface Vlan60
ip address 10.0.6.1 255.255.255.0
!
interface FastEthernet0/1
switchport mode access
switchport access vlan 50
!
interface FastEthernet0/2
switchport mode access
switchport access vlan 60
!
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
spanning-tree mode rapid-pvst
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
!
```
## SW5
```
vlan 70
name SERVERS
vlan 80
name GUESTS
!
interface Vlan1
no ip address
shutdown
!
interface Vlan70
ip address 10.0.7.1 255.255.255.0
!
interface Vlan80
ip address 10.0.8.1 255.255.255.0
!
interface FastEthernet0/1
switchport mode access
switchport access vlan 70
!
interface FastEthernet0/2
switchport mode access
switchport access vlan 80
!
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
spanning-tree mode rapid-pvst
!
access-list 100 permit tcp any any eq 22
!
line vty 0 15
transport input ssh
login local
access-class 100 in
!
```
## PC1、PC2、PC5、PC6
在这四台PC上配置IP地址即可,例如:
PC1:
```
IP Address: 192.168.1.3
Subnet Mask: 255.255.255.0
Default Gateway: 192.168.1.1
```
## PC3、PC4、PC7
这三台PC需要在DHCP服务器上获取IP地址,例如:
PC3:
```
IP Address: 10.0.4.11
Subnet Mask: 255.255.255.0
Default Gateway: 10.0.4.1
```
PC4:
```
IP Address: 10.0.7.11
Subnet Mask: 255.255.255.0
Default Gateway: 10.0.7.1
```
PC7:
```
IP Address: 10.0.8.11
Subnet Mask: 255.255.255.0
Default Gateway: 10.0.8.1
```
注意,DHCP服务器的配置在R2的配置中已经给出。
阅读全文