近期《網(wǎng)絡(luò)組建,、維護(hù)與設(shè)計(jì)》課程學(xué)習(xí)總結(jié) 一,、路由器密碼恢復(fù) ctrl+break >o >o/r 0x2142 >i would you like.........? no enable copy start runn conf t enable secret **** end copy runn start conf t config-register 0x2102 end 二、Cisco ios 文件的導(dǎo)入,、導(dǎo)出 思科IOS的導(dǎo)出 1. Router# dir 2. Router#copy flash: tftp: 3. Source filename [ ]? C2500-i-l.|2|-21.bin 4. Addres or name of remote host [ ]? 備份計(jì)算機(jī)的地址 (tftp 的地址) 5. Destination filename [C2500-i-1.|2|-21.bin]? 備份文件名.bin 回車 (!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 出現(xiàn)很多感嘆號(hào)就說明成功了) 思科ios的導(dǎo)入 1. >o /r 0x2101 2. >i 3. router(boot)>en 4. router(boot)#copy tftp flash 5. [0 bytes used, 4194304 available, 4194304 total] 6. Source file name?fengjiankun.bin(IOS映像文件名) 7. Destination file name [fengjiankun.bin]? 8. Accessing file ' fengjiankun.bin' on 192.168.25.32... 9. Device needs erasure before copying new file 10. Copy ' fengjiankun.bin' from server 11. Erasing device... eeeeeeeeeeeeeeee ...erased 12. 還原路由器虛擬寄存器的默認(rèn)值(0x2102),恢復(fù)路由器的正常啟動(dòng)順序,,依次鍵入以下命令: router(boot)#conf t router(boot)(config)#config-register 0x2102 router(boot)(config)#exit router(boot)#reload 三,、telnet En Conf t Enable secret 密碼 Line vty 0 4 Password 密碼 Login End
四、nat 轉(zhuǎn)換
Router>en Router#conf t Router(config)#int f 0/1 Router(config-if)#ip add 192.168.0.254 255.255.255.0 Router(config-if)#ip nat in Router(config-if)#no shut Router(config-if)#exit Router(config)#int f 0/0 Router(config-if)#ip add 192.168.1.1 255.255.255.0 Router(config-if)#ip nat out Router(config-if)#no shut Router(config-if)#exit Router(config)#ip nat pool net 192.168.1.1 192.168.1.1 netmask 255.255.255.0 Router(config)#ip nat inside source list 1 pool net overload Router(config)#access-list 1 permit 192.168.0.0 Router(config)#ip route Router#copy run start Destination filename [startup-config]? Building configuration... [OK]
五,、Cisco 交換路由的實(shí)驗(yàn)
Switch>en Switch#conf t s32(config)#hostname S32 -----更改交換機(jī)名稱 -----設(shè)置vlan端口 S32(config)#vlan 10 S32(config-vlan)#name vlan10 S32(config-vlan)#vlan 20 S32(config-vlan)#name vlan20 S32(config-vlan)#end ((s32>en s32#vlan ? database Configure VLAN database s32#vlan d s32(vlan)#vlan 10 name vlan10 VLAN 10 modified: Name: vlan10 s32(vlan)#vlan 20 name vlan20 VLAN 20 modified: Name: vlan20 s32(vlan)#vlan 30 name vlan30 VLAN 30 modified: Name: vlan30 s32(vlan)#exit APPLY completed. Exiting....)) ----聚合端口 S32#conf t S32(config)#int range f0/1 - 5 S32(config-if-range)#switchport mode access S32(config-if-range)#switchport access vlan 10 S32(config-if-range)#^Z %SYS-5-CONFIG_I: Configured from console by console S32#conf t Enter configuration commands, one per line. End with CNTL/Z. S32(config)#int range f0/6 - 10 S32(config-if-range)#switchport mode access S32(config-if-range)#switchport access vlan 20 S32(config)#int range f0/22 - 23 S32(config-if-range)#switchport mode access S32(config-if-range)#switchport access vlan 30 S32(config-if-range)#^Z -----設(shè)置一條主干線連接路由器 s32(config)#in f 0/24 s32(config-if)#sw m t s32(config-if)#no shut s32(config-if)#end ----設(shè)置ip地址 Router>en Router#conf t Router(config)# Router(config)#int f0/0 Router(config-if)#ip add 192.168.200.254 255.255.255.0 Router(config-if)#ip nat outside Router(config-if)#no shut Router#conf t Router(config)# Router(config)#int f0/1 Router(config-if)#ip add 192.168.0.254 255.255.255.0 Router(config-if)#ip nat inside Router(config-if)#no shut Router(config)#ip nat p net 192.168.200.254 192.168.200.254 ne Router(config)#ip nat p net 192.168.200.254 192.168.200.254 netmask 255.255.255.0 Router(config)#ip nat in s l 1 p net o Router(config)#acc Router(config)#access-list 1 p 192.168.0.0 Router(config)#ip route Router(config)#end %SYS-5-CONFIG_I: Configured from console by console ---給路由設(shè)置子端口 Router(config)#in f 0/1.1 Router(config-subif)#en d 10 Router(config-subif)#ip add 192.168.11.254 255.255.255.0 Router(config-subif)#no shut Router(config-subif)#exit Router(config)#in f 0/1.2 Router(config-subif)#en d 20 Router(config-subif)#ip add 192.168.12.254 255.255.255.0 Router(config-subif)#no shut Router(config-subif)#exit Router(config)#in f 0/1.3Router(config-subif)#en d 30 Router(config-subif)#ip add 192.168.13.254 255.255.255.0 Router(config-subif)#no shut Router(config-subif)#exit ---保存 Router#copy runn start Destination filename [startup-config]? Building configuration... [OK] 六,、跨交換機(jī)VLAN_net_vlan_
1、設(shè)置vtp domain,。 vtp domain 稱為管理域,。 交換vtp更新信息的所有交換機(jī)必須配置為相同的管理域。如果所有的交換機(jī)都以中繼線相連,,那么只要在核心交換機(jī)上設(shè)置一個(gè)管理域,,網(wǎng)絡(luò)上所有的交換機(jī)都加入該域,這樣管理域里所有的交換機(jī)就能夠了解彼此的vlan列表,。 mainswitch #vlan database 進(jìn)入vlan配置模式 mainswitch(vlan)#vtp domain mainswitch 設(shè)置vtp管理域名稱 mainswitch mainswitch(vlan)#vtp server 設(shè)置交換機(jī)為服務(wù)器模式 lanswitch01#vlan database 進(jìn)入vlan配置模式 lanswitch01(vlan)#vtp domain mainswitch 設(shè)置vtp管理域名稱mainswitch lanswitch01(vlan)#vtp client 設(shè)置交換機(jī)為客戶端模式 lanswitch02#vlan database 進(jìn)入vlan配置模式 lanswitch02(vlan)#vtp domain mainswitch 設(shè)置vtp管理域名稱mainswitch lanswitch02(vlan)#vtp client 設(shè)置交換機(jī)為客戶端模式 lanswitch03#vlan database 進(jìn)入vlan配置模式 lanswitch03(vlan)#vtp domain mainswitch 設(shè)置vtp管理域名稱mainswitch lanswitch03(vlan)#vtp client 設(shè)置交換機(jī)為客戶端模式 注意:這里設(shè)置核心交換機(jī)為server模式是指允許在該交換機(jī)上創(chuàng)建,、修改、刪除vlan及其他一些對整個(gè)vtp域的配置參數(shù),,同步本vtp域中其他交換機(jī)傳遞來的最新的vlan信息,;client模式是指本交換機(jī)不能創(chuàng)建、刪除,、修改vlan配置,,也不能在nvram中存儲(chǔ)vlan配置,但可同步由本vtp域中其他交換機(jī)傳遞來的vlan信息,。 2,、配置中繼為了保證管理域能夠覆蓋所有的分支交換機(jī),必須配置中繼,。 cisco交換機(jī)能夠支持任何介質(zhì)作為中繼線,,為了實(shí)現(xiàn)中繼可使用其特有的isl標(biāo)簽。isl(inter-switch link)是一個(gè)在交換機(jī)之間,、交換機(jī)與路由器之間及交換機(jī)與服務(wù)器之間傳遞多個(gè)vlan信息及vlan數(shù)據(jù)流的協(xié)議,,通過在交換機(jī)直接相連的端口配置isl封裝,即可跨越交換機(jī)進(jìn)行整個(gè)網(wǎng)絡(luò)的vlan分配和進(jìn)行配置,。 在核心交換機(jī)端配置如下: mainswitch(config)#interface f0/1 mainswitch(config-if)#switchport mainswitch(config-if)#switchport trunk encapsulation isl 配置中繼協(xié)議 mainswitch(config-if)#switchport mode trunk mainswitch(config)#interface f0/2 mainswitch(config-if)#switchport mainswitch(config-if)#switchport trunk encapsulation isl 配置中繼協(xié)議 mainswitch(config-if)#switchport mode trunk mainswitch(config)#interface f0/3 mainswitch(config-if)#switchport mainswitch(config-if)#switchport trunk encapsulation isl 配置中繼協(xié)議 mainswitch(config-if)#switchport mode trunk 在分支交換機(jī)端配置如下: lanswitch01(config)#interface f0/24 lanswitch01(config-if)#switchport mode trunk lanswitch02(config)#interface f0/24 lanswitch02(config-if)#switchport mode trunk lanswitch03(config)#interface f0/24 lanswitch03(config-if)#switchport mode trunk 此時(shí),,管理域算是設(shè)置完畢了。 3、創(chuàng)建vlan一旦建立了管理域,,就可以創(chuàng)建vlan了,。 mainswitch(vlan)#vlan 10 name vlan10 創(chuàng)建了一個(gè)編號(hào)為10 名字為vlan10的 vlan mainswitch(vlan)#vlan 20 name vlan20t 創(chuàng)建了一個(gè)編號(hào)為20 名字為vlan20的 vlan mainswitch(vlan)#vlan 30 name vlan30 創(chuàng)建了一個(gè)編號(hào)為30 名字為vlan30的 vlan 注意,這里的vlan是在核心交換機(jī)上建立的,,其實(shí),,只要是在管理域中的任何一臺(tái)vtp 屬性為server的交換機(jī)上建立vlan,它就會(huì)通過vtp通告整個(gè)管理域中的所有的交換機(jī),。但如果要將具體的交換機(jī)端口劃入某個(gè)vlan,,就必須在該端口所屬的交換機(jī)上進(jìn)行設(shè)置。
4,、將交換機(jī)端口劃入vlan 例如,,要將lanswitch01、lanswitch02,、lanswitch03……分支交換機(jī)的端口1劃入vlan10 vlan,,端口2劃入vlan20 vlan,端口3劃入vlan30 vlan…… lanswitch01(config)#interface fastethernet 0/1 配置端口1 lanswitch01(config-if)#switchport access vlan 10 歸屬vlan10 vlan lanswitch01(config)#interface fastethernet 0/2 配置端口2 lanswitch01(config-if)#switchport access vlan 20 歸屬vlan20 vlan lanswitch01(config)#interface fastethernet 0/3 配置端口3 lanswitch01(config-if)#switchport access vlan 30 歸屬vlan30 vlan lanswitch02(config)#interface fastethernet 0/1 配置端口1 lanswitch02(config-if)#switchport access vlan 10 歸屬vlan10 vlan lanswitch02(config)#interface fastethernet 0/2 配置端口2 lanswitch02(config-if)#switchport access vlan 20 歸屬vlan20 vlan lanswitch02(config)#interface fastethernet 0/3 配置端口3 lanswitch02(config-if)#switchport access vlan 30 歸屬vlan30 vlan lanswitch03(config)#interface fastethernet 0/1 配置端口1 lanswitch03(config-if)#switchport access vlan 10 歸屬vlan10 vlan lanswitch03(config)#interface fastethernet 0/2 配置端口2 lanswitch03(config-if)#switchport access vlan 20 歸屬vlan20 vlan lanswitch03(config)#interface fastethernet 0/3 配置端口3 lanswitch03(config-if)#switchport access vlan 30 歸屬vlan30 vlan
5,、路由器1: interface FastEthernet0/1 ip address 192.168.0.254 255.255.255.0 ip access-group duplex auto speed auto interface FastEthernet0/1.1 encapsulation dot1Q 10 ip address 192.168.11.254 255.255.255.0 interface FastEthernet0/1.2 encapsulation dot1Q 20 ip address 192.168.12.254 255.255.255.0 interface FastEthernet0/1.3 encapsulation dot1Q 30 ip address 192.168.13.254 255.255.255.0 access-list 110 deny ip any 192.168.12.0 access-list 110 permit ip any any 七,、中期總結(jié)
1、實(shí)驗(yàn)設(shè)備清單:
2,、具體配置:
交換: mainswitch #vlan database mainswitch(vlan)#vtp domain mainswitch mainswitch(vlan)#vtp server
lanswitch01#vlan database lanswitch01(vlan)#vtp domain mainswitch lanswitch01(vlan)#vtp client lanswitch02#vlan database lanswitch02(vlan)#vtp domain mainswitch lanswitch02(vlan)#vtp client lanswitch03#vlan database lanswitch03(vlan)#vtp domain mainswitch lanswitch03(vlan)#vtp client mainswitch(config)#interface f0/1 mainswitch(config-if)#switchport mode trunk mainswitch(config)#interface f0/2 mainswitch(config-if)#switchport mode trunk mainswitch(config)#interface f0/3 mainswitch(config-if)#switchport mode trunk lanswitch01(config)#interface f0/24 lanswitch01(config-if)#switchport mode trunk lanswitch02(config)#interface f0/24 lanswitch02(config-if)#switchport mode trunk lanswitch03(config)#interface f0/24 lanswitch03(config-if)#switchport mode trunk mainswitch(vlan)#vlan 10 name vlan10 mainswitch(vlan)#vlan 20 name vlan20t mainswitch(vlan)#vlan 30 name vlan30 mainswitch(vlan)#vlan 40 name vlan40
lanswitch01(config)#interface fastethernet 0/1 lanswitch01(config-if)#switchport access vlan 10 lanswitch01(config)#interface fastethernet 0/2 lanswitch01(config-if)#switchport access vlan 20 lanswitch01(config)#interface fastethernet 0/3 lanswitch01(config-if)#switchport access vlan 30 lanswitch02(config)#interface fastethernet 0/1 lanswitch02(config-if)#switchport access vlan 10 lanswitch02(config)#interface fastethernet 0/2 lanswitch02(config-if)#switchport access vlan 20 lanswitch02(config)#interface fastethernet 0/3 lanswitch02(config-if)#switchport access vlan 30 lanswitch03(config)#interface fastethernet 0/1 lanswitch03(config-if)#switchport access vlan 10 lanswitch03(config)#interface fastethernet 0/2 lanswitch03(config-if)#switchport access vlan 20 lanswitch03(config)#interface fastethernet 0/3 lanswitch03(config-if)#switchport access vlan 30 lanswitch03(config)#interface fastethernet 0/3 – 6 lanswitch03(config-if)#switchport access vlan 40 mainswitch(config)#interface f0/24 mainswitch(config-if)#switchport mode trunk
路由:interface FastEthernet0/0 ip address 192.168.15.254 255.255.255.0 ip nat outside interface FastEthernet0/1 ip address 192.168.0.254 255.255.255.0 ip nat inside interface FastEthernet0/1.1 encapsulation dot1Q 10 ip address 192.168.11.254 255.255.255.0 ip access-group ip access-group 101 out interface FastEthernet0/1.2 encapsulation dot1Q 20 ip address 192.168.12.254 255.255.255.0 ip access-group ip access-group 101 out interface FastEthernet0/1.3 encapsulation dot1Q 30 ip address 192.168.13.254 255.255.255.0 interface FastEthernet0/1.4 encapsulation dot1Q 40 ip address 192.168.14.254 255.255.255.0 ip nat pool c35 192.168.15.254 192.168.15.254 netmask 255.255.255.0 ip nat inside source list 1 pool c35 overload ip nat inside source static tcp 192.168.14.2 80 192.168.15.254 80 ip classless ip route access-list 101 deny ip 192.168.11.0 access-list 101 deny ip 192.168.11.0 access-list 101 deny ip 192.168.12.0 access-list 101 permit ip any any 3、telnet Router#conf t Enter configuration commands, one per line. End with CNTL/Z. Router(config)#enable secret 123 Router(config)#line vty 0 4 Router(config-line)#pas Router(config-line)#password 123 Router(config-line)#login Router(config-line)#exit Router(config)#acc 1 permit host 192.168.14.3 Router(config)#line vty 0 4 Router(config-line)#acc Router(config-line)#access-class Lanswitch01: lanswitch01#conf t lanswitch01(config)#int vlan 40 lanswitch01(config-if)#ip add 192.168.14.110 255.255.255.0 lanswitch01(config-if)#no shut lanswitch01(config-if)#exit lanswitch01(config)#ena pass 111 lanswitch01(config)#line vty 0 4 lanswitch01(config-line)#pass 111 lanswitch01(config-line)#login lanswitch01(config-line)#exit lanswitch01(config)#acc 1 permit host 192.168.14.3 lanswitch01(config)#exit lanswitch01# lanswitch01#copy run start Destination filename [startup-config]? Building configuration... [OK]
Lanswitch02: lanswitch02#conf t lanswitch02(config)#int vlan 40 lanswitch02(config-if)#ip add 192.168.14.111 255.255.255.0 lanswitch02(config-if)#no shut lanswitch02(config-if)#exit lanswitch02(config)#ena pass 111 lanswitch02(config)#line vty 0 4 lanswitch02(config-line)#pass 111 lanswitch02(config-line)#login lanswitch02(config-line)#exit lanswitch02(config)#acc 1 permit host 192.168.14.3 lanswitch02(config)#exit lanswitch02# lanswitch02#copy run start Destination filename [startup-config]? Building configuration... [OK]
Lanswitch03: lanswitch03#conf t lanswitch03(config)#int vlan 40 lanswitch03(config-if)#ip add 192.168.14.112 255.255.255.0 lanswitch03(config-if)#no shut lanswitch03(config-if)#exit lanswitch03(config)#ena pass 111 lanswitch03(config)#line vty 0 4 lanswitch03(config-line)#pass 111 lanswitch03(config-line)#login lanswitch03(config)#acc 1 permit host 192.168.14.3 lanswitch03(config)#exit lanswitch03# lanswitch03#copy run start Destination filename [startup-config]? Building configuration... [OK] 八,、靜態(tài)路由
Route0: nterface FastEthernet0/1 ip address 192.168.1.254 255.255.255.0 ip nat inside interface Serial1/0 ip address 192.168.2.1 255.255.255.0 ip nat outside ip route Route1: interface FastEthernet0/1 ip address 192.168.3.254 255.255.255.0 ip nat inside! interface Serial1/0 ip address 192.168.2.2 255.255.255.0 ip nat outside clock rate 128000 interface Serial1/1 ip address 192.168.4.1 255.255.255.0 ip nat outside clock rate 64000 ip route ip route Route2: interface FastEthernet0/1 ip address 192.168.5.254 255.255.255.0 ip nat inside interface Serial1/1 ip address 192.168.4.2 255.255.255.0 ip nat outside interface Serial1/2 ip address 192.168.6.1 255.255.255.0 ip nat outside clock rate 72000 ip route ip route Route4: interface FastEthernet0/1 ip address 192.168.7.254 255.255.255.0 ip nat inside interface Serial1/2 ip address 192.168.6.2 255.255.255.0 ip nat outside ip classless ip route 九,、rip 協(xié)議
Route0:interface FastEthernet0/0 ip address 192.168.2.1 255.255.255.0 interface FastEthernet0/1 ip address 192.168.1.254 255.255.255.0 router rip network 192.168.1.0 network 192.168.2.0 ip route Route1:interface FastEthernet0/0 ip address 192.168.2.2 255.255.255.0 interface FastEthernet0/1 ip address 192.168.3.254 255.255.255.0 router rip network 192.168.2.0 network 192.168.3.0 ip route pc0:192.168.1.2/24 pc1:192.168.3.2/24
|
|