##前言
隨便記錄一下吧!交換機(jī)以及路由的配置。
##eNSP模擬
首先我們搭建如下網(wǎng)絡(luò)拓?fù)?br>
PC機(jī)的配置
PC1
vlan10
ip : 192.168.10.1
默認(rèn)網(wǎng)關(guān):192.168.10.254
PC2
vlan20
ip : 192.168.20.1
默認(rèn)網(wǎng)關(guān):192.168.20.254
PC3
vlan10
ip : 192.168.10.2
默認(rèn)網(wǎng)關(guān):192.168.10.254
PC4
vlan20
ip : 192.168.20.2
默認(rèn)網(wǎng)關(guān):192.168.20.254
PC6
internet
ip : 192.168.100.1
默認(rèn)網(wǎng)關(guān): 192.168.100.254
PC8
vlan 10
ip : 192.168.10.3
默認(rèn)網(wǎng)關(guān): 192.168.10.254
交換機(jī)的配置
二層交換機(jī)
LSW1
vlan 10 20
interface GigabitEthernet 0/0/2
port link-type access
port default vlan 10
quit
interface GigabitEthernet 0/0/3
port link-type access
port default vlan 20
quit
interface GigabitEthernet 0/0/1
port link-type trunk
port trunk allow-pass vlan all
quit
LSW2
vlan 10 20
interface GigabitEthernet 0/0/1
port link-type access
port default vlan 10
quit
interface GigabitEthernet 0/0/2
port link-type access
port default vlan 20
quit
interface GigabitEthernet 0/0/3
port link-type trunk
port trunk allow-pass vlan all
quit
三層交換機(jī)
LSW3
vlan 10 20 200
interface GigabitEthernet 0/0/1
port link-type trunk
port trunk allow-pass vlan all
quit
interface GigabitEthernet 0/0/2
port link-type trunk
port trunk allow-pass vlan all
quit
interface GigabitEthernet 0/0/3
port link-type access
port default vlan 200
quit
interface Vlanif 200
ip address 192.168.200.1 24
quit
ip route-static 0.0.0.0 0.0.0.0 192.168.200.2
quit
路由器的配置
AR1
interface GigabitEthernet 0/0/0
ip address 192.168.200.2 24
quit
interface GigabitEthernet 0/0/1
ip address 192.168.100.254 24
quit
ip route-static 192.168.10.0 24 192.168.200.1
ip route-static 192.168.20.0 24 192.168.200.1
訪問控制列表ACL
首先我們可以查看AR2200的產(chǎn)品手冊(cè)
acl number 2000
rule 5 deny source 192.168.10.0 0.0.0.255
quit
acl number 2001
rule 5 permit source 192.168.20.0 0.0.0.255
quit
acl number 3001
rule 5 deny tcp source 192.168.200.0 0.0.0.255 destination 0.0.0.0 0 destination-port eq telnet
quit
interface GigabitEthernet 0/0/0
traffic-filter inbound acl 2001
quit
interface GigabitEthernet 0/0/1
traffic-filter inbound acl 3001
quit
常用的其他命令
display vlan 顯示Vlan
display ip routing-table 顯示路由表
display ip interface brief 顯示所有的接口
display acl all 顯示所有的acl表項(xiàng)
clear configuration interface GigabitEthernet 0/0/1
undo shutdown 開啟已關(guān)閉的接口
注意事項(xiàng)
一些sys ,quit 之類的命令可能不是很全,自己注意,!
#總結(jié)
其實(shí)是一些比較簡(jiǎn)單的東西,只是沒什么時(shí)間了解罷了!
|