2,、所有部門(mén)均可訪問(wèn)OA系統(tǒng),3、采購(gòu)系統(tǒng)只允許采購(gòu)部門(mén)訪問(wèn),;4、視頻監(jiān)控所有部門(mén)均可以通過(guò)內(nèi),、外網(wǎng)訪問(wèn),;5、數(shù)據(jù)中心區(qū)ip地址均為靜態(tài)設(shè)置,;6,、辦公區(qū)ip均為自動(dòng)獲取,且均可以上網(wǎng),;1,、設(shè)備管理vlan10:10.10.10.0/24;2,、生產(chǎn)部vlan1000:192.168.10.0/24,;3、采購(gòu)部vlan2000:192.168.20.0/24,;4,、核心與防火墻之間vlan300:172.16.1.0/24;5,、采購(gòu)系統(tǒng)vlan100:192.168.100.0/24,;6、OA系統(tǒng)vlan200:192.168.200.0/24,;7,、視頻監(jiān)控vlan300:192.168.30.0/24;
三,、配置步驟 vlan 10 description SheBeiGuanLi vlan 100 description CaiGouserver vlan 200 description OAserver vlan 300 description ShiPinJK vlan 1000 description ShengChan vlan 2000 description CaiGou vlan 3000 description connectFW quit
b,、將交換機(jī)的端口加入對(duì)應(yīng)的vlan: #防火墻的接口是三層口所以交換機(jī)與防火墻相連的端口用access模式 interface GigabitEthernet0/0/1 port link-type access port default vlan 3000 interface GigabitEthernet0/0/22 port link-type trunk port trunk allow-pass vlan 10 1000 interface GigabitEthernet0/0/23 port link-type trunk port trunk allow-pass vlan 10 2000 interface GigabitEthernet0/0/24 port link-type trunk port trunk allow-pass vlan 10 100 200 300 1000 2000 3000 quit
c,、配置設(shè)備遠(yuǎn)程管理: stelnet server enable telnet server enable user-interface vty 0 4 protocol inbound telnet authentication-mode aaa idle-timeout 15 quit aaa local-user admin password cipher admin@123 local-user admin privilege level 15 local-user admin service-type telnet web ssh quit
interface Vlanif10 ip address 10.10.10.254 255.255.255.0 interface Vlanif100 ip address 192.168.100.254 255.255.255.0 interface Vlanif200 ip address 192.168.200.254 255.255.255.0 interface Vlanif300 ip address 192.168.30.254 255.255.255.0 interface Vlanif1000 ip address 192.168.10.254 255.255.255.0 interface Vlanif2000 ip address 192.168.20.254 255.255.255.0 interface Vlanif3000 ip address 172.16.1.2 255.255.255.0 quit
dhcp enable interface Vlanif1000 dhcp select global interface Vlanif2000 dhcp select global quit ip pool 1000 gateway-list 192.168.10.254 network 192.168.10.0 mask 255.255.255.0 quit ip pool 2000 gateway-list 192.168.20.254 network 192.168.20.0 mask 255.255.255.0 quit
acl 3001 description CaiGouConnectCaiGouServer rule permit ip source 192.168.20.0 0.0.0.255 rule deny ip source 192.168.10.0 0.0.0.255 rule deny ip source 10.10.10.0 0.0.0.255 rule deny ip source 172.16.1.0 0.0.0.255 rule deny ip source 192.168.200.0 0.0.0.255 rule deny ip source 192.168.30.0 0.0.0.255 quit traffic-filter vlan 100 outbound acl 3001 acl 3002 description ConnectOAServer rule deny ip source 10.10.10.0 0.0.0.255 rule deny ip source 172.16.1.0 0.0.0.255 rule deny ip source 192.168.100.0 0.0.0.255 rule deny ip source 192.168.30.0 0.0.0.255 quit traffic-filter vlan 200 outbound acl 3002 quit
g、配置默認(rèn)路由 ip route-static 0.0.0.0 0.0.0.0 172.16.1.3 2,、生產(chǎn)部,、采購(gòu)部,、機(jī)房交換機(jī)配置
#生產(chǎn)部 vlan 10 description SheBeiGuanLi vlan 1000 description ShengChan quit #采購(gòu)部 vlan 10 description SheBeiGuanLi vlan 2000 description CaiGou quit #機(jī)房 vlan 10 description SheBeiGuanLi vlan 100 description CaiGouserver vlan 200 description OAserver vlan 300 description ShiPinJK vlan 1000 description ShengChan vlan 2000 description CaiGou quit b,、將交換機(jī)的端口加入對(duì)應(yīng)的vlan及配置管理地址:#生產(chǎn)部 interface Ethernet0/0/1 port link-type access port default vlan 1000 interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 1000 quit interface Vlanif10 ip address 10.10.10.251 255.255.255.0 quit #采購(gòu)部 interface Ethernet0/0/2 port link-type access port default vlan 2000 interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 2000 quit interface Vlanif10 ip address 10.10.10.252 255.255.255.0 quit #機(jī)房 interface Ethernet0/0/1 port link-type access port default vlan 100 interface Ethernet0/0/2 port link-type access port default vlan 200 interface Ethernet0/0/3 port link-type access port default vlan 300 interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 10 100 200 300 1000 2000 quit interface Vlanif10 ip address 10.10.10.253 255.255.255.0 quit
#我這里為了方便全配成一樣了,建議在實(shí)際項(xiàng)目中不要這樣配 stelnet server enable telnet server enable user-interface vty 0 4 protocol inbound telnet authentication-mode aaa idle-timeout 15 quit aaa local-user admin password cipher admin@123 local-user admin privilege level 15 local-user admin service-type telnet web ssh quit a,、配置內(nèi)、外接口地址并設(shè)置好區(qū)域注:外網(wǎng)口是我橋接到自己的電腦上了,,所以地址是和我電腦同網(wǎng)段的地址,。注:我在配置外網(wǎng)接口時(shí)已經(jīng)配置網(wǎng)關(guān),,所以這里不用再配置出口路由 1,、生產(chǎn)部訪問(wèn)采購(gòu)部,、OA、外網(wǎng),、采購(gòu)系統(tǒng),、視頻監(jiān)控2、采購(gòu)部訪問(wèn)生產(chǎn)部,、OA,、外網(wǎng)、采購(gòu)系統(tǒng),、視頻監(jiān)控 3,、外網(wǎng)訪問(wèn)視頻監(jiān)控
|