ToB企服应用市场:ToB评测及商务社交产业平台

标题: 云计算融合网络摆设实例 [打印本页]

作者: 忿忿的泥巴坨    时间: 2024-6-14 21:10
标题: 云计算融合网络摆设实例
这是我当年参加的网络比赛的练习标题,我将其分享出来。
模块一:云计算融合网络摆设

CII网络公司总部设有研发、市场、供应链、售后等4个部分,统一进行IP地址及业务资源的规划和分配。公司总部及亚太地域的网络拓扑结构如图所示。
其中两台S6000交换机(用S5750-E代替)编号为S4、S5,用于服务器高速接入;两台S5750编号为S2、S3,作为总部的核心交换机;两台RSR20路由器编号为R2、R3,作为总部的核心路由器,一台EG2000(用RSR20代替)编号为EG1,作为总部互联网出口网关1。一台S2910编号为S1,作为总部接入交换机;一台RSR20路由器编号为R1,作为分支机构路由器,一台EG2000(用RSR20代替)编号为EG2,作为分部互联网出口网关2。一台S5750编号为S6作为分部核心交换机,一台S2910编号为S7,作为分部接入交换机。3台AP520编号为AP1,AP2,AP3分别作为总部与分部的无线接入点。

请根据拓扑图及网络物理连接表完成装备的连线。
装备互联规范主要对各种网络装备的互联进行规范界说,在项目实行中,如用户无特殊要求,应根据规范要求进行各级网络装备的互联,统一现场装备互联界面,结合规范的线缆标签使用,使网络结构清晰明了,方便后续的维护。如下“表1-8 网络物理连接表”。
表1-8网络物理连接表
  1. 源设备名称        设备接口        接口描述        目标设备名称        设备接口
  2. S1        Gi0/1        Con_To_PC1        PC1         
  3. S1        Gi0/5        Con_To_PC2        PC2         
  4. S1        Gi0/21        Con_To_AP1        AP1         
  5. S1        Gi0/22        Con_To_AP2        AP2         
  6. S1        Gi0/23        Con_To_S2_Gi0/1        S2        Gi0/1
  7. S1        Gi0/24        Con_To_S3_Gi0/1        S3        Gi0/1
  8. S2        Gi0/1        Con_To_S1_Gi0/23        S1        Gi0/23
  9. S2        Gi0/2        Con_To_S3_Gi0/2        S3        Gi0/2
  10. S2        Gi0/3        Con_To_S3_Gi0/3        S3        Gi0/3
  11. S2        Gi0/4        Con_To_R2_Gi0/0        R2        Gi0/0
  12. S2        Gi0/5        Con_To_AC1_Gi0/1        AC1        Gi0/1
  13. S3        Gi0/1        Con_To_S1_Gi0/24        S1        Gi0/24
  14. S3        Gi0/2        Con_To_S2_Gi0/2        S2        Gi0/2
  15. S3        Gi0/3        Con_To_S2_Gi0/3        S2        Gi0/3
  16. S3        Gi0/4        Con_To_R3_Gi0/0        R3        Gi0/0
  17. S3        Gi0/5        Con_To_AC2_Gi0/1        AC2        Gi0/1
  18. R2        FA1/1        Con_To_S4_Gi0/1        S4        Gi0/1
  19. R2        Gi0/0        Con_To_S2_Gi0/4        S2        Gi0/4
  20. R2        Gi0/1        Con_To_EG1_Gi0/1        EG1        Gi0/0
  21. R2        S2/0        Con_To_R1_S2/0        R1        S2/0
  22. R2        S3/0        Con_To_R3_S3/0        R3        S3/0
  23. R3        FA1/1        Con_To_S5_Gi0/1        S5        Gi0/1
  24. R3        Gi0/0        Con_To_S3_Gi0/4        S3        Gi0/4
  25. R3        Gi0/1        Con_To_EG1_Gi0/1        EG1        Gi0/1
  26. R3        S2/0        Con_To_R1_S3/0        R1        S3/0
  27. R3        S3/0        Con_To_R2_S3/0        R2        S3/0
  28. S4        Gi0/1        Con_To_R2_FA1/1        R2        FA1/1
  29. S4        Gi0/2        Con_To_S5_Gi0/2        S5        Gi0/2
  30. S4        Gi0/5        Con_To_Cloud_M        云平台(主用)         
  31. S4        Gi0/23                 S5        Gi0/23
  32. S4        Gi0/24                 S5        Gi0/24
  33. S5        Gi0/1        Con_To_R3_FA1/1        R3        FA1/1
  34. S5        Gi0/2        Con_To_S4_Gi0/2        S4        Gi0/2
  35. S5        Gi0/5        Con_To_Cloud_B        云平台(备用)         
  36. S5        Gi0/23                 S4        Gi0/23
  37. S5        Gi0/24                 S4        Gi0/24
  38. R1        S2/0        Con_To_R2_S2/0        R2        S2/0
  39. R1        S3/0        Con_To_R3_S2/0        R3        S2/0
  40. R1        Gi0/0        Con_To_S6_Gi0/1        S6        Gi0/1
  41. R1        Gi0/1        Con_To_EG2_Gi0/0        EG2        Gi0/0
  42. S6        Gi0/1        Con_To_R1_Gi0/0        R1        Gi0/0
  43. S6        Gi0/2        Con_To_AP3_Gi0/0        AP3        Gi0/0
  44. S6        Gi0/3        Con_To_S7_Gi0/24        S7        Gi0/24
  45. S7        Gi0/1        Con_To_PC3        PC3         
  46. S7        Gi0/24        Con_To_S6_Gi0/3        S6        Gi0/3
  47. EG1        GI0/1        Con_To_R2_Gi0/1        R2        Gi0/1
  48. EG1        GI0/2        Con_To_R3_Gi0/1        R3        Gi0/1
  49. EG1        GI0/3        Con_To_EG2_Gi0/3        EG2        GI0/3
  50. EG2        GI0/1        Con_To_R1_Gi0/1        R1        Gi0/1
  51. EG2        GI0/3        Con_To_EG1_Gi0/3        EG1        GI0/3
复制代码
公司有4个不同业务部分和分部,彼此间必要互联互通,同时也必要对某些业务进行互访限制。别的,各业务对网络可靠性要求较高,要求网络核心地区发生故障时的停止时间尽可能短。另有,网络摆设时要考虑到网络的可管理性,并公道使用网络资源。
表1-9网络装备名称表
  1. 拓扑图中设备名称        配置主机名(hostname名)
  2. S1        ZB-S2910-01
  3. S2        ZB-S5750-01
  4. S3        ZB-S5750-02
  5. S4        ZB-VSU-S6000
  6. S5        ZB-VSU-S6000
  7. S6        FB-S5750-01
  8. S7        FB-2910-01
  9. R1        FB-RSR20-01
  10. R2        ZB-RSR20-01
  11. R3        ZB-RSR20-02
  12. AC1        ZB-WS6008-01
  13. AC2        ZB-WS6008-02
  14. EG1        ZB-EG2000-01
  15. EG2        FB-EG2000-01
  16. AP1        ZB-AP520-01
  17. AP2        ZB-AP520-02
  18. AP3        FB-AP520-01
复制代码
表1-10 IPv4地址分配表
  1. 设备        接口或VLAN        VLAN名称        二层或三层规划(XX代表工位号)        说明
  2. S1        VLAN10        Res        Gi0/1至Gi0/4        研发
  3.         VLAN20        Sales        Gi0/5至Gi0/8        市场
  4.         VLAN30        Supply        Gi0/9至Gi0/12        供应链
  5.         VLAN40        Service        Gi0/13至Gi0/16        售后
  6.         VLAN50        AP        Gi0/21至Gi0/22        无线AP
  7.         VLAN100        Manage        192.XX.100.4/24        设备管理VLAN
  8. S2        VLAN10        Res        192.XX.10.252/24        研发
  9.         VLAN20        Sales        192.XX.20.252/24        市场
  10.         VLAN30        Supply        192.XX.30.252/24        供应链
  11.         VLAN40        Service        192.XX.40.252/24        售后
  12.         VLAN50        AP        192.XX.50.252/24        无线AP
  13.         VLAN100        Manage        192.XX.100.252/24        设备管理VLAN
  14.         Gi0/4                 10.XX.0.1/30         
  15.         Gi0/5                 TRUNK        互联AC
  16.         LoopBack 0                 11.XX.0.202/32         
  17. S3        VLAN10        Res        192.XX.10.253/24        研发
  18.         VLAN20        Sales        192.XX.20.253/24        市场
  19.         VLAN30        Supply        192.XX.30.253/24        供应链
  20.         VLAN40        Service        192.XX.40.253/24        售后
  21.         VLAN50        AP        192.XX.50.253/24        无线AP
  22.         VLAN100        Manage        192.XX.100.253/24        设备管理VLAN
  23.         Gi0/4                 10.XX.0.5/30         
  24.         Gi0/5                 TRUNK        互联AC
  25.         LoopBack 0                 11.XX.0.203/32         
  26. AC1        LoopBack 0                 11.XX.0.204/32         
  27.         VLAN60        Wiressless        192.XX.60.252/24        无线用户
  28.         Vlan100        Manage        192.XX.100.2/24        管理与互联VLAN
  29. AC2        LoopBack 0                 11.XX.0.205/32         
  30.         VLAN60        Wiressless        192.XX.60.253/24        无线用户
  31.         Vlan100        Manage        192.XX.100.3/24        管理与互联VLAN
  32. S4        VLAN100        Con_To_Cloud        193.XX.0.1/30        互联云平台
  33.         Gi0/1                 10.XX.0.9/30         
  34.         LoopBack 0                 11.XX.0.45/32         
  35. S5        VLAN100        Con_To_Cloud        193.XX.0.1/30        互联云平台(备用)
  36.         Gi0/1                 10.XX.0.13/30         
  37.         LoopBack 0                 11.XX.0.45/32         
  38. EG1        GI0/2                 195.XX.0.1/24        与EG2互联
  39.         GI0/0                 10.XX.0.34/30         
  40.         GI0/1                 10.XX.0.38/30         
  41.         LoopBack 0                 11.XX.0.11/32         
  42. EG2        GI0/2                 195.XX.0.2/24        与EG1互联
  43.         GI0/0                 10.XX.0.42/30         
  44.         LoopBack 0                 11.XX.0.12/32         
  45. R1        S2/0                 10.XX.0.17/30         
  46.         S2/1                 10.XX.0.21/30         
  47.         Gi0/0                 10.XX.0.25/30         
  48.         Gi0/1                 10.XX.0.41/30         
  49.         LoopBack 0                 11.XX.0.1/32         
  50. R2        Gi0/0                 10.XX.0.2/30         
  51.         FA1/1(vlan100)                 10.XX.0.10/30        SVI接口互联
  52.         Gi0/1                 10.XX.0.33/30         
  53.         S2/0                 10.XX.0.18/30         
  54.         S3/0                 10.XX.0.29/30         
  55.         LoopBack 0                 11.XX.0.2/32         
  56. R3        Gi0/0                 10.XX.0.6/30         
  57.         FA1/1(vlan100)                 10.XX.0.14/30        SVI接口互联
  58.         Gi0/1                 10.XX.0.37/30         
  59.         S2/0                 10.XX.0.22/30         
  60.         S3/0                 10.XX.0.30/30         
  61.         LoopBack 0                 11.XX.0.3/32         
  62. S6        Gi0/1                 10.XX.0.26/30         
  63.         VLAN10        Pvlan        194.XX.10.254/24        分部有线用户
  64.         VLAN20        Wireless_user        194.XX.20.254/24        分部无线用户
  65.         VLAN30        AP        194.XX.30.254/24        分部无线AP
  66.         VLAN100        Manage        194.XX.100.254/24        设备管理VLAN
  67.         LoopBack 0                 11.XX.0.6/32         
  68. S7        VLAN10        Pvlan                 Primaty vlan
  69.         VLAN11        Community_vlan        Gi0/1至Gi0/4        community vlan
  70.         VLAN12        Isolated_vlan        Gi0/5至Gi0/8        isolated vlan
  71.         VLAN100        Manage        194.XX.100.1/24        设备管理VLAN
  72. PC机        PC1                 自动获取         
  73.         PC2                 192.XX.20.2/24         
  74.         PC3                 194.XX.10.2/24         
复制代码
表1-11 S2和S3的VRRP参数表
  1. VLAN        VRRP备份组号(VRID)        VRRP虚拟IP
  2. VLAN10        10        192.xx.10.254
  3. VLAN20        20        192.xx.20.254
  4. VLAN30        30        192.xx.30.254
  5. VLAN40        40        192.xx.40.254
  6. VLAN50        50        192.xx.50.254
  7. VLAN100(交换机间)        100        192.xx.100.254
复制代码
(6)S2作为所有主机的实际网关,S3作为所有主机的备份网关;其中各VRRP组中高优先级设置为150,低优先级设置为120。
模块二:移动互联网络组建与优化

为满足“互联网+”时代下,员工移动办公的发展趋势,公司总部与分部均必要规划和摆设移动互联无线网络,同时为保证无线用户安全、可靠的访问互联网,我们必要进行无线网络安全及性能优化设置,确保员工有良好的上网体验。
模块三:网络空间安全摆设

公司总部与分部无线用户必要通过独立的互联网线路访问外网资源,同时针对访问资源进行用户身份认证与信息审计监督,别的满足出差在外的员工可以访问总部内部服务器资源,需针对出口用户提供长途VPN功能。
具体摆设实行

方法:同时在每台装备上使用show running-config命令,查看对应装备的设置信息。
S1

  1. hostname S1
  2. redundancy
  3. auto-sync time-period 3600
  4. auto-sync standard
  5. switchover timeout 4000
  6. vlan 1
  7. vlan 10
  8. vlan 20
  9. vlan 30
  10. vlan 40
  11. vlan 50
  12. vlan 100
  13. username admin password admin
  14. no service password-encryption
  15. ip dhcp snooping
  16.        
  17. spanning-tree mst configuration
  18. revision 1
  19. name ruijie
  20. instance 0 vlan 1-9, 11-19, 21-29, 31-39, 41-49, 51-99, 101-4094
  21. instance 1 vlan 10, 20, 30, 40, 50, 100
  22. spanning-tree
  23. interface GigabitEthernet 0/1
  24. switchport access vlan 10
  25. ip verify source port-security
  26. arp-check
  27. rate-limit input 10000 1024
  28. rate-limit output 10000 1024
  29. interface GigabitEthernet 0/2
  30. switchport access vlan 10
  31. rate-limit input 10000 1024
  32. rate-limit output 10000 1024
  33. interface GigabitEthernet 0/3
  34. switchport access vlan 10
  35. rate-limit input 10000 1024
  36. rate-limit output 10000 1024
  37. interface GigabitEthernet 0/4
  38. switchport access vlan 10
  39. rate-limit input 10000 1024
  40. rate-limit output 10000 1024
  41. interface GigabitEthernet 0/5
  42. switchport access vlan 20
  43. rate-limit input 10000 1024
  44. rate-limit output 10000 1024
  45. interface GigabitEthernet 0/6
  46. switchport access vlan 20
  47. rate-limit input 10000 1024
  48. rate-limit output 10000 1024
  49. interface GigabitEthernet 0/7
  50. switchport access vlan 20
  51. rate-limit input 10000 1024
  52. rate-limit output 10000 1024
  53. interface GigabitEthernet 0/8
  54. switchport access vlan 20
  55. rate-limit input 10000 1024
  56. rate-limit output 10000 1024
  57. interface GigabitEthernet 0/9
  58. switchport access vlan 30
  59. rate-limit input 10000 1024
  60. rate-limit output 10000 1024
  61. interface GigabitEthernet 0/10
  62. switchport access vlan 30
  63. rate-limit input 10000 1024
  64. rate-limit output 10000 1024
  65. interface GigabitEthernet 0/11
  66. switchport access vlan 30
  67. rate-limit input 10000 1024
  68. rate-limit output 10000 1024
  69. interface GigabitEthernet 0/12
  70. switchport access vlan 30
  71. rate-limit input 10000 1024
  72. rate-limit output 10000 1024
  73. interface GigabitEthernet 0/13
  74. switchport access vlan 40
  75. rate-limit input 10000 1024
  76. rate-limit output 10000 1024
  77. interface GigabitEthernet 0/14
  78. switchport access vlan 40
  79. rate-limit input 10000 1024
  80. rate-limit output 10000 1024
  81. interface GigabitEthernet 0/15
  82. switchport access vlan 40
  83. rate-limit input 10000 1024
  84. rate-limit output 10000 1024
  85. interface GigabitEthernet 0/16
  86. switchport access vlan 40
  87. rate-limit input 10000 1024
  88. rate-limit output 10000 1024
  89. interface GigabitEthernet 0/17
  90. interface GigabitEthernet 0/18
  91. interface GigabitEthernet 0/19
  92. interface GigabitEthernet 0/20
  93. interface GigabitEthernet 0/21
  94. switchport access vlan 50
  95. interface GigabitEthernet 0/22
  96. switchport access vlan 50
  97. interface GigabitEthernet 0/23
  98. switchport mode trunk
  99. ip dhcp snooping trust
  100. interface GigabitEthernet 0/24
  101. switchport mode trunk
  102. ip dhcp snooping trust
  103. interface VLAN 100
  104. no ip proxy-arp
  105. ip address 192.26.100.4 255.255.255.0
  106. line con 0
  107. line vty 0 4
  108. login local
  109. end
复制代码
S2

  1. hostname S2
  2. redundancy
  3. auto-sync time-period 3600
  4. auto-sync standard
  5. switchover timeout 4000
  6. vlan 1
  7. vlan 10
  8. vlan 20
  9. vlan 30
  10. vlan 40
  11. vlan 50
  12. vlan 100
  13. username admin password admin
  14. no service password-encryption
  15. service dhcp
  16. ip helper-address 10.168.0.2
  17. ip dhcp excluded-address 192.168.50.101 192.168.50.254
  18. ip dhcp pool appool
  19. option 138 ip 11.168.0.204
  20. network 192.168.50.0 255.255.255.0
  21. default-router 192.168.50.254
  22. spanning-tree mst configuration
  23. revision 1
  24. name ruijie
  25. instance 0 vlan 1-9, 11-19, 21-29, 31-39, 41-49, 51-99, 101-4094
  26. instance 1 vlan 10, 20, 30, 40, 50, 100
  27. spanning-tree mst 1 priority 4096
  28. spanning-tree
  29. interface GigabitEthernet 0/1
  30. switchport mode trunk
  31. interface GigabitEthernet 0/2
  32. port-group 1
  33. interface GigabitEthernet 0/3
  34. port-group 1
  35. interface GigabitEthernet 0/4
  36. no switchport
  37. ip ospf network point-to-point
  38. ip ospf cost 5
  39. no ip proxy-arp
  40. ip address 10.168.0.1 255.255.255.252
  41. interface GigabitEthernet 0/5
  42. switchport mode trunk
  43. interface GigabitEthernet 0/6
  44. interface GigabitEthernet 0/7
  45. interface GigabitEthernet 0/8
  46. interface GigabitEthernet 0/9
  47. interface GigabitEthernet 0/10
  48. interface GigabitEthernet 0/11
  49. interface GigabitEthernet 0/12
  50. interface GigabitEthernet 0/13
  51. interface GigabitEthernet 0/14
  52. interface GigabitEthernet 0/15
  53. interface GigabitEthernet 0/16
  54. interface GigabitEthernet 0/17
  55. interface GigabitEthernet 0/18
  56. interface GigabitEthernet 0/19
  57. interface GigabitEthernet 0/20
  58. interface GigabitEthernet 0/21
  59. interface GigabitEthernet 0/22
  60. interface GigabitEthernet 0/23
  61. interface GigabitEthernet 0/24
  62. interface AggregatePort 1
  63. switchport mode trunk
  64. interface Loopback 0
  65. ip address 11.168.0.202 255.255.255.255
  66. interface VLAN 10
  67. no ip proxy-arp
  68. ip address 192.168.10.252 255.255.255.0
  69. vrrp 10 priority 150
  70. vrrp 10 ip 192.168.10.254
  71. interface VLAN 20
  72. no ip proxy-arp
  73. ip address 192.168.20.252 255.255.255.0
  74. vrrp 20 priority 150
  75. vrrp 20 ip 192.168.20.254
  76. interface VLAN 30
  77. no ip proxy-arp
  78. ip address 192.168.30.252 255.255.255.0
  79. vrrp 30 priority 150
  80. vrrp 30 ip 192.168.30.254
  81. interface VLAN 40
  82. no ip proxy-arp
  83. ip address 192.168.40.252 255.255.255.0
  84. vrrp 40 priority 150
  85. vrrp 40 ip 192.168.40.254
  86. interface VLAN 50
  87. no ip proxy-arp
  88. ip address 192.168.50.252 255.255.255.0
  89. vrrp 50 priority 150
  90. vrrp 50 ip 192.168.50.254
  91. interface VLAN 100
  92. no ip proxy-arp
  93. ip address 192.168.100.252 255.255.255.0
  94. vrrp 100 priority 150
  95. vrrp 100 ip 192.168.100.254
  96. router ospf 10
  97. passive-interface VLAN 10
  98. passive-interface VLAN 20
  99. passive-interface VLAN 30
  100. passive-interface VLAN 40
  101. passive-interface VLAN 50
  102. passive-interface VLAN 100
  103. network 10.168.0.0 0.0.0.3 area 0
  104. network 11.168.0.202 0.0.0.0 area 0
  105. network 192.168.10.0 0.0.0.255 area 0
  106. network 192.168.20.0 0.0.0.255 area 0
  107. network 192.168.30.0 0.0.0.255 area 0
  108. network 192.168.40.0 0.0.0.255 area 0
  109. network 192.168.50.0 0.0.0.255 area 0
  110. network 192.168.100.0 0.0.0.255 area 0
  111. ip route 10.168.0.16 255.255.255.252 10.168.0.2
  112. ip route 10.168.0.36 255.255.255.252 10.168.0.2
  113. ip route 11.168.0.204 255.255.255.255 192.168.100.2
  114. ip route 11.168.0.205 255.255.255.255 192.168.100.253
  115. ip route 194.168.30.0 255.255.255.0 10.168.0.2
  116. line con 0
  117. line vty 0 4
  118. login local
  119. end
复制代码
S3

  1. hostname S3
  2. redundancy
  3. auto-sync time-period 3600
  4. auto-sync standard
  5. switchover timeout 4000
  6. vlan 1
  7. vlan 10
  8. name Res
  9. vlan 20
  10. name Sales
  11. vlan 30
  12. name Supply
  13. vlan 40
  14. name Service
  15. vlan 50
  16. name Ap
  17. vlan 100
  18. name Manage
  19. no service password-encryption
  20. service dhcp
  21. ip helper-address 10.168.0.2
  22. ip dhcp excluded-address 192.168.50.1
  23. ip dhcp excluded-address 192.168.50.1 192.168.50.100
  24. ip dhcp excluded-address 192.168.50.201 192.168.50.255
  25. ip dhcp pool S3
  26. option 138 ip 11.168.0.204
  27. network 192.168.50.0 255.255.255.0
  28. default-router 192.168.50.254
  29. spanning-tree mst configuration
  30. revision 1
  31. name ruijie
  32. instance 0 vlan 1-9, 11-19, 21-29, 31-39, 41-49, 51-99, 101-4094
  33. instance 1 vlan 10, 20, 30, 40, 50, 100
  34. spanning-tree mst 1 priority 8192
  35. spanning-tree
  36. interface GigabitEthernet 0/1
  37. switchport mode trunk
  38. interface GigabitEthernet 0/2
  39. port-group 1
  40.          
  41. interface GigabitEthernet 0/3
  42. port-group 1
  43. interface GigabitEthernet 0/4
  44. no switch
  45. ip ospf network point-to-point
  46. ip ospf cost 10
  47. no ip proxy-arp
  48. ip address 10.168.0.5 255.255.255.252
  49. interface GigabitEthernet 0/5
  50. switchport mode trunk
  51. interface GigabitEthernet 0/6
  52. interface GigabitEthernet 0/7
  53. interface GigabitEthernet 0/8
  54. interface GigabitEthernet 0/9
  55. interface GigabitEthernet 0/10
  56. interface GigabitEthernet 0/11
  57. interface GigabitEthernet 0/12
  58. interface GigabitEthernet 0/13
  59.          
  60. interface GigabitEthernet 0/14
  61. interface GigabitEthernet 0/15
  62. interface GigabitEthernet 0/16
  63. interface GigabitEthernet 0/17
  64. interface GigabitEthernet 0/18
  65. interface GigabitEthernet 0/19
  66. interface GigabitEthernet 0/20
  67. interface GigabitEthernet 0/21
  68. interface GigabitEthernet 0/22
  69. interface GigabitEthernet 0/23
  70. interface GigabitEthernet 0/24
  71. interface AggregatePort 1
  72. switchport mode trunk
  73. interface Loopback 0
  74. ip address 11.168.0.203 255.255.255.255
  75. interface VLAN 10
  76. no ip proxy-arp
  77. ip address 192.168.10.253 255.255.255.0
  78. vrrp 10 priority 120
  79. vrrp 10 ip 192.168.10.254
  80. interface VLAN 20
  81. no ip proxy-arp
  82. ip address 192.168.20.253 255.255.255.0
  83. vrrp 20 priority 120
  84. vrrp 20 ip 192.168.20.254
  85. interface VLAN 30
  86. no ip proxy-arp
  87. ip address 192.168.30.253 255.255.255.0
  88. vrrp 30 priority 120
  89. vrrp 30 ip 192.168.30.254
  90. interface VLAN 40
  91. no ip proxy-arp
  92. ip address 192.168.40.253 255.255.255.0
  93. vrrp 40 priority 120
  94. vrrp 40 ip 192.168.40.254
  95. interface VLAN 50
  96. no ip proxy-arp
  97. ip address 192.168.50.253 255.255.255.0
  98. vrrp 50 priority 120
  99. vrrp 50 ip 192.168.50.254
  100. interface VLAN 100
  101. no ip proxy-arp
  102. ip address 192.168.100.253 255.255.255.0
  103. vrrp 100 priority 120
  104. vrrp 100 ip 192.168.100.254
  105. router ospf 10
  106. passive-interface VLAN 10
  107. passive-interface VLAN 20
  108. passive-interface VLAN 30
  109. passive-interface VLAN 40
  110. passive-interface VLAN 50
  111. passive-interface VLAN 100
  112. network 10.128.0.4 0.0.0.3 area 0
  113. network 11.128.0.203 0.0.0.0 area 0
  114. network 192.168.10.0 0.0.0.255 area 0
  115. network 192.168.20.0 0.0.0.255 area 0
  116. network 192.168.30.0 0.0.0.255 area 0
  117. network 192.168.40.0 0.0.0.255 area 0
  118. network 192.168.50.0 0.0.0.255 area 0
  119. network 192.168.100.0 0.0.0.255 area 0
  120. ip route 11.168.0.204 255.255.255.255 192.168.100.252
  121. line con 0
  122. line vty 0 4
  123. login
  124. end
复制代码
S4/S5(做的堆叠,两台当一台用)

  1. hostname VSU
  2. redundancy
  3. auto-sync time-period 3600
  4. auto-sync standard
  5. switchover timeout 4000
  6. vlan 1
  7. vlan 100
  8.   
  9. no service password-encryption
  10. interface GigabitEthernet 1/0/1
  11. no switchport
  12. ip ospf network point-to-point
  13. no ip proxy-arp
  14. ip address 10.168.0.9 255.255.255.252
  15. interface GigabitEthernet 1/0/2
  16. no switchport
  17. no ip proxy-arp
  18. no lldp enable
  19. interface GigabitEthernet 1/0/3
  20. interface GigabitEthernet 1/0/4
  21.          
  22. interface GigabitEthernet 1/0/5
  23. interface GigabitEthernet 1/0/6
  24. interface GigabitEthernet 1/0/7
  25. interface GigabitEthernet 1/0/8
  26. interface GigabitEthernet 1/0/9
  27. interface GigabitEthernet 1/0/10
  28. interface GigabitEthernet 1/0/11
  29. interface GigabitEthernet 1/0/12
  30. interface GigabitEthernet 1/0/13
  31. interface GigabitEthernet 1/0/14
  32. interface GigabitEthernet 1/0/15
  33. interface GigabitEthernet 1/0/16
  34.          
  35. interface GigabitEthernet 1/0/17
  36. interface GigabitEthernet 1/0/18
  37. interface GigabitEthernet 1/0/19
  38. interface GigabitEthernet 1/0/20
  39. interface GigabitEthernet 1/0/21
  40. interface GigabitEthernet 1/0/22
  41. interface GigabitEthernet 1/0/23
  42. interface GigabitEthernet 1/0/24
  43. interface GigabitEthernet 2/0/1
  44. no switchport
  45. ip ospf network point-to-point
  46. no ip proxy-arp
  47. ip address 10.168.0.13 255.255.255.252
  48. interface GigabitEthernet 2/0/2
  49. no switchport
  50. no ip proxy-arp
  51. no lldp enable
  52. interface GigabitEthernet 2/0/3
  53. interface GigabitEthernet 2/0/4
  54. interface GigabitEthernet 2/0/5
  55. interface GigabitEthernet 2/0/6
  56. interface GigabitEthernet 2/0/7
  57. interface GigabitEthernet 2/0/8
  58. interface GigabitEthernet 2/0/9
  59. interface GigabitEthernet 2/0/10
  60. interface GigabitEthernet 2/0/11
  61. interface GigabitEthernet 2/0/12
  62. interface GigabitEthernet 2/0/13
  63. interface GigabitEthernet 2/0/14
  64. interface GigabitEthernet 2/0/15
  65. interface GigabitEthernet 2/0/16
  66. interface GigabitEthernet 2/0/17
  67. interface GigabitEthernet 2/0/18
  68. interface GigabitEthernet 2/0/19
  69. interface GigabitEthernet 2/0/20
  70. interface GigabitEthernet 2/0/21
  71. interface GigabitEthernet 2/0/22
  72. interface GigabitEthernet 2/0/23
  73. interface GigabitEthernet 2/0/24
  74. interface Loopback 0
  75. ip address 11.168.0.45 255.255.255.255
  76. interface Loopback 1
  77. ip address 172.16.0.1 255.255.252.0
  78. interface VLAN 100
  79. no ip proxy-arp
  80. ip address 193.168.0.1 255.255.255.252
  81. switch virtual domain 1
  82. dual-active detection bfd
  83. dual-active bfd interface GigabitEthernet 1/0/2
  84. dual-active bfd interface GigabitEthernet 2/0/2
  85. router ospf 10
  86. network 10.168.0.8 0.0.0.3 area 1
  87. network 10.168.0.12 0.0.0.3 area 1
  88. network 11.168.0.45 0.0.0.0 area 1
  89. ip route 10.168.0.16 255.255.255.252 10.168.0.10
  90. ip route 10.168.0.20 255.255.255.252 10.168.0.14
  91. line con 0
  92. line vty 0 4
  93. login
  94. end
复制代码
S6

  1. hostname S6
  2. redundancy
  3. auto-sync time-period 3600
  4. auto-sync standard
  5. switchover timeout 4000
  6. diagnostic bootup level bypass
  7. vlan 1
  8. vlan 10
  9. name Pvlan
  10. private-vlan primary
  11. private-vlan association add 11-12
  12. vlan 11
  13. private-vlan community
  14. vlan 12
  15. private-vlan isolated
  16. vlan 20
  17. name Wirelessuser
  18. vlan 30
  19. name AP
  20. vlan 100
  21. name Manage
  22. username admin password admin
  23. no service password-encryption
  24. service dhcp
  25. ip dhcp pool client
  26. network 194.168.20.0 255.255.255.0
  27. default-router 194.168.20.254
  28. ip dhcp pool Wireless
  29. option 138 ip 11.26.0.204
  30. network 194.168.30.0 255.255.255.0
  31. default-router 194.168.30.254
  32. interface GigabitEthernet 0/1
  33. no switchport
  34. no ip proxy-arp
  35. ip address 10.168.0.26 255.255.255.252
  36. interface GigabitEthernet 0/2
  37. switchport mode trunk
  38. switchport trunk native vlan 30
  39. interface GigabitEthernet 0/3
  40. switchport mode trunk
  41. interface GigabitEthernet 0/4
  42. interface GigabitEthernet 0/5
  43. interface GigabitEthernet 0/6
  44. interface GigabitEthernet 0/7
  45. interface GigabitEthernet 0/8
  46. interface GigabitEthernet 0/9
  47. interface GigabitEthernet 0/10
  48. interface GigabitEthernet 0/11
  49. interface GigabitEthernet 0/12
  50. interface GigabitEthernet 0/13
  51. interface GigabitEthernet 0/14
  52. interface GigabitEthernet 0/15
  53. interface GigabitEthernet 0/16
  54. interface GigabitEthernet 0/17
  55. interface GigabitEthernet 0/18
  56. interface GigabitEthernet 0/19
  57. interface GigabitEthernet 0/20
  58. interface GigabitEthernet 0/21
  59. interface GigabitEthernet 0/22
  60. interface GigabitEthernet 0/23
  61. switchport mode trunk
  62. interface GigabitEthernet 0/24
  63. interface Loopback 0
  64. ip address 11.168.0.6 255.255.255.255
  65. interface VLAN 10
  66. no ip proxy-arp
  67. ip address 194.168.10.254 255.255.255.0
  68. private-vlan mapping add 11-12
  69. interface VLAN 20
  70. no ip proxy-arp
  71. ip address 194.168.20.254 255.255.255.0
  72. interface VLAN 30
  73. no ip proxy-arp
  74. ip address 194.168.30.254 255.255.255.0
  75. interface VLAN 100
  76. no ip proxy-arp
  77. ip address 194.168.100.254 255.255.255.0
  78. ip route 0.0.0.0 0.0.0.0 10.168.0.25
  79. line con 0
  80. line vty 0 4
  81. login local
  82. end
复制代码
R1

  1. hostname R1
  2. webmaster level 0 username admin password 7 04361c0b370d
  3. diffserv domain default
  4. no cwmp
  5. route-map fenliu permit 10
  6. match ip address 101
  7. set ip next-hop 10.168.0.18
  8. route-map fenliu permit 20
  9. match ip address 102
  10. set ip next-hop 10.168.0.22
  11. route-map fenliu permit 30
  12. vlan 1
  13. username admin password admin
  14. no service password-encryption
  15. control-plane
  16. control-plane protocol
  17. acpp bw-rate 1250 bw-burst-rate 2500
  18. control-plane manage
  19. port-filter
  20. arp-car 5
  21. acpp bw-rate 1250 bw-burst-rate 2500
  22. control-plane data
  23. glean-car 5
  24. acpp bw-rate 1250 bw-burst-rate 2500
  25. web-auth mac-check enable
  26. enable service ssh-server
  27. enable service web-server http
  28. enable service web-server https
  29. interface Serial 2/0
  30. encapsulation PPP
  31. ppp chap hostname ruijie
  32. ppp chap password ruijie
  33. ip address 10.168.0.17 255.255.255.252
  34. clock rate 64000
  35. interface Serial 2/1
  36. encapsulation PPP
  37. ppp chap hostname ruijie
  38. ppp chap password ruijie
  39. ip address 10.168.0.21 255.255.255.252
  40. interface GigabitEthernet 0/0
  41. ip address 10.168.0.25 255.255.255.252
  42. duplex auto
  43. speed auto
  44. interface GigabitEthernet 0/1
  45. ip address 10.168.0.41 255.255.255.252
  46. duplex auto
  47. speed auto
  48. interface GigabitEthernet 0/2
  49. duplex auto
  50. speed auto
  51. interface GigabitEthernet 0/3
  52. duplex auto
  53. speed auto
  54. interface GigabitEthernet 1/0
  55. interface GigabitEthernet 1/1
  56.          
  57. interface GigabitEthernet 1/2
  58. interface GigabitEthernet 1/3
  59. interface GigabitEthernet 1/4
  60. interface GigabitEthernet 1/5
  61. interface GigabitEthernet 1/6
  62. interface GigabitEthernet 1/7
  63. interface GigabitEthernet 1/8
  64. interface GigabitEthernet 1/9
  65. interface GigabitEthernet 1/10
  66. interface GigabitEthernet 1/11
  67. interface GigabitEthernet 1/12
  68. interface GigabitEthernet 1/13
  69.          
  70. interface GigabitEthernet 1/14
  71. interface GigabitEthernet 1/15
  72. interface GigabitEthernet 1/16
  73. interface GigabitEthernet 1/17
  74. interface GigabitEthernet 1/18
  75. interface GigabitEthernet 1/19
  76. interface GigabitEthernet 1/20
  77. interface GigabitEthernet 1/21
  78. interface GigabitEthernet 1/22
  79. interface GigabitEthernet 1/23
  80. interface Loopback 0
  81. ip address 11.168.0.1 255.255.255.255
  82. interface VLAN 1
  83. ip address 192.168.1.1 255.255.255.0
  84. ip route 10.168.0.0 255.255.255.252 10.168.0.18
  85. ip route 10.168.0.4 255.255.255.252 10.168.0.18
  86. ip route 11.168.0.204 255.255.255.255 10.168.0.18 10
  87. ip route 11.168.0.204 255.255.255.255 10.168.0.22 100
  88. ip route 11.168.0.205 255.255.255.255 10.168.0.18 10
  89. ip route 11.168.0.205 255.255.255.255 10.168.0.22 100
  90. ip route 172.16.0.0 255.255.252.0 10.168.0.18 10
  91. ip route 172.16.0.0 255.255.252.0 10.168.0.22 100
  92. ip route 192.168.10.0 255.255.255.0 10.168.0.18 10
  93. ip route 192.168.10.0 255.255.255.0 10.168.0.22 100
  94. ip route 192.168.20.0 255.255.255.0 10.168.0.18 10
  95. ip route 192.168.20.0 255.255.255.0 10.168.0.22 100
  96. ip route 192.168.30.0 255.255.255.0 10.168.0.18 10
  97. ip route 192.168.30.0 255.255.255.0 10.168.0.22 100
  98. ip route 192.168.40.0 255.255.255.0 10.168.0.18 10
  99. ip route 192.168.40.0 255.255.255.0 10.168.0.22 100
  100. ip route 192.168.60.0 255.255.255.0 10.168.0.18 10
  101. ip route 192.168.60.0 255.255.255.0 10.168.0.22 100
  102. ip route 193.168.0.0 255.255.255.252 10.168.0.18 10
  103. ip route 193.168.0.0 255.255.255.252 10.168.0.22 100
  104. ip route 194.168.0.0 255.255.0.0 10.168.0.26
  105. ip route 194.168.10.0 255.255.255.0 10.168.0.26
  106. ip route 195.168.0.0 255.255.255.0 10.168.0.42
  107. ref parameter 75 100
  108. line con 0
  109. line vty 0 4
  110. transport input ssh
  111. login local
  112. end
复制代码
R2

  1. hostname R2
  2. webmaster level 0 username admin password 7 073f07221c1c
  3. vlan 1
  4. vlan 100
  5. username admin password admin
  6. username ruijie password ruijie
  7. no service password-encryption
  8. service dhcp
  9. ip dhcp pool vlan10
  10. network 192.168.10.0 255.255.255.0
  11. default-router 192.168.10.254
  12. control-plane
  13. control-plane protocol
  14. no acpp
  15. control-plane manage
  16. no port-filter
  17. no arp-car
  18. no acpp
  19. control-plane data
  20. no glean-car
  21. no acpp  
  22. enable service ssh-server
  23. enable service web-server http
  24. enable service web-server https
  25. interface Serial 2/0
  26. encapsulation PPP
  27. ppp authentication chap
  28. ip address 10.168.0.18 255.255.255.252
  29. interface Serial 3/0
  30. encapsulation PPP
  31. ip ospf network point-to-point
  32. ip address 10.168.0.29 255.255.255.252
  33. interface FastEthernet 1/0
  34. interface FastEthernet 1/1
  35. switchport access vlan 100
  36. interface FastEthernet 1/2
  37. interface FastEthernet 1/3
  38. interface FastEthernet 1/4
  39. interface FastEthernet 1/5
  40. interface FastEthernet 1/6
  41. interface FastEthernet 1/7
  42. interface FastEthernet 1/8
  43. interface FastEthernet 1/9
  44. interface FastEthernet 1/10
  45. interface FastEthernet 1/11
  46. interface FastEthernet 1/12
  47. interface FastEthernet 1/13
  48. interface FastEthernet 1/14
  49. interface FastEthernet 1/15
  50. interface FastEthernet 1/16
  51. interface FastEthernet 1/17
  52. interface FastEthernet 1/18
  53. interface FastEthernet 1/19
  54. interface FastEthernet 1/20
  55. interface FastEthernet 1/21
  56. interface FastEthernet 1/22
  57. interface FastEthernet 1/23
  58. interface GigabitEthernet 0/0
  59. ip ospf network point-to-point
  60. ip ospf cost 5
  61. ip address 10.168.0.2 255.255.255.252
  62. duplex auto
  63. speed auto
  64. interface GigabitEthernet 0/1
  65. ip address 10.168.0.33 255.255.255.252
  66. duplex auto
  67. speed auto
  68. interface Loopback 0
  69. ip address 11.168.0.2 255.255.255.255
  70.          
  71. interface VLAN 100
  72. ip address 10.168.0.10 255.255.255.252
  73. router ospf 10
  74. redistribute static metric-type 1 subnets
  75. network 10.168.0.0 0.0.0.3 area 0
  76. network 10.168.0.8 0.0.0.3 area 1
  77. network 10.168.0.28 0.0.0.3 area 0
  78. network 11.168.0.2 0.0.0.0 area 0
  79. ip route 10.168.0.24 255.255.255.252 10.168.0.17
  80. ip route 11.168.0.1 255.255.255.255 10.168.0.17
  81. ip route 11.168.0.204 255.255.255.255 10.168.0.1
  82. ip route 11.168.0.205 255.255.255.255 10.168.0.1
  83. ip route 172.16.0.0 255.255.252.0 10.168.0.9
  84. ip route 194.168.10.0 255.255.255.0 10.168.0.34
  85. ip route 194.168.30.0 255.255.255.0 10.168.0.17
  86. ip route 195.168.0.0 255.255.255.0 10.168.0.34
  87. ref parameter 75 140
  88. line con 0
  89. line aux 0
  90. line vty 0 4
  91. transport input ssh
  92. login local
  93. end
复制代码
R3

  1. hostname R3
  2. vlan 1
  3. vlan 100
  4. username admin password admin
  5. username ruijie password ruijie
  6. no service password-encryption
  7. control-plane
  8. control-plane protocol
  9. no acpp
  10. control-plane manage
  11. no port-filter
  12. no arp-car
  13. no acpp
  14. control-plane data
  15. no glean-car
  16. no acpp
  17. enable service ssh-server
  18. enable service web-server http
  19. enable service web-server https
  20. interface Serial 2/0
  21. encapsulation PPP
  22. ppp authentication chap
  23. ip address 10.168.0.22 255.255.255.252
  24. clock rate 64000
  25. interface Serial 3/0
  26. encapsulation PPP
  27. ip ospf network point-to-point
  28. ip address 10.168.0.30 255.255.255.252
  29. clock rate 64000
  30. interface FastEthernet 1/0
  31. interface FastEthernet 1/1
  32. switchport access vlan 100
  33. interface FastEthernet 1/2
  34. interface FastEthernet 1/3
  35. interface FastEthernet 1/4
  36. interface FastEthernet 1/5
  37. interface FastEthernet 1/6
  38. interface FastEthernet 1/7
  39. interface FastEthernet 1/8
  40.          
  41. interface FastEthernet 1/9
  42. interface FastEthernet 1/10
  43. interface FastEthernet 1/11
  44. interface FastEthernet 1/12
  45. interface FastEthernet 1/13
  46. interface FastEthernet 1/14
  47. interface FastEthernet 1/15
  48. interface FastEthernet 1/16
  49. interface FastEthernet 1/17
  50. interface FastEthernet 1/18
  51. interface FastEthernet 1/19
  52. interface FastEthernet 1/20
  53.          
  54. interface FastEthernet 1/21
  55. interface FastEthernet 1/22
  56. interface FastEthernet 1/23
  57. interface GigabitEthernet 0/0
  58. ip ospf network point-to-point
  59. ip ospf cost 10
  60. ip address 10.168.0.6 255.255.255.252
  61. duplex auto
  62. speed auto
  63. interface GigabitEthernet 0/1
  64. ip address 10.168.0.37 255.255.255.252
  65. duplex auto
  66. speed auto
  67. interface Loopback 0
  68. ip address 11.168.0.3 255.255.255.255
  69. interface VLAN 100
  70. ip address 10.168.0.14 255.255.255.252
  71. router ospf 10
  72. redistribute static metric-type 1 subnets
  73. network 10.168.0.4 0.0.0.3 area 0
  74. network 10.168.0.12 0.0.0.3 area 1
  75. network 10.168.0.28 0.0.0.3 area 0
  76. network 11.168.0.3 0.0.0.0 area 0
  77. ip route 10.168.0.24 255.255.255.252 10.168.0.17
  78. ip route 10.168.0.24 255.255.255.252 10.168.0.21
  79. ip route 11.168.0.1 255.255.255.255 10.168.0.21
  80. ip route 11.168.0.204 255.255.255.255 10.168.0.5
  81. ip route 11.168.0.205 255.255.255.255 10.168.0.5
  82. ip route 172.16.0.0 255.255.252.0 10.168.0.13
  83. ip route 194.168.10.0 255.255.255.0 10.168.0.38
  84. ip route 194.168.30.0 255.255.255.0 10.168.0.21
  85. ip route 195.168.0.0 255.255.255.0 10.168.0.38
  86. ref parameter 75 140
  87. line con 0
  88. line aux 0
  89. line vty 0 4
  90. transport input ssh
  91. login local
  92. end
复制代码
AC1

  1. hostname AC1
  2. wlan-config 1 Ruijie-ZB_176
  3. ssid-code utf-8
  4. no enable-broad-ssid
  5. wlan-config 2 Ruijie-FB_176
  6. ssid-code utf-8
  7. no enable-broad-ssid
  8. tunnel local
  9. ap-group FB
  10. interface-mapping 2 20 ap-wlan-id 1
  11. ap-group ZB
  12. interface-mapping 1 60 ap-wlan-id 1
  13. ap-group default
  14. ap-config all
  15. ac-controller
  16. country CN
  17. 802.11g network rate 1 disabled
  18. 802.11g network rate 2 disabled
  19. 802.11g network rate 5 disabled
  20. 802.11g network rate 6 disabled
  21. 802.11g network rate 9 supported
  22. 802.11g network rate 11 mandatory
  23. 802.11g network rate 12 supported
  24. 802.11g network rate 18 supported
  25. 802.11g network rate 24 supported
  26. 802.11g network rate 36 supported
  27. 802.11g network rate 48 supported
  28. 802.11g network rate 54 supported
  29. 802.11b network rate 1 disabled
  30. 802.11b network rate 2 disabled
  31. 802.11b network rate 5 disabled
  32. 802.11b network rate 11 mandatory
  33. 802.11a network rate 6 disabled
  34. 802.11a network rate 9 supported
  35. 802.11a network rate 12 mandatory
  36. 802.11a network rate 18 supported
  37. 802.11a network rate 24 mandatory
  38. 802.11a network rate 36 supported
  39. 802.11a network rate 48 supported
  40. 802.11a network rate 54 supported
  41. ip dhcp snooping
  42. no identify-application enable
  43. no cwmp
  44. service dhcp
  45. ip dhcp pool Wireless
  46. network 192.168.60.0 255.255.255.0
  47. default-router 192.168.60.254
  48. install 0 WS6008
  49. sysmac c470.abe7.386b
  50. enable service web-server http
  51. enable service web-server https
  52. webmaster level 0 username admin password 7 06073a0e261b
  53. no service password-encryption
  54. redundancy
  55. link-check disable
  56. nfpp
  57. wids
  58. frn
  59. vlan 1
  60. vlan 60
  61. name Wireless
  62. vlan 100
  63. name Manage
  64. interface GigabitEthernet 0/1
  65. switchport mode trunk
  66. ip dhcp snooping trust
  67. interface GigabitEthernet 0/2
  68. interface GigabitEthernet 0/3
  69. interface GigabitEthernet 0/4
  70. interface GigabitEthernet 0/5
  71. interface GigabitEthernet 0/6
  72. interface GigabitEthernet 0/7
  73. interface GigabitEthernet 0/8
  74. interface Loopback 0
  75. ip address 11.168.0.204 255.255.255.255
  76. interface VLAN 1
  77. interface VLAN 60
  78. ip address 192.168.60.252 255.255.255.0
  79. vrrp 1 ip 192.168.60.254
  80. vrrp 1 priority 150
  81. interface VLAN 100
  82. ip address 192.168.100.2 255.255.255.0
  83. wlan hot-backup 11.168.0.205
  84. context 1
  85.   priority level 1
  86.   
  87. wlan hot-backup enable
  88. wlansec 1
  89. security rsn enable
  90. security rsn ciphers aes enable
  91. security rsn akm psk enable
  92. security rsn akm psk set-key ascii 12345678
  93. arp-check
  94. ip verify source port-security
  95. ip route 0.0.0.0 0.0.0.0 192.168.100.252
  96. line console 0
  97. line vty 0 4
  98. login
  99. end
复制代码
EG1

  1. interface GigabitEthernet 0/0
  2. ip address 192.168.1.1 255.255.255.0
  3. ip nat inside
  4. interface GigabitEthernet 0/1
  5. ip address 10.168.0.34 255.255.255.252
  6. ip nat inside
  7. interface GigabitEthernet 0/2
  8. ip address 10.168.0.38 255.255.255.252
  9. ip nat inside
  10. interface GigabitEthernet 0/3
  11. ip address 195.168.0.1 255.255.255.0
  12. crypto map mymap
  13. interface GigabitEthernet 0/4
  14. interface GigabitEthernet 0/5
  15. interface GigabitEthernet 0/6
  16. interface GigabitEthernet 0/7
  17.          
  18. interface GigabitEthernet 0/8
  19. interface GigabitEthernet 0/9
  20. interface Loopback 0
  21. ip address 11.168.0.11 255.255.255.255
  22. interface SSLVPN 0
  23. interface SSLVPN 1
  24. app route switch
  25. app route mode new-flow
  26. ip nat pool ssh prefix-length 24
  27. address 195.168.0.20 195.168.0.20 match interface GigabitEthernet 0/1
  28. ip nat outside source list 111 pool ssh
  29. ip nat inside source list 1 pool nat_pool overload
  30. ip nat inside source list 110 interface GigabitEthernet 0/3 overload
  31. ip route 10.168.0.0 255.255.255.252 10.168.0.33
  32. ip route 192.168.10.0 255.255.255.0 10.168.0.33 10
  33. ip route 192.168.10.0 255.255.255.0 10.168.0.37 100
  34. ip route 192.168.20.0 255.255.255.0 10.168.0.33 10
  35. ip route 192.168.20.0 255.255.255.0 10.168.0.37 100
  36. ip route 192.168.30.0 255.255.255.0 10.168.0.33 10
  37. ip route 192.168.30.0 255.255.255.0 10.168.0.37 100
  38. ip route 192.168.40.0 255.255.255.0 10.168.0.33 10
  39. ip route 192.168.40.0 255.255.255.0 10.168.0.37 100
  40. ip route 192.168.60.0 255.255.255.0 10.168.0.33 10
  41. ip route 192.168.60.0 255.255.255.0 10.168.0.37 100
  42. ip route 194.168.10.0 255.255.255.0 195.168.0.2
  43. line console 0
  44. line vty 0 4
  45. login
  46. end
复制代码
EG2

  1. hostname EG2
  2. vlan 1
  3. no service password-encryption
  4. ip access-list extended 110
  5. 10 permit ip 194.168.20.0 0.0.0.255 195.168.0.0 0.0.0.255 time-range working_time
  6. ip access-list extended 112
  7. 10 permit ip 194.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255
  8. control-plane
  9. control-plane protocol
  10. no acpp
  11. control-plane manage
  12. no port-filter
  13. no arp-car
  14. no acpp
  15. control-plane data
  16. no glean-car
  17. no acpp
  18. enable service web-server http
  19. enable service web-server https
  20. crypto isakmp policy 1
  21. encryption 3des
  22. authentication pre-share
  23. hash md5
  24.   
  25. crypto isakmp key 7 151b5f72467e7a address 195.168.0.1
  26. crypto ipsec transform-set myset esp-3des esp-md5-hmac
  27. crypto map mymap 1 ipsec-isakmp
  28. set peer 195.168.0.1   
  29. set transform-set myset
  30. match address 112
  31. interface FastEthernet 1/0
  32. interface FastEthernet 1/1
  33. interface FastEthernet 1/2
  34. interface FastEthernet 1/3
  35. interface FastEthernet 1/4
  36. interface FastEthernet 1/5
  37. interface FastEthernet 1/6
  38. interface FastEthernet 1/7
  39. interface FastEthernet 1/8
  40. interface FastEthernet 1/9
  41. interface FastEthernet 1/10
  42. interface FastEthernet 1/11
  43. interface FastEthernet 1/12
  44. interface FastEthernet 1/13
  45. interface FastEthernet 1/14
  46. interface FastEthernet 1/15
  47. interface FastEthernet 1/16
  48. interface FastEthernet 1/17
  49. interface FastEthernet 1/18
  50. interface FastEthernet 1/19
  51. interface FastEthernet 1/20
  52. interface FastEthernet 1/21
  53. interface FastEthernet 1/22
  54. interface FastEthernet 1/23
  55. interface GigabitEthernet 0/0
  56. ip nat outside
  57. ip address 195.168.0.2 255.255.255.0
  58. crypto map mymap
  59. duplex auto
  60. speed auto
  61. interface GigabitEthernet 0/1
  62. ip nat inside
  63. ip address 10.168.0.42 255.255.255.252
  64. duplex auto
  65. speed auto
  66. interface Loopback 0
  67. ip address 11.168.0.12 255.255.255.255
  68. ip nat inside source list 110 interface GigabitEthernet 0/0 overload
  69. ip route 10.168.0.24 255.255.255.252 10.168.0.41
  70. ip route 192.168.20.0 255.255.255.0 195.168.0.1
  71. ip route 194.168.10.0 255.255.255.0 10.168.0.41
  72. ip route 194.168.20.0 255.255.255.0 10.168.0.41
  73. ref parameter 75 140
  74. line con 0
  75. line aux 0
  76. line vty 0 4
  77. login
  78. End
复制代码
终极路由情况





免责声明:如果侵犯了您的权益,请联系站长,我们会及时删除侵权内容,谢谢合作!更多信息从访问主页:qidao123.com:ToB企服之家,中国第一个企服评测及商务社交产业平台。




欢迎光临 ToB企服应用市场:ToB评测及商务社交产业平台 (https://dis.qidao123.com/) Powered by Discuz! X3.4