H3c實驗室-(OSPF,Nat,STP,Dhcp,Acl)v.1)

實驗聲明

本實驗純屬學習記錄性質,如有錯誤,請大哥幫忙提出,馬上改正謝謝~
還有學習H3c心態要好,他有超級多的bug!!!!

實驗介紹

在這裏插入圖片描述

實驗條件

在這裏插入圖片描述

實驗開始

把圖設計好

先說明一下RTA-RTB的線路是Ser線,一定要他,要不然ppp協議沒法做,一切白給!!!!!
在這裏插入圖片描述

配置SWA

<H3C>sys
[H3C]sysn SWA
[SWA]vlan 10
[SWA-vlan10]port g 1/0/1
[SWA-vlan10]vlan 20
[SWA-vlan20]port g 1/0/2
[SWA-vlan20]vlan 30
[SWA-vlan30]port g 1/0/3
[SWA-vlan30]qu
[SWA]int vlan 10
[SWA-Vlan-interface10]ip add 10.1.1.2 30
[SWA-Vlan-interface10]int vlan 20
[SWA-Vlan-interface20]ip add 10.2.1.254 24
[SWA-Vlan-interface20]int vlan 30
[SWA-Vlan-interface30]ip add 10.3.1.254 24
[SWA-Vlan-interface30]qu
[SWA]stp g en
[SWAint g 1/0/2
[SWA-GigabitEthernet1/0/2]port link-type trunk
[SWA-GigabitEthernet1/0/2]port trunk per vlan all
[SWA-GigabitEthernet1/0/2]int g 1/0/3
[SWA-GigabitEthernet1/0/3]port link-type trunk
[SWA-GigabitEthernet1/0/3]port trunk per vlan all

配置SWB

<H3C>sys
System View: return to User View with Ctrl+Z.
[H3C]sysn SWB
[SWB]vlan 20
[SWB-vlan20]port g 1/0/3
[SWB-vlan20]int g 1/0/1
[SWB-GigabitEthernet1/0/1]port li
[SWB-GigabitEthernet1/0/1]port link-t
[SWB-GigabitEthernet1/0/1]port link-type t
[SWB-GigabitEthernet1/0/1]port link-type trunk
[SWB-GigabitEthernet1/0/1]port tr per vlan all
[SWB-GigabitEthernet1/0/1]int g 1/0/2
[SWB-GigabitEthernet1/0/2]port link-type trunk
[SWB-GigabitEthernet1/0/2]port tr per vlan all
[SWB-GigabitEthernet1/0/2]qu
[SWB]stp g en

配置PCA

在這裏插入圖片描述

<H3C>ping 10.2.1.254
Ping 10.2.1.254 (10.2.1.254): 56 data bytes, press CTRL_C to break
56 bytes from 10.2.1.254: icmp_seq=0 ttl=255 time=3.000 ms
56 bytes from 10.2.1.254: icmp_seq=1 ttl=255 time=2.000 ms
56 bytes from 10.2.1.254: icmp_seq=2 ttl=255 time=2.000 ms
56 bytes from 10.2.1.254: icmp_seq=3 ttl=255 time=1.000 ms
56 bytes from 10.2.1.254: icmp_seq=4 ttl=255 time=1.000 ms

--- Ping statistics for 10.2.1.254 ---

證明這時候的PCA已經vlan20了

配置SWC

<H3C>sys
[H3C]sysn SWC
[SWC]vlan 30
[SWC-vlan30]port g 1/0/3
[SWC-vlan30]int g 1/0/1
[SWC-GigabitEthernet1/0/1]port link-type trunk
[SWC-GigabitEthernet1/0/1]port t per vlan all
[SWC-GigabitEthernet1/0/1]int g 1/0/2
[SWC-GigabitEthernet1/0/2]port link-type trunk
[SWC-GigabitEthernet1/0/2]port t per vlan all
[SWC-GigabitEthernet1/0/2]qu
[SWC]stp g en

配置PCB

在這裏插入圖片描述

ping 10.2.1.1
Ping 10.2.1.1 (10.2.1.1): 56 data bytes, press CTRL_C to break
56 bytes from 10.2.1.1: icmp_seq=0 ttl=254 time=3.000 ms
56 bytes from 10.2.1.1: icmp_seq=1 ttl=254 time=2.000 ms
56 bytes from 10.2.1.1: icmp_seq=2 ttl=254 time=2.000 ms
56 bytes from 10.2.1.1: icmp_seq=3 ttl=254 time=2.000 ms
56 bytes from 10.2.1.1: icmp_seq=4 ttl=254 time=3.000 ms

--- Ping statistics for 10.2.1.1 ---

到這一步說明,配置已經非常成功了,已經讓一個地方的ping通了

配置Ospf-SWA(區域1)

[SWA]ospf
[SWA-ospf-1]a 1
[SWA-ospf-1-area-0.0.0.1]netw 10.2.1.0 0.0.0.255
[SWA-ospf-1-area-0.0.0.1]netw 10.3.1.0 0.0.0.255
[SWA-ospf-1-area-0.0.0.1]netw 10.1.1.0 0.0.0.3
[SWA-ospf-1-area-0.0.0.1]qu

配置RTA

<H3C>sys
[H3C]sysn RTA
[RTA]int g0/1
[RTA-GigabitEthernet0/1]ip add 10.1.1.1 30
[RTA-GigabitEthernet0/1]int g 0/0
[RTA-GigabitEthernet0/0]ip add 100.1.1.2 24
[RTA-GigabitEthernet0/0]int s 1/0
[RTA-Serial1/0]ip add 10.1.1.5 30
[RTA-Serial1/0]qu

配置Ospf-RTA(區域1)

[RTA]ospf
[RTA-ospf-1]area 1
[RTA-ospf-1-area-0.0.0.1]net 10.1.1.0 0.0.0.3
[RTA-ospf-1-area-0.0.0.1]qu
[RTA-ospf-1]qu

這時候PCA,PCB可以pingRTA 證明Ospf 區域1成功

ping 10.1.1.1
Ping 10.1.1.1 (10.1.1.1): 56 data bytes, press CTRL_C to break
56 bytes from 10.1.1.1: icmp_seq=0 ttl=254 time=2.000 ms
56 bytes from 10.1.1.1: icmp_seq=1 ttl=254 time=1.000 ms
56 bytes from 10.1.1.1: icmp_seq=2 ttl=254 time=1.000 ms
56 bytes from 10.1.1.1: icmp_seq=3 ttl=254 time=2.000 ms
56 bytes from 10.1.1.1: icmp_seq=4 ttl=254 time=1.000 ms

--- Ping statistics for 10.1.1.1 ---

配置RTC

<H3C>sys
[H3C]sysn RTC
[RTC]dhcp en
[RTC]dhcp server forbidden-ip 10.4.1.254
[RTC]dhcp serv ip-pool pool1
[RTC-dhcp-pool-pool1]network 10.4.1.0 24
[RTC-dhcp-pool-pool1]gateway-list 10.4.1.254
[RTC-dhcp-pool-pool1]qu
[RTC]int g 0/1
[RTC-GigabitEthernet0/1]ip add 10.4.1.254 24
[RTC-GigabitEthernet0/1]int g 0/0
[RTC-GigabitEthernet0/0]ip add 10.1.1.10 30
[RTC-GigabitEthernet0/0]qu

配置PCC

在這裏插入圖片描述

配置Ospf-RTC(區域2)

[RTC]ospf
[RTC-ospf-1]a
[RTC-ospf-1]area 2
[RTC-ospf-1-area-0.0.0.2]net 10.1.1.8 0.0.0.3
[RTC-ospf-1-area-0.0.0.2]net 10.4.1.0 0.0.0.255
[RTC-ospf-1-area-0.0.0.2]qu
[RTC-ospf-1]qu

配置RTB

<H3C>sys
[H3C]sysn RTB
[RTB]int s 1/0
[RTB-Serial1/0]ip add 10.1.1.6 30
[RTB-Serial1/0]int g 0/1
[RTB-GigabitEthernet0/1]ip add 10.1.1.9 30
[RTB-GigabitEthernet0/1]qu

配置Ospf-RTB(區域2)

[RTB]ospf
[RTB-ospf-1]a
[RTB-ospf-1]area 2
[RTB-ospf-1-area-0.0.0.2]net 10.1.1.8 0.0.0.3
[RTB-ospf-1-area-0.0.0.2]qu
[RTB-ospf-1]qu

這時候要是成功了PCC中就可以Ping到RTB

<H3C>ping 10.1.1.9
Ping 10.1.1.9 (10.1.1.9): 56 data bytes, press CTRL_C to break
56 bytes from 10.1.1.9: icmp_seq=0 ttl=254 time=1.000 ms
56 bytes from 10.1.1.9: icmp_seq=1 ttl=254 time=1.000 ms
56 bytes from 10.1.1.9: icmp_seq=2 ttl=254 time=0.000 ms
56 bytes from 10.1.1.9: icmp_seq=3 ttl=254 time=1.000 ms
56 bytes from 10.1.1.9: icmp_seq=4 ttl=254 time=2.000 ms

--- Ping statistics for 10.1.1.9 ---

配置Ospf-RTB(區域0)

[RTB]ospf
[RTB-ospf-1]a 0
[RTB-ospf-1-area-0.0.0.0]net 10.1.1.4 0.0.0.3
[RTB-ospf-1-area-0.0.0.0]qu
[RTB-ospf-1]qu

配置Ospf-RTA(區域0)

[RTA]ospf
[RTA-ospf-1]a 0
[RTA-ospf-1-area-0.0.0.0]net 10.1.1.4 0.0.0.3
[RTA-ospf-1-area-0.0.0.0]qu
[RTA-ospf-1]qu

這時候就可以去PCC電腦上Ping到PCA

[H3C]ping 10.2.1.1
Ping 10.2.1.1 (10.2.1.1): 56 data bytes, press CTRL_C to break
56 bytes from 10.2.1.1: icmp_seq=0 ttl=251 time=4.000 ms
56 bytes from 10.2.1.1: icmp_seq=1 ttl=251 time=3.000 ms
56 bytes from 10.2.1.1: icmp_seq=2 ttl=251 time=3.000 ms
56 bytes from 10.2.1.1: icmp_seq=3 ttl=251 time=2.000 ms
56 bytes from 10.2.1.1: icmp_seq=4 ttl=251 time=2.000 ms

--- Ping statistics for 10.2.1.1 ---

添加PPP協議-RTA

[RTA]local-user username class network
New local user added.
[RTA-luser-network-username]password simple password
[RTA-luser-network-username]service-type ppp
[RTA-luser-network-username]qu
[RTA]int s 1/0
[RTA-Serial1/0]ppp authentication-mode chap
[RTA-Serial1/0]qu

添加PPP協議-RTB


[RTB]int s 1/0
[RTB-Serial1/0]ppp chap user username
[RTB-Serial1/0]ppp chap password simple password
[RTB-Serial1/0]qu

這樣ppp就成功啦~~

配置Internet

<H3C>sys
[H3C]sysn Internet
[Internet]int g 0/0
[Internet-GigabitEthernet0/0]ip add 100.1.1.1 24
[Internet-GigabitEthernet0/0]int loop 1
[Internet-LoopBack1]ip add 200.1.1.1 32
[Internet-LoopBack1]qu
[Internet]ip route-static 100.1.1.0 24 100.1.1.2

Nat實現-RTA

[RTA]acl basic 2000
[RTA-acl-ipv4-basic-2000]rule 0 permit source 10.2.1.0 0.0.0.255
[RTA-acl-ipv4-basic-2000]rule 1 permit source 10.3.1.0 0.0.0.255
[RTA-acl-ipv4-basic-2000]qu
[RTA]nat add
[RTA]nat address-group 1
[RTA-address-group-1]add 100.1.1.3 100.1.1.13
[RTA-address-group-1]qu
[RTA]
[RTA]int g 0/0
[RTA-GigabitEthernet0/0]nat outbound 2000 address-group  1
[RTA-GigabitEthernet0/0]qu
[RTA]ospf
[RTA-ospf-1]default-route-advertise
[RTA-ospf-1]qu
[RTA]ip route-static 0.0.0.0 0.0.0.0 100.1.1.1

然後就能看到PCA

ping 100.1.1.2
Ping 100.1.1.2 (100.1.1.2): 56 data bytes, press CTRL_C to break
56 bytes from 100.1.1.2: icmp_seq=0 ttl=254 time=2.000 ms
56 bytes from 100.1.1.2: icmp_seq=1 ttl=254 time=1.000 ms
56 bytes from 100.1.1.2: icmp_seq=2 ttl=254 time=3.000 ms
56 bytes from 100.1.1.2: icmp_seq=3 ttl=254 time=2.000 ms
56 bytes from 100.1.1.2: icmp_seq=4 ttl=254 time=2.000 ms

--- Ping statistics for 100.1.1.2 ---

PCB

<H3C>ping 200.1.1.1
Ping 200.1.1.1 (200.1.1.1): 56 data bytes, press CTRL_C to break
56 bytes from 200.1.1.1: icmp_seq=0 ttl=253 time=3.000 ms
56 bytes from 200.1.1.1: icmp_seq=1 ttl=253 time=2.000 ms
56 bytes from 200.1.1.1: icmp_seq=2 ttl=253 time=3.000 ms
56 bytes from 200.1.1.1: icmp_seq=3 ttl=253 time=2.000 ms
56 bytes from 200.1.1.1: icmp_seq=4 ttl=253 time=2.000 ms

--- Ping statistics for 200.1.1.1 ---

PCC

ping 200.1.1.1
Ping 200.1.1.1 (200.1.1.1): 56 data bytes, press CTRL_C to break
Request time out
Request time out
Request time out
Request time out
Request time out

--- Ping statistics for 200.1.1.1 ---

ACL限制-RTC


[RTC]acl advanced 3000
[RTC-acl-ipv4-adv-3000]rule deny icmp source 10.2.1.0 0.0.0.255 destination 10.4.1.0 0.0.0.255
[RTC-acl-ipv4-adv-3000]rule deny icmp source 10.4.1.0 0.0.0.255 destination 10.2.1.0 0.0.0.255
[RTC-acl-ipv4-adv-3000]qu
[RTC]int g 0/0
[RTC-GigabitEthernet0/0]packet-filter 3000 inbound
[RTC-GigabitEthernet0/0]qu

這樣PCC就不能PingPCA,但PCC可以PingPCB

最後總結

這一篇,就是單純記錄自己學習進程,說實話H3C,模擬器太真實了,還會給我模擬線路脫落一下up,一下down。
在這裏插入圖片描述完~~謝謝觀看

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章