路由器和交换机的综合实验⑵
2013-06-23 22:26
435 查看
上一部分说明了将基础网络拓扑搭建成功的做法,这一部分将说明各个特殊要求的配置方法
⑵ R2配置策略路由
int l0
ip add 100.0.0.1 255.255.255.0
int l1
ip add 200.0.0.1 255.255.255.0
exit
access-list 10 permit 192.168.10.0 0.0.0.255
access-list 10 permit 192.168.30.0 0.0.0.255
access-lsit 20 permit 192.168.20.0 0.0.0.255
access-list 20 permit 192.168.40.0 0.0.0.255
route-map ruijie permit 10
match ip address 10
set interface l0
match ip address 20
set interface l1
exit
int f1/0
ip policy route-map ruijie
int f1/1
ip policy route-map ruijie
exit
⑶ R2配置nat转换
access-list 99 permit 192.168.0.0 0.0.255.255
ip nat pool mudi 200.1.1.2 200.1.1.6 netmask 255.255.255.0
ip nat inside source list 99 pool mudi overload
int f1/0
ip nat inside
int f1/1
ip nat inside
int s1/0
ip nat outside
int l0
ip nat outside
int l1
ip nat outside
exit
⑷ acl配置
S1\S2:
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.40.0 0.0.0.255
time-range worktime
periodic weekdays 08:00 to 16:00
access-list 101 permit tcp 192.168.20.0 0.0.0.255 host 192.168.10.101 eq ftp time-range worktime
access-list 101 permit tcp 192.168.30.0 0.0.0.255 host 192.168.10.101 eq ftp time-range worktime
access-list 101 permit tcp 192.168.40.0 0.0.0.255 host 192.168.10.101 eq ftp time-range worktime
access-list 101 deny tcp any host 192.168.10.101 eq ftp
access-list 101 permit ip any any
int vlan 10
ip access-group 101 in
int vlan 20
ip access-group 101 in
int vlan 30
ip access-group 101 in
int vlan 40
ip access-group 101 in
exit
R2:
time-range worktime
periodic weekdays 08:00 to 16:00
exit
access-list 50 deny 192.168.0.0 0.0.255.255 time-range worktime
access-list 50 deny 172.16.0.0 0.0.255.255 time-range worktime
access-list 10 permit any
int f1/0
ip access-group 50 in
int f1/1
ip access-group 50 in
exit
OK!!!
⑵ R2配置策略路由
int l0
ip add 100.0.0.1 255.255.255.0
int l1
ip add 200.0.0.1 255.255.255.0
exit
access-list 10 permit 192.168.10.0 0.0.0.255
access-list 10 permit 192.168.30.0 0.0.0.255
access-lsit 20 permit 192.168.20.0 0.0.0.255
access-list 20 permit 192.168.40.0 0.0.0.255
route-map ruijie permit 10
match ip address 10
set interface l0
match ip address 20
set interface l1
exit
int f1/0
ip policy route-map ruijie
int f1/1
ip policy route-map ruijie
exit
⑶ R2配置nat转换
access-list 99 permit 192.168.0.0 0.0.255.255
ip nat pool mudi 200.1.1.2 200.1.1.6 netmask 255.255.255.0
ip nat inside source list 99 pool mudi overload
int f1/0
ip nat inside
int f1/1
ip nat inside
int s1/0
ip nat outside
int l0
ip nat outside
int l1
ip nat outside
exit
⑷ acl配置
S1\S2:
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.40.0 0.0.0.255
time-range worktime
periodic weekdays 08:00 to 16:00
access-list 101 permit tcp 192.168.20.0 0.0.0.255 host 192.168.10.101 eq ftp time-range worktime
access-list 101 permit tcp 192.168.30.0 0.0.0.255 host 192.168.10.101 eq ftp time-range worktime
access-list 101 permit tcp 192.168.40.0 0.0.0.255 host 192.168.10.101 eq ftp time-range worktime
access-list 101 deny tcp any host 192.168.10.101 eq ftp
access-list 101 permit ip any any
int vlan 10
ip access-group 101 in
int vlan 20
ip access-group 101 in
int vlan 30
ip access-group 101 in
int vlan 40
ip access-group 101 in
exit
R2:
time-range worktime
periodic weekdays 08:00 to 16:00
exit
access-list 50 deny 192.168.0.0 0.0.255.255 time-range worktime
access-list 50 deny 172.16.0.0 0.0.255.255 time-range worktime
access-list 10 permit any
int f1/0
ip access-group 50 in
int f1/1
ip access-group 50 in
exit
OK!!!
相关文章推荐
- 路由器和交换机的综合实验
- 路由器和交换机的综合实验(1)
- 网络Cisco实验-交换机路由器综合实验(静态路由)
- 路由器和交换机的综合实验(1)
- 路由器交换机[置顶] 路由器和交换机的综合实验⑵
- 路由器和交换机的综合实验(1)
- 实验十一 路由器综合路由配置
- cisco路由器综合实验之三 网络地址转换(NAT)
- IGP综合实验,要求末梢路由器只学到默认路由的n种解决办法
- 计算机网络原理--实验二 交换机路由器的基本配置
- 实验一:配置路由器/交换机的Telnet登录
- XFBAY网络学习=++=实验十七 交换机与路由器间的端口聚合
- VRRP;ACL;路由器远程登录的综合应用实验:
- 港湾网络设备、路由器、交换机、综合布线、机房建设、网络系统集成
- cisco路由器综合实验之 ospf在多域环境下的应用
- 实验一:配置路由器/交换机的Telnet登录
- Packet Tracer 5.2实验(十一) 路由器综合路由配置
- 港湾网络设备、路由器、交换机、综合布线、机房建设、网络系统集成
- Packet Tracer 5.2实验(十一) 路由器综合路由配置