为了方便后期维护和故障定位及网络的规范性,需要对网络设备进行规范化命名。
请根据Figure 3-1实验考试拓扑对设备进行命名。
命名规则为:城市-设备的设置地点-设备的功能属性和序号-设备型号。
例如::处于杭州校园的核心层路由器,命名为:HZ-HZXiaoYuan-Core01-AR6140。
请注意大小写,务必与Figure3-1实验考试拓扑保持一致。
HZ-HZXiaoYuan-Agg01-S5731
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZXiaoYuan-Agg01-S5731
[HZ-HZXiaoYuan-Agg01-S5731]
HZ-HZXiaoYuan-Agg02-S5731
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZXiaoYuan-Agg02-S5731
[HZ-HZXiaoYuan-Agg02-S5731]
HZ-HZXiaoYuan-Acc02-S5731
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZXiaoYuan-Acc02-S5731
[HZ-HZXiaoYuan-Acc02-S5731]
HZ-HZXiaoYuan-Acc01-S5731
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZXiaoYuan-Acc01-S5731
[HZ-HZXiaoYuan-Acc01-S5731]
HZ-HZXiaoYuan-Core01-AR6140
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZXiaoYuan-Core01-AR6140
[HZ-HZXiaoYuan-Core01-AR6140]
HZ-HZXiaoYuan-Core02-AR6140
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZXiaoYuan-Core02-AR6140
[HZ-HZXiaoYuan-Core02-AR6140]
HZ-HZXiaoYuan-Edge01-AR6140
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZXiaoYuan-Edge01-AR6140
[HZ-HZXiaoYuan-Edge01-AR6140]
SH-SHXiaoYuan-Edge01-AR6140
<Huawei>undo t m
<Huawei>sy
[Huawei]sy SH-SHXiaoYuan-Edge01-AR6140
[SH-SHXiaoYuan-Edge01-AR6140]
HZ-HZEDU-Edge01-AR6140
<Huawei>undo t m
<Huawei>sy
[Huawei]sy HZ-HZEDU-Edge01-AR6140
[HZ-HZEDU-Edge01-AR6140]
校园网中用户密度极大,在学生上网的高峰时段,会产生大量的网络流量。为了保证汇聚层链路的稳定性,在不升级硬件设备的前提下最大限度的提升带宽。在Agg01与Agg02之间配置链路聚合。请通过手工模式实现二层链路聚合,成员接口为GE0/0/21、GE0/0/22、GEO/0/23,聚合组ID为1。
HZ-HZXiaoYuan-Agg01-S5731
[HZ-HZXiaoYuan-Agg01-S5731]int Eth-Trunk 1
[HZ-HZXiaoYuan-Agg01-S5731-Eth-Trunk1]t
[HZ-HZXiaoYuan-Agg01-S5731-Eth-Trunk1]trunkport g0/0/21
[HZ-HZXiaoYuan-Agg01-S5731-Eth-Trunk1]trunkport g0/0/22
[HZ-HZXiaoYuan-Agg01-S5731-Eth-Trunk1]trunkport g0/0/23
HZ-HZXiaoYuan-Agg02-S5731
[HZ-HZXiaoYuan-Agg02-S5731]int Eth-Trunk 1
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]t
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]trunkport g0/0/21
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]trunkport g0/0/22
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]trunkport g0/0/23
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]
为了确保网络的稳定与安全,避免二层网络过大可能带来的问题,在本网络中进行VLAN的规划部署。
请根据Figure 3-1实验考试拓扑和Table 3-1 VLAN信息,在对应交换机上配置所需的VLAN。
注意:为了保证网络的连通性,交换机只允许题目中规定的VLAN通过。
[HZ-HZXiaoYuan-Agg01-S5731]
[HZ-HZXiaoYuan-Agg01-S5731]v b 1 10 20 100
[HZ-HZXiaoYuan-Agg01-S5731]int g0/0/1
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/1]port link-type trunk
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/1]int g0/0/3
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/3]port link-type trunk
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/3]int g0/0/24
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/24]port link-type access
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/24]port default vlan 100
[HZ-HZXiaoYuan-Agg01-S5731-GigabitEthernet0/0/24]int et 1
[HZ-HZXiaoYuan-Agg01-S5731-Eth-Trunk1]port link-type trunk
[HZ-HZXiaoYuan-Agg01-S5731-Eth-Trunk1]po t a v 10 20
[HZ-HZXiaoYuan-Agg01-S5731-Eth-Trunk1]
[HZ-HZXiaoYuan-Agg02-S5731]
[HZ-HZXiaoYuan-Agg02-S5731]v b 10 20 101
[HZ-HZXiaoYuan-Agg02-S5731]int g0/0/2
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/2]port link-t t
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/2]po t a v 10 20
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/2]int g0/0/4
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/4]po link-t t
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/4]po t a v 10 20
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/4]int g0/0/24
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/24]po link-t a
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/24]po de v 101
[HZ-HZXiaoYuan-Agg02-S5731-GigabitEthernet0/0/24]int et 1
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]po link-t t
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]po t a v 10 20
[HZ-HZXiaoYuan-Agg02-S5731-Eth-Trunk1]
[HZ-HZXiaoYuan-Acc01-S5731]v b 10 20
[HZ-HZXiaoYuan-Acc01-S5731]int g0/0/3
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/3]po link-t t
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/3]po t a v 10 20
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/3]int g0/0/4
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/4]po link-t t
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/4]po t a v 10 20
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/4]int g0/0/24
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/24]po link-t h
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/24]port hybrid pvid vlan 20
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/24]port hybrid untagged vlan 20
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/24]
[HZ-HZXiaoYuan-Acc02-S5731]v b 10 20
[HZ-HZXiaoYuan-Acc02-S5731]int g0/0/1
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/1]po link-t t
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/1]po t a v 10 20
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/1]int g0/0/2
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/2]po link-t t
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/2]po t a v 10 20
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/2]int g0/0/23
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/23]po link-t a
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/23]po de v 10
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/23]int g0/0/24
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/24]po link-t a
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/24]po de v 10
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/24]
请根据Figure 3-1实验考试拓扑和Table 3-2 IP地址规划给出的信息,配置对应网络设备接口的IP地址。
[HZ-HZXiaoYuan-Edge01-AR6140]int g0/0/0
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/0]ip ad 10.1.12.1 24
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/0]int g0/0/1
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/1]ip ad 10.1.13.1 24
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/1]int g0/0/2
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/2]ip ad 10.1.15.1 24
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/2]int s 4/0/0
[HZ-HZXiaoYuan-Edge01-AR6140-Serial4/0/0]ip ad 10.2.15.1 24
[HZ-HZXiaoYuan-Edge01-AR6140-Serial4/0/0]int lo 0
[HZ-HZXiaoYuan-Edge01-AR6140-LoopBack0]ip ad 10.1.1.1 32
[HZ-HZXiaoYuan-Edge01-AR6140-LoopBack0]
[HZ-HZXiaoYuan-Core01-AR6140]int g0/0/0
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/0]ip ad 10.1.12.2 24
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/0]int g0/0/1
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/1]ip ad 10.1.26.2 24
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/1]int g0/0/2
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/2]ip ad 10.1.23.2 24
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/2]int lo 0
[HZ-HZXiaoYuan-Core01-AR6140-LoopBack0]ip ad 10.1.2.2 32
[HZ-HZXiaoYuan-Core01-AR6140-LoopBack0]
[HZ-HZXiaoYuan-Core02-AR6140]int g0/0/0
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/0]ip ad 10.1.37.3 24
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/0]int g0/0/1
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/1]ip ad 10.1.13.3 24
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/1]int g0/0/2
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/2]ip ad 10.1.23.3 24
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/2]int lo 0
[HZ-HZXiaoYuan-Core02-AR6140-LoopBack0]ip ad 10.1.3.3 32
[HZ-HZXiaoYuan-Core02-AR6140-LoopBack0]
[HZ-HZEDU-Edge01-AR6140]int g0/0/0
[HZ-HZEDU-Edge01-AR6140-GigabitEthernet0/0/0]ip ad 192.168.4.254 24
[HZ-HZEDU-Edge01-AR6140-GigabitEthernet0/0/0]int s 4/0/0
[HZ-HZEDU-Edge01-AR6140-Serial4/0/0]ip ad 10.2.14.4 24
[HZ-HZEDU-Edge01-AR6140-Serial4/0/0]int lo 0
[HZ-HZEDU-Edge01-AR6140-LoopBack0]ip ad 10.1.4.4 32
[HZ-HZEDU-Edge01-AR6140-LoopBack0]
[SH-SHXiaoYuan-Edge01-AR6140]int g0/0/0
[SH-SHXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/0]ip ad 10.1.15.5 24
[SH-SHXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/0]int g0/0/1
[SH-SHXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/1]ip ad 192.168.5.254 24
[SH-SHXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/1]int lo 0
[SH-SHXiaoYuan-Edge01-AR6140-LoopBack0]ip ad 10.1.5.5 32
[SH-SHXiaoYuan-Edge01-AR6140-LoopBack0]
[HZ-HZXiaoYuan-Agg01-S5731]int v 10
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif10]ip ad 192.168.10.100 24
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif10]int v 20
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif20]ip ad 192.168.20.101 24
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif20]int v100
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif100]ip a 10.1.26.6 24
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif100]int lo 0
[HZ-HZXiaoYuan-Agg01-S5731-LoopBack0]ip ad 10.1.6.6 32
[HZ-HZXiaoYuan-Agg01-S5731-LoopBack0]
[HZ-HZXiaoYuan-Agg02-S5731]int v 10
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif10]ip ad 192.168.10.101 24
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif10]int v 20
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif20]ip ad 192.168.20.100 24
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif20]int v 101
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif101]ip ad 10.1.37.7 24
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif101]int lo 0
[HZ-HZXiaoYuan-Agg02-S5731-LoopBack0]ip ad 10.1.7.7 32
[HZ-HZXiaoYuan-Agg02-S5731-LoopBack0]
为了防止二层网络中出现环路,导致广播风暴等问题。在Acc01、Acc02、Agg01、Agg02之间配置STP协议。
[HZ-HZXiaoYuan-Agg01-S5731]stp mode rstp
[HZ-HZXiaoYuan-Agg01-S5731]stp root primary
[HZ-HZXiaoYuan-Agg02-S5731]stp mode rstp
[HZ-HZXiaoYuan-Agg02-S5731]stp root secondary
[HZ-HZXiaoYuan-Acc02-S5731]stp mode rstp
[HZ-HZXiaoYuan-Acc01-S5731]stp mode rstp
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/3] stp instance 0 cost 200000
[HZ-HZXiaoYuan-Acc02-S5731]int g0/0/24
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/24]stp edged-port enable
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/24]int g0/0/23
[HZ-HZXiaoYuan-Acc02-S5731-GigabitEthernet0/0/23]stp edged-port enable
[HZ-HZXiaoYuan-Acc01-S5731]int g0/0/24
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/24]stp edged-port enable
[HZ-HZXiaoYuan-Acc01-S5731-GigabitEthernet0/0/24]
单一网关的设置,在物理设备与链路出现故障时,会导致大量用户无法上网的情况。为了保证校园网中宿舍楼及教学楼的终端访问网络的稳定性,在校园网络的网关位置进行冗余备份配置,通过在Agg01、Agg02 上部署VRRP协议,满足上述要求。
[HZ-HZXiaoYuan-Agg01-S5731]int v 10
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif10]vrrp vrid 1 virtual-ip 192.168.10.254
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif10]int v 20
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif20]vrrp vrid 2 virtual-ip 192.168.20.254
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif20]int v10
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif10]vrrp vrid 1 priority 120
[HZ-HZXiaoYuan-Agg01-S5731-Vlanif10]vrrp vrid 1 track int g0/0/24 reduced 30
[HZ-HZXiaoYuan-Agg02-S5731]int v 10
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif10]vrrp vrid 1 virtual-ip 192.168.10.254
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif10]int v 20
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif20]vrrp vrid 2 virtual-ip 192.168.20.254
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif20]vrrp vrid 2 priority 120
[HZ-HZXiaoYuan-Agg02-S5731-Vlanif20]vrrp vrid 2 track int g0/0/24 reduced 30
为了满足校园网中众多设备之间的三层访问,且避免路由环路的出现,保证后期校园网络的扩展性,选用动态路由协议OSPF作为本校园网络的IGP。
[HZ-HZXiaoYuan-Agg01-S5731]ospf 1 r 10.1.6.6
[HZ-HZXiaoYuan-Agg01-S5731-ospf-1]a 0
[HZ-HZXiaoYuan-Agg01-S5731-ospf-1-area-0.0.0.0] network 10.1.6.6 0.0.0.0
[HZ-HZXiaoYuan-Agg01-S5731-ospf-1-area-0.0.0.0]net 192.168.10.100 0.0.0.0
[HZ-HZXiaoYuan-Agg01-S5731-ospf-1-area-0.0.0.0]net 192.168.20.101 0.0.0.0
[HZ-HZXiaoYuan-Agg01-S5731-ospf-1-area-0.0.0.0]net 10.1.26.6 0.0.0.0
[HZ-HZXiaoYuan-Agg01-S5731-ospf-1-area-0.0.0.0]
[HZ-HZXiaoYuan-Agg02-S5731] ospf 1 router-id 10.1.7.7
[HZ-HZXiaoYuan-Agg02-S5731-ospf-1]a 0
[HZ-HZXiaoYuan-Agg02-S5731-ospf-1-area-0.0.0.0] network 10.1.7.7 0.0.0.0
[HZ-HZXiaoYuan-Agg02-S5731-ospf-1-area-0.0.0.0]net 192.168.10.101 0.0.0.0
[HZ-HZXiaoYuan-Agg02-S5731-ospf-1-area-0.0.0.0]net 192.168.20.100 0.0.0.0
[HZ-HZXiaoYuan-Agg02-S5731-ospf-1-area-0.0.0.0]net 10.1.37.7 0.0.0.0
[HZ-HZXiaoYuan-Core01-AR6140] ospf 1 router-id 10.1.2.2
[HZ-HZXiaoYuan-Core01-AR6140-ospf-1]a 0
[HZ-HZXiaoYuan-Core01-AR6140-ospf-1-area-0.0.0.0] network 10.1.2.2 0.0.0.0
[HZ-HZXiaoYuan-Core01-AR6140-ospf-1-area-0.0.0.0]net 10.1.12.2 0.0.0.0
[HZ-HZXiaoYuan-Core01-AR6140-ospf-1-area-0.0.0.0]net 10.1.26.2 0.0.0.0
[HZ-HZXiaoYuan-Core01-AR6140-ospf-1-area-0.0.0.0]net 10.1.23.2 0.0.0.0
[HZ-HZXiaoYuan-Core02-AR6140]ospf 1 r 10.1.3.3
[HZ-HZXiaoYuan-Core02-AR6140-ospf-1]a 0
[HZ-HZXiaoYuan-Core02-AR6140-ospf-1-area-0.0.0.0] network 10.1.3.3 0.0.0.0
[HZ-HZXiaoYuan-Core02-AR6140-ospf-1-area-0.0.0.0]net 10.1.37.3 0.0.0.0
[HZ-HZXiaoYuan-Core02-AR6140-ospf-1-area-0.0.0.0]net 10.1.13.3 0.0.0.0
[HZ-HZXiaoYuan-Core02-AR6140-ospf-1-area-0.0.0.0]net 10.1.23.3 0.0.0.0
[HZ-HZXiaoYuan-Core02-AR6140-ospf-1-area-0.0.0.0]
[HZ-HZXiaoYuan-Edge01-AR6140] ospf 1 router-id 10.1.1.1
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1]a 1
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.1]net 10.1.15.1 0.0.0.0
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.1]q
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1]a 0
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.0] network 10.1.1.1 0.0.0.0
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.0] network 10.1.12.1 0.0.0.0
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.0]network 10.1.13.1 0.0.0.0
[SH-SHXiaoYuan-Edge01-AR6140] ospf 1 router-id 10.1.5.5
[SH-SHXiaoYuan-Edge01-AR6140-ospf-1]a 1
[SH-SHXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.1] network 10.1.5.5 0.0.0.0
[SH-SHXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.1]net 10.1.15.5 0.0.0.0
[SH-SHXiaoYuan-Edge01-AR6140-ospf-1-area-0.0.0.1]net 192.168.5.254 0.0.0.0
[HZ-HZXiaoYuan-Edge01-AR6140]int g0/0/0
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/0]ospf dr-priority 255
[HZ-HZXiaoYuan-Edge01-AR6140]int g0/0/0
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/0]ospf authentication-mode md5 1 cipher huawei
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/0]int g0/0/1
[HZ-HZXiaoYuan-Edge01-AR6140-GigabitEthernet0/0/1]ospf authentication-mode md5 1 cipher huawei
[HZ-HZXiaoYuan-Core01-AR6140]int g0/0/0
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/0]ospf authentication-mode md5 1 cipher huawei
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/0]int g0/0/2
[HZ-HZXiaoYuan-Core01-AR6140-GigabitEthernet0/0/2]ospf authentication-mode md5 1 cipher huawei
[HZ-HZXiaoYuan-Core02-AR6140]int g0/0/2
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/2]ospf authentication-mode md5 1 cipher huawei
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/2]int g0/0/1
[HZ-HZXiaoYuan-Core02-AR6140-GigabitEthernet0/0/1]ospf authentication-mode md5 1 cipher huawei
1. 为保证网络出口的安全性, HZXiaoYuan-Edge01与HZEDU-Edge01之间的PPP链路采用CHAP方式进行验证,HZEDU-Edge01作为验证方,用户名为huawei,密码为Huawei123。
2. HZ-HZXiaoYuan-Edge01-AR6140配置明细静态路由使得校园网内 PC 可以访问教育网中终端PC4所在的网段( 192.168.4.0/24 ),下一跳为HZ-HZEDU-Edge01-AR6140的S4/0/0口。HZ-HZEDU-Edge01-AR6140配置缺省路由访问校园网内部,下一跳为HZ-HZXiaoYuan-Edge01-AR6140的S4/0/0口。
[HZ-HZEDU-Edge01-AR6140]aaa
[HZ-HZEDU-Edge01-AR6140-aaa]local-user huawei password cipher Huawei123
[HZ-HZEDU-Edge01-AR6140-aaa]local-user huawei service-type ppp
[HZ-HZEDU-Edge01-AR6140-aaa]int s 4/0/0
[HZ-HZEDU-Edge01-AR6140-Serial4/0/0]ppp authentication-mode chap
[HZ-HZXiaoYuan-Edge01-AR6140]int s4/0/0
[HZ-HZXiaoYuan-Edge01-AR6140-Serial4/0/0]ppp chap password cipher Huawei123
[HZ-HZEDU-Edge01-AR6140] ip route-static 0.0.0.0 0.0.0.0 10.2.14.1
[HZ-HZXiaoYuan-Edge01-AR6140] ip route-static 192.168.4.0 255.255.255.0 10.2.14.4
为了使内网用户能够访问教育网,需要将教育网中的路由条目引入校园网,且在计算开销时最大限度的保证精确,在HZ-HZXiaoYuan-Edge01-AR6140上将静态路由引入OSPF,并设置为1类外部路由。
路由引入的命令为: Import-route <protocol> type <1/2>
[HZ-HZXiaoYuan-Edge01-AR6140]ospf
[HZ-HZXiaoYuan-Edge01-AR6140-ospf-1]import-route static type 1