日日操夜夜添-日日操影院-日日草夜夜操-日日干干-精品一区二区三区波多野结衣-精品一区二区三区高清免费不卡

公告:魔扣目錄網(wǎng)為廣大站長提供免費收錄網(wǎng)站服務(wù),提交前請做好本站友鏈:【 網(wǎng)站目錄:http://www.ylptlb.cn 】, 免友鏈快審服務(wù)(50元/站),

點擊這里在線咨詢客服
新站提交
  • 網(wǎng)站:51998
  • 待審:31
  • 小程序:12
  • 文章:1030137
  • 會員:747

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

實驗要求:

①用戶的網(wǎng)關(guān)配置在核心交換機

②企業(yè)內(nèi)網(wǎng)劃分多個vlan ,減少廣播域大小,提高網(wǎng)絡(luò)穩(wěn)定性

③在連接移動外網(wǎng)出口配置NAT

④所有用戶均為自動獲取ip地址

⑤企業(yè)總部和分支采用VPN互聯(lián),使企業(yè)總部和分支員工可以互相訪問,并且分支可以訪問企業(yè)總部服務(wù)器

⑥在企業(yè)出口將內(nèi)網(wǎng)服務(wù)器的80端口映射出去,允許外網(wǎng)用戶訪問

7企業(yè)分支所有設(shè)備,在企業(yè)總部都可以用telnet遠(yuǎn)程管理

配置步驟:

步驟一、各設(shè)備的基礎(chǔ)ip配置

總部出口R1:

[R1]int gi 0/0/0
[R1-GigabitEthernet0/0/0]ip add 172.16.254.2 24
[R1]int gi 0/0/1
[R1-GigabitEthernet0/0/1]ip add 12.1.1.1 29
[R1]int gi 0/0/2
[R1-GigabitEthernet0/0/2]ip add 13.1.1.1 29

移動運營商R2:

[R2]int gi 0/0/0
[R2-GigabitEthernet0/0/0]ip add 12.1.1.6 29
[R2-GigabitEthernet0/0/0]q
[R2]int loop 0
[R2-LoopBack0]ip add 9.9.9.9 24
[R2]int gi0/0/1
[R2-GigabitEthernet0/0/1]ip add 7.7.7.1 24

聯(lián)通運營商R3

[R3]int gi 0/0/0
[R3-GigabitEthernet0/0/0]ip add 13.1.1.1 29
[R3]int gi 0/0/1
[R3-GigabitEthernet0/0/1]ip add 34.1.1.2 29

分支出口R4:

[R4]int gi 0/0/0
[R4-GigabitEthernet0/0/0]ip add 34.1.1.1 29
[R4]int gi 0/0/1
[R4-GigabitEthernet0/0/1]ip add 192.168.254.2 24

步驟二、總部和分支交換機vlan和trunk配置

總部接入交換機sw3:

[sw3]vlan batch 10 20 99
[sw3]int e0/0/2
[sw3-Ethernet0/0/2]port link-type access
[sw3-Ethernet0/0/2]port default vlan 10
[sw3]int e0/0/3
[sw3-Ethernet0/0/3]port link-type access
[sw3-Ethernet0/0/3]port default vlan 20
[sw3]int gi 0/0/1
[sw3-GigabitEthernet0/0/1]port link-type trunk
[sw3-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 99

總部接入交換機sw4:

[sw4]vlan batch 200 99
[sw4-vlan200]int gi 0/0/2
[sw4-GigabitEthernet0/0/2]port link-type access
[sw4-GigabitEthernet0/0/2]port default vlan 200
[sw4]int gi 0/0/1
[sw4-GigabitEthernet0/0/1]port link-type trunk
[sw4-GigabitEthernet0/0/1]port trunk allow-pass vlan 200 99

總部核心交換機sw1:

[sw1]vlan batch 10 20 200 100 99
[sw1]int gi 0/0/1
[sw1-GigabitEthernet0/0/1]port link-type trunk
[sw1-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20 99
[sw1]int gi 0/0/2
[sw1-GigabitEthernet0/0/2]port link-type trunk
[sw1-GigabitEthernet0/0/2]port trunk allow-pass vlan 200 99
[sw1]int vlanif 100
[sw1-Vlanif100]ip add 172.16.254.1 24
[sw1]int gi 0/0/3
[sw1-GigabitEthernet0/0/3]port link-type access
[sw1-GigabitEthernet0/0/3]port default vlan 100

分支接入交換機sw5:

[sw5]vlan batch 30 99
[sw5]int e0/0/1
[sw5-Ethernet0/0/1]port link-type access
[sw5-Ethernet0/0/1]port default vlan 30
[sw5]int gi 0/0/1
[sw5-GigabitEthernet0/0/1]port link-type trunk
[sw5-GigabitEthernet0/0/1]port trunk allow-pass vlan 30 99

分支接入交換機sw6;

[sw6]vlan batch 40 50 99
[sw6]int e 0/0/1
[sw6-Ethernet0/0/1]port link-type access
[sw6-Ethernet0/0/1]port default vlan 40
[sw6]int gi 0/0/2
[sw6-GigabitEthernet0/0/2]port link-type access
[sw6-GigabitEthernet0/0/2]port default vlan 50
[sw6]int gi 0/0/1
[sw6-GigabitEthernet0/0/1]port link-type trunk
[sw6-GigabitEthernet0/0/1]port trunk allow-pass vlan 40 50 99

分支核心交換機sw2:

[sw2]vlan batch 30 40 50 100 99
[sw2]int gi 0/0/2
[sw2-GigabitEthernet0/0/2]port link-type trunk
[sw2-GigabitEthernet0/0/2]port trunk allow-pass vlan 30 99
 
[sw2]int gi 0/0/3
[sw2-GigabitEthernet0/0/3]port link-type trunk
[sw2-GigabitEthernet0/0/3]port trunk allow-pass vlan 40 50 99
[sw2]int gi 0/0/1
[sw2-GigabitEthernet0/0/1]port link-type access
[sw2-GigabitEthernet0/0/1]port default vlan 100
[sw2]int vlanif 100
[sw2-Vlanif100]ip add 192.168.254.1 24

步驟三、配置vlanif接口,使不同vlan間三層互通

總部核心交換機sw1:

[sw1]int vlanif 10
[sw1-Vlanif10]ip add 10.10.10.1 24
[sw1]int vlanif 20
[sw1-Vlanif20]ip add 10.10.20.1 24
[sw1]int vlanif 200
[sw1-Vlanif200]ip add 10.10.200.1 24
[sw1]int vlanif 99
[sw1-Vlanif99]ip add 10.10.255.1 24

分支核心交換機sw2:

[sw2]int vlanif 30
[sw2-Vlanif30]ip add 10.10.30.1 24
[sw2]int vlanif 40
[sw2-Vlanif40]ip add 10.10.40.1 24
[sw2]int vlanif 50
[sw2-Vlanif50]ip add 10.10.50.1 24
[sw2]int vlanif 99
[sw2-Vlanif99]ip add 10.10.254.2 24

總部接入sw3:

[sw3]int vlanif 99
[sw3-Vlanif99]ip add 10.10.255.3 24

總部接入sw4:

[sw4]int vlanif 99
[sw4-Vlanif99]ip add 10.10.255.4 24

分支接入sw5:

[sw5]int vlanif 99
[sw5-Vlanif99]ip add 10.10.254.5 24

分支接入sw6:

[sw6]int vlanif 99
[sw6-Vlanif99]ip add 10.10.254.6 24

步驟四、核心交換機上配置DHCP,使客戶pc可以自動獲取到ip地址

總部核心交換機sw1:

[sw1]ip pool 10
 
[sw1-ip-pool-10]gateway 10.10.10.1
[sw1-ip-pool-10]network 10.10.10.0 mask 24
[sw1-ip-pool-10]DNS-list 114.114.114.114 8.8.8.8
[sw1]ip pool 20
 
[sw1-ip-pool-20]gateway 10.10.20.1
[sw1-ip-pool-20]network 10.10.20.0 mask 24
[sw1-ip-pool-20]dns-list 114.114.114.114 8.8.8.8
[sw1]int vlanif 10
[sw1-Vlanif10]dhcp select gl
[sw1-Vlanif10]dhcp select global
[sw1]int vlanif 20
[sw1-Vlanif20]dhcp select glo
[sw1-Vlanif20]dhcp select global

查看:

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

分支核心交換機sw2:

[sw2]int vlanif 30        
[sw2-Vlanif30]dhcp select global
[sw2]int vlanif 40 
[sw2-Vlanif40]dhcp select global
[sw2]int vlanif 30        
[sw2-Vlanif30]dhcp select global
[sw2]int vlanif 40 
[sw2-Vlanif40]dhcp select global
[sw2]int vlanif 30        
[sw2-Vlanif30]dhcp select global
[sw2]int vlanif 40 
[sw2-Vlanif40]dhcp select global

查看:

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

步驟五、在連接移動外網(wǎng)出口路由器上配置NAT地址轉(zhuǎn)換

總部出口路由器R1:

[R1]int gi 0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000//移動外網(wǎng)
[R1]int gi 0/0/2
[R1-GigabitEthernet0/0/2]nat outbound 2000//聯(lián)通外網(wǎng)
[R1]int gi 0/0/1
[R1-GigabitEthernet0/0/1]nat outbound 2000//移動外網(wǎng)
[R1]int gi 0/0/2
[R1-GigabitEthernet0/0/2]nat outbound 2000//聯(lián)通外網(wǎng)

分支出口R4:

[R4]int gi 0/0/0
[R4-GigabitEthernet0/0/0]nat outbound 2000
[R4]int gi 0/0/0
[R4-GigabitEthernet0/0/0]nat outbound 2000

步驟六、出口和運營商路由

移動運營商R2:

[R2]ip route-static 0.0.0.0 0 12.1.1.1

總部出口路由器R1:

[R1]ip route-static 0.0.0.0 0 12.1.1.6//移動外網(wǎng)
[R1]ip route-static 0.0.0.0 0 13.1.1.2 //聯(lián)通外網(wǎng)(vpn備份)

分支出口路由器R4:

[R4]ip route-static 0.0.0.0 0 34.1.1.2//聯(lián)通外網(wǎng)

步驟七、企業(yè)內(nèi)部運行ospf協(xié)議

總部核心交換機sw1:

[sw1]ospf 1 router-id 1.1.1.1
[sw1-ospf-1]area 0
[sw1-ospf-1-area-0.0.0.0]net 10.10.10.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]net 10.10.20.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]net 10.10.200.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]net 172.16.254.1 0.0.0.0
[sw1-ospf-1-area-0.0.0.0]net 10.10.255.0 0.0.0.255//宣告telnet管理網(wǎng)段

總部出口路由器R1:

[R1]ospf 1 router-id 2.2.2.2
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]net 172.16.254.2 0.0.0.0
[R1-ospf-1-area-0.0.0.0]net10.10.14.0 0.0.0.255
[R1]ospf 1
[R1-ospf-1]default-route-advertise always//引入缺省路由

分部核心交換機sw2:

[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]net 192.168.254.2 0.0.0.0
[R4-ospf-1-area-0.0.0.0]net 10.10.14.0 0.0.0.255

分支出口路由器R4:

[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]net 192.168.254.2 0.0.0.0
[R4-ospf-1-area-0.0.0.0]net 10.10.14.0 0.0.0.255

步驟八、企業(yè)總部和分支之間采用vpn通信,這里我們用GRE VPN配置

① 總部出口和分支出口路由器,配置缺省路由,使得兩邊的公網(wǎng)地址可以ping通(這些配置以上都配好了,這里重新展示一下)

總部出口路由器R1:

[R1]ip route-static 10.10.0.0 16 10.10.14.4

分支出口路由器R4:

[R4]ip route-static 0.0.0.0 0 34.1.1.2//聯(lián)通外網(wǎng)

查看是否ping通:

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

② 配置vpn

總部出口路由器R1:

[R1]ip route-static 10.10.0.0 16 10.10.14.4

分支出口路由器R4:

[R4]ip route-static 10.10.0.0  16 10.10.14.1

③ 配置vpn tunnel靜態(tài)路由

總部出口路由器R1:

[R1]ip route-static 10.10.0.0 16 10.10.14.4

分支出口路由器R4:

[R4]ip route-static 10.10.0.0  16 10.10.14.1

④ 查看

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 


案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 


案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

⑤ 驗證vpn是否連通,pc1 ping PC4

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

這里順便抓一個GRE的報文,讓大家看看報文長得什么樣子?

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

步驟九:把企業(yè)總部內(nèi)網(wǎng)web服務(wù)器的80端口映射出去,使外網(wǎng)可以訪問公司的www服務(wù)器,我們在連接移動外網(wǎng)的出口路由器R1上配

①出口R1:

[sw2]telnet server enable
 
[sw2]aaa
[sw2-aaa]local-user huawei privilege level 3 password cipher huawei@123
[sw2-aaa]local-user huawei service-type telnet
 
[sw2]user-interface vty 0 4
[sw2-ui-vty0-4]authentication-mode aaa
[sw2-ui-vty0-4]protocol inbound telnet

查看:

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

②分支員工訪問企業(yè)總部的服務(wù)器,可以直接用服務(wù)器的私有ip地址訪問即可

查看:

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

步驟十、企業(yè)分支所有設(shè)備,在企業(yè)總部都可以用telnet遠(yuǎn)程管理

① 開啟telnet命令

接入sw3:

[R1]telnet server enable
 
[R1]aaa
[R1-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R1-aaa]local-user huawei service-type telnet
 
[R1]user-interface vty 0 4
[R1-ui-vty0-4]authentication-mode aaa
[R1-ui-vty0-4]protocol inbound telnet

接入sw4:

[R4]telnet server enable

接入sw5:

[R4]aaa
[R4-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R4-aaa]local-user huawei service-type telnet
 
[R4]user-interface vty 0 4
[R4-ui-vty0-4]authentication-mode aaa
[R4-ui-vty0-4]protocol inbound telnet

接入sw6:

[R4]aaa
[R4-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R4-aaa]local-user huawei service-type telnet
 
[R4]user-interface vty 0 4
[R4-ui-vty0-4]authentication-mode aaa
[R4-ui-vty0-4]protocol inbound telnet

總部核心sw1:

[R4]aaa
[R4-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R4-aaa]local-user huawei service-type telnet
 
[R4]user-interface vty 0 4
[R4-ui-vty0-4]authentication-mode aaa
[R4-ui-vty0-4]protocol inbound telnet

分支核心sw2:

[R4]aaa
[R4-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R4-aaa]local-user huawei service-type telnet
 
[R4]user-interface vty 0 4
[R4-ui-vty0-4]authentication-mode aaa
[R4-ui-vty0-4]protocol inbound telnet

企業(yè)總部出口R1:

[R4]aaa
[R4-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R4-aaa]local-user huawei service-type telnet
 
[R4]user-interface vty 0 4
[R4-ui-vty0-4]authentication-mode aaa
[R4-ui-vty0-4]protocol inbound telnet

分支出口R4:

[R4]aaa
[R4-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R4-aaa]local-user huawei service-type telnet
 
[R4]user-interface vty 0 4
[R4-ui-vty0-4]authentication-mode aaa
[R4-ui-vty0-4]protocol inbound telnet
[R4]aaa
[R4-aaa]local-user huawei privilege level 3 password cipher huawei@123
[R4-aaa]local-user huawei service-type telnet
 
[R4]user-interface vty 0 4
[R4-ui-vty0-4]authentication-mode aaa
[R4-ui-vty0-4]protocol inbound telnet

② 總部和分支接入交換機配一條到核心交換機的回包路由

總部接入交換機:

[R4]telnet server enable

分支接入交換機:

[sw5]ip route-static 0.0.0.0 0 10.10.254.2
[sw6]ip route-static 0.0.0.0 0 10.10.254.2

查看:

案例:企業(yè)網(wǎng)遠(yuǎn)程接入V P N綜合實驗

 

 

分享到:
標(biāo)簽:VPN
用戶無頭像

網(wǎng)友整理

注冊時間:

網(wǎng)站:5 個   小程序:0 個  文章:12 篇

  • 51998

    網(wǎng)站

  • 12

    小程序

  • 1030137

    文章

  • 747

    會員

趕快注冊賬號,推廣您的網(wǎng)站吧!
最新入駐小程序

數(shù)獨大挑戰(zhàn)2018-06-03

數(shù)獨一種數(shù)學(xué)游戲,玩家需要根據(jù)9

答題星2018-06-03

您可以通過答題星輕松地創(chuàng)建試卷

全階人生考試2018-06-03

各種考試題,題庫,初中,高中,大學(xué)四六

運動步數(shù)有氧達(dá)人2018-06-03

記錄運動步數(shù),積累氧氣值。還可偷

每日養(yǎng)生app2018-06-03

每日養(yǎng)生,天天健康

體育訓(xùn)練成績評定2018-06-03

通用課目體育訓(xùn)練成績評定