一、實(shí)驗(yàn)拓?fù)?/p>

二、實(shí)驗(yàn)需求
1.所有PC均需要通過DHCP獲取IP地址-地址池名稱和設(shè)備VLAN一致,例如PC1-ip pool vlan10,其中
只有業(yè)務(wù)B網(wǎng)絡(luò)用戶需要訪問互聯(lián)網(wǎng)web服務(wù)-需要DNS信息。
2.交換機(jī)配置VLAN需要遵循最小VLAN透?jìng)髟瓌t
3.利用OSPF協(xié)議使內(nèi)外用戶互相訪問-全網(wǎng)可達(dá)(設(shè)備Router-ID需要手工配置,和設(shè)備編號(hào)一致,例
如R1-RID:1.1.1.1),并采用精準(zhǔn)宣告的方式進(jìn)行宣告(例如:172.16.64.1/24接口,宣告:
172.16.64.1 0.0.0.0)
4.內(nèi)網(wǎng)全網(wǎng)可達(dá),并且需要盡可能減小路由表?xiàng)l目數(shù)量(匯總采用精確匯總方式),能夠利用缺省省去
的配置可省略,防止環(huán)路,并且保障安全(在OSPF區(qū)域0需要配置認(rèn)證-采用MD5認(rèn)證,密碼為123456)
5.內(nèi)網(wǎng)所有用戶均可訪問互聯(lián)網(wǎng)(邊界路由器配置NAT),ACL采用基礎(chǔ)ACL,編號(hào)為2000,R3-0/0/2
接口不允許宣告在內(nèi)網(wǎng)中(包含靜態(tài))。
6.test設(shè)備需要遠(yuǎn)程登陸到內(nèi)網(wǎng)telnet-server設(shè)備,登錄賬號(hào)為 huawei 密碼 123456,登錄權(quán)限
為最高。
7.不允許VLAN 40和VLAN 50 用戶訪問內(nèi)網(wǎng)B業(yè)務(wù),acl編號(hào)為2001,不允許PC1訪問PC5,ACL編號(hào)為
3000。
8.R3-R4中間百兆鏈路作為備份鏈路,不允許正常情況下數(shù)據(jù)通過,需要降低優(yōu)先級(jí)數(shù)值配置為100。
9.所有設(shè)備嚴(yán)格按照拓?fù)鋱D標(biāo)識(shí)進(jìn)行配置,注意大小寫。
10.圖示中所有服務(wù)器和client設(shè)備均為體現(xiàn)需求,地址固定,不做更改,在配置時(shí)需求注意。
clinet1用來模擬內(nèi)網(wǎng)用戶訪問互聯(lián)網(wǎng)(ISP-服務(wù)器),test設(shè)備用來測(cè)試互聯(lián)網(wǎng)用戶遠(yuǎn)程登陸內(nèi)網(wǎng)
telent-server主機(jī)。
三、實(shí)驗(yàn)思路
以“滿足業(yè)務(wù)需求+保障網(wǎng)絡(luò)穩(wěn)定”為核心,遵循“分層劃分、協(xié)議適配、精準(zhǔn)配置”的思路,將網(wǎng)絡(luò)按功能拆分為OSPF內(nèi)網(wǎng)區(qū)、靜態(tài)業(yè)務(wù)區(qū)、互聯(lián)網(wǎng)出口區(qū),通過子網(wǎng)規(guī)劃、路由協(xié)議配置、訪問控制策略,實(shí)現(xiàn)“全網(wǎng)可達(dá)、動(dòng)態(tài)分配、安全可控”的目標(biāo)。
子網(wǎng)與IP規(guī)劃思路:基于總網(wǎng)段 172.16.0.0/16 ,按業(yè)務(wù)類型拆分: 172.16.0.0/17 分配給OSPF內(nèi)網(wǎng)(再細(xì)分為Area 0骨干區(qū)和Area 1非骨干區(qū)), 172.16.128.0/17 分配給靜態(tài)業(yè)務(wù)B,互聯(lián)網(wǎng)出口區(qū)單獨(dú)使用 100.0.0.0/24 公有網(wǎng)段,避免地址沖突;終端設(shè)備(PC、服務(wù)器)按VLAN綁定獨(dú)立/24子網(wǎng),路由器互聯(lián)鏈路使用專屬/24子網(wǎng),確保“一鏈路一網(wǎng)段、一VLAN一地址池”,簡(jiǎn)化路由管理。
OSPF內(nèi)網(wǎng)配置思路:Router-ID手工指定為設(shè)備編號(hào)(如R1:1.1.1.1),保證唯一性;采用“精準(zhǔn)宣告”(如 172.16.64.1 0.0.0.0 ),僅發(fā)布必要接口路由,減少LSA泛洪;Area 0啟用MD5認(rèn)證(密碼123456),防止非法路由更新;非骨干區(qū)(Area 1)向骨干區(qū)做路由匯總(如 172.16.64.0 255.255.248.0 ),壓縮路由表?xiàng)l目;R3-R4百兆鏈路通過設(shè)置OSPF成本值(cost=100)降低優(yōu)先級(jí),實(shí)現(xiàn)“千兆為主、百兆備份”的鏈路冗余。
終端接入與DHCP配置思路:路由器子接口封裝802.1Q協(xié)議,與交換機(jī)VLAN一一對(duì)應(yīng)(如VLAN 10對(duì)應(yīng)子接口0/0/1.1),實(shí)現(xiàn)不同VLAN終端的隔離與互聯(lián);DHCP地址池名稱與VLAN編號(hào)一致(如VLAN 10對(duì)應(yīng)ip pool vlan10),自動(dòng)分配IP、網(wǎng)關(guān)、DNS,僅業(yè)務(wù)B區(qū)域終端配置DNS信息,滿足互聯(lián)網(wǎng)訪問需求。
訪問控制與互聯(lián)網(wǎng)訪問思路:邊界路由器R3配置NAT(PAT模式),通過ACL 2000允許內(nèi)網(wǎng)網(wǎng)段(172.16.0.0/17、172.16.128.0/17)訪問互聯(lián)網(wǎng),R3互聯(lián)網(wǎng)接口(0/0/2)不參與OSPF宣告,避免外網(wǎng)路由侵入;用ACL 2001禁止VLAN 40/50(172.16.0.0/24、172.16.1.0/24)訪問業(yè)務(wù)B區(qū)域,ACL 3000精準(zhǔn)禁止PC1(172.16.64.254)訪問PC5(172.16.128.254),實(shí)現(xiàn)細(xì)粒度訪問控制。
遠(yuǎn)程登錄配置思路:Telnet-server啟用本地認(rèn)證,創(chuàng)建最高權(quán)限賬號(hào)(huawei/123456),開放VTY線路(0-4)支持多用戶并發(fā)登錄;借助NAT映射,互聯(lián)網(wǎng)test設(shè)備(100.0.0.2)通過R3公網(wǎng)IP(100.0.0.1)遠(yuǎn)程登錄內(nèi)網(wǎng)Telnet-server,驗(yàn)證跨網(wǎng)段訪問能力。
驗(yàn)證思路:按“基礎(chǔ)連通性→功能驗(yàn)證→異常測(cè)試”分步驗(yàn)證:先確認(rèn)PC動(dòng)態(tài)獲取IP、路由器鄰居狀態(tài)FULL;再測(cè)試內(nèi)網(wǎng)互訪、互聯(lián)網(wǎng)訪問、ACL過濾效果;最后斷開主鏈路驗(yàn)證備份鏈路切換,確保所有需求達(dá)標(biāo)。
四、實(shí)驗(yàn)驗(yàn)收
R1
[R1]display current-configuration
[V200R003C00]
sysname R1
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
dhcp enable
acl number 3000
rule 5 deny ip source 172.16.64.254 0 destination 172.16.128.254 0
ip pool vlan10
gateway-list 172.16.64.1
network 172.16.64.0 mask 255.255.255.0
ip pool vlan20
gateway-list 172.16.65.1
network 172.16.65.0 mask 255.255.255.0
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0`8bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.67.1 255.255.255.0
interface GigabitEthernet0/0/1
traffic-filter inbound acl 3000
interface GigabitEthernet0/0/1.1
dot1q termination vid 10
ip address 172.16.64.1 255.255.255.0
arp broadcast enable
dhcp select global
interface GigabitEthernet0/0/1.2
dot1q termination vid 20
ip address 172.16.65.1 255.255.255.0
arp broadcast enable
dhcp select global
interface GigabitEthernet0/0/1.3
dot1q termination vid 30
ip address 172.16.66.1 255.255.255.0
arp broadcast enable
dhcp select global
interface GigabitEthernet0/0/2
interface NULL0
ospf 1 router-id 1.1.1.1
silent-interface GigabitEthernet0/0/1.1
silent-interface GigabitEthernet0/0/1.2
silent-interface GigabitEthernet0/0/1.3
area 0.0.0.0
area 0.0.0.1
network 172.16.64.0 0.0.0.0
network 172.16.64.1 0.0.0.0
network 172.16.65.0 0.0.0.0
network 172.16.65.1 0.0.0.0
network 172.16.66.0 0.0.0.0
network 172.16.66.1 0.0.0.0
network 172.16.67.0 0.0.0.0
network 172.16.67.0 0.0.0.255
ip route-static 172.16.0.0 255.255.255.0 172.16.67.2
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
return
R2
<R2>display current-configuration
[V200R003C00]
sysname R2
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
dhcp enable
ip pool vlan40
gateway-list 172.16.0.1
network 172.16.0.0 mask 255.255.255.0
ip pool vlan50
gateway-list 172.16.1.1
network 172.16.1.0 mask 255.255.255.0
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0`8bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.67.2 255.255.255.0
interface GigabitEthernet0/0/1
interface GigabitEthernet0/0/1.1
dot1q termination vid 40
ip address 172.16.0.1 255.255.255.0
arp broadcast enable
dhcp select global
interface GigabitEthernet0/0/1.2
dot1q termination vid 50
ip address 172.16.1.1 255.255.255.0
arp broadcast enable
dhcp select global
interface GigabitEthernet0/0/2
ip address 172.16.2.1 255.255.255.0
interface NULL0
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 172.16.0.0 0.0.0.0
network 172.16.1.0 0.0.0.0
network 172.16.2.0 0.0.0.0
area 0.0.0.1
abr-summary 172.16.64.0 255.255.192.0
network 172.16.67.0 0.0.0.0
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
return
R3
<R3>display current-configuration
[V200R003C00]
sysname R3
board add 0/4 2FE
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
acl number 2000
rule 5 permit source 172.16.0.0 0.0.255.255
acl number 2001
rule 5 deny source 172.16.0.0 0.0.0.255
rule 10 deny source 172.16.1.0 0.0.0.255
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0`8bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface Ethernet4/0/0
ip address 172.16.130.1 255.255.255.0
interface Ethernet4/0/1
interface GigabitEthernet0/0/0
ip address 172.16.2.2 255.255.255.0
traffic-filter inbound acl 2001
interface GigabitEthernet0/0/1
ip address 172.16.129.1 255.255.255.0
interface GigabitEthernet0/0/2
nat server protocol tcp global current-interface telnet inside 172.16.66.254 te
lnet
nat outbound 2000
interface NULL0
ospf 1 router-id 3.3.3.3
default-route-advertise always
area 0.0.0.0
authentication-mode md5 1 cipher %x~gHKYL.p2_LBy"9FIIS[Qz/%
network 172.16.2.2 0.0.0.0
ip route-static 172.16.128.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.128.0 255.255.255.0 172.16.129.2
ip route-static 172.16.131.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.132.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.132.0 255.255.255.0 172.16.129.2
ip route-static 172.16.133.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.133.0 255.255.255.0 172.16.129.2
ip route-static 172.16.134.0 255.255.255.0 172.16.130.2 preference 100
ip route-static 172.16.134.0 255.255.255.0 172.16.129.2
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
return
R4
<R4>display current-configuration
[V200R003C00]
sysname R4
board add 0/4 2FE
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0`8bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface Ethernet4/0/0
ip address 172.16.130.2 255.255.255.0
interface Ethernet4/0/1
interface GigabitEthernet0/0/0
ip address 172.16.129.2 255.255.255.0
interface GigabitEthernet0/0/1
ip address 172.16.131.1 255.255.255.0
interface GigabitEthernet0/0/2
ip address 172.16.132.1 255.255.255.0
interface NULL0
ip route-static 0.0.0.0 0.0.0.0 172.16.129.1
ip route-static 0.0.0.0 0.0.0.0 172.16.130.1 preference 100
ip route-static 172.16.128.0 255.255.255.0 172.16.132.2
ip route-static 172.16.128.0 255.255.255.0 172.16.131.2
ip route-static 172.16.133.0 255.255.255.0 172.16.131.2
ip route-static 172.16.134.0 255.255.255.0 172.16.132.2
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
return
R5
<R5>display current-configuration
[V200R003C00]
sysname R5
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0`8bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.130.2 255.255.255.0
interface GigabitEthernet0/0/1
ip address 172.16.133.1 255.255.255.0
interface GigabitEthernet0/0/2
interface NULL0
ip route-static 0.0.0.0 0.0.0.0 172.16.131.1
ip route-static 172.16.128.0 255.255.255.0 172.16.133.2
ip route-static 172.16.134.0 255.255.255.0 172.16.133.2
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
return
R6
<Huawei>display current-configuration
[V200R003C00]
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0`8bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
interface GigabitEthernet0/0/1
interface GigabitEthernet0/0/2
interface NULL0
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
return
R7
<R7>display current-configuration
[V200R003C00]
sysname R7
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
dhcp enable
ip pool vlan60
gateway-list 172.16.128.1
network 172.16.128.0 mask 255.255.255.128
dns-list 172.16.128.126
ip pool vlan70
gateway-list 172.16.128.129
network 172.16.128.128 mask 255.255.255.128
dns-list 172.16.128.126
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0`8bmE3Uw}%
local-user admin service-type http
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.133.2 255.255.255.0
interface GigabitEthernet0/0/1
ip address 172.16.134.2 255.255.255.0
interface GigabitEthernet0/0/2
interface GigabitEthernet0/0/2.1
dot1q termination vid 60
ip address 172.16.28.1 255.255.255.128
arp broadcast enable
dhcp select global
interface GigabitEthernet0/0/2.2
dot1q termination vid 70
ip address 172.16.128.129 255.255.255.128
arp broadcast enable
dhcp select global
interface NULL0
ip route-static 0.0.0.0 0.0.0.0 172.16.133.1
ip route-static 0.0.0.0 0.0.0.0 172.16.134.1
ip route-static 172.16.0.0 255.255.192.0 NULL0
ip route-static 172.16.64.0 255.255.192.0 NULL0
ip route-static 172.16.131.0 255.255.255.0 172.16.133.1
ip route-static 172.16.132.0 255.255.255.0 172.16.134.1
user-interface con 0
authentication-mode password
user-interface vty 0 4
user-interface vty 16 20
wlan ac
return
SW1
<SW1>display current-configuration
sysname SW1
vlan batch 10 20 30
cluster enable
ntdp enable
ndp enable
drop illegal-mac alarm
diffserv domain default
drop-profile default
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Vlanif1
interface MEth0/0/1
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10 20 30
interface GigabitEthernet0/0/2
port link-type access
port default vlan 10
interface GigabitEthernet0/0/3
port link-type access
port default vlan 20
interface GigabitEthernet0/0/4
port link-type access
port default vlan 30
interface GigabitEthernet0/0/5
interface GigabitEthernet0/0/6
interface GigabitEthernet0/0/7
interface GigabitEthernet0/0/8
interface GigabitEthernet0/0/9
interface GigabitEthernet0/0/10
interface GigabitEthernet0/0/11
interface GigabitEthernet0/0/12
interface GigabitEthernet0/0/13
interface GigabitEthernet0/0/14
interface GigabitEthernet0/0/15
interface GigabitEthernet0/0/16
interface GigabitEthernet0/0/17
interface GigabitEthernet0/0/18
interface GigabitEthernet0/0/19
interface GigabitEthernet0/0/20
interface GigabitEthernet0/0/21
interface GigabitEthernet0/0/22
interface GigabitEthernet0/0/23
interface GigabitEthernet0/0/24
interface NULL0
user-interface con 0
user-interface vty 0 4
return
SW2
<SW2>display current-configuration
sysname SW2
vlan batch 40 50
cluster enable
ntdp enable
ndp enable
drop illegal-mac alarm
diffserv domain default
drop-profile default
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Vlanif1
interface MEth0/0/1
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 40 50
interface GigabitEthernet0/0/2
port link-type access
port default vlan 40
interface GigabitEthernet0/0/3
port link-type access
port default vlan 50
interface GigabitEthernet0/0/4
interface GigabitEthernet0/0/5
interface GigabitEthernet0/0/6
interface GigabitEthernet0/0/7
interface GigabitEthernet0/0/8
interface GigabitEthernet0/0/9
interface GigabitEthernet0/0/10
interface GigabitEthernet0/0/11
interface GigabitEthernet0/0/12
interface GigabitEthernet0/0/13
interface GigabitEthernet0/0/14
interface GigabitEthernet0/0/15
interface GigabitEthernet0/0/16
interface GigabitEthernet0/0/17
interface GigabitEthernet0/0/18
interface GigabitEthernet0/0/19
interface GigabitEthernet0/0/20
interface GigabitEthernet0/0/21
interface GigabitEthernet0/0/22
interface GigabitEthernet0/0/23
interface GigabitEthernet0/0/24
interface NULL0
user-interface con 0
user-interface vty 0 4
return
SW3
<SW3>display current-configuration
sysname SW3
vlan batch 60 70
cluster enable
ntdp enable
ndp enable
drop illegal-mac alarm
diffserv domain default
drop-profile default
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
interface Vlanif1
interface MEth0/0/1
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 60 70
interface GigabitEthernet0/0/2
port link-type access
port default vlan 70
interface GigabitEthernet0/0/3
port link-type access
port default vlan 60
interface GigabitEthernet0/0/4
port link-type access
port default vlan 60
interface GigabitEthernet0/0/5
interface GigabitEthernet0/0/6
interface GigabitEthernet0/0/7
interface GigabitEthernet0/0/8
interface GigabitEthernet0/0/9
interface GigabitEthernet0/0/10
interface GigabitEthernet0/0/11
interface GigabitEthernet0/0/12
interface GigabitEthernet0/0/13
interface GigabitEthernet0/0/14
interface GigabitEthernet0/0/15
interface GigabitEthernet0/0/16
interface GigabitEthernet0/0/17
interface GigabitEthernet0/0/18
interface GigabitEthernet0/0/19
interface GigabitEthernet0/0/20
interface GigabitEthernet0/0/21
interface GigabitEthernet0/0/22
interface GigabitEthernet0/0/23
interface GigabitEthernet0/0/24
interface NULL0
user-interface con 0
user-interface vty 0 4
return
telnet-server
<telnet-server>display current-configuration
[V200R003C00]
sysname telnet-server
snmp-agent local-engineid 800007DB03000000000000
snmp-agent
clock timezone China-Standard-Time minus 08:00:00
portal local-server load flash:/portalpage.zip
drop illegal-mac alarm
wlan ac-global carrier id other ac id 0
set cpu-usage threshold 80 restore 75
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password cipher %K8m.Nt84DZ}e#<0
8bmE3Uw}%$%$ local-user admin service-type http local-user huawei password cipher %$%$-~946Xa++')7nVv%$
local-user huawei privilege level 15
local-user huawei service-type telnet
firewall zone Local
priority 15
interface GigabitEthernet0/0/0
ip address 172.16.66.254 255.255.255.0
interface GigabitEthernet0/0/1
interface GigabitEthernet0/0/2
interface NULL0
ip route-static 0.0.0.0 0.0.0.0 172.16.66.1
user-interface con 0
authentication-mode password
user-interface vty 0 4
authentication-mode aaa
user-interface vty 16 20
wlan ac
return

五、實(shí)驗(yàn)心得
寫完了這個(gè)實(shí)驗(yàn),實(shí)現(xiàn)了OSPF內(nèi)網(wǎng)與靜態(tài)業(yè)務(wù)區(qū)的全網(wǎng)可達(dá),滿足“內(nèi)網(wǎng)訪問互聯(lián)網(wǎng)、遠(yuǎn)程登錄、訪問控制”等核心需求。
通過OSPF精準(zhǔn)宣告、路由匯總及MD5認(rèn)證,既減少了路由表大小,又保障了網(wǎng)絡(luò)安全性與穩(wěn)定性;備份鏈路與ACL的配置,進(jìn)一步提升了網(wǎng)絡(luò)的可靠性與可控性。實(shí)驗(yàn)過程中暴露了“協(xié)議參數(shù)不一致、地址池沖突”等問題,通過排查配置細(xì)節(jié)、核對(duì)規(guī)劃表得以解決,加深了對(duì)網(wǎng)絡(luò)協(xié)議原理與實(shí)操邏輯的理解。