
(1)VLAN間路由;(2)DHCP搭建;(3)STP協(xié)議;(4)VRRP配置;(5)ACL+NAT;(6)OSPF搭建
? 利用vlan進行業(yè)務(wù)隔離;通過stp技術(shù)來防止環(huán)路,保證冗余鏈路的正常通信;使用VRRP技術(shù)來實現(xiàn)負(fù)載分擔(dān)以及防止單點故障;利用OSPF協(xié)議使得總部和分布的網(wǎng)絡(luò)能夠正常通信;以及運用ACL和NAT對數(shù)據(jù)流進行控制和去外網(wǎng)通信。
(1)vlan間路由
接入層交換機LSW4
[LSW4]vlan 10
[LSW4-vlan10]vlan 20
[LSW4-vlan20]quit
[LSW4]int e0/0/1
[LSW4-Ethernet0/0/1]un sh
Info: Interface Ethernet0/0/1 is not shutdown.
[LSW4-Ethernet0/0/1]port link-t a
[LSW4-Ethernet0/0/1]port de vlan 10
[LSW4-Ethernet0/0/1]int e0/0/2
[LSW4-Ethernet0/0/2]port link-t a
[LSW4-Ethernet0/0/2]port de vlan 20
[LSW4-Ethernet0/0/2]int e0/0/3
[LSW4-Ethernet0/0/3]port link-t t
[LSW4-Ethernet0/0/3]port t allow vlan all
[LSW4-Ethernet0/0/3]int e0/0/4
[LSW4-Ethernet0/0/4]port link-t t
[LSW4-Ethernet0/0/4]port t allow vlan all
[LSW4-Ethernet0/0/4]quit
l 接入層交換機LSW5
與LSW4類似,創(chuàng)建VLAN,設(shè)置接口即可
[LSW5]vlan 30
[LSW5-vlan30]vlan 40
[LSW5-vlan40]quit
[LSW5]int e0/0/1
[LSW5-Ethernet0/0/1]port link-t a
[LSW5-Ethernet0/0/1]port de vlan 30
[LSW5-Ethernet0/0/1]int e0/0/2
[LSW5-Ethernet0/0/2]port link-t a
[LSW5-Ethernet0/0/2]port de vlan 40
[LSW5-Ethernet0/0/2]int e0/0/3
[LSW5-Ethernet0/0/3]port link-t t
[LSW5-Ethernet0/0/3]port t allow vlan all
[LSW5-Ethernet0/0/3]int e0/0/4
[LSW5-Ethernet0/0/4]port link-t t
[LSW5-Ethernet0/0/4]port t allow vlan all
[LSW5-Ethernet0/0/4]quit
核心層交換機LSW1
[LSW1]vlan 10
[LSW1-vlan10]vlan 20
[LSW1-vlan20]vlan 30
[LSW1-vlan30]vlan 40
[LSW1-vlan40]vlan 50
[LSW1-vlan50]quit
[LSW1]int g0/0/1[LSW1-GigabitEthernet0/0/1]port link-t t
[LSW1-GigabitEthernet0/0/1]port t allow vlan all
[LSW1-GigabitEthernet0/0/1]int g0/0/3
[LSW1-GigabitEthernet0/0/3]port link-t t
[LSW1-GigabitEthernet0/0/3]port t allow vlan all
[LSW1-GigabitEthernet0/0/3]int g0/0/2
[LSW1-GigabitEthernet0/0/2]port link-t t
[LSW1-GigabitEthernet0/0/2]port t allow vlan all
服務(wù)器接入VLAN50,將與服務(wù)器相連的接口設(shè)為Access口并綁定VLAN50
[LSW1-GigabitEthernet0/0/2]int g0/0/5
[LSW1-GigabitEthernet0/0/5]port link-t a
[LSW1-GigabitEthernet0/0/5]port de vlan 50
[LSW1-GigabitEthernet0/0/5]quit
給連接路由器的接口綁定VLAN*60,方便配置地址
[LSW1]vlan 60
[LSW1-vlan60]int g0/0/4
[LSW1-GigabitEthernet0/0/4]port