HCIA综合实验报告册
HCIA综合实验根据要求进行网段划分划分为172.16.0.0/24172.16.1.0/24172.16.2.0/24172.16.64.0/24172.16.65.0/24172.16.66.0/24172.16.67.0/24172.16.128.128/25172.16.128.128/25172.16.129.0/24172.16.130.0/24172.16.131.0/24172.16.132.0/24172.16.133.0/24172.16.134.0/24根据划分的网段给路由器对应接口配置IP地址Sw1的配置Sw1:system viewSw1:system name sw1Sw1:vlan batch 1 2 3Sw1:interface GigabitEthernet 0/0/2Sw1-interface GigabitEthernet 0/0/2:port link-type accessSw1-interface GigabitEthernet 0/0/2:port default vlan 1Sw1-interface GigabitEthernet 0/0/2:quitSw1:interface GigabitEthernet 0/0/3Sw1-interface GigabitEthernet 0/0/3:port link-type accessSw1-interface GigabitEthernet 0/0/3:port default vlan 2Sw1-interface GigabitEthernet 0/0/3:quitSw1:interface GigabitEthernet 0/0/4Sw1-interface GigabitEthernet 0/0/4:port link-type accessSw1-interface GigabitEthernet 0/0/4:port default vlan 3Sw1-interface GigabitEthernet 0/0/4:quitSw1:interface GigabitEthernet 0/0/1Sw1-interface GigabitEthernet 0/0/1:port link-type trunkSw1-interface GigabitEthernet 0/0/1:port trunk allow-pass vlan 1 2 3R1:VLAN配置R1:system viewR1:system name r1R1:interface GigabitEthernet 0/0/0R1-interface GigabitEthernet 0/0/0:ip address 172.16.64.1R1-interface GigabitEthernet 0/0/0:quitR1:vlan batch 1 2 3R1:interface GigabitEthernet 0/0/1.1R1-interface GigabitEthernet 0/0/1.1:ip address 172.16.65.1 24R1-interface GigabitEthernet 0/0/1.1:dotlq termination vid 1R1-interface GigabitEthernet 0/0/1.1:arp broadcast enableR1-interface GigabitEthernet 0/0/1.1:quitR1:interface GigabitEthernet 0/0/1.2R1-interface GigabitEthernet 0/0/1.2:ip address 172.16.66.1 24R1-interface GigabitEthernet 0/0/1.2:dotlq termination vid 2R1-interface GigabitEthernet 0/0/1.2:arp broadcast enableR1-interface GigabitEthernet 0/0/1.2:quitR1:interface GigabitEthernet 0/0/1.3R1-interface GigabitEthernet 0/0/1.3:ip address 172.16.67.1 24R1-interface GigabitEthernet 0/0/1.3:dotlq termination vid 3R1-interface GigabitEthernet 0/0/1.3:arp broadcast enableR1-interface GigabitEthernet 0/0/1.3:quitR1:DHCP的配置R1:dhcp enableR1:ip pool vlan1R1-ip-pool-vlan1:network 172.16.65.0 mask 24R1-ip-pool-vlan1:gateaway-list 172.16.65.1R1-ip-pool-vlan1:dns-list 114.114.114.114 8.8.8.8R1:interface GigabitEthernet 0/0/1.1R1-interface GigabitEthernet 0/0/1.1:dhcp select globalR1:ip pool vlan2R1-ip-pool-vlan1:network 172.16.66.0 mask 24R1-ip-pool-vlan1:gateaway-list 172.16.66.1R1-ip-pool-vlan1:dns-list 114.114.114.114 8.8.8.8R1:interface GigabitEthernet 0/0/1.2R1-interface GigabitEthernet 0/0/1.2:dhcp select globalR1:ip pool vlan3R1-ip-pool-vlan1:network 172.16.67.0 mask 24R1-ip-pool-vlan1:gateaway-list 172.16.67.1R1-ip-pool-vlan1:dns-list 114.114.114.114 8.8.8.8R1:interface GigabitEthernet 0/0/1.3R1-interface GigabitEthernet 0/0/1.3:dhcp select globalR2与sw2的vlan与dhcp配置过程与以上一致企业B的VLAN与DHCP的配置R7:vlan batch 6 7R7:interface GigabitEthernet 0/0/2.6R7-interface GigabitEthernet 0/0/2.6:ip address 172.16.128.1 25R7-interface GigabitEthernet 0/0/2.6:dotlq termination vid 6R7-interface GigabitEthernet 0/0/2.6:arp broadcast enableR7-interface GigabitEthernet 0/0/2.6:quitR7:interface GigabitEthernet 0/0/2.7R7-interface GigabitEthernet 0/0/2.7:ip address 172.16.128.129 25R7-interface GigabitEthernet 0/0/2.7:dotlq termination vid 7R7-interface GigabitEthernet 0/0/2.7:arp broadcast enableR7-interface GigabitEthernet 0/0/2.7:quitSw3:vlan batch 6 7Sw3:interface GigabitEthernet 0/0/2Sw3-interface GigabitEthernet 0/0/2:port link-type accessSw3-interface GigabitEthernet 0/0/2:port default vlan 7Sw3-interface GigabitEthernet 0/0/2:quitSw3:interface GigabitEthernet 0/0/3Sw3-interface GigabitEthernet 0/0/3:port link-type accessSw3-interface GigabitEthernet 0/0/3:port default vlan 6Sw3-interface GigabitEthernet 0/0/3:quitSw3:interface GigabitEthernet 0/0/4Sw4-interface GigabitEthernet 0/0/4:port link-type accessSw4-interface GigabitEthernet 0/0/4:port default vlan 6Sw4-interface GigabitEthernet 0/0/4:quitSw3:interface GigabitEthernet 0/0/1Sw3-interface GigabitEthernet 0/0/1:port link-type trunkSw3-interface GigabitEthernet 0/0/1:port trunk allow-pass vlan 6 7R7:dhcp enableR7:ip pool vlan1R7-ip-pool-vlan1:network 172.16.128.0 mask 25R1-ip-pool-vlan1:gateaway-list 172.16.128.1R7-ip-pool-vlan1:dns-list 114.114.114.114 8.8.8.8R7:interface GigabitEthernet 0/0/2.6R7-interface GigabitEthernet 0/0/2.6:dhcp select globalR7:ip pool vlan2R7-ip-pool-vlan1:network 172.16.12.129 mask 25R7-ip-pool-vlan1:gateaway-list 172.16.128.129R7-ip-pool-vlan1:dns-list 114.114.114.114 8.8.8.8R7:interface GigabitEthernet 0/0/2.7R7-interface GigabitEthernet 0/0/2.7:dhcp select global配置企业A ospf协议使得企业A全网通R1:ospf 1 router-id 1.1.1.1R1-ospf-1:area 1R1-ospf-1-area-0.0.0.1:network 172.16.64.1 0.0.0.0R1-ospf-1-area-0.0.0.1:network 172.16.65.1 0.0.0.0R1-ospf-1-area-0.0.0.1:network 172.16.66.1 0.0.0.0R1-ospf-1-area-0.0.0.1:network 172.16.67.1 0.0.0.0R1-ospf-1-area-0.0.0.1:quitR2:ospf 2 router-id 2.2.2.2R2-ospf-2:area 1R2-ospf-2-area-0.0.0.1:network 172.16.64.2 0.0.0.0R2-ospf-2-area-0.0.0.1:area 0R2-ospf-2-area-0.0.0.0:network 172.16.0.1 0.0.0.0R2-ospf-2-area-0.0.0.0:network 172.16.1.1 0.0.0.0R2-ospf-2-area-0.0.0.0:network 172.16.2.1 0.0.0.0R2-ospf-2-area-0.0.0.0:quitR3:ospf 3 router-id 3.3.3.3R3-ospf-3:area 0R3-ospf-3-area-0.0.0.0:network 172.16.0.2 0.0.0.0R2-ospf-3-area-0.0.0.0:quitR3-ospf-3:quit进行ABR汇总并进行防环R2:ospf 2R2-ospf -2:area 1R2-ospf -2-area-0.0.0.1:abr-summary 172.16.64.0 255.255.252.0R2-ospf -2-area-0.0.0.1:quitR2-ospf -2:area 0R2-ospf -2-area-0.0.0.0:abr-summary 172.16.0.0 255.255.252.0R2-ospf -2:quitR2:ip route-static 172.16.64.0 22 NULL 0配置企业B的静态路由:使得企业B全网通并进行防环R3R3:ip route-static 172.16.131.0 24 172.16.129.2R3:ip route-static 172.16.131.0 24 172.16.130.2R3:ip route-static 172.16.133.0 24 172.16.129.2R3:ip route-static 172.16.133.0 24 172.16.130.2R3:ip route-static 172.16.128.0 24 172.16.129.2R3:ip route-static 172.16.128.0 24 172.16.130.2R3:ip route-static 172.16.134.0 24 172.16.129.2R3:ip route-static 172.16.134.0 24 172.16.130.2R3:ip route-static 172.16.132.0 24 172.16.129.2R3:ip route-static 172.16.132.0 24 172.16.130.2R3:ip route-static 172.16.128.0 NULL 0R4R4:ip route-static 172.16.133.0 24 172.16.131.2R4:ip route-static 172.16.128.0 24 172.16.131.2R4:ip route-static 172.16.128.0 24 172.16.132.2R4:ip route-static 172.16.134.0 24 172.16.132.2R4:ip route-static 172.16.128.0 NULL 0R5R5:ip route-static 172.16.128.0 24 172.16.133.2R5:ip route-static 172.16.134.0 24 172.16.133.2R5:ip route-static 172.16.132.0 24 172.16.131.1R5:ip route-static 172.16.130.0 24 172.16.131.1R5:ip route-static 172.16.129.0 24 172.16.131.1R5:ip route-static 172.16.128.0 NULL 0R6R6:ip route-static 172.16.130.0 24 172.16.132.1R6:ip route-static 172.16.129.0 24 172.16.132.1R6:ip route-static 172.16.131.0 24 172.16.132.1R6:ip route-static 172.16.133.0 24 172.16.134.2R6:ip route-static 172.16.128.0 24 172.16.134.2R6:ip route-static 172.16.128.0 NULL 0R7R7:ip route-static 172.16.132.0 24 172.16.134.1R7:ip route-static 172.16.130.0 24 172.16.134.1R7:ip route-static 172.16.130.0 24 172.16.133.1R7:ip route-static 172.16.129.0 24 172.16.134.1R7:ip route-static 172.16.129.0 24 172.16.133.1R7:ip route-static 172.16.131.0 24 172.16.133.1R7:ip route-static 172.16.128.0 NULL 0公网通给r3 0/0/2和test0/0/0口配置IP地址在接口做认证R2:interface GigabitEthernet 0/0/2R2-interface GigabitEthernet 0/0/2:ospf authentication-mode md5 1 cipher 123456R2:interface GigabitEthernet 0/0/2:quitR3::interface GigabitEthernet 0/0/0R3-interface GigabitEthernet 0/0/0:ospf authentication-mode md5 1 cipher 123456R3-interface GigabitEthernet 0/0/0:quit配置easy ip实现内网pc访问外网R3:acl 2000R3-acl-basic-2000:rule permit source 172.16.0.0R3-acl-basic-2000:quitR3::interface GigabitEthernet 0/0/2R3::interface GigabitEthernet 0/0/2:nat outbound 2000R3:ospf 3R3-ospf-3:default-route-advertise always:让OSPF协议自动给下发缺省R4:ip route-static 0.0.0.0 0 172.16.129.1手动配置静态缺省R4:ip route-static 0.0.0.0 0 172.16.130.1R5:ip route-static 0.0.0.0 0 172.16.133.1R6:ip route-static 0.0.0.0 0 172.16.132.1R7:ip route-static 0.0.0.0 0 172.16.133.1R7:ip route-static 0.0.0.0 0 172.16.134.1配置远程登录协议telnet-servertelnet server enabletelnet-serveraaatelnet-server-aaa:local-user xxx privilege level 15telnet-server-aaa:local-user xxx password cipher 123456telnet-server-aaa:local-user xxx server-type telnettelnet-server-aaa:quittelnet-serveruser-interface vty 0 4telnet-server-user-interface- vty 0 -4:authentication-mode aaatelnet-server-user-interface- vty 0 -4:quitR3::interface GigabitEthernet 0/0/2R3-interface GigabitEthernet 0/0/2:nat serverprotocol tcp globalcurrent-interface 23 inside 172.16.66.254 23配置acl使vlan2与vlan5不能访问企业B的内网R2:acl 2001R2-acl-basic-2001:rule deny source 172.16.0.0 0.0.255.255R2-acl-basic-2001:rule deny source 172.16.1.0 0.0.255.255R2-acl-basic-2001:quitR2:interface GigabitEthernet 0/0/2R2-interface GigabitEthernet 0/0/2:traffic-filter outbound acl 2001配置完成后pc4无法访问企业B内网R1:aclR1-acl-basic-3000:rule deny icmp source 172.16.64.254 0.0.0.0 destination172.16.128.254 0.0.0.0R1-acl-basic-3000:quitR1:interface GigabitEthernet 0/0/0R1-interface GigabitEthernet 0/0/0:traffic-filter outbound acl 3000配置完成后PC1无法访问PC5通过改变路由的优先级将百兆路由作为备用线路R4:ip route-ststic 0.0.0.0 172.16.130.1 preterence 100可通过此命令查询路由表R4:display ip routing-table protocol staticR3:ip route-ststic 172.16.131.0 255.255.255.0 172.16.130.2 preterence 100R3:ip route-ststic 172.16.128.0 255.255.255.0 172.16.130.2 preterence 100R3:ip route-ststic 172.16.132.0 255.255.255.0 172.16.130.2 preterence 100R3:ip route-ststic 172.16.133.0 255.255.255.0 172.16.130.2 preterence 100R3:ip route-ststic 172.16.134.0 255.255.255.0 172.16.130.2 preterence 100通过tracert命令来检测是否走千兆路由