1、交换综合实验实验拓扑:实验要求:1. core-1与core-2的相互接口做成ethernetchannel 1,并将Ethernetchannel 6设置成trunk模式2. ED-SW与Core-1,Core-2互连的接口也设置成trunk模式3. 把所有交换机的vtp模式设置成transparent. 在所有的交换机上添加vlan64、65、66、67、954. 设置Core-1为vlan1、64、65的STP主根,为vlan66、67、95的备份根5. 设置Core-2为vlan66、67、95的STP主根,为vlan1、64、65的备份根6. core-1的f0/2 - 5 port
2、划分到vlan 64core-1的f0/6 - 10 port划分到vlan 65core-1的f0/11 - 15 port划分到vlan 66core-1的f0/16 - 18 port划分到vlan 67把这些port设置成生成树快速转发模式,启用bpduguard.启用vlan64、65端口的port-security功能,限制每个端口只能学习5个mac地址.7. core-2的f0/2 - 5 port划分到vlan 64core-2的f0/6 - 10 port划分到vlan 65core-2的f0/11 - 15 port划分到vlan 66core-2的f0/16 18 por
3、t划分到vlan 67把这些port设置成生成树快速转发模式,禁止这些port收发BPDU信息设置这些port只接收1M/s的broadcast数据包,2M/s的multicast数据包8. ed-sw的f0/1 - 5 port划分到vlan 64ed-sw的f0/6 - 10 port划分到vlan 65ed-sw的f0/11 - 15 port划分到vlan 66ed-sw的f0/16 - 18 port划分到vlan 679. ED-SW上启用Uplinkfast10. core-1与core-2的每个vlan接口都做HSRP core-1设置成vlan64、65主用设备 core-2
4、设置成vlan66、67、95主用设备虚拟的IP地址为:10.9.xx.254/24,xx为vlan号11. Core-1 F1/0: 10.9.96.2/30Core-1 Lo0: 10.9.96.201/32Core-2 F1/0: 10.9.96.6/30Core-2 Lo0: 10.9.96.202/32R1: F0/0: 10.9.96.1/30R1: F0/1: 10.9.96.5/30R1: Lo0: 10.9.96.203/32R1、R2、core-1、core-2启用eigrp路由协议,使所有网络互通12. R1上启用DHCP Server功能,为以下网段提供DHCP服务:1
5、0.9.64.0/2410.9.65.0/2410.9.66.0/2410.9.67.0/24保留10.9.xx.1 20,10.9.xx.201 254,xx为vlan号DNS Server: 10.9.100.203Default-gateway: 10.9.xxx.254Domain-name: 并在core-1,core-2的各个vlan端口上应用DHCP广播重定向功能,重定向到10.9.100.201这台DHCP Server,使DHCP Server能够正常为PC提供地址服务13. 启用ED-SW vlan 64 - 65的ip dhcp snooping功能,并只允许从ED-SW
6、的F0/23 24回来的dhcp reply数据包14. QOS设定a) 优先传输512kb/s voice流量,并启用RTP头部压缩b) 保障传输100kb/s 语音信令流量c) 限制传输200kb/s http流量,此类流量内部使用WFQ队列机制d) 限制传输100kb/s ftp流量e) 剩余带宽给其他流量使用,并用WRED来管理拥塞。此流量类型所有出去的IP包优先级设定为0实验答案:R1#sh running-config Building configuration.Current configuration : 2087 bytes!version 12.3service time
7、stamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname R1!boot-start-markerboot-end-marker!no network-clock-participate slot 1 no network-clock-participate wic 0 no aaa new-modelip subnet-zeroip cef!ip dhcp excluded-address 10.9.64.1 10.9.64.20ip dhcp e
8、xcluded-address 10.9.64.201 10.9.64.254ip dhcp excluded-address 10.9.65.1 10.9.65.20ip dhcp excluded-address 10.9.65.201 10.9.65.254ip dhcp excluded-address 10.9.66.1 10.9.66.20ip dhcp excluded-address 10.9.66.201 10.9.66.254ip dhcp excluded-address 10.9.67.1 10.9.67.20ip dhcp excluded-address 10.9.
9、67.201 10.9.67.254!ip dhcp pool vlan64 network 10.9.64.0 255.255.255.0 default-router 10.9.64.254 domain-name !ip dhcp pool vlan65 network 10.9.65.0 255.255.255.0 default-router 10.9.65.254 domain-name !ip dhcp pool vlan66 network 10.9.66.0 255.255.255.0 default-router 10.9.66.254 domain-name !ip dh
10、cp pool vlan67 network 10.9.67.0 255.255.255.0 default-router 10.9.67.254 domain-name !class-map match-all http match protocol httpclass-map match-any signal match ip precedence 3 match dscp af31 class-map match-all ftp match protocol ftpclass-map match-any voice match ip precedence 5 match dscp ef
11、!policy-map QOS_set class voice priority 512 compress header ip rtp class signal bandwidth 100 class ftp police 100000 conform-action transmit exceed-action drop class http bandwidth 200 class class-default set precedence 0!interface Loopback0 ip address 10.9.96.203 255.255.255.255!interface FastEth
12、ernet0/0 ip address 10.9.96.1 255.255.255.252 duplex auto speed auto!interface FastEthernet0/1 ip address 10.9.96.5 255.255.255.252 duplex auto speed auto service-policy output QOS_set!router eigrp 100 network 10.9.96.0 0.0.0.255 no auto-summary!no ip http serverip classless!line con 0line aux 0line
13、 vty 0 4!endcore1#sh runBuilding configuration.Current configuration : 5797 bytes!version 12.2no service padservice timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname core1!no aaa new-model!ip subnet-zeroip routing!vtp domain ciponvtp mode trans
14、parent! !spanning-tree mode pvstspanning-tree etherchannel guard misconfigspanning-tree extend system-idspanning-tree vlan 1,64-65 priority 24576spanning-tree vlan 66-67,95 priority 28672!vlan internal allocation policy ascending!vlan 2-10,20,30,55,64-67,88,95 !interface Loopback0 ip address 10.9.96
15、.201 255.255.255.255!interface Port-channel1 switchport trunk encapsulation dot1q switchport mode trunk switchport nonegotiate!interface Port-channel2 switchport trunk encapsulation dot1q switchport mode trunk switchport nonegotiate!interface FastEthernet0/1 no switchport ip address 10.9.96.2 255.25
16、5.255.252!interface FastEthernet0/2 switchport access vlan 64 switchport mode access switchport port-security maximum 5 switchport port-security spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/3 switchport access vlan 64 switchport mode access switchport port-security m
17、aximum 5 switchport port-security spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/4 switchport access vlan 64 switchport mode access switchport port-security maximum 5 switchport port-security spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0
18、/5 switchport access vlan 64 switchport mode access switchport port-security maximum 5 switchport port-security spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/6 switchport access vlan 65 switchport mode access switchport port-security maximum 5 switchport port-security
19、 spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/7 switchport access vlan 65 switchport mode access switchport port-security maximum 5 switchport port-security spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/8 switchport access vlan 65 swit
20、chport mode access switchport port-security maximum 5 switchport port-security spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/9 switchport access vlan 65 switchport mode access switchport port-security maximum 5 switchport port-security spanning-tree portfast spanning-
21、tree bpduguard enable!interface FastEthernet0/10 switchport access vlan 65 switchport mode access switchport port-security maximum 5 switchport port-security spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/11 switchport access vlan 66 switchport mode access spanning-tre
22、e portfast spanning-tree bpduguard enable!interface FastEthernet0/12 switchport access vlan 66 switchport mode access spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/13 switchport access vlan 66 switchport mode access spanning-tree portfast spanning-tree bpduguard enabl
23、e!interface FastEthernet0/14 switchport access vlan 66 switchport mode access spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/15 switchport access vlan 66 switchport mode access spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/16 switchport
24、access vlan 67 switchport mode access spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/17 switchport access vlan 67 switchport mode access spanning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/18 switchport access vlan 67 switchport mode access sp
25、anning-tree portfast spanning-tree bpduguard enable!interface FastEthernet0/19 switchport mode dynamic desirable!interface FastEthernet0/20 switchport mode dynamic desirable!interface FastEthernet0/21 switchport trunk encapsulation dot1q switchport mode trunk switchport nonegotiate channel-group 2 m
26、ode active!interface FastEthernet0/22 switchport trunk encapsulation dot1q switchport mode trunk switchport nonegotiate channel-group 2 mode active!interface FastEthernet0/23 switchport trunk encapsulation dot1q switchport mode trunk switchport nonegotiate channel-group 1 mode active!interface FastE
27、thernet0/24 switchport trunk encapsulation dot1q switchport mode trunk switchport nonegotiate channel-group 1 mode active! interface GigabitEthernet0/1 switchport mode dynamic desirable!interface GigabitEthernet0/2 switchport mode dynamic desirable!interface Vlan1 no ip address shutdown!interface Vl
28、an64 ip address 10.9.64.1 255.255.255.0 ip helper-address 10.9.96.1 standby 64 ip 10.9.64.254 standby 64 priority 105 standby 64 preempt standby 64 track FastEthernet0/1!interface Vlan65 ip address 10.9.65.1 255.255.255.0 ip helper-address 10.9.96.1 standby 65 ip 10.9.65.254 standby 65 priority 105
29、standby 65 preempt standby 65 track FastEthernet0/1!interface Vlan66 ip address 10.9.66.1 255.255.255.0 ip helper-address 10.9.96.1 standby 66 ip 10.9.66.254 standby 66 preempt standby 66 track FastEthernet0/1!interface Vlan67 ip address 10.9.67.1 255.255.255.0 ip helper-address 10.9.96.1 standby 67
30、 ip 10.9.67.254 standby 67 preempt standby 67 track FastEthernet0/1!interface Vlan95 ip address 10.9.95.1 255.255.255.0 standby 95 ip 10.9.95.254 standby 95 preempt standby 95 track FastEthernet0/1! router eigrp 100 no auto-summary network 10.9.64.0 0.0.0.255 network 10.9.65.0 0.0.0.255 network 10.9.66.0 0.0.0.255 network 10.9.67.0 0.0.0.255 network 10.9.95.0 0.0