1、交换机SW0可靠性功能开启交换机端口安全(1分);配置MAC地址粘滞(1分);设定每端口最多连接MAC数为1(1分);违例处理为shutdown(1分)。交换机SW1配置建立Vlan 10 、Vlan 20,将F0/2,F0/4加入Vlan 10,将F0/3,F0/5加入Vlan 20。(2分)将F0/1设置为TRUNK链路(2分)服务器及PC机按题目要求完成相应IP地址配置。各设备地址信息如下:源设备名接口Ip地址备注R0F0/0F0/1R1S0/0/0R2NAT地址池F0/单臂路由VLAN10对应接口单臂路由VLAN20对应接口SW0F0/2F0/3SW1隶属VLAN10隶属VLAN20S
2、ERVER1SERVER2PC1PC2网络拓扑:SW0 主要考察 端口安全hostname SW0interface range FastEthernet0/2-3 端口f0/3 一次性完成配置 switchport mode access switchport port-security switchport port-security mac-address sticky SW1 考察VLAN hostname SW1VLAN 10 创建VLANVLAN 20interface FastEthernet0/1 switchport mode trunkinterface FastEther
3、net0/2 switchport access vlan 10interface FastEthernet0/3 switchport access vlan 20interface FastEthernet0/4interface FastEthernet0/5路由器R0参考命令:hostname R0enable secret shaoxing 配置使能口令interface FastEthernet0/0 ip no shutdownrouter ospf 1 配置ospf路由 networkline vty 0 15 password zhejiang login路由器R1参考命令:
4、hostname R1enable secret shaoxingusername R2 password 0 1234 配置chap认证信息,对方的主机名及口令interface Serial0/0/0 encapsulation ppp ppp authentication chap clock rate 64000router ospf 1 配置ospf路由路由器R2参考命令:hostname R2username R1 password 0 1234 chap认证信息interface FastEthernet0/0 !单臂路由,物理接口必须激活!interface FastEther
5、net0/ 单臂路由子接口, nat inside接口 encapsulation dot1Q 10 ip nat insideinterface FastEthernet0/ encapsulation dot1Q 20 ip 定义外网接口 ppp封装 ip nat outsidepassive-interface FastEthernet0/0 passive-interface FastEthernet0/ip nat pool abcnetmask 定义地址池ip nat inside source list 10 pool abc overload 动态NAPTip 缺省路由acce
6、ss-list 允许内部上网地址信息如果想简单定义 内部上网地址 可以使用access-list 10 permit any (4分)发布内部web服务器,开放默认端口号。配置RIPV2路由协议;(2分)。配置RIPV2路由,使全网互联(2分)。三层交换机SW0配置建立Vlan 30 、Vlan 40,配置SVI接口地址(2分)启用F0/1,F0/10三层接口,并配置IP地址(1分)配置OSPF路由,内网互联互通。F0/5,F0/15端口配置为trunk(1分);配置交换机SW0为VLAN30 的主根桥(1分);配置交换机SW0为VLAN40 的主根桥(1分)。二层交换机SW1配置建立Vlan
7、 30 、Vlan40,将F0/1加入Vlan 30,将F0/2 加入Vlan 40。将F0/5,F0/10设置为TRUNK链路(2分)配置交换机SW1为VLAN30 的备份根桥(1分)。二层交换机SW2配置建立Vlan 3 、Vlan 40,将F0/1加入Vlan 30,将F0/2加入 Vlan 40。将F0/10,F0/15设置为TRUNK链路(2分)配置交换机SW2为VLAN40 的备份根桥(1分)。动态NAPT地址池静态NAPT地址F0/10Vlan 30Vlan 40F0/5TRUNKF0/15SERVER0PC0PC3交换机SW0参考命令:VLAN 30Vlan 40 创建vlan
8、信息ip routing 三层交换开启路由功能,三层功能开启spanning-tree vlan 30 root primary !确保该交换为 vlan30 主根桥spanning-tree vlan 40 root primary !确保该交换为 vlan40 主根桥interface FastEthernet0/1 配置三层接口 no switchportinterface range FastEthernet0/5, fa 0/15 !需要定义三层交换trunk接口,此次注意! switchport mode access 需要先设定为 access 二层接口,因为接口默认是auto不
9、能直接定义trunkswitchport mode trunkinterface FastEthernet0/10interface Vlan30 vlan30 SVI接口地址interface Vlan40network passive-interface FastEthernet0/10 注意被动接口 passive-interface Vlan30 passive-interface Vlan40交换机SW1参考命令:vlan30vlan40spanning-tree vlan 30 root secondary !确保其为vlan30 备份根桥! switchport access v
10、lan 30 switchport access vlan 40interface range FastEthernet0/5, fa 0/10交换机SW2参考命令:hostname SW2spanning-tree vlan 40 root secondary !确保其为vlan40 备份根桥!interface range FastEthernet0/10, fa 0/15username R1 password 0 1234 redistribute connected subnets default-information originateip nat pool abcnetmask
11、ip nat inside source list 10 pool abc overloadip nat inside source static tcpipaccess-list 10 permit anyusername R0 password 0 1234router rip version 2 no auto-summary passive-interface FastEthernet0/1配置OSPF路由协议,配置RIPV2路由协议;(4分)并实现相互注入使全网互联,注意直连路由的注入(4分)。F0/2-5端口开启交换机端口安全(1分); switchportinterface ra
12、nge FastEthernet0/2-5switchport mode access switchport port-securityswitchport port-security maximum 1switchport port-security violation shutdownswitchport port-security mac-address sticky interface range FastEthernet0/2, fa 0/4switchport access vlan 10interface range FastEthernet0/3, fa 0/5 redistribute rip metric 1500 subnets no auto-summary redistribute ospf 1 metric 5 redistribute connected passive-interface FastEthernet0/1